What we collect, why, and what you can do about it.
This notice describes how Kheldim Ethics handles your personal data. Written to be understood, not to hide behind. Aligned to Nepal's Individual Privacy Act 2018 and structured so that if we open to India or the EU later, we don't need to rewrite it.
On this page
- Who controls your data
- What we collect
- Why we collect it
- Legal basis (consent)
- Where the data lives
- Third-party processors
- How long we keep it
- Your rights
- Automated decision-making
- Cookies & local storage
- Data-breach notification
- Institutional dashboards (aggregate only)
- Contact & complaints
- Changes to this notice
01Who controls your data
For the Nepal beta, the data controller is Kheldim (kheldim.com), curated under the professional guidance of a Fellow of the Association of Chartered Certified Accountants (FCCA). Contact us on kheldim.ethics@gmail.com for any privacy question or request.
02What we collect
kheldim.auth key. No third-party tracking cookies.kheldim.theme.No IP address logging beyond what Cloudflare Pages routinely handles at network edges. No device fingerprinting. No behavioural advertising trackers. No analytics beacons to third parties. No sale of data.
03Why we collect it
- To run the game. Your account and profile are what make the game persistent.
- To personalize scenarios. Your decision history routes you to the next unplayed scenario and, later, may adapt difficulty to your level.
- To score and rank. Dimensions and reputation exist so competition and progression are meaningful.
- To honour our consent obligations. The audit trail records what you agreed to and when.
- To aggregate cohort insights — institutional dashboards (see Section 12) will show aggregate patterns across cohorts, never individual scores.
04Legal basis
Under Nepal's Individual Privacy Act 2018, we process your data on the basis of your consent, which you give when you sign up. You can withdraw consent at any time by deleting your account (see Section 08).
Where this notice later applies to users in the EU/UK, the equivalent basis under Article 6(1)(a) GDPR is consent. For special-category data, we do not intentionally collect any — the dimension scores are inferences from gameplay behaviour, not health, biometric, or belief data.
05Where the data lives
ap-southeast-1).06Third-party processors
Kheldim Ethics uses these processors, each of which acts on our instructions and under a written processing agreement:
- Supabase, Inc. — database, authentication, storage. Data hosted in Singapore.
- Cloudflare, Inc. — static hosting and content delivery. Cloudflare may observe request metadata (IP, user agent) for CDN and security purposes.
- Google Fonts (typography) — served from Google-operated CDNs at page load. No account is required.
We do not sell, rent, or share your personal data with third parties for marketing.
07How long we keep it
08Your rights
You can:
- Access the personal data we hold about you.
- Rectify inaccurate data via the Edit Profile modal or by writing to us.
- Delete your account and all associated profile + decision data.
- Export your data in a machine-readable format (JSON).
- Withdraw consent at any time by deleting your account. Past processing done under valid consent remains lawful.
- Object to specific processing (contact us).
- Complain to a competent supervisory authority (see Section 13).
To exercise any of these, email kheldim.ethics@gmail.com. We aim to respond within 14 days.
09Automated decision-making
Kheldim Ethics does not make legal or similarly significant decisions about you automatically. The game routes you to your next unplayed scenario using a deterministic ordering, and computes dimension deltas from your decisions — but nothing about your access, eligibility, employment, credit, or education is decided automatically.
Where GDPR's Article 22 later applies (EU/UK users), we consider our current processing outside its scope. If we ever add profiling that could have significant effects — say, an integration with formal assessment — we will surface it clearly, get fresh consent, and offer a human-review path.
10Cookies & local storage
We use local storage (not cookies) for two things:
kheldim.auth— your Supabase session token so you stay signed in.kheldim.theme— your day/night mode choice.
No advertising, analytics, or cross-site tracking cookies. Cloudflare and Supabase may set essential cookies at the network layer required for their services to function.
11Data-breach notification
If we become aware of a data breach affecting your personal data that is likely to result in a risk to your rights and freedoms, we will notify you within 72 hours of becoming aware, where reasonably feasible. We will describe what happened, what data was affected, and what we're doing about it.
12Institutional dashboards — aggregate only
When institutions (colleges, FinT, etc.) receive dashboards for their cohorts, those dashboards only ever show aggregate metrics — cohort averages, distributions, difficulty trends. A minimum cohort size of five is enforced so no small group can be de-anonymized. Individual scores never leave your account.
13Contact & complaints
14Changes to this notice
We may update this notice. When we make a material change, we'll bump the version at the top, update the effective date, and — where the change materially affects your rights — ask you to re-consent on next sign-in. Older versions are retained in the consent audit trail; ask us for the version you originally accepted.
This notice is written in plain language on purpose. It's not legal advice to you, and does not replace what a qualified data-protection lawyer might draft for a broader launch. If you're an institution considering using Kheldim Ethics in a formal setting, please reach out first.