[ last updated 15 September 2026 ]
Privacy Policy
Helmior sits in your team’s group chat, so it is fair to ask what it reads and what it keeps. The short answer: it reads messages that mention it, keeps only what a person confirms, and never sells or advertises with any of it. The detail is below.
1.Who we are
Helmior Ltd (“Helmior”, “we”, “us”) provides Helmior, an AI coordinator that works inside a team’s group chat and keeps records of their work in a dashboard (the “Service”). This policy explains how we handle personal data when you visit helmior.com, use the dashboard, or take part in a chat where Helmior has been added.
Questions about this policy or your data can be sent to privacy@helmior.com.
2.Our role: controller and processor
For account, billing and website data, Helmior is the controller: we decide why and how that data is used.
For workspace content — the records, pipelines, notes, attachments and chat messages a business puts into Helmior — the business that holds the Helmior account (the “Customer”) is the controller, and Helmior processes that data on its behalf and on its instructions. If you are a member of a chat or a person named in a record and want to exercise your rights over that content, contact the business that uses Helmior; we will help them respond.
3.What we collect
Account data. Your name, email address, the organisation you belong to and your role in it. If you sign in with Google or Microsoft, we receive your name, email address and an account identifier from that provider — never your password.
Chat data. Helmior acts only on messages that mention it and on the start phrase a Customer chooses for new records. From those messages we keep the text, the time it was sent, and the sender’s chat account identifier and display name. When a Customer connects a chat, Helmior may also note who is a member of that chat, so newcomers can be approved before their messages move anything. Other messages in the chat are not stored.
Workspace content. Everything a Customer’s team creates or confirms: records and their fields, stages, assignments, notes, attachments, and the activity history of every change — who made it, when, and the words that caused it.
Integration data. When a Customer connects a service such as Telegram, Slack, Discord, Microsoft Teams, Google Chat, WhatsApp, Signal, Google Sheets, Gmail or Meta lead ads, we store the credentials needed to use that connection and the data it delivers — for example, the answers a person submits on a Meta lead form.
Technical data. IP address, browser and device information, request logs and error logs, used to run and secure the Service.
Billing data. Plan, trial status, usage and invoices. Card details, where used, are handled by our payment provider and are not stored by us.
Correspondence. What you send us when you email us or book a walkthrough.
4.How we use it, and on what basis
- To provide the Service — reading the messages addressed to Helmior, proposing changes, saving what a person confirms, and showing it in the dashboard. Basis: performance of our contract with the Customer.
- To sign you in and keep your account secure — sessions, rate limiting, abuse prevention and audit history. Basis: contract and legitimate interests in security.
- To support, maintain and improve the Service — diagnosing errors, monitoring the quality and cost of AI responses. Basis: legitimate interests.
- To communicate with you — sign-in links, service notices and replies to your enquiries. Basis: contract and legitimate interests.
- To bill and to meet legal obligations — invoicing, tax and accounting records, and responding to lawful requests. Basis: contract and legal obligation.
We do not sell personal data, we do not use it for advertising, and we do not use workspace content to train AI models.
5.How AI is used
To understand a message and draft a reply, Helmior sends the message and the context needed to interpret it (such as the pipeline’s stages and the relevant record) to a third-party AI model provider. We use providers’ business API services, under terms that do not permit them to train their models on the data we send.
Each AI request and response is logged in an observability tool so we can investigate errors and misunderstandings. Access to those logs is restricted to the staff who need it.
The AI proposes; it does not decide. Nothing it suggests is saved until a person confirms it, and permission checks are rules applied by our software, not by the model. Helmior does not make decisions about people that have legal or similarly significant effects.
7.International transfers
Our primary database and application servers are located in India (Oracle Cloud, Mumbai region). Our service providers may process data in other countries, including the United States and the European Union.
Where personal data from the UK, the European Economic Area or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
8.How long we keep it
- Workspace content is kept for as long as the Customer’s account is active. When a person or record is deleted, it can be restored for 30 days and is then permanently removed. The activity history is kept for the life of the account.
- Integration data copied from a connected service is removed when that connection is disconnected.
- After an account closes, workspace content is deleted within 90 days, unless the Customer asks us to delete it sooner.
- Backups are overwritten on a rolling basis, so deleted data leaves them within days.
- Logs are kept for a limited period for security and debugging, then deleted.
- Billing records are kept for as long as tax and accounting law requires.
9.How we protect it
We take measures appropriate to the data we hold, including:
- encryption in transit (HTTPS) for all traffic;
- separation of every Customer’s data where it is read, not just where it is displayed;
- permission checks on every change, and a fresh sign-in before anything is deleted;
- private attachment storage, reachable only through links that expire within minutes;
- rate limiting, access controls and restricted staff access.
No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify the affected Customers and, where required, the relevant authorities without undue delay.
11.Your rights
Depending on where you live — including under the UK and EU GDPR, India’s Digital Personal Data Protection Act, and US state privacy laws — you may have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate or incomplete;
- have your data deleted;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent, where processing is based on consent;
- complain to a data protection authority, such as the UK Information Commissioner’s Office or your local regulator.
To exercise a right over your account data, email privacy@helmior.com. For workspace content, contact the business that uses Helmior (see section 2). We will respond within the time the law requires, usually one month, and may need to verify your identity first. We will not discriminate against you for exercising a right.
12.Children
Helmior is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact privacy@helmior.com and we will delete it.
13.Changes to this policy
We may update this policy as the Service changes. The date at the top shows when it was last revised. If a change materially affects how we use personal data, we will tell account admins by email or in the dashboard before it takes effect.
14.Contact
Helmior Ltd — privacy@helmior.com. If you are not satisfied with our response, you may contact your local data protection authority.