Legal

PRIVACY STATEMENT

Effective Date: August 2026
Last Updated: August 2026

1. OUR COMMITMENT TO PRIVACY

Helm AI is committed to protecting the privacy, confidentiality, integrity, and security of all information entrusted to us.

We understand that organizations rely on Helm AI to process highly sensitive operational, financial, workforce, commercial, and strategic information. Trust is fundamental to our relationship with customers, and data protection is built into every aspect of our platform, operations, and governance framework.

This Privacy Statement explains how Helm AI collects, uses, processes, stores, secures, transfers, and protects information when individuals and organizations interact with our websites, applications, products, services, support channels, and business operations.

This Privacy Statement applies to:

  • Helm AI websites
  • Helm AI software platforms
  • Helm AI mobile applications
  • Helm AI customer portals
  • Helm AI demonstrations and proof-of-concepts
  • Helm AI support services
  • Helm AI marketing and business operations
  • Helm AI integrations and APIs

By accessing or using Helm AI services, you acknowledge and agree to the practices described in this Privacy Statement.

2. PRIVACY PRINCIPLES

Helm AI operates according to the following core principles:

Customer Ownership

Customers retain full ownership of their data at all times.

Data Minimization

We collect only the information necessary to provide and improve our services.

Privacy by Design

Security and privacy controls are embedded into our products from the earliest stages of development.

Transparency

We clearly explain how information is collected, processed, stored, and protected.

Security First

We implement industry-standard safeguards designed to protect information from unauthorized access, loss, misuse, or disclosure.

Responsible AI

Artificial Intelligence is used responsibly, transparently, and with appropriate human oversight.

3. INFORMATION WE COLLECT

Helm AI may collect the following categories of information.

Personal Information

Information relating to an identified or identifiable individual, including:

  • Full name
  • Business email address
  • Telephone number
  • Job title
  • Department
  • Employer or organization
  • Business address
  • User account information
  • Authentication credentials
  • Profile information
  • Communication preferences

Customer Business Information

Depending on the services deployed, Helm AI may process customer business information, including:

Financial Information

  • Revenue data
  • Expense data
  • Budget information
  • Accounts receivable
  • Accounts payable
  • Cash flow information
  • Financial statements
  • Procurement spend

Operational Information

  • Project information
  • Production information
  • Supply chain information
  • Inventory information
  • Vendor information
  • Operational performance metrics
  • Asset information

Workforce Information

  • Organizational structures
  • Workforce allocation
  • Attendance information
  • Leave information
  • Performance information
  • Productivity metrics
  • Training records

Commercial Information

  • Customer records
  • CRM information
  • Sales performance
  • Pipeline information
  • Quotation data
  • Customer engagement information

Technical Information

We may automatically collect technical information including:

  • IP address
  • Browser type
  • Device identifiers
  • Operating system
  • Login activity
  • Usage statistics
  • Performance metrics
  • System logs
  • Diagnostic information

Information From Third Parties

We may receive information from:

  • Customer-authorized integrations
  • ERP systems
  • Accounting platforms
  • CRM platforms
  • HR systems
  • Cloud storage providers
  • Business partners
  • Publicly available sources

4. HOW WE USE INFORMATION

Helm AI uses information only for legitimate business purposes.

Service Delivery

To:

  • Deliver AI-powered services
  • Generate operational insights
  • Produce recommendations
  • Enable workflow automation
  • Provide dashboards and reporting
  • Support customer operations

Customer Support

To:

  • Respond to support requests
  • Troubleshoot issues
  • Resolve technical problems
  • Improve service quality

Platform Improvement

To:

  • Improve platform performance
  • Enhance user experience
  • Develop new capabilities
  • Improve reliability
  • Optimize infrastructure

Security Purposes

To:

  • Detect suspicious activities
  • Prevent unauthorized access
  • Monitor platform security
  • Investigate incidents
  • Protect customer environments

Legal Compliance

To:

  • Comply with applicable laws
  • Meet regulatory obligations
  • Respond to lawful requests
  • Protect rights and interests

5. CUSTOMER DATA OWNERSHIP

Customer data belongs to the customer.
Always.

Helm AI does not claim ownership of:

  • Customer records
  • Customer databases
  • Customer documents
  • Customer reports
  • Customer operational data
  • Customer financial information
  • Customer-generated outputs

Customers retain all rights, title, and interest in their data.

Helm AI acts solely as a technology provider and, where applicable, a data processor.

6. ARTIFICIAL INTELLIGENCE AND CUSTOMER DATA

Helm AI is an AI-powered platform designed to help organizations make better decisions and execute more effectively.

To maintain customer trust:

No Public AI Training

  • Customer data is never used to train public AI models.
  • Customer data is never contributed to shared public datasets.
  • Customer information is never used to improve third-party foundation models without explicit written authorization.

No Customer Data Resale

Helm AI does not:

  • Sell customer data
  • Rent customer data
  • Monetize customer data
  • Share customer data for advertising purposes

Customer Isolation

  • Each customer environment is logically segregated.
  • Customer data is isolated from other customer environments.
  • Users from one organization cannot access another organization's information.

Human Oversight

  • AI-generated outputs are designed to assist human decision-making.
  • Customers remain responsible for reviewing, validating, and approving important business decisions.

7. DATA SECURITY

Helm AI maintains a comprehensive information security program designed to protect information against unauthorized access, alteration, disclosure, destruction, or loss.

Security controls may include:

  • Encryption in transit
  • Encryption at rest
  • Role-based access controls
  • Multi-factor authentication
  • Audit logging
  • Security monitoring
  • Intrusion detection
  • Vulnerability scanning
  • Penetration testing
  • Backup systems
  • Disaster recovery procedures
  • Secure software development practices

Access to customer information is restricted based on business need and least-privilege principles.

8. ENTERPRISE SECURITY COMMITMENTS

Helm AI is designed with enterprise-grade security principles.

Where applicable, Helm AI may support:

  • Private cloud deployment
  • Dedicated environments
  • Virtual private cloud deployments
  • Customer-managed cloud deployments
  • On-premise deployments
  • Customer-controlled storage
  • Customer-controlled encryption keys

Deployment models may vary based on commercial agreements and technical requirements.

9. DATA RETENTION

Helm AI retains information only for as long as necessary to:

  • Deliver services
  • Fulfill contractual obligations
  • Comply with legal requirements
  • Resolve disputes
  • Enforce agreements

Upon termination of services, customer data may be:

  • Returned to the customer
  • Deleted securely
  • Archived where legally required

Retention periods may vary according to contractual and regulatory requirements.

10. DATA DELETION RIGHTS

Customers may request deletion of their information, subject to applicable legal and contractual obligations.

Where feasible, Helm AI will:

  • Permanently delete requested information
  • Remove backups according to retention schedules
  • Confirm deletion upon completion

Customers may also request data export prior to deletion.

11. INFORMATION SHARING

Helm AI does not sell personal information.

Information may only be disclosed under limited circumstances.

Service Providers

Trusted providers assisting with:

  • Infrastructure hosting
  • Security monitoring
  • Technical support
  • Payment processing
  • Professional services

All providers are contractually required to protect information.

Legal Obligations

Where required by:

  • Law
  • Court orders
  • Regulatory authorities
  • Government agencies

Business Transactions

In connection with:

  • Mergers
  • Acquisitions
  • Corporate restructuring
  • Asset sales

Appropriate confidentiality protections will apply.

Customer Authorization

Where customers expressly instruct or authorize disclosure.

12. INTERNATIONAL DATA TRANSFERS

Helm AI may process information in multiple regions where our infrastructure, partners, or service providers operate.

Where international transfers occur, appropriate safeguards will be implemented to maintain equivalent levels of protection.

13. COOKIES AND ANALYTICS

Helm AI uses cookies and similar technologies to:

  • Maintain website functionality
  • Improve user experience
  • Analyze website performance
  • Understand product usage
  • Enhance security

Users may manage cookie preferences through browser settings.

14. CONFIDENTIALITY OF BUSINESS INFORMATION

Helm AI recognizes that customer information often contains highly sensitive business intelligence.

This may include:

  • Financial performance
  • Strategic plans
  • Customer relationships
  • Pricing structures
  • Operational metrics
  • Workforce information
  • Proprietary methodologies

Such information is treated as confidential and protected accordingly.

Authorized personnel are subject to confidentiality obligations and access restrictions.

15. YOUR RIGHTS

Subject to applicable laws, individuals may have rights to:

  • Access personal information
  • Correct inaccurate information
  • Request deletion
  • Restrict processing
  • Object to processing
  • Withdraw consent
  • Request portability of data

Requests may be submitted through the contact channels listed below.

16. CHANGES TO THIS PRIVACY STATEMENT

Helm AI may update this Privacy Statement from time to time to reflect:

  • Legal changes
  • Regulatory requirements
  • Product updates
  • Security enhancements
  • Business developments

Updated versions will be published on our website.

17. CONTACT US

For privacy, security, or data protection enquiries:

For data protection requests, access requests, deletion requests, or privacy-related concerns, please contact: privacy@helm-ai.co

We are committed to responding to privacy requests in a timely and transparent manner.

18. DATA CONTROLLER AND DATA PROCESSOR RELATIONSHIP

For the purposes of applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR) and other applicable privacy regulations:

  • Helm AI shall act as a Data Processor where customer data is processed on behalf of a customer.
  • The customer shall remain the Data Controller and shall determine the purposes and means of processing customer data.
  • Helm AI shall process customer data solely in accordance with documented customer instructions and applicable law.

Nothing in this Privacy Statement transfers ownership, control, or decision-making authority over customer data to Helm AI.

19. CONFIDENTIAL INFORMATION

All customer information disclosed to Helm AI shall be treated as Confidential Information.

Confidential Information includes but is not limited to:

  • Financial information
  • Customer databases
  • Trade secrets
  • Source materials
  • Internal reports
  • Strategic plans
  • Operational metrics
  • Pricing information
  • Product roadmaps
  • AI outputs generated from customer data

Helm AI shall not disclose Confidential Information except:

  • With the customer's written authorization;
  • To authorized personnel with a legitimate business need;
  • To approved subprocessors bound by confidentiality obligations;
  • Where required by law.

Confidentiality obligations shall survive termination of the relationship.

20. INTELLECTUAL PROPERTY RIGHTS

All customer data remains the sole property of the customer.

Customer ownership includes:

  • Uploaded information
  • Integrated information
  • Business records
  • Customer-generated reports
  • Customer-generated AI outputs

Helm AI acquires no ownership rights over customer data by virtue of providing services.

Helm AI retains ownership of:

  • Software
  • Algorithms
  • Models
  • Source code
  • Workflows
  • System architecture
  • Platform intellectual property

Nothing in this Privacy Statement grants either party ownership of the other's intellectual property.

21. ARTIFICIAL INTELLIGENCE GOVERNANCE

Helm AI is committed to responsible and ethical use of Artificial Intelligence.

Helm AI shall implement reasonable measures designed to:

  • Reduce unintended bias
  • Improve transparency
  • Maintain accountability
  • Ensure human oversight
  • Protect customer confidentiality

AI-generated recommendations, insights, forecasts, and outputs are provided for informational purposes only.

Customers remain solely responsible for all decisions, actions, and business outcomes arising from their use of the platform.

Helm AI does not warrant that AI-generated outputs are error-free, complete, or suitable for every use case.

22. SUBPROCESSORS

Helm AI may engage trusted third-party subprocessors to support service delivery.

Subprocessors may include providers of:

  • Cloud infrastructure
  • Data hosting
  • Security monitoring
  • Identity management
  • Analytics services
  • Communication services

All subprocessors shall be contractually required to maintain security and confidentiality standards substantially equivalent to those maintained by Helm AI.

Helm AI remains responsible for the performance of its subprocessors to the extent required by applicable law.

23. DATA BREACH NOTIFICATION

In the event Helm AI becomes aware of a confirmed Security Incident affecting customer data, Helm AI shall:

  • Investigate the incident promptly;
  • Take reasonable measures to mitigate harm;
  • Notify affected customers without undue delay;
  • Provide available information regarding the nature and scope of the incident;
  • Cooperate with customers in fulfilling legal and regulatory obligations.

A Security Incident shall not include unsuccessful attempts or activities that do not compromise the confidentiality, integrity, or availability of customer data.

24. GOVERNMENT AND REGULATORY REQUESTS

Helm AI may disclose information where legally required by:

  • Courts
  • Regulatory authorities
  • Law enforcement agencies
  • Government agencies

Where legally permitted, Helm AI shall:

  • Notify affected customers;
  • Limit disclosure to the minimum legally required;
  • Challenge overly broad or unlawful requests where appropriate.

25. DATA RESIDENCY

Subject to service configuration and commercial agreement, Helm AI may offer data residency options that permit customer data to be stored and processed within designated geographic regions.

Where specific data residency commitments are agreed, Helm AI shall take reasonable measures to ensure customer data remains within the designated region.

26. AUDIT RIGHTS

Subject to reasonable notice and confidentiality obligations, enterprise customers may request information regarding Helm AI's security and privacy controls.

Helm AI may satisfy such requests through:

  • Security reports
  • Compliance certifications
  • Independent audit reports
  • Security questionnaires
  • Policy documentation

Direct audits may be permitted where required by contract or law and subject to reasonable limitations.

27. COMPLIANCE FRAMEWORKS

Helm AI is committed to maintaining security and privacy practices aligned with internationally recognized standards and applicable regulations.

Depending on deployment and service scope, Helm AI may maintain controls aligned with:

  • ISO 27001
  • SOC 2 Type II
  • GDPR
  • NIST Cybersecurity Framework
  • CIS Security Controls

Reference to any framework does not constitute certification unless expressly stated.

28. DISCLAIMER OF WARRANTIES

Except as expressly provided in a written agreement, Helm AI provides its services on an "AS IS" and "AS AVAILABLE" basis.

To the maximum extent permitted by law, Helm AI disclaims all warranties, including:

  • Merchantability
  • Fitness for a particular purpose
  • Non-infringement
  • Availability
  • Accuracy
  • Reliability

Helm AI does not guarantee uninterrupted, error-free, or completely secure operation of the platform.

29. LIMITATION OF LIABILITY

To the maximum extent permitted by applicable law, Helm AI shall not be liable for:

  • Indirect damages
  • Consequential damages
  • Special damages
  • Punitive damages
  • Lost profits
  • Lost revenue
  • Loss of business opportunity
  • Loss of goodwill
  • Business interruption

arising from or related to the use of Helm AI services.

Nothing in this section limits liability that cannot be excluded under applicable law.

30. INDEMNIFICATION

Customers agree to indemnify and hold harmless Helm AI, its affiliates, directors, officers, employees, and agents from claims, damages, losses, liabilities, costs, and expenses arising from:

  • Customer misuse of the platform;
  • Customer violation of applicable laws;
  • Customer infringement of third-party rights;
  • Unauthorized use of customer accounts;
  • Customer-provided content or data.