Who we are
NepEdu is management software for learning institutions in Nepal: schools, colleges, coaching centres, language and training institutes, and academies. It is operated by NepEdu Pvt. Ltd., of Kathmandu, Nepal. In this policy, “we”, “us” and “NepEdu” mean that company.
This policy covers two different things, and the difference matters, because it decides who you should contact about your data.
- The nepedu.com website. The marketing site you are reading now. Here we decide what data is collected and why, so we are the controller of it.
- The NepEdu platform. The application your institution signs in to. Everything inside it, from learners and guardians to staff, attendance and fees, belongs to the institution. The institution decides what goes in and who may see it; we only hold and process it on the institution’s instructions. In legal terms the institution is the controller and we are the processor.
If you are a learner, parent or guardian
Your institution is the one that decides what is recorded about you and for how long. Ask it first, because it can correct or remove records directly. If it needs us, we help it. We never sell your data, and we never use it to advertise to you.
What we collect on this website
When you use the contact form
We store what you type, meaning your name, email address, your institution’s name and your message, so that we can reply. We also record the IP address and browser user-agent the submission came from. We use those two only to filter spam and investigate abuse, not to profile you.
When you simply browse
This website uses Google Analytics to count visits and see which pages are read, and Microsoft Clarity to see where people click, scroll and get stuck. Clarity replays a visit to these public pages as movement on the page; it is not a recording of your screen, it does not follow you elsewhere, and neither tool runs inside the NepEdu application, which is where the learner records are. Between them they tell us things like “180 people read the pricing section this week”, not who you are. Neither one loads until you agree to it, and not answering counts as no. There is no advertising, no retargeting and no data brokering on this site. The Cookie Policy lists exactly what is set, and how to opt out.
Enquiries are kept while we are in touch with you and for a reasonable period afterwards as a record of the conversation. Ask us and we will delete yours.
What the platform holds for your institution
An institution uses NepEdu to run its day-to-day operations, so the platform holds the records that job requires. Exactly which fields are filled in is up to each institution. This is the full range the system can store:
| Category | What it can include |
|---|---|
| Identity & contact | Name, username, email address, phone number, and the institution and role a person belongs to. |
| Learner records | Admission or registration number and date, class, batch or section, roll number, religion, previous institution, guardian relationships, and documents the institution uploads. |
| Guardian records | Where a learner has a guardian on file: their relationship to the learner, occupation and workplace, and contact details. |
| Staff & HR records | Employee ID, designation, department, qualification, employment type, joining date, working hours, and leave. |
| Day-to-day institutional life | Attendance, homework, notices, events, the timetable, and fee invoices, payments and concessions. |
| Technical & audit | Sign-in activity, the IP address a sign-in came from (used to lock out brute-force attempts), and an audit trail of who created or changed a record. |
This includes children’s data, and we treat it accordingly
Much of what NepEdu holds is about minors. That is the reason the platform is built the way it is: every record is walled off by institution and fails closed rather than open, teachers only see the learners they actually teach, and guardians only see their own children. We do not profile learners, we do not run analytics or advertising inside the application, and we do not train any product on institution data. The Security page explains how this is enforced in the code.
Where the learners are adults, as they often are at a college, coaching centre or training institute, there may be no guardian on the record at all. Nothing above depends on one existing: the same protections apply to the learner directly, and the rights in this policy are theirs to exercise.
How we use data, and why we are allowed to
- To provide the service. We run the platform your institution pays for, and send the transactional messages it generates: an account invitation, a password reset, a notice sent by the institution.
- To keep it secure. We detect and block brute-force sign-in attempts, investigate abuse, and keep an audit trail so an institution can see who changed what.
- To support and improve it. We diagnose faults an institution reports, and learn which parts of this website people read. Support access to an institution’s live data happens only where it is genuinely needed to fix a reported problem.
- To reply to you. We answer what you send us, and we send service announcements such as planned maintenance or a change to these terms.
We process this data to perform our contract with the institution, to meet our legal obligations, and for the legitimate interest of running a secure service, consistent with Nepal’s Individual Privacy Act, 2075 (2018) and the rules made under it. Where consent is the basis, whether from an adult learner or from the parent of a child, it is the institution that collects and holds it.
What we never do
We do not sell personal data. We do not share it with advertisers or data brokers. We do not use one institution’s data to serve another. We do not use learner, guardian or staff data to train AI models.
Where the data is kept
The platform, its database and its backups run on cloud infrastructure hosted outside Nepal, and some of the providers listed above are also based outside Nepal. That means your institution’s data is transferred across borders in the course of being stored and processed.
Wherever it sits, the protections described in this policy and on the Security page follow it: encrypted in transit, access-controlled, and covered by contractual terms with our providers.
How long we keep it
- Institution data. Kept for as long as the institution’s account is active. Institutions keep learner records for years by design; that is their call, not ours.
- After an institution leaves. It has 30 days to export its data. After that window we delete it from the live system, and it is removed from our backups shortly afterwards.
- Website enquiries. Kept as a record of our correspondence, and deleted on request.
Your rights over your data
You can ask to see the personal data held about you, have it corrected if it is wrong, have it deleted where there is no reason to keep it, and object to how it is being used.
Where to send that request
If you are a learner, guardian or member of staff: go to your institution. It controls the record and can act on it immediately. If it asks us for help, we help it. But we will not change or hand over an institution’s records on a third party’s say-so, because doing that on request is exactly how data gets leaked.
If you contacted us through this website: email us and we will deal with it directly.
How we protect it
Data safety is the first thing NepEdu is built for, not a paragraph added at the end. Traffic is encrypted in transit, every record is scoped to one institution and fails closed, permissions are enforced on the server rather than hidden in the interface, sessions are revoked when a password changes, and your data is backed up automatically.
The Security page covers the principles. We keep the operational detail off the public web on purpose, but we share it with institutions who ask. If we ever suffer a breach that affects an institution’s data, we will notify that institution without undue delay.
Changes to this policy
If we change this policy we will update the date at the top of the page. If the change is significant, such as a new category of data or a new provider handling personal data, we will tell affected institutions directly rather than quietly editing the page.
Talk to us about privacy
Questions about this policy, or a request about your own data? Write to us and a person will answer. We would rather have the conversation than have you guess.
