Data and security
You are trusting me with employee records and your inbox. Here is exactly how I handle them.
Last updated October 2026
Your data stays in your systems
I work inside the accounts you create for me: your HR platform, your email, your Drive or SharePoint, your Notion. I don't copy employee or candidate data into my own storage, and I don't move it to personal devices or personal email.
Only the access each task needs
- I ask for the narrowest role that does the job, and say why I need it.
- Admin-only actions stay with your admin. Where I have no rights, I prepare the list and your admin clicks the final buttons.
- Two-step verification is on for every account you give me.
- Shared credentials live in your password manager, never in documents or chat.
Written agreements
- Every engagement has a written agreement with confidentiality terms: my consulting agreement, or your standard contractor agreement through Deel or Remote.
- UK and EU teams: India has no EU adequacy decision, so before I see staff or candidate data I sign your data processing agreement and the EU standard contractual clauses, or the UK equivalent.
- I will sign your NDA before the first call if you prefer.
When an engagement ends
You remove my access using the same offboarding checklist I run for your team, and I confirm in writing that I hold no copies of your data. Everything I built stays in your accounts.
What I don't claim
I don't hold security certifications such as SOC 2 or ISO 27001, and nothing on this site says otherwise. If your auditor or a customer's security review needs information about a contractor, I provide what they ask for.