1. Introduction
Codapulse Global Pvt. Ltd. ("Codapulse," "we," "us," or "our") respects your privacy. This Privacy Policy describes how we handle information when you use Sitora through our web application, mobile applications, APIs, and related services.
2. Data roles
For account, product, security, support, billing, and company relationship information, Codapulse Global Pvt. Ltd. is responsible for the processing described in this Privacy Policy:
Codapulse Global Pvt. Ltd. Kathmandu, Nepal
For workspace and operational data, your employer or customer organization usually controls the workspace and decides what information is entered, who can access it, which legal basis or consent applies, and how long it is retained. Codapulse Global Pvt. Ltd. processes workspace data to provide Sitora and follow the customer's lawful instructions, applicable agreement, and product settings.
3. Information we collect
We may collect the following categories of information:
- Account information such as name, email address, phone number, role, and authentication credentials or security settings.
- Workspace and operational data such as projects, schedules, progress entries, inventory records, purchase orders, invoices, journal entries, attendance, crew assignments, uploaded documents or photos, support tickets, and audit events.
- Usage, device, and technical data such as device type, browser, app version, IP address, log files, timestamps, notification delivery data, and feature usage needed for security, troubleshooting, and performance monitoring.
- Support-access records such as the operator and affected user, their role and company, reason category, written reason, ticket reference, start and end times, status, revocation, IP address, and alert-delivery metadata.
- Communications such as support requests, notifications, and administrative messages related to the service.
- Content or media you choose to upload. On mobile, camera or photo-library permissions are requested only when you choose to capture or attach files through those features.
4. How we use information
We use collected information to:
- provide, operate, and maintain Sitora;
- authenticate users and enforce role-based access controls;
- process invitations, password resets, and account administration;
- provide controlled support access, notify affected users, and maintain a reviewable security history;
- generate workspace activity, reports, exports, and audit records;
- monitor, investigate, and prevent fraud, abuse, and security incidents;
- improve product reliability, usability, and features;
- comply with legal obligations and respond to lawful requests.
5. Controlled support access and alerts
Authorized Codapulse support or security personnel may temporarily access a user's view of a workspace for a documented support request, troubleshooting, data correction, or security incident. Before access, the operator must have the required permission, reauthenticate with a password and authenticator code, and record a reason and ticket reference. The session is read-only, time-limited, logged, and blocked from designated sensitive routes.
We send the affected user an email and in-app alert when access starts and another alert when it ends, expires, or is revoked. Authenticated in-app history and email include the operator, role, company, reason, ticket, time, and status. Lock-screen push alerts intentionally omit those details to reduce disclosure on a locked device. The affected user can review and revoke an active session from web or mobile.
6. Lawful basis, consent, and purpose
We process personal and operational information where necessary to perform our contract with the customer organization, provide the service you request, protect legitimate operational and security interests, comply with applicable law, or act with consent or authorization where required. Applicable Nepal law includes the Privacy Act, 2075 and the Individual Privacy Rules, 2077.
Workspace administrators and authorized users are responsible for ensuring that personal, employee, contractor, family, financial, identity, document, photograph, or other sensitive records entered into Sitora have an appropriate legal basis, consent, or authority. We use workspace data only for the purposes described in this policy, the applicable agreement, product settings, customer instructions, or legal obligations.
8. Service providers
We use service providers for infrastructure and hosting, object storage, email and push notification delivery, monitoring and error reporting, and related operational support. These providers may process only the information needed to perform their services under contractual confidentiality, security, and data-handling obligations.
Current provider information is available to customer organizations on request. We assess material providers and will give notice of material changes when required by an applicable agreement or law.
9. Data retention
We retain information only for as long as needed to provide the service, meet contractual obligations, maintain audit and security records, resolve disputes, and comply with legal requirements. Unless a legal hold or longer written requirement applies, expired authentication verification and password-reset records are removed after 1 day. Generated export content is removed after 7 days. Terminal notification-delivery records, accepted or expired invitations, inactive push tokens, and completed storage-deletion records are removed after 30 days. Abandoned mobile form drafts are removed on the next draft read or save after 30 days. In-app notifications, expired authentication sessions, export metadata, controlled support-session records, and error-tracking events are removed after 90 days. Application logs are retained for 30 days.
Unsent mobile offline operations remain on the device until they sync or the user explicitly discards them. Audit-event retention follows the customer organization's legal and compliance policy. Audit request context is part of the tamper-evident event hash and is not altered separately by automated cleanup. Other workspace-data periods may be determined by the customer's settings, subscription terms, or internal policies. When information is no longer required, we delete or anonymize it. Copies in protected backups are removed as those backups expire through the normal rotation and are not restored to active use except for disaster recovery.
10. Security
We implement administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. Current safeguards include encryption in transit, application encryption for selected sensitive support and notification fields, role-based access controls, tenant isolation, step-up authentication for support access, audit logging, monitoring, retention limits, and secure development practices.
No transmission or storage method is completely secure. You are responsible for protecting your credentials, enabling available account-security features, reviewing unexpected security alerts, and using Sitora according to your organization's security policies.
11. Security incidents
If we discover a suspected security incident involving information covered by this policy, we will investigate, contain the issue, preserve appropriate evidence, and take corrective action. After validating the incident and identifying affected data and users, we will notify the customer organization, affected users, regulators, or other parties when required by applicable law or contract.
Security concerns, including an unexpected support-access alert, should be reported promptly to contact@codapulse.com and your workspace administrator.
12. Your rights
Under applicable law, including Nepal's Privacy Act, 2075 and Individual Privacy Rules, 2077, you may have rights to know how your personal information is handled and to request access, correction, deletion, restriction, or other available remedies.
Because Sitora is typically provided to organizations, many requests must be routed through your workspace administrator. We will assist customer organizations in responding to valid requests in accordance with applicable law.
14. International data transfers
Sitora is operated from Nepal. Infrastructure, object-storage, email, notification, or monitoring providers may process or store information in other countries. When that occurs, we use contractual, access-control, and security safeguards appropriate to the information and consistent with applicable law and our customer obligations.
15. Children's privacy
Sitora is a business platform and is not directed to children under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us so we can take appropriate action.
16. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date and, where appropriate, providing notice in the product or by other reasonable means.
Your continued use of Sitora after an update means you acknowledge the revised policy.
Contact
For legal, privacy, or data-protection inquiries, email Codapulse Global Pvt. Ltd. at contact@codapulse.com or write to us in Kathmandu, Nepal. For workspace-specific account or access requests, contact your company workspace administrator.
contact@codapulse.com