Privacy Policy
Review required before launch. This policy is a drafted starting point, not legal advice. Have it reviewed by a qualified adviser, and replace every bracketed placeholder, before you rely on it.
Last updated: 24 August 2026
1. Who we are
Whitehill IT Solution (“Whitehill”, “we”, “us”) provides software development, web development, digital health, cloud and IT consulting services, and sells software products and WordPress themes through this website.
For the purposes of data protection law we are the data controller for the personal data described in this policy.
- Registered name: [REGISTERED LEGAL NAME]
- Registered address: [COMPANY POSTAL ADDRESS]
- Email: [PRIVACY CONTACT EMAIL]
- Phone: [COMPANY PHONE]
2. Scope of this policy
This policy explains what personal data we collect through this website and in the course of providing our services, why we collect it, how long we keep it, and what rights you have over it.
It does not cover third-party websites we link to, or systems we administer on behalf of a client where that client is the data controller. Where we build, host or maintain a platform for a client, we normally act as a data processor under that client’s instructions and their own privacy notice applies to the data held in it.
3. Personal data we collect
3.1 Data you give us directly
- Enquiry and quotation forms: name, email address, phone number, organisation, and the content of your message.
- Account registration: name, email address, username and a hashed password.
- Purchases: billing name, billing address, email address, and a record of what you bought and when.
- Support requests: anything you choose to include, including screenshots, logs or files you attach.
- Newsletter or marketing sign-up: name and email address, where you have opted in.
3.2 Data we collect automatically
- Technical data: IP address, browser type and version, operating system, device type, screen size and language.
- Usage data: pages visited, time on page, referring URL, and links clicked.
- Server logs: request URLs, timestamps, response codes and error traces, kept for security and diagnostics.
- Cookies and similar technologies: see our Cookie Policy.
3.3 Payment data
We do not collect or store full payment card numbers. Card payments are processed by our payment provider, [PAYMENT PROVIDER NAME], and card details are submitted directly to them. We receive only a transaction reference, the payment status, and the last four digits of the card where the provider supplies it.
3.4 Special category data
We do not seek special category data (health, biometric, religious, political or similar) through this website. Some of our digital health engagements involve client systems that process health data; in those engagements we act as a processor under a written agreement and do not use that data for our own purposes.
4. Why we use your data, and our lawful basis
- To respond to enquiries and prepare quotations — because you asked us to, and because we have a legitimate interest in responding to prospective clients.
- To deliver services and fulfil orders — to perform our contract with you.
- To provide support, updates and licence validation — to perform our contract with you.
- To take payment and keep accounting records — to perform our contract, and to meet our legal obligations.
- To secure our systems and investigate abuse — because we have a legitimate interest in protecting our infrastructure and our clients.
- To measure and improve the website — with your consent, where analytics cookies are used.
- To send marketing — with your consent, which you can withdraw at any time.
5. Sharing your data
We share personal data only where it is necessary, and only with:
- Hosting and infrastructure providers who operate the servers this site runs on.
- Payment providers who process transactions.
- Email and communication providers used to send transactional and, where consented, marketing email.
- Analytics providers, where you have consented to analytics cookies.
- Professional advisers — accountants, auditors and lawyers — where they need it to advise us.
- Authorities, where we are legally required to disclose data.
We do not sell personal data, and we do not share it for third-party advertising.
6. International transfers
We operate from Nepal. Some of our providers store or process data outside Nepal, including in the European Union, the United Kingdom, India and the United States. Where we transfer personal data internationally, we take reasonable steps to ensure it remains protected to a comparable standard, including by using providers who offer contractual safeguards such as standard contractual clauses.
7. How long we keep data
- Enquiry and form submissions: [RETENTION PERIOD, e.g. 24 months] from last contact, unless they become a client record.
- Client and project records: for the duration of the engagement, then [RETENTION PERIOD, e.g. 7 years] to meet contractual, tax and audit obligations.
- Order, invoice and accounting records: as long as tax and company law requires.
- Account data: until you ask us to close the account, then deleted or anonymised.
- Server and security logs: [RETENTION PERIOD, e.g. 12 months].
- Marketing consent records: until you withdraw consent, plus a record of the withdrawal itself.
8. Your rights
Subject to the applicable law, you may ask us to:
- Access the personal data we hold about you, and receive a copy of it.
- Correct data that is inaccurate or incomplete.
- Erase data where we no longer have a valid reason to keep it.
- Restrict how we process it while a dispute or accuracy question is resolved.
- Port data you gave us to another provider, in a structured, machine-readable format.
- Object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent where our processing relies on it. Withdrawing consent does not affect processing already carried out.
To exercise any of these, email [PRIVACY CONTACT EMAIL]. We will respond within 30 days. We may ask you to verify your identity before we act, so that we do not disclose your data to someone else.
If you are not satisfied with our response, you may complain to the relevant supervisory authority in your country.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), access control on a least-privilege basis, hardened server configuration, patching, automated backups and logging. No system is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to affect your rights, we will notify you and the relevant authority as the law requires.
10. Children
This website and our services are directed at organisations and adults. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, contact us and we will delete it.
11. Automated decision-making
We do not make decisions about you by purely automated means that have legal or similarly significant effects.
12. Changes to this policy
We may update this policy as our services, providers or legal obligations change. The “last updated” date above shows when it last changed. Where changes are material, we will take reasonable steps to tell you, such as a notice on this website or an email to registered users.
13. Contact
Questions about this policy, or about how we handle your data, can be sent to [PRIVACY CONTACT EMAIL], or by post to [COMPANY POSTAL ADDRESS].
