This policy is being finalised ahead of launch. Contact us with any questions about how your information is handled.
Film Permits Nepal is an independent, privately owned production-support service based in Kathmandu. We are not a government office, we do not issue permits, and we are not the authority that grants filming permission in Nepal. What we do is help international productions prepare, organise and coordinate the documentation involved in seeking filming permission, and to work through that process this website and our support service necessarily handle a certain amount of personal and production information.
This Privacy Policy explains, in plain language, what information we collect when you browse our website or engage our service, why we collect it, how we store and protect it, who we share it with, how long we keep it, and the choices and rights you have over it. It covers both casual visitors who never contact us and productions who send us scripts, crew lists, passport-style identity pages and other sensitive material as part of preparing a filming application.
We have written this policy to be genuinely useful rather than a wall of boilerplate. Because our work involves confidential creative and personal information, confidentiality and careful document handling are central to how we operate, not an afterthought. Where a point depends on which country you are in or which law applies to you, we say so honestly rather than pretending a single rule fits everyone. If anything here is unclear, or you want to exercise a right described below, the Contact section tells you exactly how to reach us and what to expect. This policy sits alongside our separate Cookie Policy, Terms, and our internal document-security practices, and should be read together with them.
Who we are and the scope of this policy
Film Permits Nepal is the trading identity of an independent private production-support business operating from Kathmandu, Nepal. Throughout this policy the words "we", "us" and "our" refer to that business, and "you" refers to anyone who visits our website, sends us an enquiry, or engages us to help prepare a filming application. We want to be completely clear at the outset about what we are and what we are not, because it changes how you should think about the information you share with us.
We are a private service. We are not a ministry, a permit-issuing authority, a police body, an aviation regulator, a customs office, or any arm of the Government of Nepal. We do not decide whether a production receives permission to film, and we do not hold or control any official register on the state's behalf. When you give us information, you are giving it to a private company that helps you prepare and organise your paperwork, not lodging it with a government database.
This policy applies to our public website and to the support service delivered through it and by email or messaging. It explains our practices for personal information, meaning any information that identifies or could reasonably identify a living person, as well as production information that may contain personal details about your cast, crew, contributors or contacts.
The policy does not govern third-party websites we may link to, the internal systems of any authority to whom an application is ultimately submitted, or the independent privacy practices of tools you choose to use to reach us. Where your data leaves our hands, for example when a completed application is submitted to a relevant authority, that authority's own rules and record-keeping apply, and those are outside our control. We describe those boundaries honestly throughout, because pretending otherwise would give you a false sense of where your information travels.
Because we serve productions from many countries, more than one privacy law may be relevant to you at once. We aim to apply a consistently high standard of care to everyone regardless of location, while recognising that specific enforceable rights depend on the law that applies to you. Where that matters, we flag it plainly rather than making a blanket promise we cannot keep for every jurisdiction.
Information we collect from website visitors
You can read most of our website without telling us who you are. When you simply browse, we do not ask for your name, and we do not require you to create an account. However, like almost every website, some limited technical information is generated automatically when your browser requests a page, and some optional information is collected only if you consent to it.
The automatic, technical information typically includes the type of request your browser makes, the pages you view, the approximate region your connection appears to come from, the type of device and browser you are using, and the date and time of your visit. This kind of information is a normal by-product of serving web pages and helping keep the site secure and functioning. We treat it as low-sensitivity operational data and do not use it to build a detailed personal profile of you.
Separately, if you agree, we may use analytics that help us understand which pages productions find useful, so we can improve our planning guides. Anything beyond what is strictly necessary to run the site is treated as non-essential and is only activated after you give consent through our cookie banner. You can decline non-essential analytics and still use the site fully. Our separate Cookie Policy explains the categories in detail and how to change your choice later.
We want to be precise about what we do not do. We do not sell your browsing information. We do not knowingly combine your casual browsing with your identity to track you across unrelated websites. We do not place personal or sensitive data into the address bar or share it through link parameters, because that is poor practice and a needless exposure risk.
The things we collect from visitors, in summary, are: server and security logs generated automatically, cookie-based preferences and, only with consent, analytics signals. None of this requires you to identify yourself. The moment you choose to contact us or send documents, a different and more careful set of practices applies, and those are described in the sections that follow. If you are only reading our guides to plan a shoot, you can do so with a light footprint and no obligation to share anything about yourself.
Information we collect when you contact us or engage the service
The more meaningful data collection happens when you decide to reach out. To respond to an enquiry or prepare a filming application, we need working details about you and your production. We collect only what is relevant to the task you have asked us to help with, and we ask you not to send us more than that.
When you send an enquiry, we typically receive your name, the organisation or production you represent, an email address or messaging handle, the country you are based in, and a description of what you plan to film, where, and roughly when. This lets us understand your request and reply usefully. If you go on to engage us, the information deepens because permit preparation is document-heavy.
A production engagement often involves us receiving materials that contain personal information about people other than you. These can include crew and cast lists with names, roles and nationalities; identity-page copies such as passport bio pages; scripts, treatments, synopses or shot lists; schedules and location plans; equipment inventories; insurance summaries; and contact details for local fixers, drivers or contributors. Some of this is genuinely sensitive, which is why our handling practices are strict.
We collect this information because you have asked us to help prepare an application, and preparing that application accurately requires it. We do not go looking for extra categories of data out of curiosity. If a particular document is not needed for your scope, we would rather you did not send it. Where you provide personal data about third parties, such as your crew, you are responsible for having a proper basis to share it with us for this purpose, and we handle it only to help with your application.
We also keep a reasonable record of our correspondence with you: the emails and messages exchanged, notes of what was agreed, versions of documents as they are refined, and the status of the work. This working record helps us serve you consistently, avoid asking twice for the same thing, and pick up where we left off if your production pauses and resumes. It is retained and eventually removed according to the Retention section below.
How we use your information
We use the information described above for a small, clearly defined set of purposes, all of which trace back to helping you plan and prepare a filming application, running our service properly, and keeping our site secure. We do not use your information for unrelated commercial exploitation.
The primary purpose is delivering the support you asked for. That means reading and understanding your enquiry, assessing what your production needs, identifying gaps in your documents, helping structure and prepare the paperwork, coordinating the practical steps of preparation, and communicating with you throughout. Every core use of your data serves this workflow.
A second purpose is communication and administration. We use your contact details to reply to you, to send you document requests and updates, to clarify points, and to keep an orderly record of the engagement. If you have an active matter with us, these messages are a necessary part of the service rather than marketing.
A third purpose is improving our guidance and running the website. With consent where required, aggregated and de-identified insight into which pages are used helps us write better planning resources. Technical logs help us keep the site available and defend it against abuse. We aim to work with information in a form that does not single you out whenever that is enough for the purpose.
We want to be equally clear about what we do not do. We do not sell your personal information. We do not rent your crew lists or contact details to advertisers. We do not use your confidential scripts or production materials for any purpose other than helping with your matter. We do not publish client names, testimonials or case details that identify you without your specific agreement, and any illustrative scenarios we write are generalised and not tied to a real client.
If we ever wanted to use your information for a genuinely new purpose not covered here, we would explain that purpose and, where the law requires it, seek your consent first. We will not quietly repurpose sensitive production data you entrusted to us for one job into something you did not agree to.
The legal bases we rely on
Different data-protection laws describe the justification for processing personal data in slightly different language, but the underlying idea is similar: we should each be able to point to a proper reason for handling your information. Which specific legal framework applies to you depends on where you are and which law governs your relationship with us, and we do not assert that one single regime covers every visitor. What follows is how we think about our reasons for processing.
Much of what we do rests on performing the service you have requested. When you engage us to help prepare an application, handling the documents and details needed to do that is a natural part of fulfilling your request. Without that information, we simply cannot do the job.
For optional things, such as non-essential analytics cookies, we rely on your consent. You choose whether to allow them, you are not disadvantaged if you decline, and you can withdraw that consent later. Consent is also the basis on which you share third-party personal data with us for your production, and you should ensure you are entitled to do so.
For a limited set of activities, such as keeping our website secure, maintaining basic business records, and protecting our service against misuse, we rely on our legitimate interest in operating a safe and functional service, balanced against your privacy. We keep this narrow and do not use it as a catch-all excuse for intrusive processing.
We may also process or retain certain information where a law that applies to us requires it, for example basic records that a business is expected to keep. Where that is the reason, the retention is limited to what the obligation actually requires.
If you are covered by a law that gives you specific enumerated rights, those rights operate on top of these bases, and the Your Rights section explains how to use them. Because the precise mapping of legal bases to rights varies by jurisdiction, we describe the practical substance here and confirm the specifics with you if you ask, rather than overstating a uniform legal position we could not honour everywhere.
Confidentiality and how we handle production documents
Confidentiality is at the heart of our service, because productions routinely share material that is commercially sensitive, creatively valuable, or personally identifying. We treat the documents you send us as confidential working material, to be used only for preparing your application and not for any other purpose.
As a matter of practice, access to your production materials is limited to the people working on your matter. We do not circulate your script, crew list or identity documents more widely than the work requires. When we prepare an application, we assemble only the elements that the relevant scope calls for, rather than forwarding everything you have ever sent us.
We ask you to help us keep your data safe by sharing sensitive files through secure means rather than, for example, pasting passport numbers into the body of an ordinary email. Ordinary email is convenient but not a strongly protected channel, so where sensitive documents are involved we prefer secure upload or protected transfer, and we will guide you on the safest way to send a given item. If you do send something highly sensitive through a less secure route, we still treat it confidentially, but the transmission itself is a risk we would rather avoid together.
Within our own systems, we apply access controls so that files are reachable by those who need them and not left openly available. We avoid keeping unnecessary duplicate copies scattered across tools, and we prefer a tidy, well-controlled set of records to a sprawl of loose attachments.
When your matter reaches the point where an application is submitted to a relevant authority, the material required for that submission passes out of our exclusive control and into a process governed by that authority. We will tell you what is being submitted. From that point, the authority's own record-keeping and confidentiality rules apply to the submitted copy, which is a normal and unavoidable feature of any official process and not something we can override.
We do not publish or reuse your confidential materials. Any planning examples on our website are written as generalised illustrations and are not drawn from a specific identifiable client's confidential file.
Where your information is stored and processed
Our service is based in Kathmandu, Nepal, and the core of our work happens there. To run a modern service, however, we rely on reputable third-party tools for things like email, file storage and website hosting, and those tools may store data on servers located in various countries. This means your information may be processed or stored outside your own country.
International transfer of data is an ordinary feature of using cloud-based tools, but it is one you should be aware of. If you are in a region whose laws restrict sending personal data abroad, you should factor that in when deciding what to send us and through which channel. We are happy to discuss what is involved for your particular situation.
We choose service providers with a view to reasonable security and reliability, and we limit what we place with any given provider to what the service needs. We do not scatter your sensitive documents across every tool we happen to use; we keep production materials within the controlled storage we use for that purpose.
We want to be honest about the limits of our influence here. We do not own the infrastructure of the hosting, email or storage providers we rely on, and we cannot guarantee the internal practices of those large platforms beyond what their own terms and security commitments provide. What we can do, and do, is select established providers, restrict access, avoid unnecessary copies, and remove data when it is no longer needed.
Where information is submitted onward to an authority as part of an application, it will be stored according to that authority's systems, which may well be within Nepal, and again under rules we do not set. If cross-border handling of a specific document is a concern for your production, raise it with us early. In some cases we can suggest a way to minimise what needs to travel, for example by preparing certain material differently, though we cannot change the fundamental requirement that an application must contain what the process requires.
Third parties and service providers
We keep the circle of people and companies who touch your data deliberately small. There are, however, a few categories of third party involved in running our service, and you deserve to know who they are in general terms and why they exist.
The first category is the operational tools we use to function: a website host that serves these pages, an email provider that carries our correspondence, and secure storage where production files are kept. These providers process data on our behalf so that we can deliver the service, and they are not free to use your information for their own unrelated purposes.
The second category, only where you have consented, is analytics that help us understand website usage in aggregate. This is optional, is governed by our Cookie Policy, and can be declined without affecting your ability to use the site or engage us.
The third category is any specialist we might coordinate with directly at your request as part of your matter, for example where a particular practical step of preparation calls for it. We would not bring an outside party into your confidential materials without a clear reason connected to your engagement, and we keep any such sharing to the minimum needed for the task.
Crucially, the ultimate recipient of a completed application is the relevant authority, decided by your locations and activities. Submitting an application necessarily means the required contents reach that authority. That is the purpose of the exercise, not a leak, but it does mean your information enters an official process at that point.
We do not sell, rent or trade your personal information to data brokers, advertisers or list-builders. We do not send your data to recipients suggested by third-party content rather than by you. If a provider we rely on changes in a way that materially affects how your data is handled, we will update this policy. Should you want to know, at the time of your engagement, which specific tools would be involved in your matter, simply ask and we will tell you plainly.
How we protect your information
No service can promise perfect security, and you should be wary of anyone who claims to. What we can and do commit to is applying sensible, layered protections proportionate to the sensitivity of what you share, and being honest about the limits.
On access, we restrict production materials to the people working on your matter and avoid leaving files openly reachable. We prefer secure upload or protected transfer for sensitive documents over ordinary email, and we will steer you toward the safer channel for anything that identifies a person, such as passport pages. Where we use links to share or collect files, we favour protected links rather than permanently public ones.
On storage, we keep production data within controlled storage rather than scattering copies across every tool. We reduce duplication, because every extra copy is another thing to protect and later delete. We remove material when it is no longer needed, which shrinks the amount of sensitive data sitting around over time.
On transmission, we recognise that email is convenient but not strongly protected, so we treat it as unsuitable for the most sensitive items and guide you accordingly. We never place personal or sensitive information into web addresses or query strings, and we ask you not to either.
We also depend on you as a partner in security. Sending sensitive files through the channel we recommend, not over-sharing documents that your scope does not require, and keeping your own accounts secure all materially reduce risk. Security is a shared effort, and the tidiest, safest engagements are ones where both sides are deliberate about what is shared and how.
If, despite these measures, we became aware of a security incident that materially affected your personal information, we would act to contain it and inform you where it was appropriate and where any applicable law required us to do so. We would rather tell you plainly about a problem than paper over it. What we will not do is pretend that any system is immune, because that would be dishonest and would give you a false basis for deciding what to entrust to us.
How long we keep your information
We keep information only as long as there is a good reason to, and then we remove it. The right retention period depends on the type of data and why we hold it, so rather than quote a single figure that would be misleading, we explain the principles we follow.
While your matter is active, we keep the working file: your correspondence, the documents you have shared, the versions we have prepared, and notes on what has been agreed. This is simply the live material of the job, and keeping it is what lets us serve you consistently without asking for the same things twice.
After a matter concludes, we keep a limited record for a reasonable period. This helps if your production revives the project, if a question arises about what was done, or if we need it for ordinary business record-keeping. We do not, however, keep sensitive production materials indefinitely just because we once received them.
Highly sensitive items, such as copies of identity pages, are candidates for earlier removal once they are no longer needed for the task, because holding them longer than necessary only increases risk without benefit. Where you ask us to delete such material earlier, we will do so unless we are genuinely required to retain something, and we would explain any such exception.
Casual website data, such as technical logs and consent preferences, follows its own shorter lifecycle appropriate to operational and security needs rather than being tied to any engagement.
When the retention reason ends, our aim is deletion or secure removal from the systems within our control. We should be candid about two limits. First, routine backups may retain copies for a while before cycling out, which is normal for any backed-up system. Second, anything already submitted to an authority as part of an application lives on in that authority's records under its own retention rules, entirely outside our control. If you have a specific retention concern, tell us and we will explain what is realistic for your situation rather than promising an outcome we cannot deliver.
Cookies and website tracking
Our website uses a small number of cookies and similar technologies, and we keep this deliberately restrained. This section is a summary; our separate Cookie Policy covers the detail, but the essentials belong here too so you have the full picture in one place.
Some cookies are strictly necessary for the site to work: they do things like remember your cookie choice or keep the site secure and functioning as you move between pages. These do not require consent because the site cannot sensibly operate without them, and they are not used to profile you for advertising.
Any cookies beyond that baseline, such as analytics that help us see which planning guides are useful, are non-essential. We do not switch these on until you have given consent through our cookie banner. You are free to decline them, and if you do, the site remains fully usable and your ability to contact or engage us is unaffected.
We design our banner to make declining non-essential cookies as easy as accepting them, and to default to the more privacy-protective option rather than quietly opting you in. You can change your mind at any time by adjusting your choice, and your browser also gives you controls to block or delete cookies directly.
We do not use cookies to sell your data or to follow you around the wider web for advertising purposes. Our interest is narrow: keeping the site working and, with your permission, understanding in aggregate how our guides are used so we can improve them.
Because cookie rules and expectations differ by region, some visitors will see a consent banner and others may see a simpler notice, reflecting what is appropriate where you are. Whatever you see, the underlying commitment is the same: essential cookies only by default, anything extra only with your agreement, and a clear route to change your choice. For the categorised breakdown and instructions on managing cookies in common browsers, please see the Cookie Policy.
Your rights and choices
Depending on where you live and which law applies to you, you may have specific, enforceable rights over your personal information. We support the substance of these rights for everyone we work with as a matter of good practice, while being honest that the exact catalogue of rights, and how strictly they bind us, depends on your jurisdiction.
In practical terms, you can ask us what personal information we hold about you and request a copy of it. You can ask us to correct information that is wrong or out of date. You can ask us to delete information we no longer need, subject to any genuine obligation to retain something. You can object to or ask us to limit certain uses, and where we rely on your consent, you can withdraw it. You can also ask us not to use non-essential cookies, which you control directly through the banner.
Because our work is document-based, some of these requests are straightforward for us to action. If you ask us to delete a passport copy we no longer need, for instance, we can usually do that promptly. Where a request runs into a real limit, such as material already submitted to an authority or copies persisting briefly in backups, we will tell you plainly rather than implying a cleaner outcome than reality allows.
To exercise any of these choices, contact us using the details in the Contact section. We may need to confirm your identity before acting, so that we do not disclose or change someone's information at the wrong person's request; this protects you as much as us. We will respond within a reasonable time and, where a law sets a specific deadline that applies to you, we aim to meet it.
You will not be penalised for exercising a right. Asking what we hold, or asking us to delete something, will not cause us to treat you or your production less favourably. If you are unhappy with how we have handled your information, you may also have the right to complain to a relevant data-protection authority in your jurisdiction, and we would encourage you to raise it with us first so we can try to put it right.
Children's and third-party personal data
Our website and service are aimed at productions and professionals, not at children, and we do not knowingly collect personal information directly from children through our site. If you believe a child has provided us information directly, please contact us so we can address it.
That said, production work sometimes involves footage or documentation concerning minors, for example where a shoot includes young performers or where a documentary or institutional project features beneficiaries who are children. When your materials contain personal information about minors, that data deserves heightened care, and we treat it as sensitive. We rely on you to have obtained the proper consents from parents or guardians as required for your production, because we are helping prepare your application and are not the party running the shoot or gathering those consents on the ground.
More broadly, much of what you send us is personal data about other people: your crew, your cast, your contributors, your local contacts. When you share that with us, you are representing that you have a proper basis to do so for the purpose of preparing your application. We use it only for that purpose, keep it confidential, and remove it in line with our retention approach.
We encourage you to share the minimum third-party personal data that your scope actually requires. If a document identifying individuals is not needed for the particular permission you are seeking, it is better not to send it. This protects those individuals and reduces the amount of sensitive data that has to be handled and later deleted.
Where your project touches sensitive subjects or vulnerable contributors, the ethical handling of consent and privacy on the ground remains your responsibility as the production. Our role is to help prepare the paperwork properly and to treat whatever you entrust to us with confidentiality and care, not to substitute for the consents and safeguards that a responsible production puts in place with the people it films.
Changes to this policy and how we notify you
This policy will change over time. Our tools evolve, laws change, and our own practices improve, so a privacy policy is a living document rather than a fixed one. When we make changes, we do so openly and keep the current version available on this page.
For routine updates, such as clarifying wording or reflecting a minor operational change, we update the page and the effective date. These do not alter the fundamental commitments we make to you, and reading the refreshed page is the way to stay current. We recommend glancing at this policy again if you are about to send us a fresh batch of sensitive material after a long gap.
For material changes, meaning ones that meaningfully affect how we handle your personal information or your choices, we take more care. Where you have an active matter with us and we hold your contact details, we would aim to draw a significant change to your attention rather than relying on you to notice it, and where a change requires your consent under the law that applies to you, we would seek that consent rather than assuming it.
We will not use a quiet edit to strip away protections you were relying on when you shared sensitive documents with us. If our handling of something you already entrusted to us were to change in a way that matters, our instinct is to tell you, not to bury it in a revised clause.
Because we serve productions in many countries, the precise notification steps that a given law requires vary, and we do not claim a single universal procedure. What is constant is the principle: transparency about what changed, the current version always published here, heightened attention for material changes, and consent sought where it is legally needed. If you ever want to understand how a change affects your particular engagement, ask us and we will explain it in relation to your own situation.
How to contact us about your information
If you have any question about this policy, want to know what we hold about you, or wish to exercise any of the choices described above, please get in touch. We would always rather hear from you directly and resolve a concern than have you left uncertain about how your information is handled.
The most reliable route is to contact us through the details published on our Contact page. When you write, it helps to tell us clearly what you are asking for: for example, a copy of your information, a correction, deletion of a specific document, a question about how something is stored, or a change to your cookie choice. The more specific you are, the faster and more accurately we can help.
For sensitive requests, we may need to take reasonable steps to confirm we are dealing with the right person before we act, particularly where a request involves disclosing or deleting personal information. This is a protection for you, not an obstacle: it stops someone else from accessing or altering your data by pretending to be you. We will keep any such verification proportionate to the sensitivity of the request.
We aim to acknowledge requests promptly and to resolve them within a reasonable time. Where a law that applies to you sets a specific response deadline, we work to meet it. If a request is complex, or if part of it runs into a genuine limit such as material already submitted to an authority, we will explain the position honestly rather than going quiet.
If you are not satisfied with our response, we encourage you to tell us so we can try again, and depending on your jurisdiction you may also be able to raise the matter with a relevant data-protection authority. We treat complaints as a chance to do better. Because our work runs on trust with confidential and personal materials, keeping that trust by being reachable, straightforward and honest about your information is something we take seriously.
| Information type | When we collect it | Why we hold it | How we treat it |
|---|---|---|---|
| Server and security logs | Automatically, when you view any page | Keeping the site available and secure | Low-sensitivity operational data, short lifecycle, not used to profile you |
| Cookie preferences | When you respond to the cookie banner | Remembering your choice and running the site | Essential; retained only as long as useful for the setting |
| Analytics signals | Only if you consent | Understanding in aggregate which guides are useful | Optional, declinable, de-identified where possible |
| Enquiry details (name, contact, production summary) | When you contact us | Understanding and replying to your request | Kept as working correspondence, removed after a reasonable period |
| Production documents (scripts, schedules, plans) | When you engage the service | Preparing and organising your application | Confidential, access limited to your matter, not reused or published |
| Identity-page copies and crew personal data | When your scope requires it | Assembling required application contents | Sensitive; secure transfer preferred, earliest safe deletion |
| Correspondence and status records | Throughout an engagement | Serving you consistently and keeping an orderly record | Retained during the matter, limited record kept afterward |
What the service includes
- Plain-language explanation of what data we collect from visitors and clientsnHow we use information and the purposes we will not use it fornOur confidentiality and document-handling practices for sensitive materialsnRetention principles and honest limits (backups, submitted applications)nYour rights to access, correct, delete and object, and how to use themnCookie summary and the route to decline non-essential trackingnContact details and what to expect when you make a request
What the service excludes
- Any claim to be a government office, permit issuer or official authoritynGuarantees of perfect security or that no incident can ever occurnControl over how an authority stores an application once it is submittednControl over the internal practices of third-party hosting or email platformsnInvented statutory citations, named regulators, or jurisdiction-specific legal guarantees presented as universalnSelling, renting or trading your personal informationnLegal advice on your data-protection obligations as a production
Frequently asked questions
Are you a government body that stores my data in an official register?
No. Film Permits Nepal is an independent private production-support company in Kathmandu, not a government office and not a permit issuer. When you share information with us, you are giving it to a private service that helps prepare your paperwork, not lodging it with a state database. We help organise and prepare applications, but the decision to grant filming permission and any official record of a submitted application rest with the relevant authority, not with us. Please keep this distinction in mind when deciding what to send us.
Do I have to give you any personal information just to read your guides?
No. You can read our planning guides and browse the site without telling us who you are or creating an account. Some limited technical information is generated automatically when your browser requests pages, and optional analytics run only if you consent. If you never contact us, you never have to identify yourself. The moment you choose to send an enquiry or documents is the moment more detailed data handling begins, and that is entirely your choice.
How should I send you sensitive documents like passport pages?
Please use a secure upload or protected transfer method rather than pasting sensitive details into an ordinary email, and we will guide you to the safest channel for a given item. Ordinary email is convenient but not strongly protected, so we treat it as unsuitable for the most sensitive material such as identity pages. If you do send something highly sensitive through a less secure route, we still handle it confidentially, but the transmission itself is a risk we would rather avoid together. Sharing only the documents your scope actually requires also reduces exposure.
Do you sell or share my information with advertisers or data brokers?
No. We do not sell, rent or trade your personal information, your crew lists, or your contact details to advertisers, data brokers or list-builders. The only third parties involved are the operational tools we use to run the service, optional analytics you consent to, and the authority that ultimately receives a completed application. We do not send your data to recipients suggested by outside content rather than by you. Your confidential production materials are used only to help with your matter.
Who can see my script and production files inside your service?
Access to your production materials is limited to the people working on your matter. We do not circulate your script, crew list or identity documents more widely than the work requires, and when we prepare an application we assemble only the elements that scope calls for rather than forwarding everything you have sent. We keep files in controlled storage, avoid unnecessary duplicate copies, and remove material when it is no longer needed. We do not publish or reuse your confidential materials, and any examples on our site are generalised illustrations, not real client files.
How long do you keep my documents after the work is finished?
We keep the working file while your matter is active, then retain a limited record for a reasonable period afterward in case the project revives or a question arises. Highly sensitive items such as identity-page copies are candidates for earlier removal once they are no longer needed. When the reason for holding something ends, our aim is deletion from the systems we control. Two honest limits apply: routine backups may retain copies briefly before cycling out, and anything already submitted to an authority lives on in that authority's records under its own rules.
Can I ask you to delete my information?
Yes. You can ask us to delete information we no longer need, and because our work is document-based this is often straightforward, for example removing a passport copy we no longer require. Contact us with a clear description of what you want deleted. We will honour the request unless we are genuinely required to retain something, in which case we will explain the exception. We will also be honest about limits we cannot override, such as material already submitted to an authority or copies persisting briefly in backups before they cycle out.
What rights do I have over my personal information?
Depending on where you live and which law applies to you, you may have rights to access a copy of your information, correct it, delete it, object to or limit certain uses, and withdraw consent where we rely on it. We support the substance of these rights for everyone we work with as good practice, while being honest that the exact catalogue and how strictly it binds us depends on your jurisdiction. To exercise a right, contact us using the details on our Contact page. We may confirm your identity first so we do not act on the wrong person's request.
Is my data stored in Nepal or somewhere else?
Our service is based in Kathmandu and the core of our work happens there, but we rely on reputable third-party tools for email, storage and hosting, and those may store data on servers in various countries. This means your information may be processed outside your own country, which is a normal feature of using cloud-based tools. If you are in a region whose laws restrict sending data abroad, factor that in when deciding what to send us, and raise it with us early so we can discuss ways to minimise what needs to travel.
Do you use cookies, and can I turn them off?
We use a small number of cookies. Strictly necessary ones keep the site working and remembering your choices, and do not require consent. Anything beyond that, such as analytics, is non-essential and runs only after you consent through our banner. You can decline non-essential cookies and still use the site fully, and you can change your mind at any time or block cookies through your browser. We do not use cookies to sell your data or track you across the web for advertising. See our Cookie Policy for the full breakdown.
I am sending you crew and contributor details. What are my responsibilities?
When you share personal data about your crew, cast or contributors, you are representing that you have a proper basis to do so for the purpose of preparing your application. We use that data only for your matter, keep it confidential, and remove it in line with our retention approach. Please share the minimum that your scope actually requires; if a document identifying people is not needed for the permission you are seeking, it is better not to send it. Where your project involves minors or vulnerable contributors, obtaining the necessary consents on the ground remains your responsibility as the production.
Can you guarantee my information will never be breached?
No, and you should be cautious of anyone who claims otherwise. No system is immune, so instead of an empty promise we apply layered, proportionate protections: restricted access, secure transfer for sensitive files, controlled storage, minimal duplication, and prompt removal when data is no longer needed. If we became aware of an incident that materially affected your personal information, we would act to contain it and inform you where appropriate and where any applicable law required. Security is also a shared effort, and sending sensitive files through the recommended channel meaningfully reduces risk.
What happens to my data once an application is submitted to an authority?
Once the required contents of a completed application are submitted to the relevant authority, that material passes out of our exclusive control and into a process governed by that authority. We will tell you what is being submitted. From that point, the authority's own record-keeping, retention and confidentiality rules apply to the submitted copy, and those are outside our control. This is a normal and unavoidable feature of any official process. If cross-border or retention handling of a specific document concerns you, raise it early and we can sometimes suggest ways to minimise what needs to be included.
Will this policy change, and how will I know?
Yes, a privacy policy is a living document. For routine updates we revise this page and its effective date. For material changes that meaningfully affect how we handle your information or your choices, we take more care: where you have an active matter and we hold your contact details, we aim to draw a significant change to your attention, and where a change requires your consent under the law that applies to you, we seek it. We will not use a quiet edit to strip away protections you relied on when sharing sensitive material. The current version is always published here.
How do I contact you with a privacy question or complaint?
Reach us through the details on our Contact page, and tell us clearly what you are asking for, whether that is a copy of your information, a correction, deletion, a storage question or a cookie change. We aim to acknowledge requests promptly and resolve them within a reasonable time, meeting any specific deadline a relevant law sets for you. If a request is complex or runs into a genuine limit, we will explain it honestly rather than going quiet. If you are unhappy with our response, please tell us so we can try again, and depending on your jurisdiction you may also raise the matter with a relevant data-protection authority.