You hold data under professional secrecy, and you answer for it whatever tool you use. This page is written to be forwarded to whoever in your firm has to say yes.
Everything on it is written into the agreement as a term.
Processing can stay entirely in EU data centres, under an EU contract.
Nothing your firm writes is used to train a model, ours or anyone's.
Model providers keep nothing once the answer is returned.
The system holds no permission to send. A person sends every client email.
Permissions per person and per client, with a log of every answer.
Configuration, knowledge and documentation belong to your firm.
Eight terms, each one in the agreement you sign.
Helix Studio OÜ is an Estonian company, inside the EU and fully subject to the GDPR. There is no US parent, no US holding structure, and nothing that brings us within reach of the US CLOUD Act. We state that in writing as part of the agreement.
In the EU setup, hosting, backups and language model inference all sit on servers inside the European Union, with EU companies, in France and Germany. Nothing is transferred outside the European Economic Area. If your firm wants a model from outside the EU, the provider, where it processes and its retention terms are named in the agreement before it sees any of your data.
Zero data retention on inference, written into the contract. Your prompts and the answers are not kept by the model providers, beyond a short error and abuse investigation window that is named and bounded in the agreement.
Your content is never used to train a model, by us or by any provider we use. The people who build the underlying models have no access to it.
Access is limited to one named person on our side and to the sub-processors listed below, on a least-privilege basis, with multi-factor authentication on every account that can reach the data and an access log for administrative access.
Only the mailboxes you designate, and only to read mail and write drafts into them. The access is configured without permission to send, so no instruction to the system can make it send.
TLS in transit, encrypted at rest, automated backups held inside the EU on a defined rotation and encrypted the same way.
You own it. The client pages, the playbooks and everything written down about how your firm works are exportable at any time, in a readable format, for any reason, including because you want to stop.
The full list, named. Adding or replacing one takes thirty days' written notice, and you can object on reasonable data protection grounds.
| Sub-processor | Role | Location |
|---|---|---|
| Scaleway SAS | Language model inference | Paris, France |
| IONOS SE | Language model inference | Berlin, Germany |
| Hetzner Online GmbH | Server hosting and backups | Germany |
This is the EU setup. Any other model provider your firm chooses is added to this list in your agreement before it runs.
Your mail provider and your chat tool are not our sub-processors. You contract with them directly and you remain the controller for what sits there, so your agreements with them govern their transfers. We say this plainly because it is true of every system that reads your mail, whether or not the vendor mentions it.
Four design decisions, fixed in the contract. They change only by a written amendment signed by both sides, so no support ticket and no configuration change can undo them.
It writes drafts. A person at your firm reviews the draft, chooses the recipient, and sends it from their own mail.
No credentials for any tax authority, any client portal, or anything that files on your behalf.
No bank connections, no payment initiation, no access to accounts.
Processing, hosting and backups stay with the providers named in your agreement, inside the EU unless you choose otherwise in writing.
The GDPR annex is part of the contract. Ask, and we will send the current version before you commit to anything.
Book a call