Legal · Privacy Policy · v1.0

Your data, handled with care.

Astral Mantra Labs Pvt. Ltd. is an AI studio based in Kathmandu, Nepal. This policy explains, in plain language, what personal information we collect through astralmantralabs.com and our client engagements, what we do with it, who we share it with, and the rights you have. It is written to comply with Nepal's Individual Privacy Act, 2075 (2018) and to honour the spirit of GDPR, CCPA, and the EU AI Act where they apply to you.

Effective 15 May 2026 Last updated 15 May 2026 Version 1.0
Make a privacy request → Jump to contact

01Who we are

Astral Mantra Labs Pvt. Ltd. (“Astral Mantra Labs,” “we,” “us,” or “our”) is an AI studio based in Kathmandu, Nepal. We design and ship AI agents, conversational AI, computer vision systems, voice AI, synthetic AI, SaaS platforms, and workflow automation for clients worldwide.

This Privacy Policy explains what personal information we collect when you visit astralmantralabs.com (the “Site”) or engage with us as a prospective or active client, what we do with that information, who we share it with, and the choices and rights you have.

We are the data controller for personal information collected through the Site. For client engagements, we typically act as a data processor on behalf of our clients — that relationship is governed by a separate Data Processing Agreement (DPA), not this policy.

Privacy contact

Email info@astralmantralabs.com with “Privacy” in the subject line. A founder responds, not a ticketing bot.


02The information we collect

2.1 Information you give us directly

When you fill out the “Start a Project” brief, the demo request form, or email us, we collect:

If you apply for a role through our Careers page, we additionally collect the information you provide in your application: CV, portfolio links, work history, references.

2.2 Information collected automatically

When you browse the Site, our hosting and analytics infrastructure may collect:

2.3 Information from third parties

We may receive limited information about you from:

We do not buy contact lists or scrape personal data from social platforms for outreach.

2.4 What we do not collect


03Sensitive personal information

Some of our work — particularly in healthcare intelligence — may involve sensitive data on behalf of clients. We treat the following as sensitive and apply heightened controls:

We do not process sensitive personal information through the Site itself. Where a client engagement involves sensitive data, we operate under a written DPA, apply purpose limitation, and rely on the lawful basis the client has established with their data subjects.


04How we use your information

We use the information we collect for the following purposes:

PurposeWhat we use it forLegal basis
Respond to your inquiry Reading your project brief, replying within 24 hours, scheduling discovery calls Consent / Steps to enter a contract
Provide our services Delivering the engagement you've hired us for Contract performance
Operate the Site Hosting, security, error monitoring, performance optimization Legitimate interest
Improve our work Anonymized analytics, understanding which pages are useful Legitimate interest
Comply with law Tax records, regulatory requests, court orders Legal obligation
Defend our rights Investigating misuse of the Site, responding to claims Legitimate interest
Send relevant communications Replying to you, sending project updates, occasional studio updates if you've opted in Consent (withdraw any time)

We will not use your information for purposes materially different from those listed above without telling you first.


05How we use AI — and what that means for your data

Because we are an AI studio, we want to be specific about AI and your data.

5.1 The Site and your inquiries

5.2 Client engagements

5.3 Automated decision-making

The Site itself does not make automated decisions about you that produce legal or similarly significant effects. If a system we build for a client makes such decisions about you, the client — not Astral Mantra Labs — is responsible for explaining those decisions and providing the rights you're entitled to under applicable law (e.g., GDPR Article 22, the EU AI Act).


06Who we share your information with

We share personal information only with the following categories of recipients, and only when necessary:

The non-negotiables

We do not sell your personal information. We do not share your personal information with third parties for their own marketing. Full stop.


07Cookies & tracking

The Site uses a small number of cookies and similar technologies for:

You can control cookies through your browser settings. Blocking analytics or non-essential cookies will not break the Site.

If we add advertising cookies in the future, we will update this section and provide a consent banner before they fire.


08International data transfers

We are based in Nepal. Most of our service providers (cloud hosting, email, AI model providers) are based in the United States, the European Union, or other regions. When your data is transferred outside Nepal or outside your home country, we rely on one or more of the following safeguards:

You can contact us for a current list of subprocessors and the regions they operate in.


09How long we keep your information

We keep personal information only as long as we need it for the purpose it was collected, plus any legal retention period required of us. Indicative retention periods:

You can ask us to delete your information sooner — see Section 11.


10How we protect your information

We apply the reasonable security measures required under Nepal's Individual Privacy Act, 2075 and align with international good practice. In particular:

No system is 100% secure. If a breach affects your personal information and creates a risk of harm to you, we will notify you and any required authority as quickly as we reasonably can.


11Your rights

Under Nepal's Individual Privacy Act, 2075 (2018) and the Individual Privacy Regulation, 2077 (2020) — and under GDPR, CCPA, or other laws if they apply to you — you have the following rights:

How to exercise a right

Email info@astralmantralabs.com with “Privacy request” in the subject line. We respond within 30 days. We may need to verify your identity before acting on the request — for security, not to delay.


12Children's privacy

The Site and our services are intended for businesses and adults. We do not knowingly collect personal information from individuals under the age of 18 without the consent of a parent or legal guardian, as required under Nepal's Individual Privacy Act. If you believe we may have inadvertently collected information from a minor, please contact us and we will delete it.


13Complaints & dispute resolution

If you believe we have handled your personal information in a way that breaches this policy or applicable law:

  1. Contact us first — email info@astralmantralabs.com and we will investigate and respond within 30 days.
  2. If you are in Nepal, you may file a complaint at the concerned District Court within three months of the alleged violation, under Section 29 of the Individual Privacy Act, 2075.
  3. If you are in the EU/EEA, UK, or another jurisdiction with a supervisory authority, you have the right to lodge a complaint with the data protection authority in your country.

14Changes to this policy

We may update this Privacy Policy from time to time — for example, when we adopt new tools, change our practices, or to reflect changes in the law (including Nepal's pending Information Technology and Cyber Security Bill, 2082 and the EU AI Act).

When we make material changes, we will:

Continued use of the Site after a change means you accept the updated policy.


15Contact us

Astral Mantra Labs Pvt. Ltd.
Kathmandu, Nepal
Email: info@astralmantralabs.com
Website: https://astralmantralabs.com

For privacy-specific questions, email us with “Privacy” in the subject line.

This Privacy Policy is provided in English. If we publish a Nepali translation and there is a conflict between the two, the English version governs unless Nepali law requires otherwise.

Questions about your data?

Drop us a line. A founder reads it — no inbox triage, no ticketing bot. We respond within 24 hours.