Legal
Privacy Policy
Last updated: September 20, 2026
HELIXWORKS ("we," "us," "our") is an AI workflow automation studio. This Privacy Policy explains what personal information we collect through this website and in the course of our business, how we use and share it, how long we keep it, and the rights you may have.
Two kinds of data, two regimes. This policy covers our website and our own business contacts. When we process data on behalf of a client — documents, tickets, customer records — we act as a processor and the client is the controller. That processing is governed by our Data Processing Addendum, not by this page.
1. Information We Collect
Information you give us directly
This website has no contact forms. When you email us, call us, or meet us, we may collect:
- Name, job title, company name, email address and telephone number
- The content of your messages, meeting notes and records of our correspondence
- Business context you choose to share: the process you want automated, systems involved, approximate volumes
- Documents you send for evaluation, which we treat as confidential business information
Information collected automatically
Our hosting provider (Cloudflare Pages) logs standard technical information when a page is requested: IP address, user agent, requested URL, timestamp and response status. We use these logs for security, capacity planning and aggregate traffic analysis. We do not run advertising trackers, session recording, or third-party analytics on this website.
Information we do not collect
- We do not collect payment card numbers or bank details through this website; invoicing is handled by our accounting provider
- We do not knowingly collect information from children under 16 — our services are sold to businesses
- We do not buy personal information from data brokers
2. How We Use Personal Information
- Respond to enquiries and provide estimates, proposals and technical answers
- Deliver, support and improve the services we are contracted to provide
- Manage contracts, invoicing, accounting and tax obligations
- Communicate about projects, including service and security notices
- Protect our systems, prevent fraud and misuse, and meet legal obligations
- Send occasional business updates where permitted (see Section 6, CAN-SPAM)
3. Legal Bases (for individuals in the EEA, UK and Switzerland)
Where GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract — to provide services you or your employer have engaged us for
- Legitimate interests — to respond to business enquiries, secure our systems and improve our services, balanced against your rights
- Legal obligation — accounting, tax and record-keeping requirements
- Consent — where required, for example for marketing emails to individuals in the EU or UK. You may withdraw consent at any time
4. How We Share Personal Information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only to:
- Subprocessors and service providers — cloud hosting, email, accounting, project management and model providers, listed in our DPA, each bound by contract and, where relevant, by Standard Contractual Clauses
- Professional advisers — lawyers, accountants and insurers, under confidentiality obligations
- Authorities — where required by law, subpoena or valid legal process, and only to the extent required
- A successor entity — in a merger, acquisition or asset sale, with notice to affected individuals and continued protection of the data
5. International Transfers
We are based in the United States. Where personal data originating in the EEA, UK or Switzerland is transferred to us, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with a transfer risk assessment. Clients with data residency requirements can require US-only or EU-only processing, which we fix in writing before work starts.
6. Email Communications and CAN-SPAM
Business correspondence related to an active project is not marketing. Where we send commercial messages, we comply with the US CAN-SPAM Act: accurate header and subject information, a clear identification of the message as an advertisement where applicable, a valid physical postal address, and a working unsubscribe mechanism honoured within 10 business days. We do not sell or transfer email addresses to third parties for their own marketing.
7. Retention
- Enquiries that do not become projects — up to 12 months, then deleted
- Client project records — for the contract term plus 6 years, to satisfy tax and contractual limitation periods
- Client data processed in a project — for the term of the DPA, then deleted or returned per the client’s written instruction
- Security and access logs — typically 90 days
8. Security
We use encryption in transit (TLS 1.3) and at rest (AES-256), multi-factor authentication, SSO, least-privilege access with quarterly reviews, secrets in a managed vault, and per-project isolation. No system is perfectly secure; we maintain an incident response runbook and will notify affected clients without undue delay and no later than 72 hours after confirming a personal data breach. More detail is on our Security page.
9. Your Rights
California residents (CCPA/CPRA)
- Right to know what personal information we collect, use and disclose
- Right to delete personal information, subject to statutory exceptions
- Right to correct inaccurate personal information
- Right to opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of (see this page)
- Right to limit use of sensitive personal information — we do not use sensitive personal information for any purpose requiring limitation
- Right to non-discrimination for exercising your rights
EEA, UK and Swiss individuals
- Access, rectification, erasure, restriction, portability and objection
- Withdrawal of consent at any time, without affecting prior lawful processing
- Complaint to your supervisory authority
To exercise any right, email info@helixworks.site with the subject line "Privacy Request". We will verify your identity, respond within 45 days (extendable once by a further 45 days with notice), and never charge a fee for a reasonable request.
10. Cookies
This website sets no advertising or analytics cookies. Our hosting provider may set strictly necessary security cookies. See the Cookie Policy.
11. Changes to This Policy
We may update this policy to reflect changes in our practices or the law. The "Last updated" date above always reflects the current version, and material changes affecting client data are notified to affected clients directly.
12. Contact
HELIXWORKS
One Ferry Building, Suite 210, San Francisco, CA 94111
Email: info@helixworks.site
Phone: +1 (650) 442-5844
Questions about this document? Write to info@helixworks.site or call +1 (650) 442-5844. Postal address: One Ferry Building, Suite 210, San Francisco, CA 94111.
This document is a template provided for information and does not constitute legal advice. Have it reviewed by qualified counsel before relying on it.