Data Protection

Your Data. Your Trust. Our Responsibility.

Whether it's the details you share through this website or the business data you connect to the SolmiriX platform, this page explains exactly what we collect, how it's handled, and how you can control it.

If you're a SolmiriX client

What Happens to Your Business Data on SolmiriX

This is the question that matters most before you connect a CRM, spreadsheet, or database to any analytics platform — so we answer it here first, before anything about cookies.

What we connect to

SolmiriX links to the systems your business already runs on — spreadsheets, CRMs, invoicing tools, support-ticket systems, and databases — to unify them into one queryable layer. We only connect to the sources you explicitly authorize, and only pull the data needed to answer the questions you've asked the platform to answer.

Isolated per client

Your connected data lives in its own isolated workspace. It's never pooled or blended with any other client's data, and it is not used to train shared or general-purpose AI models. Where possible, we apply pseudonymization and de-identification techniques to reduce how much directly identifying data our systems and engineers need to handle at all.

Access is limited and logged

Only the engineers actively building or maintaining your SolmiriX instance can access your connected data, on a need-to-access basis. That access is logged, and we review those logs as part of a quarterly internal security review.

Used only to run your platform

Your business data is used exclusively to power the dashboards, queries, and insights you've asked SolmiriX to generate for your team — never resold, never repurposed for another client, never used for marketing.

Exportable and deletable on request

While your engagement is active, connected data is retained to keep your instance working. If you offboard or disconnect a source, you can request a full export, and we'll delete the underlying connected data within 30 days — except where we're legally required to keep records (see Data Retention below).

To request an export, a deletion, or a list of exactly which sources are currently connected for your account, email info.gexon@gmail.com with the subject "SolmiriX Data Request" — we'll respond within 5 business days.

If you've just contacted us

Website & Inquiry Data (and Why We Collect It)

This section covers the separate, smaller set of data collected through this website itself — before you're ever a connected SolmiriX client.

Data Type When Collected Why We Collect It
Name & EmailContact formTo respond to your inquiry
Company NameContact formTo understand your business context
Phone NumberContact form (optional)For discovery call scheduling
Project DescriptionContact formTo prepare for our first conversation
Usage DataWebsite analytics (if enabled)To improve our website experience

We NEVER collect:

  • Payment or financial information through this website
  • Passwords or authentication credentials
  • Sensitive personal data (health, biometric, political)
  • Data from third-party sources without your knowledge

How We Protect Your Data

Encryption in Transit

All data submitted is encrypted using TLS 1.2+ (HTTPS). Protected from interception at every step.

Secure Storage

Client information is stored in access-controlled environments with role-based permissions. Only team members who need your data to deliver services can access it.

No Data Selling — Ever

We do not sell, rent, or trade your personal information to any third party. Your data is used exclusively to deliver and improve our services.

Regular Security Reviews

Our systems and data handling practices are reviewed regularly to identify and address vulnerabilities before they become risks.

Your Rights (Global)

Right to Access
Right to Rectification
Right to Erasure ("right to be forgotten")
Right to Portability
Right to Object
Right to Withdraw Consent

To exercise any of these rights, email us at: info.gexon@gmail.com — We will respond within 30 days.

Nepal Data Protection Compliance

Individual Privacy Act (Nepal)

We are committed to collecting only the minimum data necessary, processing it only for the stated purpose, and not sharing with government unless legally compelled and notified.

Nepal Telecommunications Act & Electronic Transactions Act (ETA 2063)

  • We comply with Nepal's ETA 2063 governing digital communications and data security
  • All electronic records handled in accordance with ETA requirements
  • We maintain records of data processing activities as required

Upcoming: Nepal Personal Data Protection Bill

GeXOn AI is proactively aligning with the draft bill's requirements. Our commitments include:

  • Designated Data Protection contact
  • DPAs available for enterprise clients
  • Breach notification within 72 hours
  • Annual privacy reviews

International Data Protection (For Global Clients)

GDPR (EU/EEA)

We act as a Data Processor when processing data on behalf of EU clients. DPA available upon request.

UK GDPR

Equivalent EU protections for UK-based clients.

CCPA (California, USA)

Right to know, right to delete, right to opt-out of data selling (we do not sell). Requests to: info.gexon@gmail.com

PDPA/PDPL/DPDP (Asia & Middle East)

Equivalent protections applied across applicable jurisdictions.

Data Retention

Data TypeRetention PeriodReason
Contact form submissions (no engagement follows)12 months of inactivityAllows a reasonable follow-up window for an open inquiry, without holding data indefinitely
Contact form submissions (inquiry becomes a client)Merged into Active client project data, belowSame contractual and audit basis as the resulting engagement
Active client project dataDuration of engagement + 36 monthsContractual and audit purposes
Website analytics data12 months rollingPerformance optimization
Financial/invoice records7 yearsLegal/tax compliance (Nepal law)

After the retention period, data is securely deleted or anonymised.

Cookies

Cookie TypePurposeCan Be Disabled?
EssentialSite navigation, form securityNo (required for site)
AnalyticsUnderstand how visitors use siteYes (see browser settings)
MarketingRetargeting adsNot used — no marketing pixels

We do not use Facebook Pixel, Google Ads tracking, or any third-party marketing cookies.

Contact Our Data Protection Team

Email: info.gexon@gmail.com (subject: "Data Privacy Request")

Address: Kathmandu, Nepal

Response time: Within 30 business days

For urgent security concerns, mark your email: "SECURITY — URGENT"

← Back to Home Start a Conversation

This Data Protection Policy was last updated: June 2026. It will be reviewed annually or whenever significant changes occur in our data practices or applicable laws.