Privacy Policy

Last updated: June 23, 2026

This Privacy Policy explains how Helix (“Helix”, “we”, “us”) collects, uses, discloses, and protects personal information when you visit helixcall.com, create an account, or use the Helix platform (the “Service”). We’ve tried to write it plainly. If anything is unclear, contact us at the address at the end.

Who is responsible for your data (controller vs. processor)

Helix plays two different roles depending on the data:

  • For our customers’ account data (the people who sign up for and administer a Helix workspace), Helix is the controller.
  • For end-user data processed on a customer’s behalf— the calls, chats, and messages our customers’ own customers send — Helix is a processor. The Helix customer is the controller of that data and is responsible for having a lawful basis (including any notice or consent, such as call-recording consent) for processing it. That relationship is governed by our Data Processing Agreement.

Information we collect

  • Account & identity: name, email, organization, and authentication data, managed through our identity provider.
  • Billing: plan, transactions, and card metadata, processed by our payments provider (we do not store full card numbers).
  • Communications content: call audio and recordings, transcripts, chat and SMS messages, phone numbers, and related metadata that flow through the Service.
  • Usage & technical: log data, IP address, device and browser information, and cookies needed to run the Service.
  • Demo & marketing: if you request a demo call, the name, email, phone number, and use case you provide.

How we use information

  • To provide, operate, secure, and improve the Service, including the AI features that answer and route conversations.
  • To process payments and manage your subscription and credit balance.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To provide support and respond to your requests.
  • To comply with legal obligations and enforce our terms.

We do not sell your personal information, and we do not use customer communications content to train third-party AI models.

Our privacy commitments (Canada & United States)

We operate from Canada and handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. We collect, use, and disclose personal information with your consent (express or implied), or as otherwise permitted or required by law, and only for the purposes described in this policy. You may withdraw your consent at any time, subject to legal or contractual limits, by contacting us.

In the United States, we comply with applicable state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA). We do not sell or share personal information as those terms are defined under those laws.

Call recording, transcription, and AI processing

The Service records and transcribes calls and applies AI to understand and respond to conversations. Where Helix acts as a processor, the customer operating the workspace is responsible for providing any legally required notice and obtaining any required consent before recording (some jurisdictions require all-party consent). Customers can configure data-retention windows and request deletion as described below.

How we share information & our sub-processors

We share personal information with service providers that help us run the Service, under contracts that require them to protect it:

  • Clerk — authentication and identity.
  • Stripe — payment processing.
  • Telnyx — telephony, messaging, and voice/AI infrastructure.
  • Neon — database hosting.
  • Cloudflare — application hosting, storage, and content delivery.
  • Composio — optional third-party app integrations you connect.
  • Resend — transactional email.
  • Sentry — error monitoring.

We may also disclose information to comply with the law or a valid legal request, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).

Where your information is processed

We are based in Canada and may process and store information in Canada, the United States, or other countries where we and our service providers operate. When personal information crosses borders, we use appropriate contractual and organizational safeguards to protect it, consistent with PIPEDA and applicable law. Information processed in another country may be accessible to that country’s authorities under its laws.

Data retention and deletion

We keep personal information for as long as needed to provide the Service and for legitimate business or legal purposes. Workspace administrators can configure a retention window for conversations, export a customer’s data, and request erasure of a customer’s records. When an account or organization is deleted, associated workspace data is deleted in turn. You can also email us to request deletion.

Security

We protect data with encryption in transit, strict tenant isolation enforced at the database layer, role-based access controls, and a tamper-evident audit log of sensitive actions. No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. If you are in California, you have rights under the CCPA/CPRA, including the right to know, delete, and correct, and the right to opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information as those terms are defined. To exercise any right, contact us below. If Helix processes your data on behalf of one of our customers, please direct your request to that customer; we will assist them as their processor.

Cookies

We use cookies that are strictly necessary to run the Service (such as keeping you signed in and securing your session); these are always active because the Service cannot function without them. With your consent, we also use optional cookies for analytics and error monitoring to understand product usage and improve Helix. Optional cookies are off by default and are only set after you accept them. You can accept, reject, or change your choices at any time using the “Cookie settings” link in our footer.

Children

The Service is intended for businesses and is not directed to children under 13. We do not knowingly collect their personal information.

Changes to this policy

We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide additional notice where required.

Contact us

Questions or requests about this policy or your personal information: privacy@helixcall.com.

Looking for our terms? This page is also linked in the site footer.