Who we are
NepEdu is school management software built for Nepal. It is operated by NepEdu Pvt. Ltd., of Kathmandu, Nepal. In this policy, “we”, “us” and “NepEdu” mean that company.
This policy covers two different things, and the difference matters, because it decides who you should contact about your data.
- The nepedu.com website. The marketing site you are reading now. Here we decide what data is collected and why, so we are the controller of it.
- The NepEdu platform. The application your school signs in to. Everything inside it, from students and guardians to staff, attendance and fees, belongs to the school. The school decides what goes in and who may see it; we only hold and process it on the school’s instructions. In legal terms the school is the controller and we are the processor.
If you are a parent, guardian or student
Your school is the one that decides what is recorded about you and for how long. Ask your school first, because they can correct or remove records directly. If they need us, we help them. We never sell your data, and we never use it to advertise to you.
What we collect on this website
When you use the contact form
We store what you type, meaning your name, email address, your school’s name and your message, so that we can reply. We also record the IP address and browser user-agent the submission came from. We use those two only to filter spam and investigate abuse, not to profile you.
When you simply browse
This website uses Google Analytics to count visits and see which pages are read. It tells us things like “180 people read the pricing section this week”, not who you are. There is no advertising, no retargeting and no data brokering on this site. The Cookie Policy lists exactly what is set, and how to opt out.
Enquiries are kept while we are in touch with you and for a reasonable period afterwards as a record of the conversation. Ask us and we will delete yours.
What the platform holds for your school
A school uses NepEdu to run its day-to-day operations, so the platform holds the records that job requires. Exactly which fields are filled in is up to each school. This is the full range the system can store:
| Category | What it can include |
|---|---|
| Identity & contact | Name, username, email address, phone number, and the school and role a person belongs to. |
| Student records | Admission number and date, class and section, roll number, religion, previous school, guardian relationships, and documents the school uploads. |
| Guardian records | Relationship to the student, occupation and workplace, and contact details. |
| Staff & HR records | Employee ID, designation, department, qualification, employment type, joining date, working hours, and leave. |
| Day-to-day school life | Attendance, homework, notices, events, the class timetable, and fee invoices, payments and concessions. |
| Technical & audit | Sign-in activity, the IP address a sign-in came from (used to lock out brute-force attempts), and an audit trail of who created or changed a record. |
This includes children’s data, and we treat it accordingly
Most of what NepEdu holds is about minors. That is the reason the platform is built the way it is: every record is walled off by school and fails closed rather than open, teachers only see the students they actually teach, and guardians only see their own children. We do not profile students, we do not run analytics or advertising inside the application, and we do not train any product on school data. The Security page explains how this is enforced in the code.
How we use data, and why we are allowed to
- To provide the service. We run the platform your school pays for, and send the transactional messages it generates: an account invitation, a password reset, a notice sent by the school.
- To keep it secure. We detect and block brute-force sign-in attempts, investigate abuse, and keep an audit trail so a school can see who changed what.
- To support and improve it. We diagnose faults a school reports, and learn which parts of this website people read. Support access to a school’s live data happens only where it is genuinely needed to fix a reported problem.
- To reply to you. We answer what you send us, and we send service announcements such as planned maintenance or a change to these terms.
We process this data to perform our contract with the school, to meet our legal obligations, and for the legitimate interest of running a secure service, consistent with Nepal’s Individual Privacy Act, 2075 (2018) and the rules made under it. Where the school has collected the underlying consent from parents and guardians, it is the school that holds it.
What we never do
We do not sell personal data. We do not share it with advertisers or data brokers. We do not use one school’s data to serve another. We do not use student, guardian or staff data to train AI models.
Where the data is kept
The platform, its database and its backups run on cloud infrastructure hosted outside Nepal, and some of the providers listed above are also based outside Nepal. That means your school’s data is transferred across borders in the course of being stored and processed.
Wherever it sits, the protections described in this policy and on the Security page follow it: encrypted in transit, access-controlled, and covered by contractual terms with our providers.
How long we keep it
- School data. Kept for as long as the school’s account is active. Schools keep student records for years by design; that is their call, not ours.
- After a school leaves. The school has 30 days to export its data. After that window we delete it from the live system, and it is removed from our backups shortly afterwards.
- Website enquiries. Kept as a record of our correspondence, and deleted on request.
Your rights over your data
You can ask to see the personal data held about you, have it corrected if it is wrong, have it deleted where there is no reason to keep it, and object to how it is being used.
Where to send that request
If you are a student, guardian or member of staff: go to your school. They control the record and can act on it immediately. If they ask us for help, we help them. But we will not change or hand over a school’s records on a third party’s say-so, because doing that on request is exactly how data gets leaked.
If you contacted us through this website: email us and we will deal with it directly.
How we protect it
Data safety is the first thing NepEdu is built for, not a paragraph added at the end. Traffic is encrypted in transit, every record is scoped to one school and fails closed, permissions are enforced on the server rather than hidden in the interface, sessions are revoked when a password changes, and school data is backed up automatically.
The Security page covers the principles. We keep the operational detail off the public web on purpose, but we share it with schools who ask. If we ever suffer a breach that affects a school’s data, we will notify that school without undue delay.
Changes to this policy
If we change this policy we will update the date at the top of the page. If the change is significant, such as a new category of data or a new provider handling personal data, we will tell affected schools directly rather than quietly editing the page.
Talk to us about privacy
Questions about this policy, or a request about your own data? Write to us and a person will answer. We would rather have the conversation than have you guess.
