1. Who this notice covers
This review draft describes the current marketing-site contact form and the proposed privacy framework for Helix services. The responsible legal entity, business contact details, applicable regional provisions, and service-provider arrangements must be confirmed before the policy is finalized.
For organization-managed workspaces, the organization generally determines why personal data is entered and how it is used. The respective controller and processor roles, instructions, and obligations must be established in the applicable service agreement and data processing agreement.
2. Information collected
| Context | Information |
|---|---|
| Contact inquiries | Name, email, organization, optional role and team size, inquiry topic, message, submission reference, and submission time. |
| Website protection | Derived email and network identifiers used to limit repeated form submissions; hosting services may also process request and security data. |
| Workspace use | Account and organization details, permissions, records, files, workflow observations, decisions, and activity information supplied or generated during service use. |
| Commercial relationship | Business contact information, subscription details, invoices, and payment-related records handled under the final billing arrangement. |
| Authorized integrations | Information exchanged with connected systems or AI clients according to the access and actions you authorize. |
3. How information is used
Contact-form information is collected to respond to your inquiry and manage the resulting business conversation. The form stores inquiries and uses derived identifiers to limit repeated submissions; it does not automatically send the message to an AI service.
The proposed service purposes include delivering and administering workspaces, supporting users, carrying out authorized workflows, maintaining security, troubleshooting, managing subscriptions, and meeting legal obligations. Applicable legal bases and any additional purposes must be confirmed for each processing activity and jurisdiction.
Information collected for an inquiry should not be treated as blanket permission for unrelated marketing. Any separate marketing activity must have the appropriate notice and choices.
5. AI and external connections
When you authorize an API integration, webhook destination, or MCP client, that connection may receive the information required for the permitted operation. Your organization should review the recipient, scope, purpose, and data practices before connecting it.
AI features may send relevant context to the configured model or tool provider. Provider selection, model-training use, logging, and retention commitments must be established in the service configuration and agreement; this draft does not make an unverified blanket promise about every external AI client or provider.
Once information is sent to a third-party system at your direction, its handling is also subject to that system’s policies and your agreement with it. Revoking access prevents future authorized access but does not itself erase previously received information.
7. Retention and deletion
Retention should be tied to the purpose of the information, the customer’s instructions, contractual commitments, and applicable obligations. Inquiry records, operational records, security logs, backups, and billing information can have different retention needs.
The final schedule must specify the retention period or meaningful criteria for each category, the treatment of backups, and the export and deletion process after a subscription ends. No fixed retention period or automatic deletion deadline is represented as implemented by this draft.
An organization may need to retain particular audit or operating records. A deletion request must be evaluated against those obligations rather than silently removing evidence from a completed process.
8. Security and international processing
Access restrictions, secure transport, authorization, and operational safeguards should match the sensitivity and use of information. No internet service can promise absolute security. The final security commitments are those established in the applicable agreement.
Hosting and service providers may process information in countries different from yours. The applicable locations, transfer mechanisms, and safeguards must be confirmed before making deployment-specific residency or international-transfer commitments.
9. Your choices and requests
Depending on the law that applies and your relationship to the information, you may have rights to access, correct, delete, restrict, object to processing, obtain a portable copy, or withdraw consent where processing relies on consent. Some rights have exceptions.
Use the contact form’s privacy topic to ask about information submitted through this website. Include enough context to identify the request, but do not send passwords, identity documents, or sensitive records in the initial message. Verification may be needed before acting on a request.
For information controlled by your employer or another organization using Helix, contact that organization first. Helix should assist it according to the applicable agreement and law. Regional complaint, appeal, and supervisory-authority information must be added where applicable.
10. Children, changes, and contact
Helix is intended for business and professional use by adults, rather than services directed to children. Contact us if you believe a child’s personal information has been submitted inappropriately.
Material changes to the finalized policy should be communicated as required, with a clear updated date and any additional choices that apply. A revised policy should not be treated as retroactive consent to a materially different use.
For privacy questions, use the dedicated privacy topic on the contact page. This draft’s review date is 16 September 2026; it has not yet been designated an effective policy.