Privacy Policy
We take your privacy seriously. This policy explains what data we collect, why, and how we protect it.
Effective: April 1, 2026 · Last Updated: April 1, 2026
The short version
We only collect data needed to run the platform
Your data is encrypted at rest and in transit
We never sell your data to third parties
1. Information We Collect
Account Information
When you register, we collect your name, email address, phone number, and role (consultancy admin, counselor, or student). For consultancies, we also collect the organization name, address, and branding preferences.
Student Data
Consultancies enter student information including names, contact details, target countries, intake preferences, university applications, visa applications, and document uploads. This data is owned by the consultancy and processed by Qylantis on their behalf.
Documents
Documents uploaded to the platform (passports, transcripts, IELTS scores, financial statements) are stored encrypted on Google Cloud Storage. Only authorized users within the consultancy can access them.
Payment Information
Subscription payments are processed through Khalti and eSewa payment gateways. We do not store credit card or bank account details. Payment gateway tokens and transaction references are stored for billing records.
Usage Data
We automatically collect IP addresses, browser type, device information, pages visited, and actions taken within the platform. This data helps us improve performance and detect issues.
2. How We Use Your Information
Providing and maintaining the Qylantis CRM platform and its features.
Processing student applications, documents, and visa tracking as directed by consultancies.
Sending transactional emails including stage updates, document reminders, OTP codes, and appointment confirmations.
Calculating commissions, incentives, and financial reporting for consultancy administrators.
Monitoring platform health, detecting bugs, and preventing fraudulent activity.
Improving the platform based on aggregated, anonymized usage patterns.
3. Data Sharing
We do NOT sell your data.
Period. We never have and never will sell personal information to advertisers, data brokers, or any third party.
Service Providers
We share data with essential service providers: Google Cloud (hosting & storage), MongoDB Atlas and Neon (databases), Redis Labs (caching), Khalti/eSewa (payments), Google SMTP (email delivery), and Firebase / Google Play Services (push notifications on the mobile app). Each provider is bound by their own privacy and security policies.
Legal Requirements
We may disclose information if required by law, court order, or government regulation — specifically under Nepali law and applicable international regulations.
Consultancy Data Ownership
Student data entered by a consultancy belongs to that consultancy. Qylantis processes it on their behalf. If a consultancy terminates their subscription, they may request a full data export before account deletion.
4. Data Security
All data is encrypted in transit using TLS 1.2+ (HTTPS everywhere).
Database is hosted on Neon PostgreSQL with SSL enforcement and connection pooling.
Documents are stored on Google Cloud Storage with server-side encryption and signed URLs (7-day expiry).
Passwords are hashed using bcrypt with salt. We never store plaintext passwords.
JWT tokens expire after 24 hours. Session management is enforced via Redis with automatic invalidation.
Role-based access control (RBAC) ensures users can only access data relevant to their role and consultancy.
All user actions are logged in an immutable audit trail for compliance and security review.
5. Cookies & Tracking
We use localStorage for authentication tokens and user preferences (theme, session). We do not use third-party advertising cookies or tracking pixels.
Sentry is used for error monitoring — it collects anonymous error reports and stack traces to help us fix bugs. No personally identifiable information is sent to Sentry.
We do not use Google Analytics, Facebook Pixel, or any advertising tracker.
6. Your Rights
Access
You can request a copy of all personal data we hold about you.
Correction
You can update your profile information at any time through the platform settings.
Deletion
You can request account deletion. For consultancy accounts, all associated student data will be permanently deleted after a 30-day grace period.
Data Export
Consultancy admins can export student data, documents, and financial records in CSV/Excel format at any time.
Opt-Out
You can opt out of non-essential email notifications through your settings. Transactional emails (OTPs, security alerts) cannot be disabled.
7. Data Retention
Active account data is retained for the duration of the subscription plus 30 days after cancellation.
Audit logs are retained for 1 year from creation for compliance purposes.
Deleted student records are permanently purged from all systems within 90 days of deletion.
Payment records are retained for 5 years as required by Nepali tax regulations.
8. Mobile Application & Third-Party Services
Mobile apps
Our Android and iOS apps are built with React Native (Expo). They access the same account data described above and may request device permissions for push notifications, camera, and file storage so you can upload documents and receive updates.
Firebase Cloud Messaging (Google)
We use Firebase Cloud Messaging to deliver push notifications. For this we store a device push token. Google may process device identifiers in line with Google’s Privacy Policy.
Google Play Services
On Android, the app relies on Google Play Services for app distribution, integrity/security checks, and push-notification delivery. Google Play Services may collect device and diagnostic information governed by Google’s policies.
Expo
We use Expo to build and update the mobile app. Expo may process basic device and update-delivery information needed to ship app updates.
No advertising SDKs
The app contains no third-party advertising SDKs and no advertising identifiers are used.
Privacy questions or data requests? Contact privacy@qylantis.com
To remove your data, see Account Deletion and Data Deletion.