1. Scope and our data roles
This Policy applies to ovhok.com, inquiries, demonstrations, courses, career applications, customer onboarding, contracts, billing, support, marketing, hosted products and other interactions with Ovhok.
For our own website, sales, accounts, recruitment and business administration, Ovhok decides why and how information is handled. For data a customer enters into a hosted product, the customer normally determines the purpose and Ovhok processes the data to provide the contracted Service. The applicable customer agreement may define these roles more specifically.
This Policy does not control third-party websites, payment services, social platforms or integrations that publish their own privacy terms.
2. Information we may collect
Please do not send passwords, private keys, full payment-card information, government secrets or sensitive personal information unless the Service expressly requires it and an authorized secure process is available.
3. Sources of information
We obtain information directly from you; from your employer, school, cooperative, customer or authorized administrator; from use of our Services; from connected services you authorize; from public business sources; and from lawful service providers such as payment, email, SMS, hosting and analytics providers.
4. Why and on what grounds we use information
- Provide and administer Services: create accounts, deliver projects, host data, process transactions, provide support, training, reports and notifications.
- Contract and pre-contract steps: respond to inquiries, prepare proposals, verify requirements, manage subscriptions, invoices, payments and renewals.
- Security and integrity: authenticate users, prevent abuse and fraud, maintain audit evidence, investigate incidents and protect customers, Ovhok and the public.
- Legal obligations: comply with tax, accounting, corporate, employment, court, regulatory and lawful government requirements.
- Service improvement: diagnose errors, measure performance, understand feature use and improve accessibility, reliability and usability using data minimized where practical.
- Communications and marketing: send requested information, operational notices and lawful promotions. Consent is requested where required, and promotional messages include an opt-out method.
Depending on the activity and applicable law, handling may be based on consent, steps requested before a contract, performance of a contract, a legal duty, protection of security or a legitimate and proportionate business need that does not override mandatory privacy rights.
5. Cookies and similar technologies
Essential cookies maintain security, sessions, anti-forgery protection, preferences and core site functions. Disabling them may prevent the Service from working.
Optional analytics or marketing technologies are used only where configured and permitted. The Cookie Policy identifies categories, purposes and available controls. Browser controls may also remove or block cookies.
7. Cross-border processing
Some cloud, email, messaging or technical providers may process information outside Nepal. Where this occurs, Ovhok uses reasonable contractual, access and security safeguards and considers the nature of the information, provider and destination. A customer may request information about material providers used for its contracted Service.
8. Retention and deletion
We keep information only as long as reasonably required for the stated purpose, contractual service, security, dispute, backup, audit, tax, accounting or legal obligation. Typical operational periods are below; a signed agreement or law may require a different period.
| Record | Typical rule | Reason |
|---|---|---|
| Inquiry and lead | Up to 24 months after last meaningful contact | Follow-up, history and suppression of unwanted contact |
| Customer contract and billing | Contract term plus the period required by tax, accounting and limitation rules | Legal, tax, audit and dispute evidence |
| Career application | Normally up to 12 months after the recruitment decision unless consent or law supports longer | Recruitment and future opportunities |
| Security and audit logs | Risk-based period, commonly 90 days to 24 months | Detection, investigation and accountability |
| Hosted customer data | Contract term plus the agreed export/deletion window and protected backup cycle | Service delivery and recovery |
Deletion from active systems may not immediately remove protected backup copies. Backup data is isolated, expires on schedule and is restored only for recovery, after which applicable deletion rules resume.
9. Security and incident handling
Our safeguards include role and resource authorization, least-privilege access, secure password hashing, encryption in transit, protected secrets, audit logging, backups, update and vulnerability management, rate limits and incident procedures appropriate to the Service.
No method of storage or transmission is completely secure. If we confirm an incident affecting personal information, we will contain and investigate it, preserve evidence, reduce harm, notify affected customers or authorities where required and take corrective action.
Customers must configure permissions correctly, remove former users, protect devices and credentials, review activity and promptly report suspected misuse.
10. Your rights and choices
Subject to identity verification, applicable law and the customer relationship, you may ask whether we hold your personal information and request access, correction, completion, restriction, deletion, withdrawal of consent or objection to promotional communication.
Where Ovhok processes data only for a customer organization, requests about that hosted data should normally be directed to that organization. We will support the customer as required by the agreement and law.
Some requests may be limited where information must be retained for tax, accounting, security, legal claims, rights of others or another lawful reason. We will explain a material refusal where permitted.
Promotional email may be stopped through the unsubscribe method or by contacting us. SMS recipients may reply with the opt-out instruction stated in the message or contact us. Operational, billing and security messages may still be required while a Service is active.
11. Children and school data
Our public website is not designed to collect personal information directly from children without appropriate adult or institutional involvement. School products may process student information under the direction of the school and authorized guardians. Schools are responsible for notices, authority, permissions, accuracy and access controls required by applicable law and policy.
12. Automated processing and AI-assisted features
We may use automation to route inquiries, detect abuse, create reports or assist authorized users. We do not make a solely automated decision with significant legal effect about a public website visitor unless clearly disclosed and lawfully authorized. AI-assisted output must be reviewed by an authorized person before important use.
13. Changes to this Policy
We may update this Policy to reflect law, technology, providers or Services. The current version will show its effective and review dates. Material changes may also be communicated through the Service or registered contact details where appropriate.
14. Contact, requests and complaints
Ovhok Software Solutions Pvt. Ltd.
Arjundhara-8, Jhapa, Nepal
Email: [email protected]
Phone: +977 9862911301
Describe the information or account involved and the request. Do not email passwords or highly sensitive documents. We may request proportionate proof of identity and authority before acting.
15. Nepal legal references
This Policy was prepared with reference to official Nepal legislation, including the following. The law and any amendment prevail over this explanation: