Privacy Policy
Version 2026-07-25
What we collect
We collect information you provide directly (contact and account details, consultation and assessment requests, incident reports, job applications, uploaded documents) and limited, privacy-respecting technical data (page paths and referrer domain, aggregated by day — see our Cookie Policy). We do not use third-party advertising trackers.
Why we collect it
To respond to enquiries, deliver engagements, operate the client portal, meet our own legal and contractual obligations, and improve the site. Client engagement data (documents, risk registers, audit findings) is used solely to deliver the relevant service and is treated as confidential.
Legal basis and cross-border considerations
Where we process personal data on your behalf as part of an engagement, we do so under instructions set out in the relevant service agreement or data-processing agreement. If data is transferred outside Nepal (for example, to cloud infrastructure), we assess the transfer and apply appropriate safeguards.
Retention
We retain personal data only as long as needed for the purpose it was collected, or as required by law or professional obligation, after which it is deleted or anonymised. Clients may request deletion of their portal data subject to any retention obligations tied to an active or recently closed engagement.
Your rights
You may request access to, correction of, or deletion of your personal data by contacting privacy@pristinelextech.example. We log consent and policy-acceptance events for accountability purposes.
Security
We apply security-by-design principles: encryption in transit, access controls scoped by role and organisation, audit logging, and file-upload validation. No system is absolutely secure, and we do not claim otherwise.
Contact
Questions about this policy: privacy@pristinelextech.example