Privacy
Privacy notice
This notice explains how account, usage, billing, and support data is handled when you visit HelioDesk or use a workspace.
This policy is issued by HelioDesk. Legal notices are available through the support page. Configure the final legal entity and mailbox before public launch.
01Information we collect
- Account and workspace details, such as name, business email, role, organization, and authentication identifiers.
- Customer content you choose to process, including conversations, knowledge sources, instructions, follow-up records, and integration metadata.
- Subscription and transaction references from the payment provider; HelioDesk does not receive or store full card numbers or security codes.
- Device, log, security, and product-usage data needed to operate, protect, and improve the service.
02How we use information
Information is used to provide the service, authenticate users, route and improve support workflows, process subscriptions, prevent abuse, investigate incidents, communicate service updates, and meet legal obligations. Customer content is not used to train a general model unless an authorized customer explicitly opts in under separate terms.
03Legal bases and choices
Depending on location, processing is based on contract, legitimate interests, consent, or legal obligation. Available workspace controls can manage configured integrations. Retention, cookie choices, member access, and marketing preferences must follow the controls and contact paths actually published by the final operator.
04Service providers and disclosure
Information may be shared with vetted hosting, model, observability, email, support, and payment providers acting under contract; with integrations you direct us to use; during a corporate transaction; or when required to protect rights or comply with law. A current subprocessors list should be published before launch.
05International transfers
Where information moves across borders, appropriate safeguards such as adequacy decisions or standard contractual clauses are used when required. Available data regions and any residency limits are shown in the service or an order form.
06Retention and deletion
Account, billing, customer-content, and security-record retention must follow the final operator's documented schedule and applicable law. This release has no self-service retention or export control. Authorized users may request export, correction, or deletion through the published legal or support contact.
07Security
Technical measures in this release include HTTPS deployment requirements, tenant-scoped application access, audit records, secrets separation, and provider-hosted payment. No system is risk-free; report suspected incidents immediately through the published legal or support contact.
08Your rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection, and may complain to a regulator. The operator will verify requests and respond within the applicable period. Workspace customers generally handle requests about their end users, with HelioDesk assisting as processor.
09Children and changes
HelioDesk is a business service and is not directed to children. Material notice changes will be identified by a new effective date and, when required, a direct notice.