Skip to main content
Privacy

How YDLC handles information.

This page describes the actual system YDLC has implemented — not an aspirational privacy framework. It is a template pending legal review.

Status: template. This privacy structure describes what YDLC has actually implemented. It is not a substitute for legal review. Final wording will be confirmed with counsel before this policy is formally adopted.
Who we are

Youth Development and Leadership for Change (YDLC) is a Nepal-based organisation. This policy explains what information we collect through this website, how we use it, how it is classified and protected, how consent works, and how long information is kept.

What we collect

Through our forms — programme interest, volunteer, mentor, partner, newsletter, and safeguarding reporting — we collect the information you provide directly: typically your name and email, and any details you choose to share in free-text fields. Safeguarding reports may include a description of the concern and, where you choose to provide them, contact details.

We collect only what is needed for the specific purpose of each form. We do not collect information "because it might become useful later." Where a date of birth is requested, it is optional and is never displayed publicly.

Why we collect it
  • To respond to your inquiry, application, or registration.
  • To send updates you have specifically opted into (e.g. newsletter).
  • To administer programmes, including safeguarding-related record-keeping.
  • To act on safeguarding concerns raised through the reporting channel.
How we use it

Information is used only for the legitimate operational purpose for which it was collected. We do not sell participant or subscriber data. We do not use your information to build profiles for third parties.

Who can access it

Access is controlled at the database level. Public website visitors can only read content that has been published and verified. Sensitive records — safeguarding cases, consent records, retention rules, conflict-of-interest disclosures — are restricted to authorised administrators and are never exposed publicly. Ordinary users can only read their own records where applicable.

The access-control system distinguishes administrators from ordinary users at the database level. Finer separation between different staff roles (for example, a safeguarding officer versus a finance manager) is enforced in the admin interface. We limit the number of administrator accounts and restrict them to cleared personnel. There is no field-level encryption; protection relies on access control.

What is never public

The following are never displayed on public pages:

  • Safeguarding report contents and case details.
  • Consent records.
  • Date of birth — never used as a public category, filter, or eligibility label.
  • Private email and phone numbers.
  • Conflict-of-interest disclosure details.
  • Internal identifiers and administrative notes.
How information is classified

Every piece of information we hold falls into one of four classification tiers, which determines how strictly it is protected:

Public
Approved for public release on the YDLC website.
Internal
Operational information available only to authorised YDLC personnel.
Confidential
Sensitive organisational or personal information. Restricted access.
Highly Sensitive
Safeguarding and similarly sensitive information. Strictest access control.

Safeguarding reports and consent records are treated as Confidential or Highly Sensitive and are never returned to public pages.

How long we keep it

YDLC maintains a configurable set of retention rules — one per data type — describing how long information is held, when the retention period starts, and what happens at the end (delete, anonymise, archive, or retain for a legal or operational reason).

Retention periods are being formally reviewed and will be applied according to approved organisational policy. Where a legal retention period has not yet been confirmed, the rule is marked Pending legal review and no retention period is invented.

Consent

Consent at YDLC is purpose-specific. Agreeing to one purpose (for example, programme participation) is not agreement to another (for example, publishing a story or photograph). Each consent is recorded for a single purpose.

You can withdraw consent where consent is the lawful basis. Withdrawal does not necessarily invalidate prior lawful processing. Withdrawing consent for published content removes that content from public view where consent was the basis for publishing it.

See our Safeguarding page for how concerns and consent are handled.

Information from young applicants

Our forms may collect information from young applicants. Where a programme involves participants under 18, we seek parent or guardian contact and appropriate consent before participation. Our approach to data from young applicants, including any applicable parental or guardian consent, will be confirmed with counsel before this policy is adopted. Date of birth is never used as a public category, filter, or eligibility label.

Your choices

You can request access to, correction of, or deletion of your information, or withdraw consent, through our Contact page. We will act on requests within our operational capability and as required by applicable law. Formal legal procedures and response timelines will be confirmed with counsel.

Terms of use

By using this website, you agree to use it for its intended purpose — learning about YDLC and engaging with our programmes — and not to misuse forms, attempt unauthorised access, or misrepresent your identity or eligibility when applying to a programme.

Standard liability, intellectual property, and governing-law clauses will be confirmed with counsel before this section is finalised.