1. Scope, relationship and data roles
This Policy applies to ovhok.com, inquiries, demonstrations, marketing, customer onboarding, contracts, billing, support, courses, recruitment, events, hosted products, APIs, integrations and other interactions with Ovhok.
For Ovhok's own website, sales, security, recruitment, accounts, operations and administration, Ovhok decides the business purposes for processing. For customer-hosted data, the customer normally determines why information is entered and who may access it, while Ovhok processes it to operate, secure, support and maintain the Service. A signed data-processing or service agreement may define these roles more specifically.
This Policy does not govern independent third-party websites, payment providers, government portals, social networks or integrations that publish their own terms and privacy policies.
2. Information we may collect or receive
Please do not provide passwords, private keys, complete payment-card credentials, government secrets or sensitive personal information unless the relevant Service expressly requires that information and a secure authorized process is available.
3. Sources of information
Information may come directly from you; from your employer, school, cooperative, customer, parent/guardian or authorized administrator; from your use of our Services; from connected systems you or a customer authorize; from service providers; from payment, email, SMS, hosting, analytics and security systems; and from public or lawfully available business sources.
4. Purposes and lawful use of information
Ovhok may process information where reasonably necessary to perform a contract or requested pre-contract step, comply with legal obligations, protect systems and rights, operate our business, or where consent or another lawful basis is required and available under applicable law.
- Service delivery: create accounts, configure products, host customer data, process authorized transactions, provide support, training, maintenance, reports, backups and notifications.
- Sales and contracts: respond to inquiries, prepare proposals, manage demonstrations, onboarding, subscriptions, renewals, billing, collections and customer relationships.
- Security and abuse prevention: authenticate users, enforce permissions, detect fraud, investigate incidents, block malicious activity, preserve audit evidence and protect Ovhok, customers and third parties.
- Operations and improvement: diagnose errors, measure performance, capacity and reliability, understand feature usage, improve usability, develop products, train personnel and manage quality.
- Legal and compliance: satisfy tax, accounting, corporate, employment, court, regulatory, audit, record-keeping and lawful government requirements and establish, exercise or defend legal claims.
- Communications and marketing: send service, security, billing, product and relationship messages and, where permitted, relevant marketing communications. Promotional choices can be changed as described below.
Ovhok may create aggregated or de-identified statistics and operational insights for analytics, security, capacity planning, benchmarking and product improvement where the information is not used to identify a person contrary to applicable law.
5. Cookies, device information and online analytics
Our websites and Services may use essential cookies, session identifiers, anti-forgery tokens, preference storage, server logs and, when enabled under the applicable consent or configuration, analytics or marketing technologies. These help operate secure sessions, remember settings, measure performance, diagnose errors, prevent abuse and understand public-site usage. More detail is provided in the Cookie Policy.
7. Service providers, subprocessors and third-party integrations
Ovhok may use qualified service providers and subprocessors for infrastructure, support, communications, security, analytics and other operational functions. Providers are selected and managed according to the nature of the Service and information involved. Customer-authorized third-party integrations may receive data according to the permissions and configuration selected by the customer. Once data is sent to an independent third party, that party's own terms and practices may apply.
8. Cross-border processing
Cloud, communications, security or technical providers may process information outside Nepal. Where cross-border processing occurs, Ovhok considers the nature of the information, the provider, contractual protections, access controls and available security safeguards and acts subject to applicable legal requirements. A customer may request reasonable information about material providers used for its contracted Service.
9. Retention, backups, legal holds and deletion
Ovhok retains information for as long as reasonably necessary for the purpose for which it was collected and for service delivery, security, fraud prevention, audit, backup, accounting, tax, corporate records, dispute resolution, legal claims, enforcement and other lawful obligations. Retention may be extended where a dispute, investigation, legal hold, unpaid account, security incident or legal requirement applies.
| Record | Typical operational approach | Primary reason |
|---|---|---|
| Inquiry and lead | Usually up to 24 months after last meaningful contact, longer where a relationship, suppression record or legal reason continues | Sales history, follow-up and contact preference |
| Contracts, billing and accounting | Contract term plus the period required by tax, accounting, audit, dispute and applicable limitation rules | Legal, financial and evidentiary obligations |
| Career application | Normally up to 12 months after the recruitment decision unless a lawful reason supports longer retention | Recruitment, audit and future opportunities |
| Security and audit logs | Risk-based period, commonly 90 days to 24 months, longer for an incident or legal hold | Security, investigation and accountability |
| Hosted customer data | Contract term plus the applicable export/deletion window and protected backup cycle | Service delivery, recovery and contractual obligations |
Deletion from active systems may not immediately remove protected backups, immutable security records or records that must be retained. Backups expire or are overwritten according to operational schedules and are generally restored only for disaster recovery or continuity purposes.
10. Security and incident handling
Depending on the Service, safeguards may include role- and resource-based authorization, least-privilege access, secure password hashing, TLS encryption in transit, protected secrets, environment separation, logging, rate limits, backups, vulnerability management and incident procedures.
No internet, software or storage system can be guaranteed absolutely secure. Customer is responsible for correctly configuring its users and permissions, removing former users, protecting endpoints and credentials, maintaining lawful access controls and promptly reporting suspected misuse.
If Ovhok confirms an incident affecting information under its control, Ovhok will investigate and contain it, preserve relevant evidence, take proportionate corrective action and provide notices required by applicable law or contract.
11. Rights, requests and choices
Subject to identity and authority verification, applicable law and the relevant customer relationship, a person may request information about personal data Ovhok controls and may request access, correction, completion, deletion, restriction, withdrawal of consent or another right available under applicable law.
Where Ovhok processes hosted data only on behalf of a customer organization, requests concerning that data should ordinarily be directed to that organization. Ovhok may refer the request to the customer and will provide reasonable contractual assistance where required.
A request may be limited or refused where information must be retained or processed for legal obligations, tax or accounting, security, fraud prevention, rights of others, legal claims, contract administration or another lawful reason. Ovhok may request proportionate information to verify identity, authority and the scope of a request and may decline manifestly abusive or legally unsupported requests to the extent permitted by law.
Promotional email may be stopped through an available unsubscribe mechanism or by contacting Ovhok. Operational, billing, security, contractual and service messages may still be sent where necessary to administer an active relationship.
12. Children, students and institution-managed data
The public website is not intended to invite children to provide sensitive personal information without appropriate adult or institutional involvement. School and education products may process student information under the direction of the relevant institution and authorized users. The institution remains responsible for notices, permissions, lawful authority, data accuracy, role assignment and access controls required for its use of the Service.
13. Automated processing and AI-assisted features
Ovhok may use automation to route inquiries, detect abuse, classify records, assist support, generate reports, improve products or help authorized users. AI-assisted output may be probabilistic and must be reviewed by an authorized person before consequential use. Where applicable law requires special notice, consent or human review for a particular automated use, the relevant Service or customer workflow must implement that requirement.
14. Business records, anonymized data and service analytics
Ovhok may preserve non-personal business records, security evidence, audit records and aggregated or de-identified analytics after other data is deleted where reasonably necessary for compliance, security, product planning, capacity, fraud prevention and business continuity. Ovhok will not intentionally re-identify de-identified information in a manner prohibited by applicable law.
15. Changes to this Policy
Ovhok may update this Policy to reflect legal, regulatory, security, operational, provider, technology or product changes. The published version will show its effective and review dates. Where required by law or contract, material changes will receive additional notice or consent before they apply.
16. Contact, requests and complaints
Ovhok Software Solutions Pvt. Ltd.
Arjundhara-8, Jhapa, Nepal
Email: [email protected]
Phone: +977 9862911301
Describe the relevant account, organization, information and requested action. Do not send passwords or highly sensitive documents by ordinary email. Ovhok may request proportionate proof of identity and authority before acting.
17. Nepal legal references and mandatory-law savings clause
This Policy is intended to operate subject to applicable Nepal law. Any mandatory statutory requirement prevails over a conflicting statement in this Policy to the extent required by law. Official references include: