Legal
Privacy Policy
Last updated: 21 May 2025
Nepalese Business Directory Ltd (“we”, “us”, “our”) operates https://nepalesebusinessdirectory.co.uk. We are committed to protecting your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Nepalese Business Directory Ltd is the data controller responsible for your personal data collected through this website.
Contact: info@nepalesebusinessdirectory.co.uk
If you have concerns about how we handle your data, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.
2. Data We Collect
We collect the following categories of personal data:
Account & Identity
Full name, email address, hashed password, profile photo, city, and account type.
Business Listing Data
Business name, address, phone, website, opening hours, category, description, and images.
Payment Data
Stripe customer ID, transaction reference, amount, and status. We do NOT store card numbers — these are held by Stripe.
Event & Ticket Data
Name, email, ticket quantity and type for event bookings.
Job & Room Listings
Listing details, CVs, cover letters, and answers to custom application questions.
User-Generated Content
Reviews, community posts, questions, comments, and saved businesses.
Communications
Emails, enquiry forms, and direct messages sent through the platform.
Technical & Usage Data
IP address, browser type, device, pages visited, and analytics data.
Marketing Preferences
Whether you have opted in or out of newsletter and email marketing.
3. How We Use Your Data
We use your personal data to:
- Create and manage your account
- Display business listings, jobs, and rooms to other users
- Process event ticket purchases and send booking confirmations
- Process payments via Stripe and manage subscriptions
- Send transactional emails (confirmations, password resets, listing approvals)
- Send marketing emails where you have opted in
- Display reviews and community content
- Verify business ownership claims
- Prevent fraud, abuse, and spam
- Improve the platform through analytics
- Comply with our legal obligations
- Respond to enquiries and support requests
4. Legal Basis for Processing
| Activity | Legal Basis |
|---|---|
| Account creation & management | Contract — Article 6(1)(b) |
| Processing payments | Contract — Article 6(1)(b) |
| Transactional emails | Contract — Article 6(1)(b) |
| Marketing emails (newsletter) | Consent — Article 6(1)(a) |
| Analytics & site improvement | Legitimate interests — Article 6(1)(f) |
| Fraud prevention | Legitimate interests — Article 6(1)(f) |
| Legal compliance | Legal obligation — Article 6(1)(c) |
6. Data Retention
- Account data: Until you delete your account, plus 30 days for recovery.
- Payment records: 7 years (UK financial regulation requirement).
- Event ticket data: 2 years after the event date.
- Job applications: 6 months after the closing date.
- Analytics data: Up to 26 months; aggregated data indefinitely.
- Newsletter subscribers: Until you unsubscribe.
7. Your Rights
Under UK GDPR you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data (subject to legal obligations).
- Restrict processing — limit how we use your data.
- Data portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interests or for direct marketing.
- Withdraw consent — unsubscribe from marketing at any time.
Email info@nepalesebusinessdirectory.co.uk to exercise any of these rights. We will respond within 30 days.
9. Security
We implement HTTPS encryption, hashed passwords, row-level database security, and restricted access to production systems. No system is 100% secure. If you believe your data has been compromised, contact us immediately at info@nepalesebusinessdirectory.co.uk.
10. Children's Privacy
Our services are not directed at individuals under 13. We do not knowingly collect data from children. If you believe a child has provided us with their data, contact us and we will delete it promptly.
11. International Data Transfers
Some service providers (Supabase, Stripe, Netlify) may process data outside the UK. We ensure appropriate safeguards including Standard Contractual Clauses (SCCs) or UK adequacy decisions are in place.
12. Changes to This Policy
We may update this policy periodically. Significant changes will be communicated by email or a prominent site notice. The “Last updated” date at the top reflects the most recent revision.
13. Contact Us
Nepalese Business Directory Ltd
