We protect personal information through data minimization, clear ownership, restricted access, secure engineering, and accountable response when something goes wrong.
This Data Protection Notice describes BhaiBahini’s commitments for protecting personal information across the website, pilot, platform, and supporting operations. It complements the Privacy Policy: The Privacy Policy explains what people can expect, while this notice explains the controls and governance BhaiBahini uses or is establishing to meet those commitments.
BhaiBahini should classify information so stronger controls apply to higher-risk data:
Restricted data must never be copied into design mockups, public demos, ordinary email threads, test environments, or analytics tools unless a documented, approved process permits it.
These are operational commitments, not a claim of certification. Before publication, the team must verify which controls are live and adjust the wording if implementation is still planned.
Children’s information receives heightened protection. Public forms are intended for people aged 13 or older, and children under 13 must not submit personal information directly. For minors who join the program, BhaiBahini may require guardian notice or consent and should separate guardian records from the young person’s mentoring content where practical.
Before a provider handles personal information, BhaiBahini should assess the provider’s purpose, data access, security, retention, child-privacy implications, location, subcontractors, incident-notification terms, deletion support, and ability to assist with rights requests. Agreements should require confidentiality and use only for authorized purposes.
High-risk providers include identity or background-check services, video and messaging tools, analytics, AI services, payment services, and systems storing safeguarding records.
BhaiBahini may operate across Nepal and the United States and use providers in other countries. Cross-border access must be limited to legitimate duties, protected by appropriate contracts and security measures, and documented in a data inventory. The team must confirm where each material system stores and backs up data.
BhaiBahini will maintain a retention schedule by data type, owner, purpose, system, and deletion method. As a starting rule:
BhaiBahini will maintain a process to receive, verify, track, and respond to requests for access, correction, deletion, withdrawal of consent, or other applicable rights. Requests involving minors must verify the requester’s identity and authority while considering the young person’s rights, welfare, and applicable law.
Security incidents involving a child or a safety report require coordinated privacy and safeguarding review, not a security-only response.
Receive occasional updates about our pilot, founding community, learning resources, and upcoming opportunities to participate.