Back to Home

Privacy
Policy

Last Updated: April 19, 2026

Summary

  • We collect only what's needed to provide the Service
  • We never sell your personal data
  • Your organization owns its data — we're the processor
  • You can export or delete your data at any time
  • All data is encrypted in transit and at rest

1. Information We Collect

We collect information you provide directly: name, email address, phone number, organization details, and payment information. We also collect usage data automatically, including IP addresses, browser type, device information, pages visited, and interaction patterns within the Service. For student records managed through the Service, the data controller is your organization — we act as a data processor.

2. How We Use Your Information

We use your information to: (a) provide, maintain, and improve the Service; (b) process transactions and send billing notifications; (c) send service-related communications including security alerts and support messages; (d) analyze usage patterns to improve user experience; (e) comply with legal obligations. We do not sell your personal information to third parties.

3. Data Storage & Security

Your data is stored on secure cloud infrastructure provided by Appwrite. We implement industry-standard security measures including encryption in transit (TLS 1.3) and at rest (AES-256), regular security audits, access controls, and automated backups. While we strive to protect your data, no method of electronic storage is 100% secure.

4. Data Sharing

We may share your information with: (a) service providers who assist in operating the Service (e.g., email delivery via Resend, cloud hosting); (b) law enforcement when required by law or to protect our rights; (c) in connection with a merger, acquisition, or sale of assets, with advance notice to affected users. All third-party service providers are bound by data processing agreements.

5. Cookies & Tracking

We use essential cookies for authentication and session management. We may use analytics cookies to understand Service usage. You can control cookie preferences through your browser settings. Disabling essential cookies may affect Service functionality. We do not use third-party advertising cookies.

6. Your Rights

You have the right to: (a) access your personal data; (b) correct inaccurate data; (c) request deletion of your data; (d) export your data in a machine-readable format; (e) object to processing of your data; (f) withdraw consent at any time. To exercise these rights, contact us at privacy@aesthera.tech. We will respond within 30 days.

7. Data Retention

We retain your data for as long as your account is active. Upon account deletion, personal data is permanently removed within 30 days. Some data may be retained longer if required by law or for legitimate business purposes (e.g., billing records for tax compliance). Anonymized usage data may be retained indefinitely for analytics.

8. Children's Privacy

The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us.

9. International Transfers

Your data may be transferred to and processed in countries other than Nepal. When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements that meet applicable privacy standards.

10. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Last Updated" date at the top reflects the most recent revision. Continued use of the Service after changes constitutes acceptance.

11. Contact Us

For privacy-related inquiries, data requests, or complaints, contact our Data Protection Officer at privacy@aesthera.tech. You may also write to us at: Aesthera Systems, Kathmandu, Nepal. We aim to resolve all privacy concerns within 30 business days.

Privacy Concerns?

Reach our Data Protection Officer at aestheralimited@gmail.com