Legal
Data Processing Addendum
Last updated 1 September 2026
This addendum forms part of the terms of service and applies where Helix processes personal data as a processor on behalf of a customer acting as controller.
Roles
For data you upload, connect or generate through the platform — including visitor identification data on your sites — you are the controller and Helix is the processor. For your own account and billing data, Helix is the controller and the privacy policy applies.
Scope and instructions
We process personal data only to provide the service and on your documented instructions, which include your configuration of the platform. We will tell you if an instruction appears to breach applicable data protection law.
Categories of data and subjects
Subjects: your personnel, your website visitors, and contacts in connected CRM systems. Data: identifiers, business contact details, organisation-level firmographic data, page interaction records, and content submitted through the platform.
Sub-processors
We use sub-processors for hosting, model inference, email delivery, payment processing and error monitoring. A current list is available on request. We will give notice of new sub-processors and you may object on reasonable data protection grounds.
Security
Encryption in transit and at rest, role-based access control, least-privilege internal access, logging of administrative actions, and periodic review of dependencies and access. Personnel with access are bound by confidentiality obligations.
International transfers
Where personal data is transferred outside its region of origin, we rely on an appropriate transfer mechanism such as standard contractual clauses, together with supplementary measures where required.
Assistance, breach and audit
We will assist you with data subject requests, impact assessments and regulator engagement. We will notify you without undue delay after becoming aware of a personal data breach affecting your data. We will provide the information reasonably necessary to demonstrate compliance.
Deletion and return
On termination we delete or return personal data in accordance with the retention periods described in the privacy policy, except where retention is required by law.