BhaiBahini Logo

Data Protection Notice

We protect personal information through data minimization, clear ownership, restricted access, secure engineering, and accountable response when something goes wrong. 

  1. Purpose

    This Data Protection Notice describes BhaiBahini’s commitments for protecting personal information across the website, pilot, platform, and supporting operations. It complements the Privacy Policy: The Privacy Policy explains what people can expect, while this notice explains the controls and governance BhaiBahini uses or is establishing to meet those commitments. 

  2. Our data-protection principles

    • Purpose limitation: collect and use information for clear, legitimate program purposes.
    • Data minimization: request only what is reasonably needed, especially for children and young people.
    • Accuracy: Provide ways to correct important information and review stale records.
    • Storage limitation: define retention periods instead of keeping information indefinitely.
    • Security and confidentiality: protect information according to its sensitivity and the risk to the person.
    • Transparency and choice: explain important uses in plain language and seek consent where required.
    • Accountability: assign owners, document decisions, review vendors, train personnel, and respond to incidents.
    • Equity: do not use data practices that unfairly exclude or profile people based on caste, Indigenous identity, disability, economic status, geography, or other protected or marginalized identity.
  3. Data classification

    BhaiBahini should classify information so stronger controls apply to higher-risk data:

    • Public: approved website content and mentor-profile details authorized for publication.
    • Internal: ordinary operational records that are not intended for public access.
    • Confidential: applications, contact details, scheduling records, guardian information, verification results, and participant communications.
    • Restricted: safeguarding reports, identity documents, background-check information, precise location, sensitive health or wellbeing disclosures, and credentials or security secrets.

    Restricted data must never be copied into design mockups, public demos, ordinary email threads, test environments, or analytics tools unless a documented, approved process permits it.

  4. Access controls

    • Role-based access and least privilege for staff, contractors, and administrators.
    • Unique accounts; shared administrator credentials are prohibited.
    • Multi-factor authentication for privileged and high-risk access supported.
    • Prompt removal or adjustment of access when a person changes roles or leaves.
    • Periodic access reviews for systems holding confidential or restricted data.
    • Audit logging for material administrative and safeguarding actions where feasible.
  5. Secure design and operations

    • Encryption in transit and appropriate protection at rest for systems holding personal information.
    • Secure software development practices, code review, dependency management, and separation of development, test, and production environments.
    • Use of synthetic or de-identified test data instead of real participant information wherever possible.
    • Security updates, vulnerability review, backups, recovery procedures, and monitoring proportionate risk.
    • Safe configuration of forms, video tools, calendars, email, analytics, and cloud services.
    • A documented process for security reports, incidents, containment, recovery, and lessons learned.

    These are operational commitments, not a claim of certification. Before publication, the team must verify which controls are live and adjust the wording if implementation is still planned.

  6. Children’s and mentees’ information

    Children’s information receives heightened protection. Public forms are intended for people aged 13 or older, and children under 13 must not submit personal information directly. For minors who join the program, BhaiBahini may require guardian notice or consent and should separate guardian records from the young person’s mentoring content where practical. 

    • Do not display full birth dates, precise home or school addresses, personal contact details, or guardian details on public profiles. 
    • Do not use children’s information for targeted advertising, sale, or unrelated profiling. 
    • Limit sponsors and partners to aggregate or de-identified reporting unless specific permission and a lawful basis support more. 
    • Design deletion, correction, consent, and account-closing processes that account for both the young person and guardian where applicable. 
    • Use additional review before introducing AI features that score, rank, recommend, summarize, or moderate information about young people. 
  7. Service providers and partners

    Before a provider handles personal information, BhaiBahini should assess the provider’s purpose, data access, security, retention, child-privacy implications, location, subcontractors, incident-notification terms, deletion support, and ability to assist with rights requests. Agreements should require confidentiality and use only for authorized purposes.

    High-risk providers include identity or background-check services, video and messaging tools, analytics, AI services, payment services, and systems storing safeguarding records.

  8. International transfers and distributed teams

    BhaiBahini may operate across Nepal and the United States and use providers in other countries. Cross-border access must be limited to legitimate duties, protected by appropriate contracts and security measures, and documented in a data inventory. The team must confirm where each material system stores and backs up data.

  9. Retention and disposal

    BhaiBahini will maintain a retention schedule by data type, owner, purpose, system, and deletion method. As a starting rule:

    • Interest-list records should be deleted or reconfirmed after a defined period of inactivity.
    • Application and verification of records should be retained only for the period justified by selection, reapplication, audit, and safety needs.
    • Active participant records should be retained while needed to deliver and support the program.
    • Safeguarding and incident records may require longer, restricted retention based on risk and law.
    • Backups should expire on a defined cycle and not become permanent shadow archives.
    • Legal holds temporarily override ordinary deletion when counsel or an authorized owner documents the need.
  10. Individual requests

    BhaiBahini will maintain a process to receive, verify, track, and respond to requests for access, correction, deletion, withdrawal of consent, or other applicable rights. Requests involving minors must verify the requester’s identity and authority while considering the young person’s rights, welfare, and applicable law.

  11. Incident response

    • Report suspected loss, unauthorized access, disclosure, alteration, or misuse immediately to the designated security or privacy owner.
    • Contain the incident without destroying evidence.
    • Assess the information, people, systems, countries, and safeguarding risks involved.
    • Engage qualified security, privacy, safeguarding, legal, and service provider contacts as appropriate.
    • Notify affected people, guardians, partners, insurers, or authorities when required or reasonably necessary.
    • Document decisions, remediate weaknesses, and review whether policies or training need to change.

    Security incidents involving a child or a safety report require coordinated privacy and safeguarding review, not a security-only response.

  12. Governance and accountability

    • Name a privacy owner, security owner, safeguarding lead, and backup contacts.
    • Maintain data inventory and list of material service providers.
    • Review new high-risk features and data uses before launch.
    • Train personnel according to their access and role.
    • Review this notice, the Privacy Policy, retention schedule, and incident process atleast annually and after material changes.
    • Document exceptions and remediation dates rather than silently accepting unmanaged risk.

Follow the BhaiBahini Journey

Receive occasional updates about our pilot, founding community, learning resources, and upcoming opportunities to participate.