Effective 2026-06-03 · Operated by the MyGreaterNepal Innovations Pvt Ltd (MyGreaterNepal Innovations), Nepal · Kathmandu, Kathmanduलागू मिति २०२६-०६-०३ · माईग्रेटरनेपाल इनोभेसन्स (MyGreaterNepal Innovations), नेपाल · सिंहदरबार, काठमाडौँ द्वारा सञ्चालित
Plain-English summary:सोझो-सोझो भाषामा सारांश:
DigiNPL is built for professionals in Nepal to communicate securely. We collect the minimum information needed to verify you're a government officer and to deliver your messages — your phone number, your email, your name, and organization. Messages between you and other officers are end-to-end encrypted; only the sender and recipient can read them. Everything is hosted in Nepal — your data stays within our sovereign perimeter.
DigiNPL नेपालका कर्मचारीहरूले सुरक्षित रूपमा सञ्चार गर्न बनाइएको हो। तपाईंको परिचय प्रमाणित गर्न र सन्देश पुर्याउन आवश्यक न्यूनतम जानकारी मात्र हामी सङ्कलन गर्छौं — फोन नम्बर, इमेल, नाम, मन्त्रालय र पद। तपाईं र अन्य कर्मचारीबीच आदानप्रदान हुने सन्देशहरू इन्ड-टु-इन्ड एन्क्रिप्टेड हुन्छन्; पठाउने र प्राप्त गर्ने दुई जनाले मात्र पढ्न सक्छन्। सबै कुरा नेपालभित्र होस्ट गरिएको छ — तपाईंको डाटा सम्प्रभु सीमाभन्दा बाहिर जाँदैन।
1. Who is the data controller
१. डाटा नियन्त्रक को हुन्
The MyGreaterNepal Innovations Pvt Ltd (MyGreaterNepal Innovations), Nepal, is the data controller for DigiNPL. Contact: hello@diginpl.com.
DigiNPL को लागि डाटा नियन्त्रक माईग्रेटरनेपाल इनोभेसन्स (MyGreaterNepal Innovations), नेपाल हो। सम्पर्क: hello@diginpl.com।
2. What we collect
२. हामी के सङ्कलन गर्छौं
2.1 Identity data
२.१ परिचय डाटा
Phone number — required, used for OTP verification at signup and again on each new device.
Email — required, must end in your email. We use it to sign you in and deliver notifications.
Full name, ministry, designation — what other officers see when they look you up in the directory.
Device identifier — a per-install random ID. We do not collect your hardware IMEI, MAC address, or Apple/Google advertising ID.
फोन नम्बर — अनिवार्य, साइनअपमा र हरेक नयाँ यन्त्रमा OTP प्रमाणीकरणका लागि प्रयोग हुन्छ।
इमेल — अनिवार्य, प्रमाणीकरण र सन्देश पठाउन प्रयोग गरिन्छ।
पूरा नाम, मन्त्रालय, पद — निर्देशिकामा अन्य कर्मचारीले तपाईंलाई हेर्दा देखिने जानकारी।
यन्त्र पहिचायक — प्रति-इन्स्टल अनियमित आईडी। हामी तपाईंको हार्डवेयर IMEI, MAC ठेगाना वा Apple/Google विज्ञापन आईडी सङ्कलन गर्दैनौं।
2.2 Message data
२.२ सन्देश डाटा
Messages between you and other officers are end-to-end encrypted. The server stores only the encrypted bytes, the sender ID, the recipient ID, and a timestamp. We cannot read your messages. We cannot recover them if you lose your encryption keys (the keys live only on your devices).
तपाईं र अन्य कर्मचारीबीचको सन्देश इन्ड-टु-इन्ड एन्क्रिप्टेड हुन्छ। सर्भरले एन्क्रिप्टेड बाइट, पठाउनेको आईडी, प्राप्तकर्ताको आईडी र समय मात्र राख्छ। हामी तपाईंको सन्देश पढ्न सक्दैनौं। तपाईंले एन्क्रिप्सन कुञ्जी गुमाउनुभयो भने पुनः प्राप्त गर्न सक्दैनौं (कुञ्जीहरू तपाईंकै यन्त्रमा मात्र रहन्छन्)।
2.3 Operational data
२.३ सञ्चालन डाटा
Server access logs (IP, time, request path, status) retained 30 days for security monitoring.
OTP delivery records (masked phone, success/failure) retained 7 days.
No advertising identifiers, no behaviour tracking, no third-party analytics.
सुरक्षा अनुगमनका लागि सर्भर पहुँच लग (IP, समय, अनुरोध मार्ग, स्थिति) ३० दिनसम्म राखिन्छ।
OTP डेलिभरी रेकर्ड (मास्क गरिएको फोन, सफलता/असफलता) ७ दिन।
विज्ञापन पहिचायक छैन, व्यवहार ट्र्याकिङ छैन, तेस्रो पक्षको एनालिटिक्स छैन।
3. Who we share data with
३. डाटा कससँग साझा गर्छौं
DOIT (Department of Information Technology, GoN) — receives your phone number to deliver the OTP SMS. DOIT's SMS gateway terms apply for the duration of the SMS delivery.
Let's Encrypt (Internet Security Research Group) — issues the TLS certificate used to secure connections to diginpl.com. They receive only the hostnames, no user data.
That is the complete list. We do not share data with any other third party, including foreign cloud providers, advertising networks, or non-Nepali government bodies.
DOIT (सूचना प्रविधि विभाग, ने.स.) — OTP एसएमएस पठाउन तपाईंको फोन नम्बर पाउँछ। एसएमएस डेलिभरीको अवधिभर DOIT एसएमएस गेटवेका सर्तहरू लागू हुन्छन्।
Let's Encrypt (Internet Security Research Group) — diginpl.com सँगको जडान सुरक्षित गर्ने TLS प्रमाणपत्र जारी गर्छ। तिनलाई होस्टनाम मात्र थाहा हुन्छ, कुनै प्रयोगकर्ता डाटा होइन।
यो नै पूरा सूची हो। हामी विदेशी क्लाउड प्रदायक, विज्ञापन सञ्जाल वा गैर-नेपाली सरकारी निकायलगायत कुनै पनि तेस्रो पक्षसँग डाटा साझा गर्दैनौं।
4. Where your data lives
४. तपाईंको डाटा कहाँ बस्छ
All DigiNPL servers are located inside Nepal, hosted within the Nepal's sovereign perimeter at Kathmandu. Backups are kept inside Nepal. Your data does not cross the border.
DigiNPL का सबै सर्भरहरू नेपालभित्र, सिंहदरबारस्थित नेपालको सम्प्रभु परिधिमा होस्ट गरिएका छन्। ब्याकअप पनि नेपालभित्रै राखिन्छ। तपाईंको डाटा सीमा पार गर्दैन।
5. How long we keep it
५. कति लामो समयसम्म राख्छौं
Profile (phone, email, name, ministry, designation) — kept while your account is active, deleted within 30 days of you requesting deletion.
Messages — retained until you or the recipient deletes them. The server stores only ciphertext.
Access logs — 30 days.
OTP records — 7 days.
प्रोफाइल (फोन, इमेल, नाम, मन्त्रालय, पद) — तपाईंको खाता सक्रिय रहेसम्म राखिन्छ; मेटाउन अनुरोध गरेमा ३० दिनभित्र हटाइन्छ।
सन्देश — तपाईं वा प्राप्तकर्ताले नमेटुन्जेल राखिन्छ। सर्भरमा एन्क्रिप्टेड पाठ मात्र।
पहुँच लग — ३० दिन।
OTP रेकर्ड — ७ दिन।
6. Your rights
६. तपाईंका अधिकार
You can at any time:
तपाईं जुनसुकै बेला:
See your profile from the in-app Settings screen.
Update your name, ministry, or designation in-app.
Request deletion of your account and all server-stored data by emailing hello@diginpl.com from the email address on your account.
Export a copy of your stored profile and message history by emailing the same address.
एपको सेटिङ स्क्रिनबाट आफ्नो प्रोफाइल हेर्न सक्नुहुन्छ।
एपभित्रै नाम, मन्त्रालय वा पद अद्यावधिक गर्न सक्नुहुन्छ।
आफ्नो खातामा दर्ता भएको इमेलबाट hello@diginpl.com मा पत्राचार गरी खाता र सर्भरमा भएको सबै डाटा मेटाउन अनुरोध गर्न सक्नुहुन्छ।
उही ठेगानामा पत्र पठाई आफ्नो प्रोफाइल र सन्देश इतिहासको प्रतिलिपि लिन सक्नुहुन्छ।
7. Security
७. सुरक्षा
Connections are protected by TLS 1.3 with certificates from a publicly trusted issuer (Let's Encrypt). Messages are end-to-end encrypted at the protocol layer. Server-side storage is on hardened Linux hosts with disk-level encryption and strict access controls — only audited MyGreaterNepal Innovations administrators have shell access, and that access is logged. We follow the principle of least privilege throughout.
जडानहरू सार्वजनिक रूपमा भरपर्दो निकाय (Let's Encrypt) का प्रमाणपत्रसहित TLS 1.3 द्वारा सुरक्षित हुन्छन्। सन्देशहरू प्रोटोकल तहमा इन्ड-टु-इन्ड एन्क्रिप्टेड हुन्छन्। सर्भर भण्डारण डिस्क-स्तरीय एन्क्रिप्सन र कडा पहुँच नियन्त्रणसहित कठोर लिनक्स होस्टमा छ — अडिट गरिएका MyGreaterNepal Innovations प्रशासकलाई मात्र शेल पहुँच छ, र त्यो पहुँच लग गरिएको हुन्छ। हामी न्यून-विशेषाधिकारको सिद्धान्त पालना गर्छौं।
8. Children
८. नाबालिग
DigiNPL is for serving officers of the Nepal. It is not intended for and not available to anyone under 18.
DigiNPL नेपालमा कार्यरत कर्मचारीका लागि हो। यो १८ वर्षमुनिका कसैका लागि होइन र उपलब्ध छैन।
9. Changes to this policy
९. यस नीतिमा परिवर्तन
If we materially change this policy we will notify all active officers in-app at least 14 days before the change takes effect, and update the effective date above. The current version is always at this URL.
हामी यस नीतिमा महत्त्वपूर्ण परिवर्तन गरेमा सक्रिय कर्मचारीहरूलाई परिवर्तन लागू हुनुभन्दा कम्तीमा १४ दिनअघि एपमै सूचित गर्नेछौं र माथिको लागू मिति अद्यावधिक गर्नेछौं। पछिल्लो संस्करण सधैँ यसै URL मा हुन्छ।