Skip to content
HELIXCMO

Legal

Data Processing Addendum

Last updated 1 September 2026

This addendum forms part of the terms of service and applies where Helix processes personal data as a processor on behalf of a customer acting as controller.

Roles

For data you upload, connect or generate through the platform — including visitor identification data on your sites — you are the controller and Helix is the processor. For your own account and billing data, Helix is the controller and the privacy policy applies.

Scope and instructions

We process personal data only to provide the service and on your documented instructions, which include your configuration of the platform. We will tell you if an instruction appears to breach applicable data protection law.

Categories of data and subjects

Subjects: your personnel, your website visitors, and contacts in connected CRM systems. Data: identifiers, business contact details, organisation-level firmographic data, page interaction records, and content submitted through the platform.

Sub-processors

We use sub-processors for hosting, model inference, email delivery, payment processing and error monitoring. A current list is available on request. We will give notice of new sub-processors and you may object on reasonable data protection grounds.

Security

Encryption in transit and at rest, role-based access control, least-privilege internal access, logging of administrative actions, and periodic review of dependencies and access. Personnel with access are bound by confidentiality obligations.

International transfers

Where personal data is transferred outside its region of origin, we rely on an appropriate transfer mechanism such as standard contractual clauses, together with supplementary measures where required.

Assistance, breach and audit

We will assist you with data subject requests, impact assessments and regulator engagement. We will notify you without undue delay after becoming aware of a personal data breach affecting your data. We will provide the information reasonably necessary to demonstrate compliance.

Deletion and return

On termination we delete or return personal data in accordance with the retention periods described in the privacy policy, except where retention is required by law.