Sanothimi
Data Sovereignty

Privacy Policy.

April 21, 2026Data Protection CompliantNepal Jurisdiction

1. Who We Are

"Sanothimi" refers to the software and technology services operated by Chandan Sharma ("Sanothimi," "we," "us," or "our"), based in Nepal, developing and operating software, SaaS products, websites, applications, APIs, and related technology services, including NUVORA. This Privacy Policy explains how we collect, use, share, and protect personal information across our Services. Sanothimi, operated by Chandan Sharma, Nepal.

2. Scope

This Privacy Policy applies to website visitors, Customers, Customer employees and Users, prospective customers, support contacts, partners, vendors, and job applicants who interact with Sanothimi. It does not override any product-specific privacy notice or Data Processing Agreement that applies to a particular Service.

3. Controller and Processor Roles

For information Sanothimi collects for its own business purposes — such as website analytics, marketing contacts, billing information, and support communications — Sanothimi acts as the controller (or equivalent responsible organization). Where a business Customer uses a Sanothimi Service to process personal information on the Customer's behalf (for example, student, staff, or employee data a school or business enters into a Service), Sanothimi acts as a processor or service provider, and the Customer determines the purposes and means of that processing. That relationship may be further defined in a Data Processing Agreement, available at /dpa.

4. Information We Collect

Depending on how you interact with us, we may collect: identity and contact information (name, email, phone); account information (login credentials, role); business information (organization name, registration details); billing information (payment details, processed by our payment provider); technical and usage information (IP address, browser, device, pages visited); location information (general, derived from IP address); support communications; and cookie information as described in our Cookie Policy.

5. Customer / SaaS Data

Customers may submit their own operational data into a Service — for example, records relating to their staff, students, employees, or clients, depending on the Service. Sanothimi processes this data as instructed by the Customer, as further described in Part 3 (Controller and Processor Roles) and our Data Processing Agreement.

6. Sensitive Information

Some Customer Data submitted to a Service may include categories of information treated as sensitive under applicable law. Sanothimi applies additional access controls to such information where technically supported by the Service, and Customers are responsible for ensuring they have a lawful basis to submit such information.

7. How We Use Information

We use personal information to: provide and operate the Services; create and manage accounts; authenticate Users; process Subscriptions and payments; provide support; send service-related communications; improve and secure our products; detect and prevent fraud or abuse; analyze usage to improve the Services; comply with legal obligations; and enforce our agreements.

8. Legal Bases

Where applicable data protection law requires a legal basis for processing (for example, under GDPR-equivalent frameworks), Sanothimi relies on one or more of the following: performance of a contract, compliance with a legal obligation, our legitimate interests (such as securing and improving the Services), your consent, or protection of vital interests.

9. Consent

Where we rely on your consent for a specific processing activity (such as certain marketing communications or non-essential cookies), you may withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

10. Cookies

We use cookies and similar technologies on our websites. Details of the categories of cookies we use, their purposes, and how to manage your preferences are described in our Cookie Policy, available at /cookies.

11. Marketing

We may send promotional emails, product announcements, and event communications where permitted. You may opt out of marketing communications at any time using the unsubscribe link in those messages or by contacting us directly. This does not affect transactional or service-related communications necessary to operate your Account.

12. Data Sharing

We may share personal information with: hosting and infrastructure providers; payment providers; email and communication providers; analytics and security providers; professional advisers; integrations you authorize; government or law enforcement authorities where legally required; and any party involved in a merger, acquisition, or sale of assets, subject to appropriate confidentiality obligations.

13. Subprocessors

Sanothimi engages third-party subprocessors to help provide the Services, such as cloud hosting and database providers. A current list of key subprocessors is available at /subprocessors, or on request to privacy@sanothimi.com.

14. International Transfers

Sanothimi uses third-party cloud and infrastructure providers and may process information in jurisdictions outside your own, depending on the Service, Customer configuration, and operational requirements. Where required by applicable law, we use appropriate safeguards for such transfers.

15. Data Storage

We do not commit to a single, permanent infrastructure location for all Services. Data is stored with reputable third-party cloud providers selected for performance, reliability, and security, and the specific storage region may vary by Service and may change as our infrastructure evolves.

16. Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including: active account data, for the life of the Account; Customer Data, per the applicable Service's retention settings and Part 21 of our Terms; billing records, as required by tax and accounting law; security logs, for a limited operational period; support records, for a reasonable service-quality period; and backups, which are deleted on a rolling schedule after the underlying data is deleted.

17. Security

We maintain administrative, technical, and organizational measures designed to protect personal information, as further described in our Security Policy, available at /security.

18. Data Subject / Privacy Rights

Depending on your location and applicable law, you may have rights to: access the personal information we hold about you; request correction of inaccurate information; request deletion; restrict or object to certain processing; request portability of your data; and withdraw consent where processing is based on consent. To exercise these rights, contact privacy@sanothimi.com.

19. Nepal Privacy

Sanothimi seeks to comply with applicable Nepalese privacy law, including the Individual Privacy Act, 2075 (2018) and its implementing regulations, as published by the Nepal Law Commission, with respect to personal information we handle as a controller.

20. International Privacy Rights

Where applicable law grants you additional rights — for example, under EU/EEA or UK data protection law, or California privacy law — those rights apply to you to the extent that law applies to your relationship with Sanothimi. We do not assume that every regional privacy law applies to every user; applicability depends on your location and the nature of our processing.

21. Children’s Privacy

Sanothimi's Services are intended for use by organizations and their authorized adult Users. Where a Customer's use of a Service (for example, an educational institution) involves data relating to children, that Customer is responsible for ensuring it has an appropriate legal basis and any required parental or guardian consent for submitting such data, consistent with our Data Processing Agreement.

22. AI and Automated Processing

Certain Services may include AI-assisted features, automated analytics, or automated decision-support tools, which may rely on third-party AI providers. We do not use Customer Data to train third-party foundation models without appropriate safeguards or Customer agreement. Where a Service uses automated processing that produces a decision with a significant effect on an individual, we aim to provide appropriate transparency and, where required by law, a means of human review.

23. Data Breaches

We maintain processes to detect, investigate, and respond to security incidents involving personal information. Where a breach is likely to result in a risk to affected individuals, we will notify affected Customers and, where legally required, relevant authorities, without undue delay.

24. Complaints

If you have a concern about how we handle personal information, please contact privacy@sanothimi.com first so we can try to resolve it. Where applicable law provides a right to lodge a complaint with a supervisory or regulatory authority, you may also do so.

25. Changes

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last Updated" date on this page, and where appropriate, communicated to Account administrators.

26. Contact

Sanothimi Operated by: Chandan Sharma Nepal Privacy: privacy@sanothimi.com Legal: legal@sanothimi.com

Request Data Extract

As an institutional client, you have the right to request a full encrypted copy of your data at any time.