Who is responsible for what
This addendum applies whenever NepEdu Pvt. Ltd. (“NepEdu”) processes personal data on behalf of a school using the platform. It forms part of the Terms of Service, and where the two conflict on the handling of personal data, this addendum wins.
The split, in one line
The school is the controller. It decides what personal data is collected, why, and who may see it. NepEdu is the processor. We hold and process that data only to run the service, on the school’s instructions.
Practically, that means the school answers to its students, guardians and staff for what is in the system, and we answer to the school for keeping it safe and doing only what we are asked.
The processing, in detail
| Item | Detail |
|---|---|
| Subject matter | Providing the NepEdu school management platform to the school. |
| Duration | For as long as the school's subscription is active, plus the 30-day export window that follows it. |
| Nature and purpose | Hosting, storing, transmitting, backing up and displaying the school's records so that its staff, students and guardians can use them; sending the transactional messages the school triggers; and providing support when the school asks for it. |
| Data subjects | Students (who are, for the most part, children), their parents and guardians, and the school's teaching and administrative staff. |
| Categories of data | Identity and contact details; student and admission records; guardian relationships; staff and HR records; attendance, homework, notices, timetable and fee records; and technical sign-in and audit data. |
What we commit to
- We act on your instructions. We process the school’s personal data only to provide and support the service, and to comply with the law. We will not process it for our own purposes.
- We will not sell it, mine it, or train on it. No advertising, no data broking, no using one school’s data to serve another, and no using student, guardian or staff data to train AI models.
- We keep it confidential. Access is restricted to the people who need it to run the platform, and they are bound to keep it confidential.
- We secure it. We maintain the technical and organisational measures set out on the Security page, which is incorporated into this addendum by reference.
- We help you meet your obligations. If a student, guardian or staff member exercises their rights, or you need to assess a risk or handle an incident, we will give you reasonable assistance and the information you need.
We will not act on a third party’s say-so
If someone who is not the school asks us to hand over, change or delete a school’s records, we will refuse and refer them to the school. Acting on a plausible-sounding request from outside the school is precisely how data gets leaked.
Sub-processors
We use a small number of providers to run the platform. Each is bound by terms no weaker than these, and each is used only for the purpose listed:
| Provider | Purpose | Data it can access | Location |
|---|---|---|---|
| Cloud infrastructure provider | Hosts the NepEdu application, database and backups. | All school data at rest and in transit. | Outside Nepal |
| Zoho Mail (SMTP) | Delivers transactional email: invitations, password resets and notices. | Recipient name and email address, message content. | Outside Nepal |
| Google Analytics | Aggregate traffic measurement on the nepedu.com marketing site only. It does not run inside the NepEdu application. | Marketing-site visitors: device, approximate location, pages viewed. | Outside Nepal |
We will update this page before engaging a new sub-processor that handles school data. If your school objects to a new one on reasonable grounds, tell us. If we cannot resolve it, you may terminate without penalty rather than be stuck with it.
Where processing happens
The platform, its database and its backups are hosted on cloud infrastructure outside Nepal, and some of our sub-processors are based outside Nepal. Personal data is therefore transferred across borders in the ordinary course of running the service. Wherever it is processed, the commitments in this addendum apply to it.
If something goes wrong
If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of your data, we will notify you without undue delay, and in any event within 72 hours of becoming aware of it.
What the notice will contain
- What happened, and what data and roughly how many people are affected.
- The likely consequences, said plainly rather than minimised.
- What we have done to contain it, and what we are doing to prevent a recurrence.
- What you may need to do, including anyone you may need to tell.
We will not wait until we have the complete picture to tell you something is wrong. You will get a partial notice quickly and the rest as we learn it.
Return and deletion
You can export your data at any time while your subscription is active. When it ends, the data stays available to you for 30 days so you can take a copy. After that we delete it from the live system, and it is removed from our backups shortly afterwards. We will confirm the deletion in writing if you ask.
If you want it deleted sooner than that, ask and we will do it, except where a law requires us to keep something. In that case we will tell you what, and why.
Audits and evidence
We will give your school the information it reasonably needs to satisfy itself that we are meeting this addendum, including answering security questionnaires and explaining how a particular control works.
Please ask before testing anything against the live platform. We do not want a genuine assessment mistaken for an attack, and other schools’ data is on the same system, which is exactly the kind of thing you are auditing us for.
Need this signed?
Many schools want a countersigned copy for their records, or have their own processing terms they would like us to review. Both are fine. Write to us and we will sort it out.
