Privacy and data
Privacy Policy
What personal data WeGrowNepal collects, why, who it is shared with, how long it is kept, and the rights you hold over it under Nepali law.
- Version
- v2.0
- Effective
- Contents
- 13 sections · 88 clauses
- Document ref.
- WGN-LEGAL-PRIVACY-V2.0
The PDF is a watermarked controlled copy. If it differs from this page, this page governs.
At a glance
A plain-language summary. The numbered clauses below are what legally applies.
- You can read and download everything without an account and without giving us anything.
- With an account we hold your name, email, and what you contributed.
- We do not sell your data, and we do not run advertising networks on the Service.
- You can see, correct, export or delete what we hold, from your account or by asking.
- Data is held in Nepal and in India, and the sub-processors are listed publicly.
1. Who we are and what governs this
- 1.1
Lacspace Corporation Pvt. Ltd., registered in Nepal under number 377566/82/83 at Bhimsengola, Sinamangal, Kathmandu, Bagmati Province, Nepal, is the controller of personal data processed through the Service.
- 1.2
This policy is issued under the Individual Privacy Act 2075 (2018) of Nepal and the Electronic Transactions Act 2063 (2008), and reflects the principles of those statutes.
- 1.3
Where you access the Service from outside Nepal, we apply this policy to you regardless of where you are.
- 1.4
Privacy questions and requests should be sent to legal@lacspace.com with "Privacy" in the subject line.
- 1.5
This policy applies to the website, the mobile applications and any related service. It does not apply to third-party sites we link to.
2. Reading without an account
- 2.1
You may read, search and download material on the Service without creating an account and without providing any personal information.
- 2.2
When you visit, our servers and our hosting provider record technical information automatically: IP address, browser type, device type, referring page, pages requested and timestamps.
- 2.3
That technical information is used to deliver the page, to secure the Service against abuse, and to understand aggregate usage. It is not used to build a profile of you.
- 2.4
We do not place advertising cookies and we do not operate an advertising network on the Service.
- 2.5
Cookies and local storage are described in the Cookie and Local Storage Policy.
- 2.6
Server logs containing IP addresses are retained for ninety days and then deleted, except where a record is preserved for a security investigation.
3. What we collect when you hold an account
- 3.1
Identity data — the name you choose to display and your email address.
- 3.2
Authentication data — a cryptographic hash of your password. We never store your password itself and cannot recover it.
- 3.3
Profile data — anything you choose to add, such as a biography, an avatar image, an institution or a course.
- 3.4
Contribution data — the notes, questions, answers, comments and votes you submit, and the metadata attached to them.
- 3.5
Activity data — what you have saved, what you have downloaded, and which groups you belong to.
- 3.6
Communication data — messages you send us, reports you make, and our replies.
- 3.7
Technical data — as described above, associated with your account while you are signed in.
- 3.8
We do not collect payment card details, because there is nothing to buy.
- 3.9
We do not ask for your citizenship number, date of birth, address or telephone number, and you should not send them to us.
Why this is here
Data we do not hold cannot be lost in a breach. This is a deliberate design choice, not an oversight.
4. Why we process it
- 4.1
To create and operate your account, and to authenticate you.
- 4.2
To publish your contributions and attribute them to you.
- 4.3
To provide the features you use, including saving, downloading and group membership.
- 4.4
To moderate the Service, enforce our policies and investigate reports of abuse.
- 4.5
To secure the Service against unauthorised access, fraud and automated abuse.
- 4.6
To send you service messages, such as a password reset or a notice that content was removed.
- 4.7
To understand in aggregate which subjects are used, so that gaps in the library can be identified.
- 4.8
To comply with a legal obligation or a lawful request.
- 4.9
We do not process your data for profiling, behavioural advertising or automated decisions producing legal effects.
5. The basis on which we process it
- 5.1
Your consent, given when you create an account and when you choose to submit a contribution.
- 5.2
The performance of our agreement with you, being the Terms of Use.
- 5.3
Our legitimate interest in operating, securing and improving the Service, where that interest is not overridden by your rights.
- 5.4
Compliance with a legal obligation.
- 5.5
You may withdraw consent at any time by closing your account. Withdrawal does not affect processing carried out before it.
6. What is public
- 6.1
Your display name, your avatar if you set one, your contributions and your position on the leaderboard are public.
- 6.2
Your email address is never public and is never shown alongside your contributions.
- 6.3
Your saved items, your downloads and your reading history are private to you.
- 6.4
Reports you make are not public and your identity is not disclosed to the person reported.
- 6.5
Anything you publish may be indexed by search engines and may be copied by other people. We cannot recall a copy somebody else has made.
Why this is here
This is the practical limit of every deletion right on every public platform, and it is more honest to say so here than to imply otherwise.
- 6.6
Do not put information in a public field that you would not want indexed.
7. Who we share it with
- 7.1
We do not sell personal data. We have never sold personal data and we do not intend to.
- 7.2
We do not share personal data with advertisers or data brokers.
- 7.3
We share data with the service providers necessary to run the Service — hosting, storage, content delivery, email delivery and error monitoring.
- 7.4
Those providers are listed by name, function and location in the Sub-processors document, which is updated when the list changes.
- 7.5
Each provider is bound to process data only on our instructions and only for the purpose we engaged them for.
- 7.6
We may disclose data where required by law, by a court, or by a competent authority, in accordance with the Law Enforcement and Legal Requests Policy.
- 7.7
We may disclose data where reasonably necessary to protect a person from serious harm.
- 7.8
We may disclose data to our professional advisers where necessary for legal advice.
- 7.9
If the business is reorganised, merged or sold, data may transfer with it. You will be notified and this policy will continue to apply until replaced by one no less protective.
8. Where it is held
- 8.1
Data is hosted on infrastructure located in India and on globally distributed content delivery networks.
- 8.2
Static files, including uploaded notes, are stored in object storage located in the Asia Pacific and European regions.
- 8.3
Transfers outside Nepal are made only to providers who offer appropriate technical and organisational safeguards, under contract.
- 8.4
Traffic between your device and our servers is encrypted in transit using TLS.
- 8.5
Data at rest is encrypted by the storage provider.
- 8.6
The regions in use are stated in the Sub-processors document.
9. How long we keep it
- 9.1
Account data is kept while your account is open.
- 9.2
On closure, account data is deleted or irreversibly anonymised within thirty days, subject to the exceptions in the Data Retention and Deletion Policy.
- 9.3
Server logs containing IP addresses are kept for ninety days.
- 9.4
Moderation and enforcement records are kept for five years.
- 9.5
Records relating to a legal claim, a takedown notice or a lawful request are kept for as long as the matter is live and for five years afterwards.
- 9.6
Backups are retained on a rolling cycle of no more than thirty-five days and are not used to restore deleted accounts.
- 9.7
Full detail is in the Data Retention and Deletion Policy.
10. Your rights
- 10.1
You have the right to be told what personal data we hold about you.
- 10.2
You have the right to obtain a copy of it in a portable format.
- 10.3
You have the right to have inaccurate data corrected, which you can do yourself from your settings.
- 10.4
You have the right to have your data deleted, subject to the retention exceptions.
- 10.5
You have the right to object to processing based on our legitimate interests.
- 10.6
You have the right to withdraw consent and close your account at any time.
- 10.7
You have the right to complain to us under the Grievance and Complaints Policy, and to the relevant authority in Nepal.
- 10.8
We respond to a rights request within thirty days, and we do not charge for it.
- 10.9
We may ask you to verify your identity before acting on a request, so that we do not disclose your data to somebody else.
- 10.10
Account deletion is available directly from the account deletion page and does not require you to email anybody.
11. Security
- 11.1
Passwords are stored only as salted cryptographic hashes.
- 11.2
Access to production data is restricted to the personnel who require it, and is logged.
- 11.3
Sessions expire and tokens are rotated. Sign-in from a new device is recorded.
- 11.4
We apply rate limiting and automated abuse detection to authentication endpoints.
- 11.5
No system is perfectly secure, and we do not claim otherwise.
- 11.6
Where a breach occurs that is likely to result in a risk to you, we will notify affected users and the relevant authority without undue delay, and in any event within seventy-two hours of becoming aware of it.
Why this is here
A fixed deadline is what turns a breach commitment into something that can be held against us.
- 11.7
Vulnerability reports are welcome under the Security and Vulnerability Disclosure Policy.
12. Children
- 12.1
The minimum age for an account is 13.
- 12.2
A person under 18 may hold an account only with the knowledge and permission of a parent or guardian.
- 12.3
We do not knowingly collect personal data from a person under 13, and we delete it if we discover it.
- 12.4
A parent or guardian may ask us to access, correct or delete data relating to their child.
- 12.5
Additional protections are set out in the Child Safety and Protection of Minors Policy.
13. Changes
- 13.1
We may amend this policy. The current version and its effective date are always published in the Legal Centre.
- 13.2
A material change is notified on the Service, and by email to account holders, at least fourteen days before it takes effect.
- 13.3
The version history records what changed and when.
- 13.4
If you do not accept an amended policy you may close your account before it takes effect.
Version history
Every change to this document is recorded here, so amendments can be inspected rather than taken on trust.
v2.0 ·
- Restructured into numbered, citable clauses.
- Stated the statutory basis under the Individual Privacy Act 2075 and the Electronic Transactions Act 2063.
- Stated expressly that we do not collect citizenship numbers, dates of birth, addresses or telephone numbers.
- Added a fixed 72-hour breach notification commitment.
- Added fixed retention periods for logs, moderation records and backups.
- Added a plain statement that copies made by others cannot be recalled.
v1.0 ·
- Initial publication.