Privacy Policy

Effective Date: 1st June, 2025  |  Last Updated: 22nd June, 2026

This Privacy Policy explains how Pedal Group Pvt. Ltd., a company registered in Nepal under registration number 606569022, with its registered office at Lalitpur-1, Kathmandu, Nepal (together with its affiliates, "Pedal1", "we", "us", or "our") collects, uses, discloses, retains, and protects personal information when you visit our websites, contact us, or access and use our software-as-a-service platform and related services (collectively, the "Services").

This Privacy Policy should be read together with our Terms and Conditions and any applicable order or data-processing addendum, which are incorporated by reference. Capitalised terms not defined here have the meaning given in the Terms and Conditions.

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Services.


1. Scope and Our Role

This Privacy Policy applies to:

  • Website visitors – individuals who browse our public websites and marketing pages;

  • Account holders and Authorized Users – the personnel of our subscribing organizations who register for, administer, or use the Services; and

  • Prospects and enquirers – individuals who contact us, request a demo, or subscribe to our communications.

Two distinct roles. Our responsibilities differ depending on the data involved:

  • Where we collect personal information directly for our own purposes – such as website analytics, account registration, billing, support, and marketing – we act as the data controller. This Privacy Policy governs that processing.

  • Where personal information is contained within the data that a subscribing organization (our "Customer") uploads to or generates within its portal ("Customer Data") – including data about the Customer's own employees, contractors, customers, and contacts – we act as a data processor acting on that Customer's documented instructions. In that case, the Customer is the data controller, and its own privacy notice (not this one) governs how that data is collected and used. See Section 14.


2. Personal Data We Collect

  • 2.1 Information you provide to us. When you register for an Account, subscribe, request a demo, contact support, or otherwise interact with us, we may collect your name, business contact details (email, phone, organization, role), account credentials, billing and payment information, the contents of your communications with us, and any information you choose to provide.

  • 2.2 Customer Data you upload. When you use the Services, you and your Authorized Users may submit Customer Data into the HRM (Nexara), CRM, Project Management, and Accounting Modules. This may include personal information about third parties such as your employees, contractors, customers, and contacts. We process this data only as a processor on your behalf, in accordance with your instructions and the Terms. You are responsible for having a lawful basis and any required notices or consents for this data.

  • 2.3 Information collected automatically. When you access the Services, we may automatically collect technical and usage information, including IP address, device and browser type, operating system, log files, pages viewed, feature usage, timestamps, and referring URLs. We use cookies and similar technologies as described in Section 5.

  • 2.4 Geo-location data. The Services include an optional geo-location feature. Where, and only where, a Customer activates this feature for a given user, location data for that user is captured from the time the user clocks in until the time the user clocks out. The Services are designed so that no location data is collected outside that clock-in-to-clock-out window, including at the back-end level. Activation is controlled entirely by the Customer, who acts as the data controller for such monitoring and is responsible for the required notices and consents.

  • 2.5 Credential Vault data. Credentials you store in the Vault are stored in a highly encrypted form. They are designed to be inaccessible to Pedal1 personnel and to any Authorized User other than those you authorize. We do not have the ability to view your Vault contents in the ordinary course. See Section 9.

  • 2.6 Information from third parties. We may receive information from our subprocessors, payment providers, analytics partners, and (where you sign in through a third party) authentication providers, used solely to provide, secure, and improve the Services.

We do not intentionally seek to collect special categories of sensitive personal data through our own controller activities. Where Customers upload such data into their portal, they do so as controllers and are responsible for the lawfulness of that processing.


3. How We Use Personal Data

As a data controller, we use personal information to:

  • provide, operate, maintain, and secure the Services, and to create and administer your Account;

  • process subscriptions, payments, invoicing, and renewals;

  • provide customer support and respond to your enquiries;

  • authenticate users and prevent fraud, abuse, and security incidents;

  • monitor, analyze, and improve the performance, reliability, and features of the Services;

  • send service-related communications and, where permitted, marketing communications you may opt out of at any time;

  • generate aggregated, de-identified, or anonymized data that does not identify any individual; and

  • comply with legal obligations and enforce our Terms and agreements.


4. Legal Bases for Processing

Where required by applicable law, we rely on one or more of the following legal bases to process personal information as a controller: performance of a contract with you; our legitimate interests in operating, securing, and improving the Services (balanced against your rights); your consent (for example, for certain cookies or marketing, which you may withdraw); and compliance with legal obligations. Our processing of Customer Data as a processor is carried out on the basis of, and limited to, the Customer's instructions.


5. Cookies and Similar Technologies

We use cookies and similar technologies to operate our websites and Services, remember your preferences, maintain sessions, measure usage, and improve performance. Some cookies are strictly necessary; others are used for analytics or functionality. You can manage non-essential cookies through your browser settings or any cookie controls we provide. Disabling certain cookies may affect functionality.


6. How We Share and Disclose Personal Data

We do not sell your personal information. We may share personal information only as follows:

  • Subprocessors and service providers – hosting, infrastructure, payment processing, analytics, communications, and support providers who process data on our behalf under appropriate confidentiality and data-protection obligations, and only as needed to deliver the Services.

  • Within your organization – Customer Data is accessible to the Authorized Users and roles your Superadmin configures within your Account.

  • Legal and safety – where we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request, or is necessary to protect the rights, property, or safety of Pedal1, our users, or the public.

  • Business transfers – in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Privacy Policy continuing to apply to the affected personal information.

  • With your direction or consent – where you instruct us to share data or otherwise consent to disclosure.


7. Our Access Limitations

The Services are designed using technical and organizational measures so that Pedal1 personnel do not, in the ordinary course of operations, have functional access to view, read, enter, or extract Customer Data inside your portal. We do not access the contents of your Account to view your data.

The only administrative capability we retain in respect of your Account is the ability to reset or change the Superadmin password, and only (a) at your request or to assist you where the password has been lost or forgotten and identity verification is satisfied, or (b) where we reasonably determine that you are not complying with our Terms, Corporate Guidelines, or applicable law. A Superadmin password reset does not, by itself, grant us access to view your Customer Data. While we maintain strong access controls, no security measure can be guaranteed to be infallible.


8. Automatic Deletion of Project Files

To maintain healthy storage performance, the Services are designed to automatically and permanently delete files associated with a task in the Project Management Module fifteen (15) days after that task is marked as completed. This deletion is automatic, irreversible, and may not be recoverable. You are solely responsible for downloading, exporting, or otherwise backing up any files you wish to retain before the 15-day window elapses. We have no liability for files removed in accordance with this policy.


9. Credential Vault and Encryption

Credentials stored in the Vault are designed to be stored in a highly encrypted form, inaccessible to Pedal1 personnel and to any Authorized User beyond those you authorize. Because of this encrypted, restricted-access design, we may be unable to recover, decrypt, or reset Vault contents if the relevant keys, master credentials, or access mechanisms are lost. You are responsible for safeguarding the means of access to your Vault and for maintaining independent records of critical credentials. No method of electronic storage or transmission is fully secure.


10. Data Retention

We retain personal information for as long as necessary to provide the Services, maintain your Account, comply with our legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Project files are subject to the automatic 15-day deletion described in Section 8. Following termination of your Subscription, you may request export of your Customer Data within the limited window we specify; after that window, we may permanently delete Customer Data, and such deletion is irreversible. We may retain aggregated or anonymized data that does not identify any individual.


11. International Data Transfers

Pedal1 operates from Nepal and the United States and serves customers across multiple markets. Your personal information may be stored and processed in Nepal, the United States, or other jurisdictions where we or our subprocessors operate, which may have data-protection laws different from those of your country. Where we transfer personal information across borders, we take steps intended to ensure an appropriate level of protection consistent with applicable law. By using the Services, you understand that your information may be transferred to and processed in these locations.


12. Data Security

We implement and maintain reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss, or destruction. These include access controls, encryption of Vault credentials, and restricted personnel access as described above. Security is a shared responsibility: you are responsible for securing your own credentials, devices, networks, and user-access configuration, and for the conduct of your Authorized Users. Despite reasonable safeguards, no system can be guaranteed to be completely secure. In the event of a confirmed personal-data breach, we will notify affected parties as required by applicable law.


13. Your Rights and Choices

Subject to applicable law and your jurisdiction, you may have the right to access, correct, update, or delete your personal information; to object to or restrict certain processing; to withdraw consent where processing is based on consent; to request a portable copy of certain data; and to lodge a complaint with a competent authority. You may also opt out of marketing communications at any time using the unsubscribe link or by contacting us.

How to exercise rights. To exercise any of these rights in respect of personal information for which Pedal1 is the controller, contact us using the details in Section 18. We will respond within the timeframe required by applicable law and may need to verify your identity before acting on a request.


14. Data Subjects Whose Data Is Uploaded by Customers

If you are an employee, contractor, customer, or contact of an organization that uses the Services, and your personal information has been entered into that organization's portal, then that organization – not Pedal1 – is the data controller of your information. We process such information only as a processor on the organization's instructions.

Requests to access, correct, delete, or otherwise act on such information should be directed to the relevant organization. If we receive a request directly from such a data subject, we will, where appropriate and permitted, refer the request to the responsible Customer or act only on that Customer's instructions.


15. Children’s Privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children as a controller. If you believe a child's information has been provided to us in error, please contact us so we can take appropriate action.


16. Third-Party Links and Services

The Services and our websites may contain links to, or integrations with, third-party websites and services that we do not control. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party service you use.


17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised "Last Updated" date and, where changes are material, take reasonable steps to notify you. Your continued use of the Services after the changes take effect constitutes acceptance of the updated Privacy Policy.


18. How to Contact Us

If you have questions, requests, or complaints regarding this Privacy Policy or our handling of personal information, please contact us:

We will use reasonable efforts to address your concerns. Where applicable law provides for it, you may also have the right to contact the relevant data-protection or privacy authority in your jurisdiction.


This Privacy Policy is provided for general informational purposes and forms part of the agreement between you and Pedal Group Pvt. Ltd. It should be reviewed by qualified legal counsel for each market in which the Services are offered before deployment.

Need Help? We’re Here to Assist You!

At Pedal1, we’re committed to providing you with the support you need. Whether you have questions, need guidance, or just want to learn more, our team is ready to help.