Skip to content
UGRATARAInfrastructure
Legal

Privacy policy

A plain-language account of the personal information this website handles and the controls intended to protect it.

Publication notice

This draft establishes the intended policy structure. Company registration details, retention periods, service providers and governing-law language must be confirmed by authorised management and qualified legal counsel before launch.

Who this policy covers

This policy applies to people who visit this website, make a project or general enquiry, register as a supplier, apply for work, or otherwise provide personal information through the website.

Ugratara Infrastructure Pvt. Ltd. is intended to act as the organisation responsible for that information. The registered office, company registration number and named privacy contact must be verified before this policy is published.

Placeholder — controller details

Insert the verified registered address, company number and person or role authorised to receive privacy requests.

Information we collect

We collect information you choose to provide, together with limited technical information needed to operate and protect the website.

  • Contact details, including your name, organisation, job title, email address and phone number.
  • Project information, including location, service requirements, anticipated programme, budget range and documents you attach.
  • Supplier information, including registration details, supply categories and capability statements.
  • Career application information, including qualifications, experience, covering notes and an uploaded CV.
  • Technical records such as submission time, network address, browser information, consent choice and security logs.
  • Analytics information only where an analytics service is configured and you have accepted analytics in the consent banner.

How we use information

  • Assess and respond to project, commercial and general enquiries.
  • Evaluate supplier registrations and manage prequalification activity.
  • Review applications, communicate about roles and administer recruitment.
  • Maintain a record of correspondence, instructions and consent.
  • Protect the website against spam, misuse, fraud and security incidents.
  • Understand website performance and improve content where optional analytics consent has been given.
  • Meet contractual, regulatory, audit and legal obligations that apply to the company.

The basis for each use may be your consent, steps requested before entering a contract, performance of a contract, the company's legitimate administrative and security needs, or a legal obligation. Counsel must confirm the final basis used for each processing activity.

When information is shared

Access should be limited to authorised staff and advisers who need the information for the purpose described above. We may also use vetted providers for website hosting, email delivery, database storage, security, file storage and consented analytics.

  • Project and commercial teams handling an enquiry or tender.
  • Procurement teams handling supplier registration or due diligence.
  • Human-resources and hiring managers handling an application.
  • Professional advisers, auditors, insurers or public authorities where disclosure is required or properly authorised.
  • Technology providers operating under documented instructions and appropriate confidentiality controls.

Placeholder — processor register

List the production hosting, email, database, file-storage, anti-spam and analytics providers, including the country in which each provider processes data.

Processing outside Nepal

Some technology providers may process information outside Nepal. Before production launch, the company must identify those locations, assess the safeguards available and describe any transfer mechanism or contractual protection required by applicable law.

How long information is kept

Information should be retained only for as long as it is reasonably needed for the purpose for which it was collected, to establish or defend legal rights, and to meet record-keeping obligations. It should then be securely deleted or anonymised.

Placeholder — retention schedule

Management and legal counsel must approve specific periods for enquiries, unsuccessful and successful job applications, supplier records, tender documents, consent records, security logs and analytics data.

How information is protected

The website is designed to use encrypted transport, server-side validation, access controls, spam protection and rate limiting. Production systems should also use least-privilege access, service-provider review, secure backups, monitoring and an incident-response process.

No internet service can guarantee absolute security. Do not submit sensitive personal records, payment-card details or confidential project documents unless the company has confirmed an approved transfer method.

Your choices and requests

Subject to applicable law, you may ask what information the company holds about you, request correction, withdraw consent, object to a use, or ask for deletion or restriction. The company may need to verify your identity before acting and may retain records where the law requires it.

Send a privacy request to info@ugratarainfrastructure.com. This address and the response procedure are placeholders until the company appoints and verifies its privacy contact.

Policy updates and complaints

We may update this policy when the website, service providers or legal requirements change. The current version and revision date will be published on this page.

Concerns should first be sent to the verified privacy contact. The final policy must also identify any regulator, authority or formal complaint route that applies to the company and the people whose information it handles.