Privacy Policy

Margintop Solutions · MDESK

Effective: 18 August 2026Last Updated: 18 August 2026Jurisdiction: Nepal
MDESK holds institute records on behalf of the institute. Student and inquiry data is entered by the institute — not by students logging into MDESK.

1. Introduction

MDESK is an institute management platform developed and operated by Margintop Solutions Pvt. Ltd. ("Margintop Solutions", "we", "us", or "our"), a company registered in Nepal. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information.

This policy covers all MDESK products and channels, including our marketing website (mdesk.net), the institute administration portal (app.mdesk.net), the teacher attendance app (including the progressive web app), related APIs, support channels, optional modules (including the marketing module for posting to Facebook, Instagram, TikTok, and LinkedIn), and any other module you enable.

Please read this policy together with our Terms of Service. By using MDESK, you agree to the practices described here. If you do not agree, do not use the Services.

2. Who this policy applies to

This policy applies to:

People we interact with directly
  • Website visitors and people who contact us for a demo, quote, support, or career enquiry
  • Institute owners, administrators, co-founders, sub-admins, and staff who create or are invited to an MDESK account
  • Teachers and other personnel who sign in to the teacher app
People whose data an institute enters into MDESK
  • Prospective students and walk-in inquiries
  • Enrolled students
  • Teachers and staff whose profiles the institute maintains
  • Anyone named in notes, follow-ups, payments, documents, or custom fields the institute adds

Students and inquiry contacts typically do not have their own MDESK login. Their information is entered and managed by the institute that uses MDESK.

3. Roles: who is responsible for the data

Under Nepal's Individual Privacy Act, 2018, it matters who decides why personal data is processed, and who only processes it on someone else's instructions.

Your institute is the data controller for institute records
  • The institute decides what student, inquiry, attendance, fee, teacher, and document data to enter, how long to keep it, and who on its team may see it.
  • The institute must have a lawful basis to collect and use that data — including consent from the person (or a parent/guardian, where the person is a minor) where Nepali law requires it.
  • If you are a student, parent, inquiry, or staff member whose details were entered by an institute, that institute is the first place to go for access, correction, or deletion requests.
Margintop Solutions is the data processor for institute records
  • We host and process institute data solely to provide, maintain, secure, and support the Service, as instructed by the institute and as described in this policy.
  • Our platform administrators may access institute data only as needed for support, security, billing, abuse prevention, or legal compliance — not for unrelated commercial use.
Margintop Solutions is the data controller for account, billing, and website data
  • When you create an MDESK user account, sign in with Google, buy credits, submit a contact form, or browse our website, we decide how that information is used to operate MDESK as a business.
  • We are also the controller for support tickets, security logs, and communications we send you about the Service.

4. Information we collect

The information we process depends on how you use MDESK. We do not require students to create accounts.

a. Account & authentication
  • Name, email, username or teacher ID, hashed password, role, and account status
  • Institute affiliation and, where a person belongs to more than one institute, the institute they select while signed in
  • Google Sign-In details when you choose that option: Google account ID, name, email, and profile photo as provided by Google
  • One-time passwords (OTPs) emailed to you for password reset, stored only long enough to verify the code
  • Profile photo or other media you upload to your user account
b. Institute profile
  • Institute name, address, prefix/code, contact phone, and whether the institute is active
  • Optional public listing details the institute chooses to publish, such as description, logo, map location, contact emails/phones, and website or social links
c. Inquiry & lead data (entered by the institute)
  • Name, phone, email, and address
  • How the inquiry was received, source, learning mode and medium, preferred shift, expected joining date
  • Course interests, follow-up dates, notes, and status
  • Any extra fields the institute adds (custom/dynamic fields)
d. Student records (entered by the institute)
  • Name, phone, address, joined date, and enrolment status
  • Course and class enrolments, fee amounts, payment history, and outstanding balances
  • Attendance marks (present, absent, or other statuses), dates, class, and related remarks
  • Any extra fields the institute adds. Those fields may include information the institute considers operationally necessary — we process whatever the institute stores
e. Teacher & staff records
  • Name, title, email, phone, assigned courses and classes, and employment/status fields the institute maintains
  • Attendance sessions a teacher marks, including timestamps and the students in that class
f. Finance records
  • Fee payments linked to a student, course, amount, date, method, and notes
  • If an advanced-finance module is enabled: expenses, salary disbursements, and related ledger entries
  • Who recorded or updated a payment (audit trail)
g. Files, imports, and optional document storage
  • Spreadsheets and other files uploaded to import students, inquiries, or similar records — including file name, headers, sample rows, and mapping the institute approves
  • If a document-processing module is enabled: files the institute uploads (for example student documents). File size and storage limits are as stated on the pricing page. Institutes must not upload data they are not allowed to hold
h. Billing & credits
  • Credit balance, module selections, purchase or top-up history, and related invoices or payment references when payment collection is enabled
  • Contact details used for billing and account administration
i. Support, contact, and careers
  • Support tickets: title, description, category, priority, app version, and related account
  • Website contact form: name, email, phone, organisation, topic, student-count estimate, and message. These submissions are sent through our email delivery provider (currently EmailJS) so we can reply
  • WhatsApp messages you send to the number published on our site
  • Career applications and related materials you submit
j. Device, session, and technical data
  • IP address, browser or app type, device type, operating system, language, and approximate region
  • Pages or screens viewed, feature use needed to operate the Service, timestamps, and error or crash reports
  • Authentication tokens stored on your device so you can stay signed in
  • Push-notification device tokens (FCM) if notifications are enabled
  • PWA cache on the teacher app, which may temporarily store class and attendance data for offline or low-connectivity use
k. Marketing module & connected social accounts
  • If you enable the marketing module and connect a network, we receive the account identifiers and tokens that network issues so MDESK can act on your behalf. Today that is planned for Facebook Pages, Instagram professional/business accounts, TikTok, and LinkedIn Pages or profiles the platform allows us to publish to. We may add other networks later; we will name them in-product when you connect.
  • From the platform (only what you grant in the consent screen): account or page ID, name, username, profile or page picture, granted permission scopes, token expiry, and the list of pages or accounts you can manage
  • Content you create in MDESK: captions, hashtags, mentions, first comments, media files (images, video, thumbnails), target platforms, schedule time, and draft/publish status
  • Publish results returned by the platform (success, error, post ID, permalink where provided)
  • Engagement and insight metrics the platform makes available to us when you grant that permission (for example reach, views, likes, comments, and similar breakdowns)
  • Who on your institute team created, edited, scheduled, or published a post

We do not collect payment-card numbers on MDESK itself. If you pay through a third-party payment provider, that provider processes your payment details under its own privacy policy. We do not receive your Facebook, Instagram, TikTok, or LinkedIn password. Those logins happen on the platform's own site.

5. How we use information

We use personal information only for these purposes:

Provide the Service
  • Create and authenticate accounts, including Google Sign-In and OTP reset
  • Let institutes manage inquiries, students, courses, classes, teachers, attendance, and fees
  • Let teachers view assigned classes and mark attendance from a phone or computer
  • Sync attendance and other records between the teacher app and the institute office in near real time
  • Support multi-institute logins and role-based access (owner, sub-admin, teacher, staff)
  • Import records from spreadsheets, including AI-assisted column mapping as described in Section 7
  • Run optional modules the institute enables (for example documents, advanced finance, or marketing)
  • If the marketing module is on: let you create, edit, schedule, publish, and review posts to connected Facebook, Instagram, TikTok, and LinkedIn accounts from MDESK, and show you the engagement metrics those platforms return
Operate, secure, and improve MDESK
  • Diagnose bugs, prevent abuse, and keep the platform secure
  • Maintain audit logs of important changes (for example student and payment edits)
  • Understand aggregated product usage so we can improve reliability and features
  • Train support staff and, where needed, reproduce an issue you reported
Communicate with you
  • Service messages: security alerts, outages, billing, and material policy changes
  • Replies to demos, quotes, onboarding, support, and privacy requests
  • In-app or push notifications related to classes, attendance, or account activity, where enabled
Billing and legal
  • Charge for modules and credits as published on our pricing page, and keep accounting records
  • Comply with Nepali law, respond to lawful requests, and enforce our Terms of Service

We do not sell personal data. We do not use institute student records to serve third-party advertising. We do not use your institute's identifiable records to train public AI models.

6. Student records and children's data

MDESK accounts are for adult institute personnel — owners, staff, and teachers. The teacher app and admin portal are not designed as a student-facing product, and we do not knowingly create logins for children.

Institutes often teach minors (for example computer classes, language schools, coaching, and similar). When an institute enters a student or inquiry record, that record may identify a person under 18. We process that data only as the institute's processor.

What the institute must do
  • Collect only what it needs to run the institute
  • Obtain any consent or other lawful basis required under Nepali law, including from a parent or guardian where the student is a minor
  • Not use custom fields to store unnecessary sensitive data (for example identity documents, health information, or caste) unless the institute has a clear lawful reason and appropriate safeguards
  • Not post photos, videos, names, or other identifying details of students (especially minors) to Facebook, Instagram, TikTok, LinkedIn, or any other network through MDESK unless the institute has a lawful basis and any required parent/guardian consent
  • Respond to parents, students, and inquiry contacts who ask to see, correct, or delete their data

If you believe a child has been given an MDESK login, or that a record was entered without a lawful basis, contact the institute first. You may also email us at [email protected] with the subject [MDesk Privacy]. We will work with the institute to correct or remove the data where we are required or able to do so.

7. Artificial intelligence

Some MDESK features use third-party AI services so that the product can help with operational tasks.

Spreadsheet import (current)
  • When an institute uploads a spreadsheet, we may send column headers and a small sample of rows to an AI provider to suggest how columns map to MDESK fields (name, phone, course, and so on).
  • The institute reviews and confirms the mapping before records are created. AI suggestions can be wrong; the institute is responsible for checking the preview.
  • Imported files are stored so the import can be completed, audited, or retried.
Future insight features
  • We may add features that summarise institute activity or answer questions about the institute's own records. If we do, those features will still run on data the institute already stores in MDESK.
  • Where a new AI feature would send additional personal data to a third-party model, we will describe that in-product or by updating this policy before it is required for core use.

AI providers may process data on servers outside Nepal. See Section 11. We instruct providers to use the data to return a result for that request, not to sell it. We do not permit providers to use identifiable institute records to train their general public models where the contract allows us to prevent that.

8. How we share information

We share personal information only as follows:

Inside your institute
  • People the institute invites, with the permissions the institute assigns, can see the institute data those permissions allow — for example a teacher seeing students in assigned classes, or an admin seeing fees.
  • Attendance a teacher marks is visible to the institute office. That is the point of the product.
Service providers (processors we use)
  • Cloud hosting, database, file storage, and backup providers
  • Email delivery (transactional mail such as OTPs and welcome messages; contact-form delivery via EmailJS)
  • Google, when you use Google Sign-In
  • AI providers used for import mapping and any similar features we enable
  • Push-notification infrastructure, if notifications are turned on
  • Payment providers, if you buy credits through them
Optional connections the institute chooses
  • Marketing module: when you connect Facebook, Instagram, TikTok, LinkedIn, or another supported network, we share with that network the media, captions, and targeting you chose, using the access tokens you granted, so the post can be published or scheduled. The network then processes that content under its own terms and privacy policy. See Section 9.
  • Public listing information the institute chooses to publish may appear on MDESK or related discovery pages.
Legal, safety, and business transfers
  • We may disclose information if required by Nepali law, a court, or a competent authority
  • We may disclose information to prevent serious harm, fraud, or abuse of the Service
  • If Margintop Solutions is involved in a merger, acquisition, or sale of assets, data may transfer to the successor. We will give notice where the law requires it

We never sell, rent, or trade personal information for advertising.

9. Marketing module and connected social accounts

The marketing module is optional. Nothing is posted to a social network until an authorised institute user connects that network and creates, schedules, or publishes a post in MDESK.

What you can do from MDESK
  • Connect Facebook Pages and related Instagram professional or business accounts
  • Connect TikTok accounts the TikTok API allows for business publishing
  • Connect LinkedIn Pages or profiles the LinkedIn API allows for organisational posting
  • Create a post once (text, image, or video), choose one or more of those networks, and publish immediately or on a schedule
  • See draft, scheduled, published, and failed status, and view engagement metrics the platform returns when you have granted that permission
How we use platform data
  • Only to provide this publishing and reporting feature for your institute: to keep you signed in to the connection, to upload and publish the content you submit, to show status and insights, and to diagnose failed posts
  • We do not sell Facebook, Instagram, TikTok, or LinkedIn data. We do not use it to advertise MDESK to your followers. We do not give it to other institutes
  • We request only the permissions needed to list the accounts you can manage, publish content you create, and (where you opt in) read insights. You can refuse a permission in the platform dialog; some features will then be unavailable
Where the data goes
  • Access tokens and connection metadata are stored on our servers so scheduled posts can go out without you sitting at the computer. Tokens are treated as secrets and are not shown in full in the product or in logs
  • Media and captions are sent to Meta (Facebook and Instagram), TikTok Pte. Ltd. / ByteDance, LinkedIn (Microsoft), and any other network you connect. Those companies process data on servers that are often outside Nepal. Their privacy policies apply to what they receive
  • A person who comments on or views your post on that network is a user of that network, not of MDESK. We only see comment or insight data if the platform API returns it to us for your connected account
Disconnect, revoke, and delete
  • You can disconnect a Facebook, Instagram, TikTok, or LinkedIn account from MDESK. We then stop new publishes and delete or revoke the stored access token for that connection as soon as reasonably possible
  • You should also revoke MDESK in that platform's own settings (for example Facebook Settings → Apps and websites, Instagram, TikTok, or LinkedIn authorized apps) so the platform stops issuing tokens to us
  • Disconnecting does not take down posts already published. Those remain on the platform until you delete them there
  • Drafts, schedules, media files, and publish logs kept in MDESK can be deleted in the product by an authorised user, or by emailing [email protected] with the subject [MDesk Privacy] from the institute admin address
  • If Meta, TikTok, or LinkedIn sends us a user-data deletion request for a connected account, we will delete that connection's tokens and related social data we hold, except records we must keep for security or law

People who appear in your posts (students, staff, parents) are not asked by MDESK for consent. The institute must have that consent or another lawful basis before uploading their image, name, or story. See Section 6.

10. Cookies and local storage

MDESK uses cookies and similar storage to make the Service work. We do not currently use advertising cookies or third-party marketing pixels on mdesk.net.

What we store on your device
  • Authentication tokens so you stay signed in (typically in the browser's local storage, not an advertising cookie)
  • Preferences: language, theme, selected institute, and sidebar state
  • Teacher-app cache for offline or interrupted attendance marking
  • Essential cookies needed to run the website and apps

You can sign out to clear session tokens. Clearing site data in your browser will also remove local preferences. Some features (including staying signed in and offline attendance) will not work without this storage.

Our marketing website contact form is processed by EmailJS. WhatsApp links open WhatsApp's service, which has its own privacy policy.

11. International processing

Margintop Solutions is based in Nepal. Some subprocessors — including Google (sign-in), Meta (Facebook and Instagram), TikTok, LinkedIn, AI providers, email delivery, and cloud infrastructure — may process data in other countries.

Where data is processed outside Nepal, we take contractual and practical steps that are reasonable for a service of this kind, including using reputable providers and limiting what we send (for example, sample rows for import mapping rather than an entire student database, where that is sufficient).

By using MDESK, the institute acknowledges that this cross-border processing is necessary to provide parts of the Service.

12. Security

We implement safeguards appropriate to the nature of institute data, including:

Measures we use
  • TLS encryption for data in transit between your device and our servers
  • Hashed password storage — we never store passwords in plaintext
  • Role-based access so institute users only see what their role allows
  • API authentication tokens, session expiry, and logout invalidation
  • Social-network access tokens stored as secrets so scheduled posts can publish; they are not shown in full in the product
  • Activity logging for sensitive actions such as student and payment changes
  • Access by our team limited to support, operations, and security needs

No method of transmission or storage is perfectly secure. You must use a strong unique password, keep your login private, and tell us at [email protected] if you suspect unauthorised access.

Institutes are responsible for who they invite, which permissions they grant, and for removing access when staff leave.

13. How long we keep data

We keep information only as long as needed for the purposes in this policy, or as required by law.

Typical periods
  • User accounts: while the account is active, then a short period after deletion or institute request so we can complete removal and resolve disputes
  • Institute operational data (students, inquiries, attendance, fees, files): for the life of the institute workspace, unless the institute deletes records earlier or requests export and deletion after the account ends
  • After an institute account is closed: we allow a window (typically 30 days) for the institute to request an export; after that we may delete or irreversibly anonymise remaining personal data, except where we must keep a subset for tax, accounting, security, or legal claims
  • OTPs: until they expire
  • Security, audit, and server logs: generally up to 2 years, or longer if needed to investigate an incident
  • Contact-form and support records: as long as needed to handle the request and keep a reasonable customer-service history
  • Aggregated statistics that no longer identify a person may be kept to understand product use
  • Marketing connections: access tokens until you disconnect, the token expires, or the platform revokes them; post drafts, media, and publish logs while the institute workspace exists or until you delete them; insight snapshots for a limited operational period (generally up to 2 years unless you delete sooner)

Deletion of a teacher or staff login does not automatically erase historical attendance or payment rows they created, because those are institute records. The institute can correct or delete those rows in the product, subject to its own record-keeping duties.

14. Your rights

Under Nepal's Individual Privacy Act, 2018 (व्यक्तिगत गोपनीयता ऐन, २०७५) and the Constitution of Nepal, 2015, you may have the right to:

Rights
  • Be informed about collection and use of your personal data
  • Access a copy of personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion, subject to legal and contractual retention needs
  • Withdraw consent for optional processing (this does not affect processing we must do to provide the Service or to comply with law)
  • Lodge a grievance with our Privacy Officer
How to exercise them
  • If your data was entered by an institute (student, inquiry, or similar): contact that institute. They control the record. We will support the institute in fulfilling a valid request.
  • If you have an MDESK login: you can update much of your profile in the app. For deletion of your user account, ask your institute administrator or email us.
  • Website visitors and people without an account: email [email protected] with the subject [MDesk Privacy].
  • Connected social accounts: disconnect in MDESK and revoke the app on Facebook, Instagram, TikTok, or LinkedIn. For deletion of tokens and post records we store, use the product or email us as in Section 9.

We will respond within 30 days of receiving a valid request, or explain if the law allows a longer period. We may need to verify your identity and, for institute records, confirm that the institute authorises the change. We may refuse a request that is unfounded, excessive, or would prevent us or the institute from meeting a legal duty.

15. Third-party sites and connected services

MDESK may link to an institute website, maps, WhatsApp, Google, social networks, or payment pages. Those services are not controlled by us. Their privacy practices are their own. Review their policies before you share information with them.

Facebook and Instagram are operated by Meta Platforms. TikTok is operated by TikTok Pte. Ltd. / ByteDance. LinkedIn is operated by LinkedIn Corporation (Microsoft). Connecting those accounts means you also agree to that platform's terms and privacy policy. We are not responsible for a platform changing its API, rejecting a post, limiting impressions, or suspending your account.

16. Changes to this policy

We may update this Privacy Policy when our product, providers, or legal duties change. For material changes we will:

How we notify you
  • Update the "Last Updated" date at the top of this page
  • Show a notice in the Service, and/or email the institute administrator, at least 15 days before the change takes effect where practicable

Continued use after the effective date means you accept the updated policy. If you do not agree, stop using the Service and ask your institute administrator to close or restrict your access.

17. Governing law

This Privacy Policy is governed by the laws of Nepal, including the Individual Privacy Act, 2018, the Electronic Transaction Act, 2063 (2008), and other applicable Nepali law.

Courts of competent jurisdiction in Nepal have exclusive jurisdiction over disputes, except that nothing here limits a data subject's right to approach a competent authority under Nepali privacy law. Please contact us first so we can try to resolve the issue.

18. Contact and Privacy Officer

Questions, access requests, and grievances:

Margintop Solutions Pvt. Ltd. — Privacy Officer
  • Email: [email protected]
  • Phone: +977-9845926945
  • Subject line: [MDesk Privacy] — Your request
  • For a formal grievance: [MDesk Grievance]
  • Response: within 30 days
  • Registered jurisdiction: Pulchowk, Lalitpur, Nepal

If we cannot resolve a privacy grievance, you may escalate to the authority competent under Nepali law.