Legal
Privacy Policy
CAS Nepal holds records about children. This policy explains exactly what is collected, who can see it, and what rights schools and guardians have.
Last updated: 21 August 2026
1.Our role
The School is the controller of the student and staff data in its workspace — it decides what is recorded and why. CAS Nepal is the processor: we store and process that data on the School's instructions, to run the assessment platform. We do not sell data, run advertising, or share records with third parties for their own purposes.
2.What we collect
School data. School name, address, province/district/municipality, principal name, registration and affiliation numbers, contact email and phone, logo, gallery images, public profile text.
Staff data. Full name, email, username, phone, profile photo, role (organisation admin, teacher), class and subject assignments, last sign-in time.
Student data. Full name, date of birth, gender, roll number, grade and class, admission date and class, photo, addresses, mother tongue and other languages, parents'/guardian's names, occupations and contact details, local guardian details, and enrolment status.
Health data. Periodic weight and height measurements, recorded disease notes and disability notes, where the School chooses to maintain the health record required by the CDC assessment framework. This is sensitive data and is treated as such.
Assessment data. Rubric indicator scores (1–4) for regular and remedial passes, evaluation dates, assessment method, teacher remarks, attendance records, portfolio items and evidence uploads (photos, scans or documents a teacher attaches to a score).
Guardian data. Guardian account name, email and phone, and the link between a guardian account and their child's record.
Website data. Messages submitted through the contact and school-registration forms, plus standard server logs (IP address, user agent, timestamps) kept for security and diagnostics.
3.Why we use it
- To record continuous assessment against CDC learning indicators and calculate achievement levels.
- To generate cumulative assessment records and report cards.
- To give guardians visibility of their own child's progress.
- To operate accounts, authentication and role-based access.
- To keep the service secure, diagnose faults, and prevent misuse.
We do not use identifiable student data to train third-party AI models. Where an assistive feature drafts narrative text, it operates on the minimum data required and the teacher remains responsible for the final wording.
4.Who can access it
Access is enforced in the database itself, not only in the interface. The role model is:
- Teacher — students in the classes and subjects they are assigned to; their own evaluations and evidence uploads.
- Organisation administrator — all records belonging to their own school only: students, staff, classes, subjects, rubrics, attendance, reports.
- Guardian — only the students explicitly linked to their account, and only that child's assessment, attendance and report data.
- Super Admin (CAS Nepal) — platform oversight: school onboarding, account provisioning, support and integrity checks. Super Admin access is limited to named staff, is used only where necessary to operate the service, and administrative actions are written to an audit log.
Every record carries the organisation it belongs to, and row-level security prevents one school's users from reading another school's data under any circumstances.
5.Children's data
Students do not hold accounts on the platform and are not asked to provide data directly. Records about a child are entered by the School under its own legal basis and duty of care. Guardians can view their child's record and can ask the School to correct anything inaccurate. If a guardian is not satisfied with the School's response, they may contact us at the address below and we will work with the School to resolve it.
6.Retention
- Student, assessment and attendance records are retained for as long as the School's account is active, since cumulative records span multiple academic years.
- Evidence uploads follow the record they are attached to and are deleted when that record is deleted.
- When a School leaves the platform, its data is exported to the School and then deleted within 60 days, unless the School asks in writing for a longer handover window.
- Contact-form and registration messages are kept up to 24 months.
- Audit logs and security logs are kept up to 12 months.
7.Your rights
Staff and guardians may ask to access, correct or delete their own account data. Requests concerning a student's record are handled through the School, which holds the underlying legal responsibility. We respond to requests within 30 days.
8.Contact for privacy concerns
Privacy questions, data requests or concerns about how a record is being handled: privacy@casnepal.com — or write to CAS Nepal, Kathmandu, Nepal. Suspected data incidents should be reported immediately to the same address.
