Confidentiality and document security sit at the centre of any working relationship between a foreign production and a local support service. When you prepare a film permit application for Nepal, you assemble a package of sensitive material: passport pages, company registration papers, insurance certificates, scripts or treatments, crew lists with personal details, equipment inventories with declared values, and sometimes contributor consent forms. This material belongs to you and to the people named within it, and it deserves careful handling from the moment it reaches us to the moment it is deleted.
Film Permits Nepal is an independent private production-support service based in Kathmandu. We are not a government office and we do not issue permits. What we do is help you organise, review, and present the documents that the relevant authorities expect, so this page explains exactly how the information you share is received, stored, accessed, retained, and eventually removed. It also states plainly where the practical limits lie, because honest description of limits is part of real security.
The aim here is not to overwhelm you with jargon or to promise perfection. It is to give you a clear, calm picture of how we treat your files so that you can make an informed decision before you send anything. We describe our own handling, your responsibilities as the sender, and the shared habits that keep a document package safe across a project that may run for weeks. Read this alongside our privacy policy and our terms, which cover the wider legal framework for the service.
What this page covers and why it matters
A film permit package is a concentration of sensitive information. In one folder you may hold identity documents for a dozen people, financial figures for imported equipment, an unreleased creative treatment, and the personal details of interview contributors who never signed up to have their data travel across borders. Treated carelessly, that folder is a liability. Treated properly, it is simply a working set of files that moves through a defined process and is then cleared away.
This page exists so that you know, before you share anything, how we handle that concentration of information. It describes the categories of data we typically receive, the way files are stored and named, who can open them, how we move drafts back and forth, how long anything is kept, and how it is deleted. It also sets out the boundaries of what any private service can realistically guarantee, because a security page that only lists strengths is not telling you the whole story.
We write this in plain terms rather than legal abstraction. Where a specific technical or regulatory point depends on your circumstances, we say so rather than assert a blanket rule. The document-handling described here reflects our standard working practice. Individual engagements can be adjusted, for example when a broadcaster or studio has its own information-security requirements that we agree to follow, and those specifics are confirmed with you directly rather than promised in advance on a public page.
Confidentiality is not only a technical matter of servers and passwords. It is also a matter of discipline: knowing which files should exist, keeping the number of copies small, and removing material when the work is done. Much of what follows is about that discipline, because in practice it protects a production at least as much as any single tool or setting. If any part of this page raises a question about your particular project, the security contact at the end is the right place to start.

Categories of data we typically receive
Before explaining how material is handled, it helps to be specific about what a permit package usually contains. Foreign productions preparing to work in Nepal generally share several distinct categories of information, and each carries a different sensitivity profile.
Identity and personal documents form the first category. These include passport pages, photographs, and personal details for producers, crew, and sometimes cast or contributors. This material identifies real people and is the most sensitive to mishandle.
Company and financial documents form the second category. These include business registration papers, letters of authority, insurance certificates, and equipment inventories that state declared values. They reveal commercial information about your organisation and your production budget.
Creative materials form a third category. Scripts, treatments, storyboards, shot lists, and synopses are often confidential for competitive or editorial reasons, and in some cases are under embargo until release.
Operational records form the fourth category. Shooting schedules, location lists, crew movement plans, and equipment logistics fall here. They may seem mundane but together they describe where your people will be and when.
Finally, contributor and consent material can appear, particularly for documentary and factual work: interviewee details, release forms, and notes about vulnerable participants.
- Identity documents: passport pages, photos, personal details
- Company records: registration, authority letters, insurance
- Creative materials: scripts, treatments, storyboards
- Operational records: schedules, location and movement plans
- Contributor material: consent forms, interviewee details

How files are received
The first moment of risk in any document exchange is the handover itself. How a file travels from your side to ours matters as much as how it is stored afterwards, because information intercepted in transit is just as exposed as information left unguarded on a shelf.
Our preference is for files to reach us through a controlled upload route rather than as loose email attachments. A controlled route means you place the file into a defined destination we have set up for your project, rather than sending it into the general flow of email where copies scatter across servers and inboxes outside anyone's control. When you request permit support, we provide guidance on the current preferred method so that you are not guessing.
When you send material, a few habits on your side strengthen the whole chain. Send only what is asked for, so that sensitive documents are not shared speculatively. Name files clearly so that they can be identified without being opened repeatedly. Where a document contains information beyond what the permit process needs, consider whether portions can be redacted before sending, particularly for contributor material.
We confirm receipt of what you send so that you are never left wondering whether a sensitive file arrived or drifted. If something looks incomplete or appears to have been sent to the wrong place, we tell you promptly rather than quietly working around it. The exact upload mechanism can evolve as tools change, so we describe the current method to you directly at the point of engagement rather than fixing a specific product name on this page, which could become outdated. The underlying principle stays constant: a defined destination, confirmed receipt, and the smallest reasonable number of copies in motion.

How files are stored
Once a file reaches us, it needs a home that is organised rather than scattered. Disorganised storage is itself a security weakness, because nobody can protect or delete what they cannot find. Our working approach is to keep the documents for each engagement grouped together in a defined project space rather than spread across personal devices, random folders, and message threads.
Within that project space, files are organised by the categories described earlier, so that identity documents, creative materials, and operational records each sit in a predictable place. This structure serves a security purpose as well as a practical one: it means that when a project closes, the material to be removed is in known locations rather than hidden in forgotten corners.
We aim to keep the number of copies of any sensitive document small. Every additional copy is another thing that must be tracked and eventually deleted, so restraint in duplication is a deliberate habit rather than an afterthought. Working drafts, such as an application form being assembled, are kept in the same controlled space rather than emailed around as attachments.
Storage that carries sensitive material should be protected by access controls rather than left open, and the accounts that reach it should themselves be protected by strong, unique credentials. The specific storage arrangements can vary with the tools in use and with any client-specific requirements a broadcaster or studio brings, and we confirm those details with you rather than stating a fixed technical configuration here that might change. What does not change is the principle: grouped, organised, access-controlled storage with the fewest copies necessary to do the work.

Who can access your documents
Security is not only about where files live but about who can open them. A document held in a well-protected space is still exposed if too many people can reach it. Our working principle is that access to your material is limited to the people working directly on your engagement.
In practice this means the coordinator or coordinators handling your project, and where necessary a reviewer checking the document package, can reach your files. It does not mean that everyone associated with the service browses every client's material as a matter of routine. Access follows need: a person who is not working on your project has no working reason to open your files.
Where a specialist is brought in for a particular task, for example a customs specialist reviewing an equipment inventory, they receive only the material relevant to that task rather than your entire package. This keeps the circle of people who have seen any given document as small as the work allows, which is one of the most effective and least technical security measures available.
We also treat the human side of access seriously. The people handling your documents understand that the material is confidential and is not to be discussed, forwarded, or shown outside the working relationship. Confidentiality obligations of this kind are part of how the service operates, and any specific contractual confidentiality terms relevant to your engagement are set out in your agreement rather than promised in the abstract here. If your production requires a signed non-disclosure arrangement before you share anything, that can be discussed at the outset.

How drafts and links are shared
Much of the work involves moving drafts back and forth: an application form takes shape, a document list is annotated, a gap report is returned to you for action. How these exchanges happen affects security just as much as the initial upload, because every round trip is another opportunity for a file to end up somewhere it should not.
Where we share a document or a draft back to you, our preference is to use a controlled sharing method rather than scattering attachments across email. A controlled method means the material sits in a defined place that you can reach, rather than being copied into every reply in a long thread. When a shared link is used to give you access to a file, that link is intended for you and the people on your side who need it, not for wider distribution.
We ask that you treat links and shared material with the same care on your side. A link that reaches your project is a route into a document, so it should not be forwarded beyond the people who genuinely need it, and it should not be posted into open channels or public messages. If you believe a link has been shared too widely or has reached the wrong person, tell us so that access can be reconsidered.
The specific tools used for sharing can change over time, and any particular product may offer options such as links that expire or that require the recipient to be recognised. We use the controls available in the tools in play for your engagement and describe the current arrangement to you directly. Rather than name a specific feature here as a permanent promise, the commitment we make is to the principle: shared material goes to defined recipients through controlled routes, and access can be revisited if circumstances change.

Retention and deletion
Keeping documents forever is not a virtue. A file that no longer serves a working purpose is not an asset; it is a standing risk that must still be protected and could still be exposed. Our approach to retention is therefore to hold your material for as long as the work reasonably requires and then to remove it.
During an active engagement, your documents are kept because they are in use: the application is being prepared, clarifications are being handled, additional permissions may be in progress. Retaining the package during this period is simply part of doing the work you have asked for.
Once a project reaches its natural close, the material generally no longer needs to be held. At that point the working practice is to remove the documents that are no longer required, so that your sensitive material does not accumulate indefinitely on our side. Because storage is organised by project, this removal is a deliberate act on known locations rather than a hopeful sweep.
There are sensible exceptions to immediate deletion. Some records may be kept for a limited period to support follow-up questions, corrections, or a related phase of the same production, and some retention may reflect ordinary business or legal record-keeping. The specific retention arrangement for your engagement, including how long anything is kept and what is kept, is confirmed with you rather than stated as a single fixed rule here, because it depends on the nature of your project and any requirements your organisation brings. If you want particular material removed at a particular time, that is a reasonable request to make explicitly, and it is easier to honour when it is agreed at the outset rather than assumed.

The limits of email
Email deserves its own honest discussion, because it is both the most convenient tool and one of the least controlled. Ordinary email was not designed as a secure channel for sensitive documents, and pretending otherwise would do you a disservice.
When a document travels as an email attachment, copies of it come to rest in several places outside anyone's direct control: your sent folder, our inbox, the servers that carried it, and any device where the message is downloaded. Each of those copies persists after the moment of sending and is difficult to retrieve or delete. A single attachment can quietly become half a dozen lasting copies.
Email is also vulnerable to simple human error. A message can be sent to the wrong recipient with one mistaken character, forwarded onward without thought, or included in a reply-all that widens the audience far beyond what was intended. None of these failures involve any sophisticated attack; they are everyday mistakes, and sensitive attachments make them costly.
For these reasons we prefer that sensitive documents move through a controlled upload or sharing route rather than as email attachments. Email remains perfectly appropriate for ordinary correspondence, questions, and coordination, and we use it for that. Where a sensitive document does need to be discussed over email, we favour referring to it rather than attaching it repeatedly. We also ask that you avoid placing highly sensitive details, such as passport numbers or personal identifiers, directly into the body of an email where they become part of a lasting, widely copied record. When in doubt, send less by email and use the controlled route for the document itself.

Backups and continuity
Backups sit at an interesting tension in any security discussion. On one hand, keeping a copy of important material protects you against accidental loss, which is itself a form of protecting your interests. On the other hand, every backup is another copy of sensitive information that must be secured and eventually removed. Good practice respects both sides of that tension.
Where backup copies of working material exist, the same principles that govern the primary files apply to them: they should be access-controlled, limited in number, and included in the deletion process when a project closes. A backup that is forgotten becomes exactly the kind of orphaned copy that undermines retention discipline, so backups are treated as part of the managed set rather than as a separate, invisible layer.
Continuity matters to you as a client because a production runs to a schedule. If a working file were lost at a critical moment, the consequence would be practical disruption to your project, not merely an inconvenience to us. Sensible backup practice exists to prevent that kind of disruption while a project is live.
We do not make elaborate claims about backup infrastructure, because the specific arrangements depend on the tools in use and can change over time. What we can say plainly is the principle we work to: copies made for continuity are managed with the same care as the originals, are not allowed to multiply without control, and are cleared as part of closing out an engagement. If your organisation has specific requirements about how copies of its material may be stored or where, raise them at the start so that they can be reflected in how your engagement is handled.

Hosting and third-party tools
No modern service operates entirely on its own equipment. Storage, sharing, and communication typically rely on third-party tools and hosting providers, and honesty requires acknowledging that some of your document security therefore depends on parties beyond us. Pretending that everything happens within a sealed system we fully control would be misleading.
What we can do, and do, is choose working tools thoughtfully and use the controls those tools provide. Where a tool offers access controls, we use them. Where it offers the ability to limit sharing, we prefer the more restrictive setting. The aim is to configure the tools we rely on in a way that respects the sensitivity of what you have shared, rather than accepting loose defaults.
There are limits to this that we cannot honestly overstate. A hosting provider or platform has its own security practices, its own jurisdiction, and its own terms, and those are ultimately outside our direct control. If a widely used platform experiences a problem, that is a risk shared by everyone who uses it, and no private service can promise immunity from it. Being clear about this is more useful to you than a false guarantee.
Because tools change, this page does not lock itself to specific product names that might be outdated tomorrow. If you have a concern about a particular platform, or a requirement that certain tools be used or avoided for your material, tell us at the outset. Where a broadcaster or studio brings its own approved systems, we can discuss working within them. The commitment we make is to use available controls conscientiously and to be straightforward with you about where the boundaries of our control actually lie.

Your responsibilities as the sender
Document security is a shared effort, not something one party can deliver alone. A great deal of the real exposure in any exchange sits on the sending side, before a file ever reaches us, and there are practical steps within your control that protect your own material.
The first is discipline about what you send. Share the documents that the permit process needs, rather than sending everything speculatively because it is easier. The fewer sensitive documents in circulation, the smaller the surface that can be exposed. This is especially important for contributor material and identity documents.
The second is care about how you send. Use the controlled route we describe rather than defaulting to email attachments for sensitive files. Double-check the destination before sending, since a mistaken recipient is one of the most common and avoidable failures. Confirm that the file you are sending is the one you intend.
The third is discipline on your own side. The security of your files depends partly on the security of your own devices and accounts: a strong, unique password on the account you send from, a locked device, and awareness of who on your team can reach your production's shared folders. A carefully protected upload route does little good if the sending account is itself compromised.
- Send only the documents the permit process actually requires
- Use the controlled route rather than email for sensitive files
- Verify the destination before sending anything sensitive
- Protect your own devices and sending accounts with strong credentials
- Limit who on your team can reach shared production folders
- Tell us promptly if you suspect a file went to the wrong place

Confidentiality of creative and contributor material
Two categories of material deserve special attention because their sensitivity goes beyond ordinary data protection: creative works and contributor information. Each carries risks that are not purely technical, and each benefits from deliberate handling.
Creative material, meaning scripts, treatments, storyboards, and synopses, is often confidential for competitive or editorial reasons and may be under embargo until a release date. A leaked treatment can undermine a project commercially or spoil a planned announcement. We treat creative documents as confidential working material, share them only with the people who need them for the permit work, and do not circulate them beyond that circle. If your project is under a formal embargo or non-disclosure regime, tell us so that we handle it with the appropriate care from the start.
Contributor material, which appears most often in documentary, factual, journalism, and institutional work, is sensitive for a different and important reason: it concerns real people who may be vulnerable, and who consented to appear in your project, not to have their details handled by additional parties. Interviewee details, consent forms, and notes about participants deserve particular restraint.
For contributor material we encourage you to share only what the permit process genuinely requires, and to consider whether identifying details can be minimised or redacted before sending. Where a project involves sensitive subjects, minors, or people who could be put at risk by exposure, the handling of their information is a serious matter that should be discussed explicitly rather than left to routine. We do not treat consent forms and participant details as ordinary paperwork, and we will not knowingly circulate them beyond the necessary working circle. If your project carries this kind of sensitivity, raise it early so that handling can be agreed in detail.

When something goes wrong
Honest security planning assumes that mistakes and incidents are possible, not impossible. A page that only describes safeguards, without acknowledging what happens when something slips, is incomplete. This section describes the practical stance we take when a problem arises with a document.
If we become aware that a file has gone somewhere it should not, that a link has been shared too widely, or that material has been accessed or sent in error, our approach is to tell you rather than to quietly work around it. You are the person with the most at stake in your own documents, and you cannot make good decisions about your project if you are kept in the dark about a problem affecting your material.
Equally, if you discover a problem on your side, the most useful thing you can do is tell us promptly. If a wrong file was sent, a link was forwarded too far, or a document should never have been shared, letting us know quickly gives the best chance of limiting the consequences, for example by reconsidering access to a shared link. Delay tends to make matters harder to contain.
We do not make dramatic promises about guaranteed outcomes when something goes wrong, because no honest service can guarantee that a file, once exposed, is fully recoverable. What we can commit to is a straightforward response: prompt notification, a practical effort to limit further exposure using the controls available, and clear communication with you about what happened and what is being done. The security contact at the end of this page is the direct route for raising any concern of this kind, and we would always rather hear about a suspected problem early than discover it late.

How this connects to the wider service
Document security does not stand alone. It is one part of how the whole support service operates, and it connects to several other commitments that together describe how we work with you. Understanding those connections helps you see where this page fits.
Our privacy policy covers the wider legal framework for the personal data you share: what is collected, how it is used, the basis for using it, and the rights you have over it. This document-security page describes the practical handling of files, while the privacy policy addresses the legal dimension, and the two are meant to be read together.
Our terms of service set out the scope of what we do and do not do, including the important fact that we are an independent private service and not a permit-issuing authority. Nothing on this security page changes that scope: careful document handling is part of the support we provide, not a claim to any official function.
Our source and verification approach governs how we check regulatory facts, and our corrections process governs how errors in published guidance are fixed. Those are separate from document security but reflect the same underlying attitude: be careful, be honest about limits, and be straightforward when something needs correcting. Taken together, these commitments describe a service that treats both your information and your trust as things to be handled with care. If you are weighing whether to work with us, reading this page alongside the privacy policy and terms gives you the fullest picture of how your material and your project will be handled.

| Material category | Sensitivity | Preferred sharing method | Handling principle |
|---|---|---|---|
| Identity documents (passport pages, personal details) | High: identifies real people | Controlled upload route | Access limited to project coordinators; removed at project close |
| Company and financial records (registration, insurance, equipment values) | Commercially sensitive | Controlled upload route | Grouped in project space; shared only with those doing the work |
| Creative materials (scripts, treatments, storyboards) | Confidential, sometimes embargoed | Controlled upload or sharing route | Treated as confidential; not circulated beyond the working circle |
| Operational records (schedules, location and movement plans) | Sensitive in aggregate | Controlled upload route | Kept organised; access follows need |
| Contributor material (consent forms, interviewee details) | High: concerns real, sometimes vulnerable people | Controlled route; minimise or redact first | Handled with special restraint; discussed explicitly for sensitive subjects |
| Ordinary correspondence and questions | Low | Email is appropriate | Sensitive details kept out of email bodies |
How each category of material is typically handled through an engagement
What this includes
- Guidance on a controlled route for sending sensitive documents to us
- Organised, access-controlled storage of your material grouped by project
- Access limited to coordinators and reviewers working on your engagement
- Controlled sharing of drafts and documents back to you
- Confirmation of receipt for sensitive files you send
- Retention of your package for as long as the work reasonably requires, then removal
- Prompt notification to you if we become aware of a problem with your material
- Confidential handling of creative and contributor material within the working circle
- A direct security contact for questions and concerns
What this does not include
- Any claim to be a government office or to issue permits
- A guarantee that any file, once exposed, can be fully recovered
- Full control over third-party hosting providers and their own security practices
- Immunity from platform-wide outages or incidents affecting widely used tools
- Responsibility for the security of your own devices and sending accounts
- A promise of specific named tools or features that may change over time
- Legal data-protection terms, which are covered in the privacy policy
- Long-term or indefinite storage of documents beyond agreed retention
- Secure handling of files sent through channels we did not advise you to use
Frequently asked questions
Our preference is a controlled upload route that we set up for your project, rather than loose email attachments. A controlled route places the file into a defined destination instead of scattering copies across inboxes and servers. When you request permit support, we describe the current preferred method so you are not left guessing. This keeps the number of lasting copies small and makes the whole exchange easier to protect.
Ordinary email was not designed as a secure channel for sensitive documents. When you attach a file, copies of it come to rest in your sent folder, our inbox, the servers that carried it, and any device where it is downloaded, all of which are hard to retrieve or delete later. Email is also easy to misdirect with a single mistaken character or an unthinking forward. For these reasons we prefer a controlled route for sensitive documents, while email remains fine for ordinary correspondence and questions.
Access is limited to the people working directly on your engagement, typically the coordinator or coordinators handling your project and, where needed, a reviewer checking the package. It does not mean everyone associated with the service can browse your material. Where a specialist is brought in for a particular task, they receive only the material relevant to that task rather than your entire package. This keeps the circle of people who have seen any document as small as the work allows.
We keep your material for as long as the work reasonably requires and then remove what is no longer needed. During an active engagement your documents are held because they are in use for the application, clarifications, and any additional permissions. Once a project reaches its natural close, the working practice is to remove documents that are no longer required. The specific retention arrangement for your engagement is confirmed with you rather than stated as a single fixed rule, because it depends on your project.
Yes, that is a reasonable request. It is easiest to honour when agreed at the outset rather than assumed later, so tell us if you want particular material removed at a particular point. Because storage is organised by project, deletion is a deliberate act on known locations rather than a hopeful sweep. Bear in mind that some records may be kept for a limited period to support follow-up questions or ordinary business record-keeping, and we will be clear with you about that.
Confidentiality is already part of how the service operates, and the people handling your documents understand the material is not to be discussed or forwarded outside the working relationship. If your production requires a formal signed non-disclosure arrangement before you share anything, that can be discussed at the outset. Any specific contractual confidentiality terms relevant to your engagement are set out in your agreement rather than promised in the abstract. Raise this early so it can be arranged before sensitive material changes hands.
Creative material is treated as confidential working material, shared only with the people who need it for the permit work and not circulated beyond that circle. Scripts and treatments are often confidential for competitive reasons or under embargo until a release date, so we handle them accordingly. If your project is under a formal embargo or non-disclosure regime, tell us so we apply the appropriate care from the start. As with all material, we keep the number of copies small and remove it when the work is done.
Contributor material is handled with particular restraint because it concerns real people who consented to appear in your project, not to have their details handled by additional parties. We encourage you to share only what the permit process genuinely requires and to consider minimising or redacting identifying details before sending. Where a project involves sensitive subjects, minors, or people who could be put at risk, the handling should be discussed explicitly rather than left to routine. We do not treat these forms as ordinary paperwork or circulate them beyond the necessary working circle.
Storage typically relies on third-party tools and hosting providers, and the specific arrangements depend on the tools in use and can change over time, so we do not fix a single location claim on this page. What we can say is that we use the access controls those tools provide and keep material organised and limited in copies. If your organisation has a requirement about where its material may be stored, raise it at the outset so it can be reflected in how your engagement is handled. Where a broadcaster or studio brings its own approved systems, we can discuss working within them.
If we become aware that a file has gone somewhere it should not, or that a link was shared too widely, our approach is to tell you rather than quietly work around it. We make a practical effort to limit further exposure using the controls available, for example by reconsidering access to a shared link, and we communicate clearly about what happened. We do not promise that a file, once exposed, can be fully recovered, because no honest service can guarantee that. The security contact on this page is the direct route for raising any concern of this kind.
Document security is a shared effort. Send only what the permit process needs rather than sharing everything speculatively, use the controlled route rather than email for sensitive files, and double-check the destination before sending since misdirection is a common and avoidable failure. The security of your files also depends on your own devices and accounts, so protect the account you send from with a strong, unique password and limit who on your team can reach shared folders. If you suspect a file went to the wrong place, tell us promptly.
The specific tools used for sharing can change, and any particular tool may offer options such as links that expire or that require a recognised recipient. We use the controls available in the tools in play for your engagement and describe the current arrangement to you directly, rather than naming a specific feature here as a permanent promise that might become outdated. The principle we commit to is that shared material goes to defined recipients through controlled routes, and access can be revisited if circumstances change. If a link reaches the wrong person, tell us so access can be reconsidered.
No, and we would be misleading you if we claimed otherwise. Some of your document security depends on third-party hosting providers and platforms whose own practices are outside our direct control, and a widely used platform can experience problems that affect everyone using it. What we can commit to is using available controls conscientiously, keeping copies few and access narrow, being straightforward about where the limits of our control lie, and responding promptly if something goes wrong. Honest description of limits is part of real security, not a weakness in it.
This page describes the practical handling of your files: how they are received, stored, accessed, retained, and deleted. Our privacy policy covers the wider legal framework for the personal data you share, including what is collected, how it is used, the basis for using it, and the rights you have over it. The two are meant to be read together, one practical and one legal. Our terms of service separately set out the scope of what we do, including that we are an independent private service and not a permit-issuing authority.
Use the security contact route described at the end of this page for any question about how your material is handled or any concern that something has gone wrong. We would always rather hear about a suspected problem early than discover it late, so do not hesitate to raise even a minor worry. If you have specific requirements about tools, storage location, or a non-disclosure arrangement, the same contact is the right place to start, ideally before you send anything sensitive. Raising things at the outset makes them far easier to accommodate.