Skip to content
Responsible company. Ovhok Software Solutions Pvt. Ltd., Arjundhara-8, Jhapa, Nepal, is responsible for personal information it controls for its own business purposes. For information a customer organization places in an Ovhok-hosted product, that customer ordinarily determines the purpose and Ovhok processes the information to provide the contracted Service, subject to the applicable agreement and law.

1. Scope, relationship and data roles

This Policy applies to ovhok.com, inquiries, demonstrations, marketing, customer onboarding, contracts, billing, support, courses, recruitment, events, hosted products, APIs, integrations and other interactions with Ovhok.

For Ovhok's own website, sales, security, recruitment, accounts, operations and administration, Ovhok decides the business purposes for processing. For customer-hosted data, the customer normally determines why information is entered and who may access it, while Ovhok processes it to operate, secure, support and maintain the Service. A signed data-processing or service agreement may define these roles more specifically.

This Policy does not govern independent third-party websites, payment providers, government portals, social networks or integrations that publish their own terms and privacy policies.

2. Information we may collect or receive

Identity and contactName, organization, role, email, mobile number, address, profile details and preferred contact channel.
Account and securityUser ID, role, permission, login events, device/session information, authentication events, password-reset records, API usage and security logs. Passwords are stored as protected hashes rather than readable text.
Business and CRMRequirements, leads, proposals, quotations, contracts, project decisions, customer contacts, service history, support messages and meeting records.
Billing and compliancePAN/VAT information, invoices, receipts, payment references, account records, reconciliation information and other tax or compliance records.
ApplicationsCourse enrollment information, career history, CV, education, skills, portfolio, interview records and communications.
Customer contentFiles, images, documents, records, messages and other data intentionally uploaded, synchronized or generated in a Service under customer configuration and instructions.
Technical usageIP address, browser, operating system, device identifiers, page and feature activity, timestamps, referral information, performance metrics, error logs, audit events, cookies and similar identifiers.
CommunicationsEmail, SMS, support tickets, call notes, feedback, survey responses and communications reasonably necessary to manage the relationship.

Please do not provide passwords, private keys, complete payment-card credentials, government secrets or sensitive personal information unless the relevant Service expressly requires that information and a secure authorized process is available.

3. Sources of information

Information may come directly from you; from your employer, school, cooperative, customer, parent/guardian or authorized administrator; from your use of our Services; from connected systems you or a customer authorize; from service providers; from payment, email, SMS, hosting, analytics and security systems; and from public or lawfully available business sources.

4. Purposes and lawful use of information

Ovhok may process information where reasonably necessary to perform a contract or requested pre-contract step, comply with legal obligations, protect systems and rights, operate our business, or where consent or another lawful basis is required and available under applicable law.

  • Service delivery: create accounts, configure products, host customer data, process authorized transactions, provide support, training, maintenance, reports, backups and notifications.
  • Sales and contracts: respond to inquiries, prepare proposals, manage demonstrations, onboarding, subscriptions, renewals, billing, collections and customer relationships.
  • Security and abuse prevention: authenticate users, enforce permissions, detect fraud, investigate incidents, block malicious activity, preserve audit evidence and protect Ovhok, customers and third parties.
  • Operations and improvement: diagnose errors, measure performance, capacity and reliability, understand feature usage, improve usability, develop products, train personnel and manage quality.
  • Legal and compliance: satisfy tax, accounting, corporate, employment, court, regulatory, audit, record-keeping and lawful government requirements and establish, exercise or defend legal claims.
  • Communications and marketing: send service, security, billing, product and relationship messages and, where permitted, relevant marketing communications. Promotional choices can be changed as described below.

Ovhok may create aggregated or de-identified statistics and operational insights for analytics, security, capacity planning, benchmarking and product improvement where the information is not used to identify a person contrary to applicable law.

5. Cookies, device information and online analytics

Our websites and Services may use essential cookies, session identifiers, anti-forgery tokens, preference storage, server logs and, when enabled under the applicable consent or configuration, analytics or marketing technologies. These help operate secure sessions, remember settings, measure performance, diagnose errors, prevent abuse and understand public-site usage. More detail is provided in the Cookie Policy.

6. When information may be shared or disclosed

Ovhok does not needlessly disclose personal information. Information may be shared with employees, affiliates, contractors, advisers and service providers that need it to perform authorized work and are subject to appropriate duties or contractual restrictions.

Depending on the Service, recipients may include hosting and cloud providers, domain and infrastructure providers, payment processors, banks, email/SMS providers, customer-authorized integrations, analytics/security providers, accountants, auditors, legal advisers and other professional service providers.

Information may also be disclosed to the relevant customer organization and its authorized administrators; to comply with law, court orders or lawful government requests; to investigate fraud, misuse or security incidents; to protect rights, safety, systems or property; to enforce agreements; or to establish, exercise or defend legal claims.

If Ovhok is involved in a merger, financing, restructuring, acquisition, sale of business or assets, insolvency process or similar transaction, relevant information may be disclosed to professional advisers and prospective or actual transaction parties subject to appropriate safeguards and applicable law.

7. Service providers, subprocessors and third-party integrations

Ovhok may use qualified service providers and subprocessors for infrastructure, support, communications, security, analytics and other operational functions. Providers are selected and managed according to the nature of the Service and information involved. Customer-authorized third-party integrations may receive data according to the permissions and configuration selected by the customer. Once data is sent to an independent third party, that party's own terms and practices may apply.

8. Cross-border processing

Cloud, communications, security or technical providers may process information outside Nepal. Where cross-border processing occurs, Ovhok considers the nature of the information, the provider, contractual protections, access controls and available security safeguards and acts subject to applicable legal requirements. A customer may request reasonable information about material providers used for its contracted Service.

9. Retention, backups, legal holds and deletion

Ovhok retains information for as long as reasonably necessary for the purpose for which it was collected and for service delivery, security, fraud prevention, audit, backup, accounting, tax, corporate records, dispute resolution, legal claims, enforcement and other lawful obligations. Retention may be extended where a dispute, investigation, legal hold, unpaid account, security incident or legal requirement applies.

RecordTypical operational approachPrimary reason
Inquiry and leadUsually up to 24 months after last meaningful contact, longer where a relationship, suppression record or legal reason continuesSales history, follow-up and contact preference
Contracts, billing and accountingContract term plus the period required by tax, accounting, audit, dispute and applicable limitation rulesLegal, financial and evidentiary obligations
Career applicationNormally up to 12 months after the recruitment decision unless a lawful reason supports longer retentionRecruitment, audit and future opportunities
Security and audit logsRisk-based period, commonly 90 days to 24 months, longer for an incident or legal holdSecurity, investigation and accountability
Hosted customer dataContract term plus the applicable export/deletion window and protected backup cycleService delivery, recovery and contractual obligations

Deletion from active systems may not immediately remove protected backups, immutable security records or records that must be retained. Backups expire or are overwritten according to operational schedules and are generally restored only for disaster recovery or continuity purposes.

10. Security and incident handling

Depending on the Service, safeguards may include role- and resource-based authorization, least-privilege access, secure password hashing, TLS encryption in transit, protected secrets, environment separation, logging, rate limits, backups, vulnerability management and incident procedures.

No internet, software or storage system can be guaranteed absolutely secure. Customer is responsible for correctly configuring its users and permissions, removing former users, protecting endpoints and credentials, maintaining lawful access controls and promptly reporting suspected misuse.

If Ovhok confirms an incident affecting information under its control, Ovhok will investigate and contain it, preserve relevant evidence, take proportionate corrective action and provide notices required by applicable law or contract.

11. Rights, requests and choices

Subject to identity and authority verification, applicable law and the relevant customer relationship, a person may request information about personal data Ovhok controls and may request access, correction, completion, deletion, restriction, withdrawal of consent or another right available under applicable law.

Where Ovhok processes hosted data only on behalf of a customer organization, requests concerning that data should ordinarily be directed to that organization. Ovhok may refer the request to the customer and will provide reasonable contractual assistance where required.

A request may be limited or refused where information must be retained or processed for legal obligations, tax or accounting, security, fraud prevention, rights of others, legal claims, contract administration or another lawful reason. Ovhok may request proportionate information to verify identity, authority and the scope of a request and may decline manifestly abusive or legally unsupported requests to the extent permitted by law.

Promotional email may be stopped through an available unsubscribe mechanism or by contacting Ovhok. Operational, billing, security, contractual and service messages may still be sent where necessary to administer an active relationship.

12. Children, students and institution-managed data

The public website is not intended to invite children to provide sensitive personal information without appropriate adult or institutional involvement. School and education products may process student information under the direction of the relevant institution and authorized users. The institution remains responsible for notices, permissions, lawful authority, data accuracy, role assignment and access controls required for its use of the Service.

13. Automated processing and AI-assisted features

Ovhok may use automation to route inquiries, detect abuse, classify records, assist support, generate reports, improve products or help authorized users. AI-assisted output may be probabilistic and must be reviewed by an authorized person before consequential use. Where applicable law requires special notice, consent or human review for a particular automated use, the relevant Service or customer workflow must implement that requirement.

14. Business records, anonymized data and service analytics

Ovhok may preserve non-personal business records, security evidence, audit records and aggregated or de-identified analytics after other data is deleted where reasonably necessary for compliance, security, product planning, capacity, fraud prevention and business continuity. Ovhok will not intentionally re-identify de-identified information in a manner prohibited by applicable law.

15. Changes to this Policy

Ovhok may update this Policy to reflect legal, regulatory, security, operational, provider, technology or product changes. The published version will show its effective and review dates. Where required by law or contract, material changes will receive additional notice or consent before they apply.

16. Contact, requests and complaints

Ovhok Software Solutions Pvt. Ltd.
Arjundhara-8, Jhapa, Nepal
Email: [email protected]
Phone: +977 9862911301

Describe the relevant account, organization, information and requested action. Do not send passwords or highly sensitive documents by ordinary email. Ovhok may request proportionate proof of identity and authority before acting.

17. Nepal legal references and mandatory-law savings clause

This Policy is intended to operate subject to applicable Nepal law. Any mandatory statutory requirement prevails over a conflicting statement in this Policy to the extent required by law. Official references include: