HIMALAYATalents

European governance. Global talent.

International delivery should not mean losing control of your information. Our model combines European infrastructure, controlled access and documented safeguards for delivery from Nepal.

Four principles we build on

EU-hosted core

Himalaya's own core systems are hosted in Europe.

Least privilege

Only required access is granted, based on assignment and role.

Controlled devices

Client access occurs from approved work environments according to assignment requirements.

Auditability

Important platform actions are logged and reviewable.

Your data should stay in your systems.

Our operating principle is simple: client information remains inside the client's environment whenever practical. We do not unnecessarily copy client datasets into Himalaya systems; your consultant works in your repositories, your tools and your environments, with authorised, named access.

  1. EU customer
    Your organisation
  2. Client systems
    Your data stays here
  3. Authorised access
    Explicit, role-based, revocable
  4. Named Himalaya consultant
    Working in your environment

We are open about what international delivery means.

Nepal is outside the EU/EEA and does not currently benefit from an EU adequacy decision. We do not hide that. We prepare for it.

Where access from Nepal constitutes an international transfer of personal data, Himalaya's delivery model is designed to support appropriate contractual and organisational safeguards, including EU Standard Contractual Clauses where applicable.

Prepared before procurement asks.

Our goal is to make privacy and security review easier by maintaining a clear and repeatable documentation framework. Your legal and security teams get structured answers, not improvisation.

GDPR responsibility is shared, and our framework is designed to support your assessment, not replace it.

  • Swedish commercial agreement
  • Data Processing Agreement
  • Subprocessor documentation
  • Standard Contractual Clauses where applicable
  • Transfer assessment
  • Technical and organisational measures
  • Access controls
  • Security policies
  • Subprocessor register
  • Incident procedure

Sensitive data does not need to follow the developer.

Most development work does not require production personal data. Assignments can be structured so your consultant builds and tests against development, synthetic, anonymised or pseudonymised data, while production personal data stays restricted.

  • Development and test environments
  • Synthetic data
  • Anonymised data
  • Pseudonymised data
  • Restricted production access by default

Share this with your security team.

A one-page overview of our security and data-protection model It is made for forwarding to legal, security and procurement.

Download Overview (PDF)

Have your security team take a look.

We are happy to walk your legal, security or procurement colleagues through the model and documentation framework.