Lagani Shiksha

Privacy Policy

This document details the processing, protection, retention, and collection standards of personal and operational data within the Lagani Shiksha learning ecosystem.

Last revised: July 26, 2026 Publisher: Abilash Media Pvt. Ltd.

1. Legal Entity & Scope of Coverage

This Privacy Policy represents a binding statement of commitment by Abilash Media Private Limited (herein referred to as "the Company", "We", "Us", or "Our"), a legally registered corporate entity in Bharatpur, Chitwan, Nepal (the parent operator of the Lagani Shiksha digital learning ecosystem and the Nepse Bajar financial analysis portal).

This Policy details our protocols for the collection, systemic processing, transmission, security profiling, storage, and eventual disposal of Personally Identifiable Information (PII) of registered learners, account holders, guests, payment initiators, and partners in our affiliate roster (herein collectively referred to as "Users", "You", or "Your").

This Policy governs all access paths, including the website (ebook.nepsebajar.com), secure user dashboards, the proprietary HTML-based ebook reader environment, payment settlement forms, and API calls. By engaging with the platform, you declare that you have read, understood, and consented to the data practices defined in this Policy.

2. Taxonomy of Collected Telemetry

We collect diverse data categories to verify licenses, secure our paid intellectual property, satisfy tax reporting directives, and handle platform infrastructure:

A. Direct Account Registry Info

Full Name, legal email address, verified cellular contact number, and encrypted password hashes. We also collect profile images or avatars uploaded by the user, social channel handles, and communication preferences.

B. Order & Payment Meta-Logs

Corporate invoice items, checkout values, active promotional coupon codes, transaction states, external merchant gateway transaction IDs, and settlement responses. Payment Detail Security: We do not store sensitive payment details on our local databases. All eSewa, Khalti, ConnectIPS, and Fonepay transactions are processed via secure external API routers.

C. Interactive Reading Telemetry

To synchronize progress across user devices, we record opened digital assets, exact reading coordinates, page index markers, active book markers, chapter completion flags, quiz scoring performance matrices, and support request histories.

D. Device, Security & Logs

IP address sequences, browser user agent strings, platform and device identifiers, cookie variables, failed login attempts, concurrent session logs, device reset logs, and security alert events.

3. Systemic Processing Objectives

Your information is collected and processed under the provisions of the Individual Privacy Act, 2075 (2018) and the Electronic Transactions Act, 2063 of Nepal, for the following verified business and operational objectives:

  • License Verification & Provisioning: Authenticating user registration, issuing secure access keys to digital ebooks, and verifying receipt records.
  • DRM Enforcement: Monitoring device counts (enforcing the 2-device limit) and detecting concurrent logins to prevent piracy and unauthorized account sharing.
  • Billing & Legal Compliance: Assuring tax compliance by generating VAT/PAN receipts, reporting transaction records to appropriate Nepalese fiscal portals, and handling accounting.
  • Affiliate Administration: Tracking partner referrals, verifying conversion paths, executing anti-fraud review logs, and calculating payouts.
  • Service Communication: Transmitting necessary transaction updates, password reset requests, server maintenance announcements, and critical security warnings.

4. DRM Protocols & Anti-Piracy Safeguards

Digital rights management and asset security are critical to protecting our content creator intellectual property. Consequently, the Lagani Shiksha ebook reader runs background security processes:

DRM Tracking & IP Protection Terms

All digital media assets displayed on our reader are embedded with dynamic invisible and visible watermarks. These watermarks link the active page directly to your User Account ID, email, IP sequence, and phone number.

The reader tracks security alerts, block events, browser-level clipboard operations, screenshot captures, context menu calls, and inspector console interactions. In case of verified piracy or scrap attempts, this data will be cataloged and delivered to legal authorities as formal evidence under copyright law.

5. Authorized Disclosures to Third Parties

We do not trade, lease, or sell personal information to advertising brokers. We only share specific data segments with trusted service providers under confidentiality agreements to operate the platform:

  • Financial Settlers: Data is shared with gateways (e.g. eSewa, Khalti, ConnectIPS, Fonepay) solely to process checkout actions and verify transaction state updates.
  • Storage Clusters: Secured book files and static assets reside on high-speed, enterprise-grade storage networks (such as Cloudflare R2 and secure hosting nodes).
  • Transactional Email Engines: Automated delivery of system alerts, password updates, invoice receipts, and progress tracking notifications via secure SMTP mail services.
  • Legal Directives & Authorities: We disclose user telemetry if required under Nepalese Law (Electronic Transactions Act, Criminal Code, etc.) or when served a formal warrant by judicial, financial, or state investigators.

6. Cookie Taxonomy & Local Storage Logs

Cookies are small text files placed on your device to ensure correct platform operation. We deploy the following:

Cookie Type Objective & Lifespan Impact of Rejection
Session Identifier (laravel_session) Maintains state, authenticates dashboard access, and tracks checkout baskets. Cleared on browser close. Critical. Blocks login, dashboard routing, and digital reading entirely.
Security Token (XSRF-TOKEN) Blocks Cross-Site Request Forgery (CSRF) attempts on settings, payment and checkout forms. Critical. Prevents form submissions, settings saves, and secure actions.
Reader Preference (Local Storage) Remembers local reader coordinates, text magnification levels, page orientation, and active bookmark. Minor. Resets custom ebook styling preferences to default upon fresh loading.

7. Technical & Structural Security Controls

The Company implements modern, multi-layered security measures to protect user records and digital books:

  • All network transactions are forced over high-grade Secure Socket Layer/Transport Layer Security (SSL/TLS HTTPS) channels.
  • User passwords reside in the database as salted, irreversible cryptographic hashes (BCrypt algorithm).
  • All admin and developer access points are restricted through firewalls and multi-factor validation requirements.
  • Ebook digital assets are delivered securely through temporary signed URL routers from Cloudflare R2, preventing direct asset URL extraction and hotlinking.

8. Data Retention & Disposal Framework

We preserve your PII only for as long as your account remains active. However, legal and fiscal obligations demand special retention windows:

  • Financial & Invoice logs: Preserved for a statutory minimum of 7 (seven) years, satisfying legal requirements from the Inland Revenue Department (IRD) of Nepal.
  • Security & Anti-Piracy Alerts: In cases of verified security incidents or piracy alerts, related IP history, device records, and log sequences are retained indefinitely for judicial or investigative use.
  • Operational Backup nodes: Server backups are preserved in secure off-site locations for 30 days before systematic overwrite cycling.

9. Your Legal Rights as a Data Subject

Subject to identity verification, users can submit data requests to our compliance unit:

  • Access & Rectification: The right to demand a copy of your personal data held by us and request immediate correction of inaccurate elements.
  • Erase / System Deletion: The right to request account termination and personal data destruction. If triggered, we erase or anonymize all non-mandatory records, keeping only legal financial logs, piracy evidence, and tax records.
  • Processing Restriction: The right to revoke consent for promotional updates, affiliate tracking, and diagnostic emails.

10. Special Affiliate & Referral Telemetry Rules

Affiliate program participants are subject to specialized telemetry policies:

To protect the platform against fraud and self-referrals, our system logs referral coordinates. This includes comparing the referrer IP address and payout banking coordinates with the buyer's IP sequence, location data, and card details.

Affiliate commission approvals are dependent on this verification process. In cases of verified referral fraud, related logs will be permanently linked to the offending user profile and restricted from payout execution.

11. International Data Operations

While our operations are centralized in Nepal, our underlying cloud infrastructure (such as Cloudflare CDN proxies and storage clusters) operates across international nodes.

By accessing the platform, users acknowledge that their data may cross borders to be cached or processed. We ensure that our infrastructure partners meet industry standard data protection regulations.

12. System Updates & Policy Revisions

We may update this Privacy Policy to reflect platform features, legal standards, security protocols, or operational changes.

When updates occur, the revision date at the top of this document will change. Your continued use of the platform after the publication of an updated Policy indicates your acceptance of the revised terms.

13. Contact Compliance & Support Nodes

For questions about data processing, legal compliance, copyright policies, or data deletion requests, contact our Compliance Team:

Administrative Headquarters

Abilash Media Private Limited
Registration Operator of Lagani Shiksha & Nepse Bajar
Bharatpur, Chitwan, Nepal

Official Support Gateway

To submit a data access or deletion request, please open a secure support ticket in your verified User Dashboard.