Skip to main content
Your Data, Your Control

Privacy Policy

We take your privacy seriously. This policy explains what data we collect, why, and how we protect it.

Effective: April 1, 2026 · Last Updated: April 1, 2026

The short version

We only collect data needed to run the platform

Your data is encrypted at rest and in transit

We never sell your data to third parties

1. Information We Collect

Account Information

When you register, we collect your name, email address, phone number, and role (consultancy admin, counselor, or student). For consultancies, we also collect the organization name, address, and branding preferences.

Student Data

Consultancies enter student information including names, contact details, target countries, intake preferences, university applications, visa applications, and document uploads. This data is owned by the consultancy and processed by Qylantis on their behalf.

Documents

Documents uploaded to the platform (passports, transcripts, IELTS scores, financial statements) are stored encrypted on Google Cloud Storage. Only authorized users within the consultancy can access them.

Payment Information

Subscription payments are processed through Khalti and eSewa payment gateways. We do not store credit card or bank account details. Payment gateway tokens and transaction references are stored for billing records.

Usage Data

We automatically collect IP addresses, browser type, device information, pages visited, and actions taken within the platform. This data helps us improve performance and detect issues.

2. How We Use Your Information

Providing and maintaining the Qylantis CRM platform and its features.

Processing student applications, documents, and visa tracking as directed by consultancies.

Sending transactional emails including stage updates, document reminders, OTP codes, and appointment confirmations.

Calculating commissions, incentives, and financial reporting for consultancy administrators.

Monitoring platform health, detecting bugs, and preventing fraudulent activity.

Improving the platform based on aggregated, anonymized usage patterns.

3. Data Sharing

We do NOT sell your data.

Period. We never have and never will sell personal information to advertisers, data brokers, or any third party.

Service Providers

We share data with essential service providers: Google Cloud (hosting & storage), MongoDB Atlas and Neon (databases), Redis Labs (caching), Khalti/eSewa (payments), Google SMTP (email delivery), and Firebase / Google Play Services (push notifications on the mobile app). Each provider is bound by their own privacy and security policies.

Legal Requirements

We may disclose information if required by law, court order, or government regulation — specifically under Nepali law and applicable international regulations.

Consultancy Data Ownership

Student data entered by a consultancy belongs to that consultancy. Qylantis processes it on their behalf. If a consultancy terminates their subscription, they may request a full data export before account deletion.

4. Data Security

All data is encrypted in transit using TLS 1.2+ (HTTPS everywhere).

Database is hosted on Neon PostgreSQL with SSL enforcement and connection pooling.

Documents are stored on Google Cloud Storage with server-side encryption and signed URLs (7-day expiry).

Passwords are hashed using bcrypt with salt. We never store plaintext passwords.

JWT tokens expire after 24 hours. Session management is enforced via Redis with automatic invalidation.

Role-based access control (RBAC) ensures users can only access data relevant to their role and consultancy.

All user actions are logged in an immutable audit trail for compliance and security review.

5. Cookies & Tracking

We use localStorage for authentication tokens and user preferences (theme, session). We do not use third-party advertising cookies or tracking pixels.

Sentry is used for error monitoring — it collects anonymous error reports and stack traces to help us fix bugs. No personally identifiable information is sent to Sentry.

We do not use Google Analytics, Facebook Pixel, or any advertising tracker.

6. Your Rights

Access

You can request a copy of all personal data we hold about you.

Correction

You can update your profile information at any time through the platform settings.

Deletion

You can request account deletion. For consultancy accounts, all associated student data will be permanently deleted after a 30-day grace period.

Data Export

Consultancy admins can export student data, documents, and financial records in CSV/Excel format at any time.

Opt-Out

You can opt out of non-essential email notifications through your settings. Transactional emails (OTPs, security alerts) cannot be disabled.

7. Data Retention

Active account data is retained for the duration of the subscription plus 30 days after cancellation.

Audit logs are retained for 1 year from creation for compliance purposes.

Deleted student records are permanently purged from all systems within 90 days of deletion.

Payment records are retained for 5 years as required by Nepali tax regulations.

8. Mobile Application & Third-Party Services

Mobile apps

Our Android and iOS apps are built with React Native (Expo). They access the same account data described above and may request device permissions for push notifications, camera, and file storage so you can upload documents and receive updates.

Firebase Cloud Messaging (Google)

We use Firebase Cloud Messaging to deliver push notifications. For this we store a device push token. Google may process device identifiers in line with Google’s Privacy Policy.

Google Play Services

On Android, the app relies on Google Play Services for app distribution, integrity/security checks, and push-notification delivery. Google Play Services may collect device and diagnostic information governed by Google’s policies.

Expo

We use Expo to build and update the mobile app. Expo may process basic device and update-delivery information needed to ship app updates.

No advertising SDKs

The app contains no third-party advertising SDKs and no advertising identifiers are used.

Privacy questions or data requests? Contact privacy@qylantis.com

To remove your data, see Account Deletion and Data Deletion.