Privacy Policy
Automation holds records about real people: students, clients, visitors and staff. This policy explains what we collect, why, who else is involved, and what you can ask us to do about it.
1. Two different roles
Automation is operated by Insource Inc Pvt. Ltd. ("we", "us"), a private limited company registered in Nepal, registration number 299184/079/080. The distinction below decides who you should approach about what.
Data we control
Information about the organisations that subscribe and the people who sign in. Account details, billing, support conversations and security logs. We decide how this is used, and this policy governs it directly.
Data we process for you
The records inside a workspace: students, clients, visitors, staff, documents and accounts. The subscribing organisation decides what goes in and why. We only act on its instructions. If you are in those records, contact that organisation first; see section 10.
2. What we collect
Account information
Name, email address, mobile number, password (stored as a salted hash, never in readable form), profile photo if you upload one, and the projects and roles assigned to you.
Sign-in and security records
To operate two-step verification and let you review your own sessions, we record sign-in attempts and their outcome, one-time codes and the channel they were sent on, the device, browser and operating system reported by your browser, your IP address, and an approximate location derived from that IP address. Changes to an account's email address or mobile number are logged with the time, the IP address and the previous value.
Acceptance of these documents
When you accept these terms, either by creating an account or by accepting a revised version, we record which document and version you accepted, the date and time, your IP address and your browser's user-agent string. This is kept as evidence of the agreement. You can see your own record from the profile panel.
Customer Data
Whatever the subscribing organisation puts into its workspace. In practice this often includes contact details, education and visa records, uploaded documents and photographs, attendance, payments and accounting entries, notes and comments, and visitor entries. The fields themselves are configurable, so the exact content varies by workspace.
Mailbox content, if connected
An organisation can connect its own email account. When it does, we store the credentials it supplies and the messages and attachments synced from that mailbox, so they can be read and sent inside the platform.
Usage and diagnostic data
Pages visited, actions taken within a workspace, and error reports produced when something goes wrong. Error reports can include the request that failed; we mask passwords and tokens before storing them.
Analytics
We use Google Analytics to understand how the platform is used in aggregate. See our Cookie Policy.
3. Why we use it
- To provide the Service: store and display your records, generate documents and reports, sync and send mail, run scheduled jobs.
- To sign you in securely: verify your password, send one-time codes, recognise trusted devices, show you your own active sessions.
- To protect accounts: detect unusual sign-in patterns, rate-limit verification codes, alert you when contact details change.
- To support you: investigate problems you report.
- To keep the platform working: diagnose errors, plan capacity, improve performance.
- To bill you: apply plan limits and collect fees.
- To meet legal obligations: respond to lawful requests and keep records we are required to keep.
We do not sell personal information, and we do not use Customer Data to train AI models of our own.
4. Our lawful basis
Where data protection law requires a basis for processing, we rely on: performance of a contract for running the Service and billing; legitimate interests for security, fraud prevention, diagnostics and improving the platform; consent for optional analytics cookies; and legal obligation where a law requires us to act.
For Customer Data, the subscribing organisation determines the basis. We process it under our agreement with that organisation.
5. Who else is involved
Running the platform means relying on other providers. Each receives only what it needs for its part, and is bound to protect it.
| Provider | What it does | What it receives |
|---|---|---|
| Cloudflare R2 | File and document storage | Files uploaded to a workspace |
| SMS gateway | Delivers SMS, including one-time codes | Mobile number and message text |
| Email (SMTP) provider | Delivers outbound email | Recipient address and message content |
| Google reCAPTCHA | Blocks automated sign-in attempts | IP address and browser signals |
| Google Analytics | Aggregate usage statistics | Pseudonymous usage events |
| IPInfoDB | Approximate location for sign-in records | IP address |
| AI providers (OpenAI, Google Gemini, DeepSeek) | Powers AI-assisted features when you use them | Only the content submitted to that feature |
We may also disclose information where the law requires it. That includes responding to a court order, a lawful request from the police or a regulator, or where we reasonably believe disclosure is necessary to investigate or prevent a crime, to protect someone's safety, or to establish or defend a legal claim. Where we are permitted to tell you, we will; where an order forbids it, we cannot.
We may also disclose information to enforce our agreements, or as part of a merger or sale of the business, in which case we will tell affected customers beforehand.
This list changes as the platform does. Write to us at the address in section 14 to be told about changes before they take effect.
6. Where data is stored
The platform and its database are hosted on servers operated for us. Files are stored with Cloudflare R2, and several providers in section 5 operate internationally, so some data is processed outside Nepal.
Where information leaves Nepal, we rely on the provider's contractual commitments to protect it to a standard consistent with this policy.
7. How long we keep it
- Customer Data: for as long as the subscription is active. After it ends, we keep the workspace for 30 days so it can be recovered or exported, then delete it. Ask us and we will delete it sooner.
- Data deleted inside the platform: moves to the workspace's trash and is removed permanently on the schedule that workspace has configured.
- Account records: for as long as the account exists.
- Sign-in and security logs: kept as a security record and reviewed periodically; we remove what is no longer needed for that purpose.
- Acceptance records: kept for as long as the agreement lasts and for a period afterwards, since they are the evidence that it was entered into.
- Billing records: for as long as tax and company law requires.
- Backups: deleted content persists in backups for a short period before those backups rotate out.
One exception applies to all of the above: where we are required by law to retain something, or where it is needed as evidence in an actual or anticipated investigation or legal claim, we keep it for as long as that purpose lasts and delete it afterwards.
8. How we protect it
- Traffic is encrypted in transit with HTTPS.
- Passwords are stored as salted hashes, never in readable form.
- Signing in requires a one-time code sent to a registered mobile number or email address.
- Changing the email address or mobile number on an account requires two verification codes, sent on different channels, and signs the account out everywhere.
- Verification codes are stored hashed, expire after a few minutes, and are limited in how many times they can be attempted.
- Each workspace is separated from every other, and access within one is governed by roles and permissions the organisation sets.
- Passwords and tokens are masked before anything is written to error logs.
- You can see your own active sessions and end any of them.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authority as the law requires, without undue delay.
9. Your rights
Subject to the law that applies to you, you can ask us to:
- tell you what personal information we hold about you;
- give you a copy of it;
- correct it if it is wrong;
- delete it, where we have no continuing need or legal duty to keep it;
- restrict or object to how we use it; or
- withdraw consent you have given, without affecting what was done beforehand.
Much of this you can do yourself: your profile page lets you update your name, email address and mobile number, review active sessions and change your password.
Write to [email protected] for anything else. We will respond within 30 days, and may need to verify your identity first.
10. If you are in someone's records
If a consultancy, institute or office holds your details in Automation, that organisation decides what is held and why, not us. We store it on their behalf.
Please contact that organisation directly to see, correct or delete your information. If you approach us instead, we will pass your request on and tell you we have done so, but we cannot change their records without their instruction.
11. Children
Automation is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16.
Our customers' records may include information about students who are minors. Where they do, the organisation holding those records is responsible for having proper consent, and we process that information only on its instructions.
13. Changes to this policy
We update this policy as the platform changes. The "last updated" date above always reflects the current version. For changes that materially affect how we handle personal information, we will give notice by email or inside the platform before they take effect.
14. Contact us
For privacy questions, or to exercise any right in section 9:
Insource Inc Pvt. Ltd.Buddhanagar, Kathmandu
Nepal · Reg. No. 299184/079/080
Phone: +977 9802324841
Privacy: [email protected]
Security: [email protected]
Support: [email protected]