- Version
- 1.0
- Reading time
- 18 minutes
- Effective
- 21 July 2026
- Last updated
- 21 July 2026
- Next review
- 21 January 2027
- Reviewed by
- Wakil Nepal Legal Team
Company: Genuine Law Associate and Research Center Pvt. Ltd.
Important privacy notice
Do not send sensitive identity or legal documents through ordinary email. Use the secure upload channel provided for your matter.
1. Introduction and scope
Genuine Law Associate and Research Center Pvt. Ltd., operating as Wakil Nepal (Wakil Nepal, we, us or our), provides legal and business-support services in Nepal. This Privacy Policy explains how we handle personal information when you visit our website, create an account, request a consultation, submit an application, upload documents, make a payment, communicate with us, or otherwise use our services.
Legal matters can contain highly sensitive information about individuals, families, businesses, assets, disputes and government records. We apply this Policy to information processed through our website, client portal, administrative systems and service communications. A matter-specific engagement letter, consent, government form or separate notice may add to this Policy. If a specific notice conflicts with this general Policy for that processing, the more specific notice applies.
This Policy is a transparency document, not legal advice and not a contract for legal representation. Sending an inquiry or uploading a document does not by itself create an advocate-client relationship; that relationship begins only when Wakil Nepal accepts an engagement under agreed terms.
2. Key definitions
Personal information means information relating to an identified or identifiable natural person. Processing includes collecting, recording, organizing, storing, reviewing, using, transferring, disclosing, correcting, restricting and deleting information. Client content means documents, facts, messages and other material supplied for an inquiry or matter. Service provider means an organization that processes information to provide infrastructure or a service to us.
3. Information we collect
The information we collect depends on the service, applicant, legal requirement and way you interact with us. Please provide only information relevant to your request and do not upload another person's information unless you are authorized to do so.
- Account and contact data: name, email, telephone number, address, login identifiers, account role, communication preferences and authentication records.
- Identity and government records: citizenship, passport, photograph, signature, date of birth, nationality, PAN/VAT details, identity numbers, relationship evidence and verification results.
- Business and professional data: entity name, registration details, ownership, directors, shareholders, beneficial owners, employees, licences, tax records, financial details and authorized representatives.
- Legal-matter data: instructions, facts, contracts, applications, evidence, correspondence, court or regulator records, deadlines, opinions, work product and matter status.
- Uploaded documents: scans, photographs, PDFs, certificates, deeds, government forms, corporate records, financial documents and generated or signed deliverables.
- Payment data: amount, currency, invoice, transaction reference, payment status and limited billing information. Card, wallet or bank credentials are normally entered directly with the payment provider and should not be stored by us unless expressly disclosed.
- Technical data: IP address, device and browser type, operating system, language, referring page, identifiers, timestamps, pages viewed, errors and security or audit logs.
- Communications: emails, calls, messages, consultation notes, support requests, feedback and marketing preferences. Calls are not recorded unless we provide notice and obtain any required permission.
- Information from others: co-applicants, employers, representatives, counterparties, public registers, courts, regulators, government offices, professional advisers and authorized verification providers.
5. How we use information
We use information only for defined legal, operational and security purposes and do not sell personal information. Unless we give a separate notice and obtain any authorization required by law or professional duty, we do not permit confidential client documents to be used to train a public artificial-intelligence model.
- Create and secure accounts, authenticate users and maintain audit trails.
- Assess inquiries, conduct conflict and eligibility checks, provide consultations and perform agreed legal or business-support services.
- Prepare, review, submit and track applications with the Office of Company Registrar, Inland Revenue Department, Department of Industry, intellectual-property authorities, courts, local bodies and other competent offices when instructed or legally required.
- Verify identity, authority, ownership and compliance information and prevent fraud, abuse, unauthorized access and unlawful activity.
- Generate, sign, deliver and retain legal documents, invoices, receipts and service records.
- Process and reconcile payments, refunds and accounting records through authorized providers.
- Send service messages, deadline alerts, document requests, security notices and support responses.
- Improve accessibility, reliability, content and workflow performance using appropriately minimized or aggregated information.
- Establish, exercise or defend legal claims; comply with professional duties, court orders and applicable law; and respond to lawful government requests.
- Send marketing only where permitted and consistent with your preference; you may unsubscribe without affecting service communications.
6. Grounds for processing
Nepal's Individual Privacy Act, 2075 and Individual Privacy Regulation, 2077 provide the principal local privacy framework. Depending on the processing and any other applicable law, we rely on your consent or instruction; steps requested before engagement; performance of an engagement or other contract; compliance with legal, regulatory, tax, accounting and professional obligations; protection of vital or legitimate interests where permitted; establishment or defense of legal claims; and tasks required by competent public authorities.
Where consent is the applicable ground, you may withdraw it for future processing. Withdrawal does not invalidate earlier lawful processing and may make a requested service impossible where the information is necessary.
8. OCR, automation and artificial intelligence
OCR may refer to the Office of Company Registrar and also to optical character recognition. When you request company-registration work, we may submit authorized information to the Office of Company Registrar. We may also use optical character recognition or assisted drafting to extract text, classify documents, identify missing fields or prepare a first draft.
Material legal work remains subject to appropriate human review. Automated output can be incomplete or inaccurate and should not be treated as a final legal determination. We require providers handling client material to use it only for authorized service delivery and safeguards; sensitive documents should not be placed into unapproved consumer AI tools.
Where an electronic or digital signature is offered, we process the signer's identity and contact information, signature or certificate data, authentication events, IP address, timestamps, document version and audit evidence to execute and verify the record. A digital-signature provider may independently process some information under its own notice. The legal form accepted for a particular government filing or instrument must be confirmed; clicking an acceptance box is not represented as a statutory digital signature in every context.
9. Payments and financial information
Payments may be processed by banks, wallets, gateways or other regulated providers displayed at checkout or on the invoice. The provider's terms and privacy notice apply to information submitted directly to it. We generally receive transaction identifiers, payer details, amount, status and anti-fraud results rather than full payment credentials.
We retain invoices, receipts and tax or accounting records for the period required by applicable law. Do not send card PINs, one-time passwords or online-banking passwords to Wakil Nepal.
10. Legal-service confidentiality
Information accepted in a legal engagement is handled subject to applicable advocate confidentiality, conflict, professional and evidentiary duties. Confidentiality is not absolute: disclosure may be authorized by the client, necessary to perform the engagement, required by law or court order, or otherwise permitted under professional rules. Portal security does not itself determine whether a communication is legally privileged.
11. Data retention and deletion
We retain information only while reasonably necessary for the purposes described, the engagement, professional recordkeeping, limitation periods, dispute defense, tax and accounting obligations, fraud prevention, backups and lawful government requirements. Retention is based on record category, sensitivity, matter status and legal obligation rather than one universal period.
Uncompleted inquiries and abandoned uploads should be deleted or anonymized after a documented short operational period unless a legal, security or conflict-record reason requires retention. Active matter records are retained through service completion and the applicable professional and legal period. Financial and statutory filing records are retained for the legally required period. Security logs and backups follow shorter technical schedules and expire through controlled rotation. A future Data Retention Policy should publish the approved category-by-category schedule.
Deletion from active systems may not immediately remove encrypted backups. Backup copies are isolated, expire on schedule and are restored only for continuity or security purposes. We may retain a minimal suppression, conflict or transaction record where deletion of the full file is appropriate but another lawful obligation remains.
12. Security measures and incidents
We use risk-based administrative, technical and physical safeguards intended to protect confidentiality, integrity and availability. Depending on the system and risk, measures may include encrypted transport, protected storage where supported, role-based and least-privilege access, strong authentication, secret management, logging, backups, environment separation, vulnerability and dependency management, staff confidentiality, provider review and secure deletion. Specific controls must not be represented as deployed until they have been technically verified.
No internet or storage system is completely secure. Users must protect account credentials, use unique passwords, avoid sharing one-time codes and notify us promptly of suspicious activity. If a security incident affects information, we will investigate, contain and document it and provide notices to affected persons or authorities where applicable law requires.
13. Cloud processing and international transfers
Some infrastructure or support providers may store or access information outside Nepal. Before using such a provider for sensitive legal material, we assess purpose, location, security, confidentiality, subcontractors and lawful-transfer requirements and apply contractual and technical safeguards appropriate to the risk. Contact us for current material processor-location information relevant to your matter.
14. Your privacy rights and choices
Subject to identity verification, applicable law, privilege, third-party rights and lawful exceptions, you may ask whether we hold your information; request access or a copy; correct incomplete or inaccurate information; withdraw consent; object to or restrict particular processing; request deletion where retention is no longer lawful or necessary; opt out of marketing; and complain about our handling of information.
Send a request to the contact details below and describe the account, matter and right involved. We may request proportionate proof of identity or authority and will not disclose another person's information. We will respond within the period required by applicable law or explain a lawful restriction. A service request may be refused or limited where it would reveal privileged material, prejudice another person, conflict with professional duties, undermine security or violate a retention obligation.
15. Children and represented persons
Our accounts and general commercial services are not directed to children. A child's information may nevertheless be necessary for a family, immigration, inheritance or other legal matter. In that situation we collect only what is relevant, verify appropriate guardian or legal authority, consider the child's interests and apply heightened access and disclosure controls. A child should not create an account or upload documents without appropriate adult involvement.
16. Third-party services and external links
Our services may link to government portals, payment providers, maps, social networks and other third-party sites. Their privacy and security practices are governed by their own notices. A link is not an endorsement, and we are not responsible for a third party's independent processing. Review the destination and avoid uploading legal documents through an unverified link.
17. Responsibility and legal limitations
We take reasonable steps to protect information and remain responsible to the extent required by applicable law and agreed professional duties. Nothing in this Policy excludes a right or remedy that cannot lawfully be excluded. We are not responsible for a user's insecure device, voluntary disclosure to an unauthorized person, inaccurate instructions, or an independent third party outside our control, except to the extent the law provides otherwise.
18. Changes to this Policy
We may update this Policy when services, providers, laws or practices change. The page states its version, publication date, review date and material revision history. Where a change materially affects ongoing processing, we will provide additional notice through the account, email or another appropriate channel and obtain consent if required. Earlier versions should remain available from the version history.
19. Contact, privacy requests and grievances
The organization responsible for this Policy is Genuine Law Associate and Research Center Pvt. Ltd. (Wakil Nepal), Anamnagar-29, Kathmandu, Bagmati Province 44600, Nepal. Privacy questions and rights requests may be sent to info@wakilnepal.com. Service inquiries may be sent to consult@wakilnepal.com.
State 'Privacy Request' in the subject line and provide enough information for us to identify the relevant account or matter. Do not email identity documents unless requested through a secure channel. If you are dissatisfied, first ask us to escalate the matter under our future Contact & Grievance Policy; you may also use any complaint or remedy available under applicable Nepal law.
20. Policy governance and related notices
Version 1.0 was last updated on 21 July 2026, is scheduled for review by 21 January 2027, and was reviewed by the Wakil Nepal Legal Team. Legal content governance should follow Wakil Nepal's Editorial Policy and change-control process.
Related legal pages are Terms & Conditions, Disclaimer, Cookie Policy, Refund & Cancellation Policy, Data Retention Policy, AML/KYC Policy if regulated verification is introduced, Editorial Policy, Accessibility Statement, Contact & Grievance Policy, and Legal Notice. Until each linked policy is published, it should not be represented as an operative policy.
Was this page helpful?
Need help?
Contact Wakil Nepal
Ask about this policy, your account or a legal-service request. Do not attach sensitive identity documents to ordinary email.
