Legal

Privacy Policy

Last updated: September 24, 2026

Geofinity Solutions Pvt. Ltd. (“Geofinity”, “we”, “us”, “our”) is the data controller for personal data processed through the OptERP website and platform, including its editions for Hospital, Fertility, Manufacturing, Education and SME.

This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you can exercise. For workspaces provisioned to a customer organisation, that customer is the controller of end-user data uploaded into OptERP and Geofinity acts as the processor.

1. Who we are

Geofinity Solutions Pvt. Ltd., Kathmandu, Nepal.

  • Email: info@geofinity.com.np
  • Phone: +977 9802372660
  • Website: https://geofinity.com.np

2. Information we collect

Information you provide. Name, business email, phone, company, job title, product interest, and message when you submit a demo or contact request; account credentials, profile fields and workspace configuration when an OptERP tenant is provisioned; content, records and files you upload while using OptERP modules (e.g. patients, inventory, orders, students, employees, invoices).

Information collected automatically. Device and browser details, IP address, approximate location derived from IP, pages visited, referring URL, actions performed, and diagnostic logs. Collected via cookies, local/session storage and server logs (see our Cookies Policy).

Information from third parties. Authentication and integration data from services you choose to connect — email, calendar, payment, identity or accounting providers — and enrichment data from publicly available business sources.

Sensitive data. Certain OptERP editions (Hospital, Fertility) allow customers to process health data. Where we act as processor on such data, we do so only on customer instructions and under an executed data processing agreement.

3. How we use information

  • Provide, operate, secure, monitor and improve OptERP and this website.
  • Provision tenants, authenticate users and enforce role-based access.
  • Respond to demo requests, sales enquiries and customer support tickets.
  • Send transactional notifications (billing, security, service status).
  • With your consent, send product updates, newsletters and event invitations.
  • Detect, prevent and investigate fraud, abuse and security incidents.
  • Comply with legal, tax and accounting obligations and enforce our Terms.
  • Produce aggregated, de-identified analytics that do not identify individuals.

4. Legal bases

  • Contract — to deliver the services you or your organisation requested.
  • Legitimate interests — to secure, operate and improve OptERP, balanced against your rights.
  • Consent — for optional cookies, marketing communications and certain integrations.
  • Legal obligation — where processing is required by applicable law.

5. Sharing and disclosure

We do not sell personal data. We share information only with:

  • Vetted service providers who help us run the platform (cloud hosting, database, email delivery, analytics, error monitoring, customer support).
  • Payment processors when you subscribe to paid plans.
  • Authorities, regulators or law enforcement where legally required or to protect rights, safety or property.
  • Professional advisers under confidentiality.
  • A successor entity in the context of a merger, acquisition or asset transfer, with continued protection of your data.

All processors are bound by written contracts including confidentiality, security and data protection obligations.

6. Sub-processors

A current list of the main sub-processors supporting OptERP is available on request from info@geofinity.com.np. We assess each sub-processor for security and compliance before engagement and review them periodically.

7. Data retention

  • Demo and contact submissions: up to 24 months from last interaction.
  • Customer account and workspace data: for the term of the subscription plus up to 90 days for export, then deletion.
  • Billing and tax records: as required by applicable law (typically 5–7 years).
  • Security logs: up to 12 months, longer where legally required.
  • Backups: rolling window, overwritten on schedule.

8. Security

OptERP is designed with a security architecture aligned to ISO/IEC 27001 recommendations: encryption in transit (TLS 1.2+) and at rest, role-based access control, least-privilege administration, hardened infrastructure, audit logging, vulnerability management and routine backups. No system can be perfectly secure — report concerns to info@geofinity.com.np.

9. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your personal data.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent at any time (without affecting past processing).
  • Lodge a complaint with a competent supervisory authority.

To exercise any right, contact info@geofinity.com.np. Where you use OptERP through an employer or customer, please contact them directly — we will support them in responding to your request.

10. International transfers

Data may be processed in regions where our infrastructure and providers operate. When personal data is transferred outside your country, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms.

11. Children

OptERP is intended for business use and is not directed to individuals under 16. The OptERP Education edition is used by institutions and processes student records under the institution’s instructions and lawful basis.

12. Automated decision-making

OptERP includes AI-assisted features (e.g. recommendations, summarisation). These support human decision-making and do not produce legal or similarly significant effects on you without human review.

13. OptIVF mobile app

OptIVF is a staff-facing clinical companion app we publish for authorised clinicians and staff of fertility clinics that run OptERP Fertility. Because it handles clinical data on behalf of clinics rather than website visitors, its data practices are summarised separately here.

Who controls the data. OptIVF connects to a server operated by, or on behalf of, the clinic that employs the user (the “Clinic”). Patient and clinical information accessed through the app belongs to and is controlled by the Clinic (the data controller); Geofinity acts as a processor under the Clinic’s instructions.

Information the app handles. Account credentials and role used to authenticate staff; a device push-notification token (Apple Push Notification service / Firebase Cloud Messaging); clinical/patient information viewed or entered (cases, cycles, observations, vitals, medications, lab and consent data), stored on the Clinic’s server and cached on-device only to function; photos staff explicitly choose to attach to a record; and standard, non-personal crash/diagnostic logs. We do not operate third-party analytics or advertising SDKs in the app.

How it’s used, and sharing. Solely to authenticate staff, display and update the Clinic’s records, send operational notifications, and keep the app secure — never sold or used for advertising or cross-app tracking. Information is exchanged only with the Clinic’s server and with Apple/Google push-notification services.

Security & retention. All network communication is encrypted (HTTPS); cached data is encrypted at rest with the key held in the device keychain. Staff can enable an optional biometric/passcode app-lock and screen-capture protection. Signing out clears session and cached data from the device. Clinical records themselves are retained on the Clinic’s server per the Clinic’s own policy.

Rights & children. Because the Clinic controls clinical data, requests to access, correct, or delete patient information should be directed to the Clinic. OptIVF is intended for clinical professionals and is not directed to children.

14. OptDAI mobile app

OptDAI (Opt Doctor Assistance Intelligence) is a medical assistant app for doctors and clinicians to record patient encounters, vital signs and clinical notes, with on-device dictation, document scanning and decision support. It is offline-first: patient records are kept on the user’s own device and are not sent to Geofinity or any server we operate.

Who controls the data. The doctor or clinic using OptDAI decides what is recorded and is the data controller for the patient information held in the app. Geofinity provides the software only; we have no access to the records on your device and cannot view, recover or disclose them.

Information the app handles. Patient and clinical information you enter (demographics, encounters, vitals, notes and letters), stored only in an encrypted database on the device; an app PIN and optional biometric unlock, where biometric matching is performed by the operating system and never reaches the app; microphone audio, only while you dictate, transcribed by an on-device speech model and never sent off the device; photos and documents you choose to attach, with any text recognition run on the device; and questions you ask the built-in assistant, answered on the device from your local records, including by an optional on-device language model.

Network use and sharing. OptDAI has no account, no backend and no analytics, advertising or crash-reporting SDKs. Its only network requests download optional speech or language models from a public model host (Hugging Face) when you tap Install in Settings; they contain no patient data or identifiers, although the host will see your IP address as with any download. Nothing is sold or used for advertising or tracking. Information leaves the device only when you choose to — for example by printing or sharing a PDF letter through the system share sheet, or by starting a call or message to a contact.

Security & retention. The database is encrypted at rest with a key held in the device keychain/keystore, and the app locks behind your PIN or biometrics. Operating-system cloud and device backups are disabled for the app so records are not copied off the device. Data stays on the device until you delete it in the app or uninstall the app, which permanently removes it; you are responsible for retaining records as required by your professional and legal obligations.

Rights & children. Patients who wish to access, correct or delete their information should contact the doctor or clinic that recorded it. OptDAI is intended for healthcare professionals and is not directed to children.

15. OptHealth mobile app

OptHealth is a staff-facing mobile app we publish for authorised doctors, nurses and staff of hospitals that run OptERP Hospital. Because it handles clinical data on behalf of hospitals rather than website visitors, its data practices are summarised separately here.

Who controls the data. OptHealth connects to a server operated by, or on behalf of, the hospital that employs the user (the “Hospital”). Patient and clinical information accessed through the app belongs to and is controlled by the Hospital (the data controller); Geofinity acts as a processor under the Hospital’s instructions.

Information the app handles. Account credentials, department and role used to authenticate staff; a device push-notification token (Apple Push Notification service / Firebase Cloud Messaging); clinical/patient information viewed or entered (registrations, appointments, OPD/IPD encounters, admissions, vitals, orders, medications, lab and imaging results), stored on the Hospital’s server and cached on-device only to function; photos staff explicitly choose to attach to a record; and standard, non-personal crash/diagnostic logs. We do not operate third-party analytics or advertising SDKs in the app.

How it’s used, and sharing. Solely to authenticate staff, display and update the Hospital’s records, send operational notifications, and keep the app secure — never sold or used for advertising or cross-app tracking. Information is exchanged only with the Hospital’s server and with Apple/Google push-notification services.

Security & retention. All network communication is encrypted (HTTPS); cached data is encrypted at rest with the key held in the device keychain. Staff can enable an optional biometric/passcode app-lock and screen-capture protection. Signing out clears session and cached data from the device. Clinical records themselves are retained on the Hospital’s server per the Hospital’s own policy.

Rights & children. Because the Hospital controls clinical data, requests to access, correct, or delete patient information should be directed to the Hospital. OptHealth is intended for healthcare professionals and is not directed to children.

16. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the product or by email where appropriate. The “Last updated” date reflects the latest revision. Continued use after the effective date constitutes acceptance.

Contact

For any questions about this document, contact Geofinity Solutions at info@geofinity.com.np or +977 9802372660.