Data Declaration
Last Updated: September 16, 2026 • Formal data processing, security, and AI handling standards by Avadh Bajaj.
01.Purpose of this Declaration
As an independent freelance website developer and AI automation expert, I build mission-critical web applications, SaaS tools, and automated pipelines that interact directly with customer communications, CRMs, and business intelligence.
This Data Declaration serves as a transparent and binding public commitment to how data is accessed, processed, isolated, and destroyed across every project built on avadhbajaj.com.
02.AI Pipeline Privacy & Zero Model Training
When I build AI workflows (using OpenAI API, Anthropic Claude API, Google Gemini, or local LLMs), all integrations are configured via developer-tier API endpoints. By contractual design, your proprietary data, customer prompts, and pipeline inputs are NEVER used to train or fine-tune public foundation AI models.
- No Data Leakage: Your business records and user queries remain strictly confined to your private application pipeline.
- Prompt Engineering Transparency: You retain complete visibility into all system prompts, guardrails, and context windows configured in your automation.
- Direct Client Ownership of API Accounts: All production AI keys are hosted inside your own billing accounts with OpenAI or Anthropic, ensuring you maintain 100% legal ownership of your data processing agreements.
03.Data Minimization & Staging Protocol
I practice strict data minimization during all stages of development:
Synthetic Staging Data
During development and testing of custom web apps or automations, I actively encourage and utilize synthetic (mock) customer data rather than connecting directly to production databases containing sensitive PII.
Principle of Least Privilege
I only ask for the specific API scopes and database read/write permissions required to implement the features specified in our agreed scope.
04.Credential Security & Secret Management
Protecting client API keys, database credentials, and authentication tokens is handled with high engineering discipline:
.env.local excluded via .gitignore) or injected directly into secure cloud platforms (Vercel Environment Variables, AWS Secrets Manager, Supabase Vault).05.Data in Transit & at Rest
Every production web system and automated workflow I build adheres to modern security baselines:
Standard Architecture Protections:
- Encryption in Transit: Strict HTTPS / TLS 1.3 encryption across all public web pages, API calls, and webhook payload routes.
- Encryption at Rest: AES-256 standard encryption utilized on database providers (Supabase / AWS RDS / PostgreSQL).
- Database Access Control: Row-Level Security (RLS) policies implemented on modern databases to guarantee users can only query their own data records.
06.Data Retention & Purging Schedule
30-Day Auto-Purge: Any local test logs, temporary CSV/JSON test datasets, or staging database dumps created on my local machines during development are securely deleted within 30 days of project sign-off.
Immediate Deletion on Demand: You may request the immediate deletion of any temporary files, communication archives, or project notes at any time by emailing hello@avadhbajaj.com.
07.Compliance & Legal Safeguards
My engineering practices and data handling comply with India's Digital Personal Data Protection Act (DPDP Act) and adhere to international standards including GDPR data privacy principles. I am fully prepared to execute client-specific Data Processing Addendums (DPA) and bilateral Non-Disclosure Agreements (NDA).
08.Data Protection Inquiries & Requests
If you have any questions regarding how your data will be handled for an upcoming build or wish to submit a data erasure or compliance verification request:
Avadh Bajaj — Freelance Website Developer & AI Automation Expert • Indore, India