Privacy Policy

Margintop Solutions · MDESK

Effective: 18 August 2026Last Updated: 7 October 2026Jurisdiction: Nepal
MDESK holds institute records on behalf of the institute. Student and inquiry data is entered by the institute — not by students logging into MDESK.

1. Introduction

MDESK is an institute management platform developed and operated by Margintop Solutions Pvt. Ltd. ("Margintop Solutions", "we", "us", or "our"), a company registered in Nepal. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information.

This policy covers all MDESK products and channels, including our marketing website (mdesk.net), the institute administration portal (app.mdesk.net), the teacher attendance app (including the progressive web app), MDESK Counsellor (counsellor.mdesk.net) — our free study-abroad assistant and country guides for students from Nepal — related APIs, support channels, optional modules (including the marketing module for posting to Facebook, Instagram, and TikTok), and any other module you enable.

Please read this policy together with our Terms of Service, Cookie Notice, and Data Processing Addendum. By using MDESK, you agree to the practices described here. If you do not agree, do not use the Services.

2. Who this policy applies to

This policy applies to:

People we interact with directly
  • Website visitors and people who contact us for a demo, quote, support, or career enquiry
  • Visitors who use MDESK Counsellor to ask study-abroad questions or read a country guide. No account is needed and we do not ask who you are
  • Institute owners, administrators, co-founders, sub-admins, and staff who create or are invited to an MDESK account
  • Teachers and other personnel who sign in to the teacher app
People whose data an institute enters into MDESK
  • Prospective students and walk-in inquiries
  • Enrolled students
  • Teachers and staff whose profiles the institute maintains
  • Anyone named in notes, follow-ups, payments, documents, or custom fields the institute adds

Students and inquiry contacts typically do not have their own MDESK login. Their information is entered and managed by the institute that uses MDESK.

3. Roles: who is responsible for the data

Under Nepal's Individual Privacy Act, 2018, it matters who decides why personal data is processed, and who only processes it on someone else's instructions.

Your institute is the data controller for institute records
  • The institute decides what student, inquiry, attendance, fee, teacher, and document data to enter, how long to keep it, and who on its team may see it.
  • The institute must have a lawful basis to collect and use that data — including consent from the person (or a parent/guardian, where the person is a minor) where Nepali law requires it.
  • If you are a student, parent, inquiry, or staff member whose details were entered by an institute, that institute is the first place to go for access, correction, or deletion requests.
Margintop Solutions is the data processor for institute records
  • We host and process institute data solely to provide, maintain, secure, and support the Service, as instructed by the institute and as described in this policy and the Data Processing Addendum.
  • Our platform administrators may access institute data only as needed for support, security, billing, abuse prevention, or legal compliance — not for unrelated commercial use.
Margintop Solutions is the data controller for account, billing, and website data
  • When you create an MDESK user account, sign in with Google, buy credits, submit a contact form, or browse our website, we decide how that information is used to operate MDESK as a business.
  • We are also the controller for support tickets, security logs, and communications we send you about the Service.

The processor relationship for institute records is set out in the Data Processing Addendum, which forms part of the Terms of Service.

4. Information we collect

The information we process depends on how you use MDESK. We do not require students to create accounts.

a. Account & authentication
  • Name, email, username or teacher ID, hashed password, role, and account status
  • Institute affiliation and, where a person belongs to more than one institute, the institute they select while signed in
  • Google Sign-In details when you choose that option: Google account ID, name, email, and profile photo as provided by Google
  • One-time passwords (OTPs) emailed to you for password reset, stored only long enough to verify the code
  • Profile photo or other media you upload to your user account
b. Institute profile
  • Institute name, address, prefix/code, contact phone, and whether the institute is active
  • Optional public listing details the institute chooses to publish, such as description, logo, map location, contact emails/phones, and website or social links
c. Inquiry & lead data (entered by the institute)
  • Name, phone, email, and address
  • How the inquiry was received, source, learning mode and medium, preferred shift, expected joining date
  • Course interests, follow-up dates, notes, and status
  • Any extra fields the institute adds (custom/dynamic fields)
d. Student records (entered by the institute)
  • Name, phone, address, joined date, and enrolment status
  • Course and class enrolments, fee amounts, payment history, and outstanding balances
  • Attendance marks (present, absent, or other statuses), dates, class, and related remarks
  • Any extra fields the institute adds. Those fields may include information the institute considers operationally necessary — we process whatever the institute stores
e. Teacher & staff records
  • Name, title, email, phone, assigned courses and classes, and employment/status fields the institute maintains
  • Attendance sessions a teacher marks, including timestamps and the students in that class
f. Finance records
  • Fee payments linked to a student, course, amount, date, method, and notes
  • If an advanced-finance module is enabled: expenses, salary disbursements, and related ledger entries
  • Who recorded or updated a payment (audit trail)
g. Files, imports, and optional document storage
  • Spreadsheets and other files uploaded to import students, inquiries, or similar records — including file name, headers, sample rows, and mapping the institute approves
  • If a document-processing module is enabled: files the institute uploads (for example student documents). File size and storage limits are as stated on the pricing page. Institutes must not upload data they are not allowed to hold
h. Billing & credits
  • Credit balance, module selections, purchase or top-up history, and related invoices or payment references when payment collection is enabled
  • Contact details used for billing and account administration
i. Support, contact, and careers
  • Support tickets: title, description, category, priority, app version, and related account
  • Website contact form: name, email, phone, organisation, topic, student-count estimate, and message. These submissions are sent through our email delivery provider (currently EmailJS) so we can reply
  • WhatsApp messages you send to the number published on our site
  • Career applications and related materials you submit
j. Device, session, and technical data
  • IP address, browser or app type, device type, operating system, language, and approximate region
  • Pages or screens viewed, feature use needed to operate the Service, timestamps, and error or crash reports
  • Authentication tokens stored on your device so you can stay signed in
  • Push-notification device tokens (FCM) if notifications are enabled
  • PWA cache on the teacher app, which may temporarily store class and attendance data for offline or low-connectivity use
k. Marketing module & connected social accounts
  • If you enable the marketing module and connect a network, we receive the account identifiers and tokens that network issues so MDESK can act on your behalf. Today this covers Facebook Pages, Instagram professional accounts, and TikTok accounts. We may add other networks later; we will name them in-product when you connect and update this policy.
  • From the platform (only what you grant in the consent screen): account or page ID, name, username, profile or page picture, granted permission scopes, token expiry, and the list of pages or accounts you can manage
  • For TikTok specifically, we store: your TikTok open ID and display name, the access and refresh tokens (encrypted), token expiry, and the scopes you granted. The TikTok account details shown before each post (nickname, avatar, available privacy options, interaction settings, and maximum video length) are fetched live from TikTok and are not stored
  • Content you create in MDESK: captions, hashtags, mentions, first comments, media files (images, video, thumbnails), target platforms, schedule time, and draft/publish status
  • Publish results returned by the platform (success, error, post ID, permalink where provided), including publish status updates TikTok sends us by webhook
  • Engagement and insight metrics the platform makes available to us when you grant that permission (for example reach, views, likes, comments, and similar breakdowns). For TikTok, this is the view, like, comment, and share counts and share link of videos published through MDESK; other videos on your TikTok account are not stored
  • Who on your institute team created, edited, scheduled, or published a post
l. MDESK Counsellor (study-abroad assistant)
  • The question you type, and the recent turns of that conversation, so the assistant can answer in context. Before we store anything or send it to an AI provider, we automatically strip personal details we can detect — email addresses, phone numbers, names given as "my name is…", passport, citizenship and other ID numbers, dates of birth, and social-media links
  • We do not keep a copy of your conversation on our servers. The visible chat lives in your own browser only, and the Clear button removes it
  • A random visitor ID generated in your browser (local storage) plus a signed anti-abuse session cookie, so we can count usage and rate-limit misuse. Neither is linked to your name, and we do not store your IP address against them
  • Aggregate usage records for each question answered: the visitor ID, a timestamp, whether the answer came from a guide or the AI model, the country asked about, and processing volume. These do not contain your message text
  • When the assistant does not know something, we save a short rephrased research summary of the topic — for example "student visa steps for Japan" — so we can add it to a guide later. This is written to describe the topic, not to quote you, and runs through the same personal-detail stripping

We do not collect payment-card numbers on MDESK itself. If you pay through a third-party payment provider, that provider processes your payment details under its own privacy policy. We do not receive your Facebook, Instagram, or TikTok password. Those logins happen on the platform's own site.

MDESK Counsellor is open to the public and does not verify age. Please do not type personal details, identity documents, or someone else's information into the chat — you never need to in order to get an answer.

5. How we use information

We use personal information only for these purposes:

Provide the Service
  • Create and authenticate accounts, including Google Sign-In and OTP reset
  • Let institutes manage inquiries, students, courses, classes, teachers, attendance, and fees
  • Let teachers view assigned classes and mark attendance from a phone or computer
  • Sync attendance and other records between the teacher app and the institute office in near real time
  • Support multi-institute logins and role-based access (owner, sub-admin, teacher, staff)
  • Import records from spreadsheets, including AI-assisted column mapping as described in Section 7
  • Run optional modules the institute enables (for example documents, advanced finance, or marketing)
  • If the marketing module is on: let you create, edit, schedule, publish, and review posts to connected Facebook, Instagram, and TikTok accounts from MDESK, and show you the engagement metrics those platforms return
Operate, secure, and improve MDESK
  • Diagnose bugs, prevent abuse, and keep the platform secure
  • Maintain audit logs of important changes (for example student and payment edits)
  • Understand aggregated product usage so we can improve reliability and features
  • Train support staff and, where needed, reproduce an issue you reported
Communicate with you
  • Service messages: security alerts, outages, billing, and material policy changes
  • Replies to demos, quotes, onboarding, support, and privacy requests
  • In-app or push notifications related to classes, attendance, or account activity, where enabled
Billing and legal
  • Charge for modules and credits as published on our pricing page, and keep accounting records
  • Comply with Nepali law, respond to lawful requests, and enforce our Terms of Service

We do not sell personal data. We do not use institute student records to serve third-party advertising. We do not use your institute's identifiable records to train public AI models.

6. Student records and children's data

MDESK accounts are for adult institute personnel — owners, staff, and teachers. The teacher app and admin portal are not designed as a student-facing product, and we do not knowingly create logins for children.

Institutes often teach minors (for example computer classes, language schools, coaching, and similar). When an institute enters a student or inquiry record, that record may identify a person under 18. We process that data only as the institute's processor.

What the institute must do
  • Collect only what it needs to run the institute
  • Obtain any consent or other lawful basis required under Nepali law, including from a parent or guardian where the student is a minor
  • Not use custom fields to store unnecessary sensitive data (for example identity documents, health information, or caste) unless the institute has a clear lawful reason and appropriate safeguards
  • Not post photos, videos, names, or other identifying details of students (especially minors) to Facebook, Instagram, TikTok, or any other network through MDESK unless the institute has a lawful basis and any required parent/guardian consent
  • Respond to parents, students, and inquiry contacts who ask to see, correct, or delete their data

If you believe a child has been given an MDESK login, or that a record was entered without a lawful basis, contact the institute first. You may also email us at [email protected] with the subject [MDesk Privacy]. We will work with the institute to correct or remove the data where we are required or able to do so.

7. Artificial intelligence

Some MDESK features use third-party AI services so that the product can help with operational tasks.

Spreadsheet import (current)
  • When an institute uploads a spreadsheet, we may send column headers and a small sample of rows to an AI provider to suggest how columns map to MDESK fields (name, phone, course, and so on).
  • The institute reviews and confirms the mapping before records are created. AI suggestions can be wrong; the institute is responsible for checking the preview.
  • Imported files are stored so the import can be completed, audited, or retried.
MDESK Counsellor chat (current)
  • MDESK Counsellor answers using a third-party AI provider. Your question, the recent turns of the conversation, and extracts from our published country guides are sent to that provider so it can compose a reply.
  • We strip personal details we can detect before the text leaves our servers, as described in Section 4(l). Do not type identity documents or contact details into the chat.
  • The provider processes the request to return that answer. We do not permit it to use the content to train its general public models where our contract allows us to prevent that.
  • Answers are informational and can be incomplete or out of date. Fees, exam requirements, and visa rules change often — always confirm on the official government or university source before you act or pay.
Future insight features
  • We may add features that summarise institute activity or answer questions about the institute's own records. If we do, those features will still run on data the institute already stores in MDESK.
  • Where a new AI feature would send additional personal data to a third-party model, we will describe that in-product or by updating this policy before it is required for core use.

AI providers may process data on servers outside Nepal. See Section 11. We instruct providers to use the data to return a result for that request, not to sell it. We do not permit providers to use identifiable institute records to train their general public models where the contract allows us to prevent that.

8. How we share information

We share personal information only as follows:

Inside your institute
  • People the institute invites, with the permissions the institute assigns, can see the institute data those permissions allow — for example a teacher seeing students in assigned classes, or an admin seeing fees.
  • Attendance a teacher marks is visible to the institute office. That is the point of the product.
Service providers (processors we use)
  • Cloud hosting, database, file storage, and backup providers
  • Email delivery (transactional mail such as OTPs and welcome messages; contact-form delivery via EmailJS)
  • Google, when you use Google Sign-In
  • AI providers used for import mapping, MDESK Counsellor chat replies, and any similar features we enable
  • Bot protection for MDESK Counsellor (currently Cloudflare Turnstile), which checks that a visitor is human before the chat runs
  • Push-notification infrastructure, if notifications are turned on
  • Payment providers, if you buy credits through them
Optional connections the institute chooses
  • Marketing module: when you connect Facebook, Instagram, TikTok, or another supported network, we share with that network the media, captions, and targeting you chose, using the access tokens you granted, so the post can be published or scheduled. The network then processes that content under its own terms and privacy policy. See Section 9.
  • Public listing information the institute chooses to publish may appear on MDESK or related discovery pages.
Legal, safety, and business transfers
  • We may disclose information if required by Nepali law, a court, or a competent authority
  • We may disclose information to prevent serious harm, fraud, or abuse of the Service
  • If Margintop Solutions is involved in a merger, acquisition, or sale of assets, data may transfer to the successor. We will give notice where the law requires it

We never sell, rent, or trade personal information for advertising.

9. Marketing module and connected social accounts

The marketing module is optional. Nothing is posted to a social network until an authorised institute user connects that network and creates, schedules, or publishes a post in MDESK.

What you can do from MDESK
  • Connect Facebook Pages and Instagram professional accounts
  • Connect your institute's TikTok account to publish videos and photo posts
  • Create a post once (text, image, or video), choose one or more of those networks, and publish immediately or on a schedule
  • See draft, scheduled, published, and failed status, and view engagement metrics the platform returns when you have granted that permission
Posting to TikTok
  • Before each TikTok post, MDESK shows the TikTok account the post will go to and asks you to choose the privacy level from the options TikTok provides. No privacy level is pre-selected
  • You decide whether to allow comments, Duet, and Stitch (where TikTok allows them for that post), and whether to disclose the post as commercial content (your own brand or branded content)
  • You must agree to TikTok's Music Usage Confirmation (and the Branded Content Policy when applicable) before the post can be published
  • The post is only sent to TikTok when you click publish or when a schedule you set comes due. MDESK does not alter your video or add watermarks
  • TikTok may take a few minutes to process a post. MDESK shows the post as publishing until TikTok confirms the result
How we use platform data
  • Only to provide this publishing and reporting feature for your institute: to keep you signed in to the connection, to upload and publish the content you submit, to show status and insights, and to diagnose failed posts
  • We do not sell Facebook, Instagram, or TikTok data. We do not use it to advertise MDESK to your followers. We do not give it to other institutes
  • We request only the permissions needed to list the accounts you can manage, publish content you create, and (where you opt in) read insights. You can refuse a permission in the platform dialog; some features will then be unavailable
Where the data goes
  • Access tokens and connection metadata are stored on our servers so scheduled posts can go out without you sitting at the computer. Tokens are treated as secrets and are not shown in full in the product or in logs
  • Media and captions are sent to Meta (Facebook and Instagram), TikTok Pte. Ltd. / ByteDance, and any other network you connect. Those companies process data on servers that are often outside Nepal. Their privacy policies apply to what they receive
  • A person who comments on or views your post on that network is a user of that network, not of MDESK. We only see comment or insight data if the platform API returns it to us for your connected account
Disconnect, revoke, and delete
  • You can disconnect a Facebook, Instagram, or TikTok account from MDESK. We then stop new publishes and delete or revoke the stored access token for that connection as soon as reasonably possible. For TikTok, we also ask TikTok to revoke the token
  • You can also revoke MDESK in that platform's own settings (for example Facebook Settings → Apps and websites, Instagram, or TikTok's authorized apps). When TikTok tells us you removed access, MDESK automatically deletes the stored TikTok tokens and account name and marks the connection as disconnected
  • Disconnecting does not take down posts already published. Those remain on the platform until you delete them there
  • Drafts, schedules, media files, and publish logs kept in MDESK can be deleted in the product by an authorised user, or by emailing [email protected] with the subject [MDesk Privacy] from the institute admin address
  • If Meta or TikTok sends us a user-data deletion request for a connected account, we will delete that connection's tokens and related social data we hold, except records we must keep for security or law

People who appear in your posts (students, staff, parents) are not asked by MDESK for consent. The institute must have that consent or another lawful basis before uploading their image, name, or story. See Section 6.

10. Cookies and local storage

MDESK uses cookies and similar storage to make the Service work. The marketing website (mdesk.net) uses Google Analytics 4 to measure site usage. We do not use advertising cookies or third-party marketing pixels on mdesk.net. The full table of what we store, and how to control it, is in the Cookie Notice.

What we store on your device
  • Authentication tokens so you stay signed in (typically in the browser's local storage, not an advertising cookie)
  • Preferences: language, theme, selected institute, and sidebar state
  • Teacher-app cache for offline or interrupted attendance marking
  • MDESK Counsellor: a random visitor ID in local storage, a signed anti-abuse session cookie, and your current chat, which is held in the browser and cleared with the Clear button. Cloudflare Turnstile also sets its own storage while it checks that you are human
  • Essential cookies needed to run the website and apps
  • Google Analytics identifiers and related storage on the marketing website so we can understand visits and page use (measurement ID G-90NS9MEGXE)

You can sign out to clear session tokens. Clearing site data in your browser will also remove local preferences. Some features (including staying signed in and offline attendance) will not work without this storage.

Our marketing website contact form is processed by EmailJS. WhatsApp links open WhatsApp's service, which has its own privacy policy.

11. International processing

Margintop Solutions is based in Nepal. Some subprocessors — including Google (sign-in and Google Analytics on the marketing website), Meta (Facebook and Instagram), TikTok, AI providers, Cloudflare (bot protection for MDESK Counsellor), email delivery, and cloud infrastructure — may process data in other countries.

Where data is processed outside Nepal, we take contractual and practical steps that are reasonable for a service of this kind, including using reputable providers and limiting what we send (for example, sample rows for import mapping rather than an entire student database, where that is sufficient).

By using MDESK, the institute acknowledges that this cross-border processing is necessary to provide parts of the Service.

12. Security

We implement safeguards appropriate to the nature of institute data, including:

Measures we use
  • TLS encryption for data in transit between your device and our servers
  • Hashed password storage — we never store passwords in plaintext
  • Role-based access so institute users only see what their role allows
  • API authentication tokens, session expiry, and logout invalidation
  • Social-network access tokens stored as secrets so scheduled posts can publish; they are not shown in full in the product
  • Activity logging for sensitive actions such as student and payment changes
  • Access by our team limited to support, operations, and security needs

No method of transmission or storage is perfectly secure. You must use a strong unique password, keep your login private, and tell us at [email protected] if you suspect unauthorised access.

Institutes are responsible for who they invite, which permissions they grant, and for removing access when staff leave.

13. How long we keep data

We keep information only as long as needed for the purposes in this policy, or as required by law.

Typical periods
  • User accounts: while the account is active, then a short period after deletion or institute request so we can complete removal and resolve disputes
  • Institute operational data (students, inquiries, attendance, fees, files): for the life of the institute workspace, unless the institute deletes records earlier or requests export and deletion after the account ends
  • After an institute account is closed: we allow a window (typically 30 days) for the institute to request an export; after that we may delete or irreversibly anonymise remaining personal data, except where we must keep a subset for tax, accounting, security, or legal claims
  • OTPs: until they expire
  • Security, audit, and server logs: generally up to 2 years, or longer if needed to investigate an incident
  • Contact-form and support records: as long as needed to handle the request and keep a reasonable customer-service history
  • Aggregated statistics that no longer identify a person may be kept to understand product use
  • MDESK Counsellor: chat text is not stored on our servers at all — it stays in your browser until you clear it. The visitor ID, per-question usage records, and redacted research summaries are kept while they remain useful for guide coverage and abuse prevention
  • Marketing connections: access tokens until you disconnect, the token expires, or the platform revokes them; post drafts, media, and publish logs while the institute workspace exists or until you delete them; insight snapshots for a limited operational period (generally up to 2 years unless you delete sooner)

Deletion of a teacher or staff login does not automatically erase historical attendance or payment rows they created, because those are institute records. The institute can correct or delete those rows in the product, subject to its own record-keeping duties.

14. Your rights

Under Nepal's Individual Privacy Act, 2018 (व्यक्तिगत गोपनीयता ऐन, २०७५) and the Constitution of Nepal, 2015, you may have the right to:

Rights
  • Be informed about collection and use of your personal data
  • Access a copy of personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion, subject to legal and contractual retention needs
  • Withdraw consent for optional processing (this does not affect processing we must do to provide the Service or to comply with law)
  • Lodge a grievance with our Privacy Officer
How to exercise them
  • If your data was entered by an institute (student, inquiry, or similar): contact that institute. They control the record. We will support the institute in fulfilling a valid request.
  • If you have an MDESK login: you can update much of your profile in the app. For deletion of your user account, ask your institute administrator or email us.
  • Website visitors and people without an account: email [email protected] with the subject [MDesk Privacy].
  • MDESK Counsellor users: use the Clear button to wipe the chat from your browser, and clear site data to reset the visitor ID. Because we do not hold your transcript or your name, quote the approximate date and topic if you want us to look for a stored research summary.
  • Connected social accounts: disconnect in MDESK and revoke the app on Facebook, Instagram, or TikTok. For deletion of tokens and post records we store, use the product or email us as in Section 9.

We will respond within 30 days of receiving a valid request, or explain if the law allows a longer period. We may need to verify your identity and, for institute records, confirm that the institute authorises the change. We may refuse a request that is unfounded, excessive, or would prevent us or the institute from meeting a legal duty.

15. Third-party sites and connected services

MDESK may link to an institute website, maps, WhatsApp, Google, social networks, or payment pages. Those services are not controlled by us. Their privacy practices are their own. Review their policies before you share information with them.

Facebook and Instagram are operated by Meta Platforms. TikTok is operated by TikTok Pte. Ltd. / ByteDance. Connecting those accounts means you also agree to that platform's terms and privacy policy. We are not responsible for a platform changing its API, rejecting a post, limiting impressions, or suspending your account.

16. Changes to this policy

We may update this Privacy Policy when our product, providers, or legal duties change. For material changes we will:

How we notify you
  • Update the "Last Updated" date at the top of this page
  • Show a notice in the Service, and/or email the institute administrator, at least 15 days before the change takes effect where practicable

Continued use after the effective date means you accept the updated policy. If you do not agree, stop using the Service and ask your institute administrator to close or restrict your access.

17. Governing law

This Privacy Policy is governed by the laws of Nepal, including the Individual Privacy Act, 2018, the Electronic Transaction Act, 2063 (2008), and other applicable Nepali law.

Courts of competent jurisdiction in Nepal have exclusive jurisdiction over disputes, except that nothing here limits a data subject's right to approach a competent authority under Nepali privacy law. Please contact us first so we can try to resolve the issue.

18. Contact and Privacy Officer

Questions, access requests, and grievances:

Margintop Solutions Pvt. Ltd. — Privacy Officer
  • Email: [email protected]
  • Phone: +977-9845926945
  • Subject line: [MDesk Privacy] — Your request
  • For a formal grievance: [MDesk Grievance]
  • Response: within 30 days
  • Registered jurisdiction: Pulchowk, Lalitpur, Nepal

If we cannot resolve a privacy grievance, you may escalate to the authority competent under Nepali law.