Legal

Privacy policy.

What we collect, why, how long we keep it, and what you can ask us to do about it — written to be read rather than to be defensible.

Last updated 1 August 2026

We collect as little personal data as we can get away with, keep it only as long as it is useful, and never sell it. This page sets out the detail.

1. Who we are

Sadhyata Consultancy Limited ("Sadhyata", "we", "us") is the technology arm of the Sadhyata Group, headquartered in Kathmandu, Nepal. We are the data controller for personal data collected through this website and through our commercial relationships.

This policy explains what we collect, why, how long we keep it, and what you can ask us to do about it. It covers this website and our direct business relationships. It does not cover systems we build and operate on behalf of clients, where the client is the controller and their own policy applies.

2. Data we collect

We collect only what we need to respond to you and to run the business relationship.

  • Contact details you submit through our forms — name, email address, telephone number, organisation, and the content of your message.
  • Recruitment data where you apply for a role, including your CV and any information you choose to include in it.
  • Business relationship records for clients, partners, and suppliers, including contract and billing information.
  • Technical data from your visit: IP address, browser type, pages viewed, and referring source, used in aggregate to understand how the site is used.

3. Why we use it, and our lawful basis

We process personal data on one of the following bases, depending on the purpose.

  • Legitimate interests — responding to enquiries, delivering engagements, securing our systems, and understanding aggregate site usage.
  • Contract — administering an engagement, supplier arrangement, or partnership we have entered into with you or your organisation.
  • Consent — sending you material you have specifically asked for, such as a white paper or event invitation. You can withdraw consent at any time.
  • Legal obligation — retaining records required by tax, corporate, and employment law.

4. Who we share it with

We do not sell personal data, and we do not share it for third-party advertising.

We share data with processors who provide our infrastructure, email, and business systems, each under a written agreement restricting them to our instructions. Where a processor operates outside your jurisdiction, transfers are covered by appropriate safeguards. We will also disclose data where we are legally required to, and will tell you unless prohibited from doing so.

5. How long we keep it

We keep personal data only as long as it serves the purpose it was collected for.

  • Enquiry correspondence: 24 months from the last contact, unless it becomes a client relationship.
  • Unsuccessful applications: 12 months, so we can contact you about future roles. Ask us and we will delete it sooner.
  • Client and supplier records: for the duration of the relationship plus the period required by law, typically seven years.
  • Aggregate website analytics: 14 months, after which it is retained only in non-identifying form.

6. Your rights

You can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict how we use it, or object to processing based on legitimate interests. Where processing is based on consent you may withdraw that consent at any time.

Write to us and we will respond within 30 days. There is no charge. If you are not satisfied with our response you may complain to the relevant supervisory authority in your jurisdiction.

7. How we protect it

Personal data is encrypted in transit and at rest. Access is granted on a least-privilege basis, reviewed periodically, and logged. Our own systems are subject to the same security standard we apply to client engagements, including dependency scanning, secret scanning, and independent assessment.

If a breach occurs that is likely to affect your rights, we will notify you and the relevant authority within the statutory time limit, and tell you what we are doing about it.

8. Changes to this policy

We update this policy when our practices change. The date at the top of this page always reflects the current version. Where a change materially affects how we use data you have already given us, we will contact you directly rather than relying on this page alone.

Questions about this policy?

Write to privacy@sadhyata.com and we will respond within four business hours.