Legal & Transparency
Privacy Policy
Last Updated: September 13, 2026 · Effective Date: January 1, 2025
Commitment to Privacy & Data Minimization
This policy describes how Akshat Kushwaha (“we”, “us”, or “our”) collects, handles, stores, and protects your information when you visit this website (https://a3ro.dev) or interact with our contact forms and blog comments. We operate on a strict data minimization principle: we only collect the bare minimum information needed to communicate with you or provide this site, and we never sell, rent, or trade your personal data.
1. Data Controller & Grievance Officer
For the purposes of applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (DPDP Act, India), the General Data Protection Regulation (EU GDPR), and the UK Data Protection Act 2018:
Data Controller: Akshat Kushwaha
Affiliation: Co-founder & CTO, Bits&Bytes Foundation
Location: Prayagraj, Uttar Pradesh 211001, India
Primary Email: akshatsingh14372@outlook.com
Institutional Email: akshat@gobitsnbytes.org
Grievance & Data Protection Officer: Akshat Kushwaha (Report Data Grievance)
2. Personal Data We Collect
We collect personal data only when you affirmatively provide it or through standard, privacy-preserving infrastructure operation:
- Contact Inquiries: When you submit a project brief or message via our Contact form, we collect your Name, Email address, and the Message text you provide. This data is collected solely to evaluate your brief and reply to you.
- Blog Comments: When you post a response on a technical article, we collect your Display Name, Email address, and Comment content. Your display name and comment are published publicly. Your email is strictly kept private and used only to verify submission authenticity and prevent spam.
- Technical Server Logs: When accessing the site, standard HTTP request metadata (such as masked IP address, browser user-agent, operating system, and request timestamps) may be temporarily processed by our hosting provider (Vercel) solely for network security, DDoS prevention, and rate-limiting.
- Administrative Credentials: For authorized administrative access to manage site content, authentication tokens and session cookies are processed.
3. Legal Grounds for Processing
We process personal data only where we have a valid legal basis:
Consent (Art. 6(1)(a) GDPR / Section 6 DPDP)
When you voluntarily submit our contact form or leave a comment, you provide informed consent for us to store and process those details. You can withdraw this consent at any time.
Legitimate Interests (Art. 6(1)(f) GDPR)
To protect our infrastructure against cyber attacks, spam, or malicious intrusions, and to ensure network availability and performance.
4. Analytics & Third-Party Services
We believe surveillance-style tracking is harmful and unnecessary. Our analytics configuration adheres to the highest privacy standards:
- Vercel Web Analytics: We use Vercel Web Analytics, a privacy-first, cookieless telemetry service. It does not use third-party cookies, does not track visitors across websites, does not fingerprint devices, and does not store personally identifiable information (PII). Visitor IPs are ephemeral, anonymized, and never retained.
- No Advertising Trackers: We do not deploy Meta Pixel, Google Ads tags, TikTok Pixels, or any cross-context behavioral advertising trackers.
- External Scheduling (Calendly): If you choose to schedule a discussion via our Calendly link, you will be navigated to Calendly's external service, which operates under its own independent privacy policy.
- Avatar Delivery: The site references public avatars via GitHub CDN (avatars.githubusercontent.com), subject to GitHub's privacy policy.
5. Data Sharing & Processors
We do not sell, rent, or monetize your personal information under any circumstance. We only transfer data to trusted infrastructure sub-processors necessary to run this platform:
- Vercel Inc. (USA / Global edge network) — Website hosting, serverless compute, and cookieless telemetry.
- PostgreSQL Cloud Provider — Encrypted database storage for submitted messages and comments.
All sub-processors are bound by strict Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs) to guarantee data integrity and confidentiality.
6. Data Retention Schedules
We retain personal data only for as long as necessary to satisfy the purpose for which it was collected:
- Contact Form Messages: Retained up to 24 months to maintain business communication context, or until you request deletion.
- Blog Comments: Retained for the public lifecycle of the relevant article, or until requested to be removed by the author.
- Server Access Logs: Ephemeral logs are rotated and purged within 30 days.
7. Your Statutory Rights
Regardless of your geographic location, you enjoy comprehensive control over your personal data:
Right of Access
You may request a copy of any personal data we hold about you.
Right to Rectification
You may request correction of inaccurate or incomplete information.
Right to Erasure
You may request that we permanently delete your comments or messages.
Right to Withdraw Consent
You can revoke consent previously granted for message processing.
Right to Grievance Redressal
Under the DPDP Act 2023, you have a statutory right to prompt redressal of grievances.
Right to Non-Discrimination
We never penalize or discriminate against anyone exercising privacy rights.
To exercise any of these rights, email our Grievance Officer at akshatsingh14372@outlook.com. We acknowledge all requests within 48 hours and process them within 30 days without charge.
8. Protection of Minors
This website is a professional engineering portfolio and technical blog. We do not knowingly solicit or collect personal information from individuals under the age of 18 without verifiable parental consent in compliance with the DPDP Act 2023 and COPPA. If you believe a child has provided us with personal data, please contact us immediately for prompt deletion.
9. Information Security
We implement industry-standard organizational and technical security controls:
- Enforced HTTPS/TLS 1.3 encryption across all website traffic.
- Encrypted database connections with restricted, role-based credential scoping.
- Input sanitization, parameterized queries, and strict CSRF/CORS protections.
- No storage of raw passwords; administrative access secured with multi-factor protections.
10. Changes to this Policy
We may update this Privacy Policy from time to time to reflect technological or statutory changes. Any modifications will be posted here with an updated “Last Updated” date. Material updates will be highlighted prominently on our website.