Trust & data

Where your client data goes, and where it does not.

You hold data under professional secrecy, and you answer for it whatever tool you use. This page is written to be forwarded to whoever in your firm has to say yes.

Everything on it is written into the agreement as a term.

EU processing

Processing can stay entirely in EU data centres, under an EU contract.

Never trained on your data

Nothing your firm writes is used to train a model, ours or anyone's.

Zero retention

Model providers keep nothing once the answer is returned.

Nothing sends itself

The system holds no permission to send. A person sends every client email.

Access you control

Permissions per person and per client, with a log of every answer.

Yours to keep

Configuration, knowledge and documentation belong to your firm.

How it is processed

Eight terms, each one in the agreement you sign.

01Jurisdiction

Helix Studio OÜ is an Estonian company, inside the EU and fully subject to the GDPR. There is no US parent, no US holding structure, and nothing that brings us within reach of the US CLOUD Act. We state that in writing as part of the agreement.

02Where it runs

In the EU setup, hosting, backups and language model inference all sit on servers inside the European Union, with EU companies, in France and Germany. Nothing is transferred outside the European Economic Area. If your firm wants a model from outside the EU, the provider, where it processes and its retention terms are named in the agreement before it sees any of your data.

03Retention

Zero data retention on inference, written into the contract. Your prompts and the answers are not kept by the model providers, beyond a short error and abuse investigation window that is named and bounded in the agreement.

04Training

Your content is never used to train a model, by us or by any provider we use. The people who build the underlying models have no access to it.

05Access

Access is limited to one named person on our side and to the sub-processors listed below, on a least-privilege basis, with multi-factor authentication on every account that can reach the data and an access log for administrative access.

06Mail access

Only the mailboxes you designate, and only to read mail and write drafts into them. The access is configured without permission to send, so no instruction to the system can make it send.

07Encryption

TLS in transit, encrypted at rest, automated backups held inside the EU on a defined rotation and encrypted the same way.

08Your data

You own it. The client pages, the playbooks and everything written down about how your firm works are exportable at any time, in a readable format, for any reason, including because you want to stop.

Who else touches it

The full list, named. Adding or replacing one takes thirty days' written notice, and you can object on reasonable data protection grounds.

Sub-processorRoleLocation
Scaleway SASLanguage model inferenceParis, France
IONOS SELanguage model inferenceBerlin, Germany
Hetzner Online GmbHServer hosting and backupsGermany

This is the EU setup. Any other model provider your firm chooses is added to this list in your agreement before it runs.

The part most vendors leave out

Your mail provider and your chat tool are not our sub-processors. You contract with them directly and you remain the controller for what sits there, so your agreements with them govern their transfers. We say this plainly because it is true of every system that reads your mail, whether or not the vendor mentions it.

What it is forbidden to do

Four design decisions, fixed in the contract. They change only by a written amendment signed by both sides, so no support ticket and no configuration change can undo them.

Forbidden · 01

Send a message to a client

It writes drafts. A person at your firm reviews the draft, chooses the recipient, and sends it from their own mail.

Forbidden · 02

Hold a portal login

No credentials for any tax authority, any client portal, or anything that files on your behalf.

Forbidden · 03

Connect to a bank

No bank connections, no payment initiation, no access to accounts.

Forbidden · 04

Use a provider you did not approve

Processing, hosting and backups stay with the providers named in your agreement, inside the EU unless you choose otherwise in writing.

A data processing agreement comes with it.

The GDPR annex is part of the contract. Ask, and we will send the current version before you commit to anything.

Book a call