HELIXIA PRIVACY POLICY

Last updated: 2025

We are Helixia Ltd ("Helixia", "we" or "us"), a company that provides custom AI conversational sales agents and related services. Our company registration number is 15525142 and our registered address is at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

For the purposes of UK laws regarding data protection, the data controller is Helixia and we are registered with the UK Information Commissioner's Office (ICO): ZB786131.

This privacy policy applies to individuals who (i) visit our website at https://www.helixia.io/ (the "Website") (ii) engage with us via email, our Website, and/or social media accounts; or (iii) we otherwise deal with in their business capacity, including representatives of our customers, prospective customers, suppliers, investors, contractors, and agents ("you", "your"). It is important that you read this privacy policy together with any other privacy policy or fair processing policy we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data.

Helixia – Privacy Statement

At Helixia, your privacy is important to us. We believe in a responsible and pro-active approach when dealing with their personal information.

This policy sets out how and why we collect, store, use and share personal information generally, our dedication to protect it, as well as your rights in relation to your personal information and details of how to contact us and supervisory authorities if you have a complaint.

If you have any questions about how we use your personal data, please contact: mohamed@helixia.io

The types of personal data we collect

We collect and use the following information about you:

  • Your Identity Data including your title, first name and surname.
  • Your Contact Data including your work address, email address, billing address, delivery address and telephone numbers.
  • Your Financial Data including bank account details.
  • Your Transactional Data including information about our business dealings, transactions and interactions with you.
  • Your Technical Data including your IP address when you visit or engage with our Website or social media accounts or via our services.
  • Usage Data including information about how you use our Website and services.
  • Marketing and Communications Data including your preferences in receiving marketing from us and your communication preferences.
  • Recruitment Data including information within your CV or provided by recruitment agencies, information within your social media accounts such as LinkedIn, information relating to your performance during the application process and information provided by third party references, criminal records check (if applicable) and any relevant recruitment test results (if applicable).
  • Other Data such as information we receive where you register to receive our newsletters or to attend an event or to submit an enquiry via our Website.

We will indicate where any personal information we have requested is mandatory. We will also explain the consequences should you decide not to provide information which we have indicated is mandatory. In some circumstances this may mean we are unable to provide you with a certain service.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of an agreement we have with you, and you fail to provide that data when requested, we may not be able to perform the agreement we have or are trying to enter into with you (for example, to provide you with our services). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time.

How we use personal data

We use personal data relating to you that we collect, or that you provide to us, for the following purposes:

  • to respond to your queries;
  • to fulfil the terms of our engagement with customers, service providers and suppliers;
  • to ensure legal and regulatory compliance;
  • to handle any complaints and disputes;
  • to perform our day-to-day business operations including business development;
  • for processing your application to work for us;
  • for financial management;
  • to ensure that content from the Website is presented in the most effective manner for you and for your computer and/or mobile device;
  • to notify you about changes to the Website and the materials on the Website;
  • as part of our efforts to keep the Website safe and secure; and
  • to provide you with marketing information related to our services which we believe may be of interest to you.

We will mostly use any personal data collected via our AI conversational agent as a processor on behalf of our customer (acting in capacity as the controller). This means that we will only act on the instructions of our customer in processing such personal data. In such instances, we recommend you obtain a copy of the relevant controller's privacy policy in order to find our more information about how your data will be used.

Lawful basis for processing

We will only process your personal data where we have a lawful basis to do so. The lawful basis will depend on the purposes for which we have collected and use your personal information. In almost every case, the lawful basis will be one of the following:

  • Our legitimate business interests Where we have a legitimate interest to use personal data regarding you in relation to the operation of our business, including the monitoring and improving of our service. Also, where it is necessary for system administration purposes and for internal operations.
  • Performance of an agreement with you: For example, where you have provided your information in order to receive a service from us.
  • Compliance with the law: where we are subject to a legal obligation and need to use your personal information in order to comply with that obligation.

How we share your personal data with third-parties

We may share your personal information with our suppliers, business partners and other service providers, where they are helping us to market, advertise or supply our services, for them to use for the purposes set out in this privacy policy. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We may disclose your personal information to other third parties in the following cases:

  • for the purposes of research, evaluation, and analysis of our services;
  • in the event that we sell any business or assets, in which case we may disclose your personal information to the prospective buyer of such business or assets;
  • if we or substantially all of our assets are acquired by a third party, in which case personal information held by us about our clients, contractors, suppliers and visitors to our Website will be one of the transferred assets;
  • if we are under a duty to disclose or share your personal information in order to comply with any legal or regulatory obligation or request; or
  • to protect the rights, property or safety of us or our users, or others, and in order to enforce or apply our terms and conditions.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Marketing

We may send you marketing materials which we believe may be of interest to you.

You may receive marketing communications from us if you have engaged with us, requested information from us or used our services and you have not opted out of receiving that marketing.

Third-party marketing. We will not sell or rent your personal data to any third parties. We will not share your personal data with third parties for marketing purposes.

Opting out. You can ask us or third parties to stop sending you marketing messages at any time by contacting us at any time. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a service purchase, service experience or other transactions.

Cookies

Our Website uses cookies to distinguish you from other users of our Website. This helps us to provide you with a good experience when you browse our Website and also allows us to improve our Website. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive. We use the following cookies:

  • Strictly necessary cookies. These are cookies that are required for the operation of our Website. They include, for example, cookies that enable you to log into secure areas of our Website.
  • Analytical or performance cookies. These allow us to recognise and count the number of visitors and to see how visitors move around our Website when they are using it. This helps us to improve the way our Website works, for example, by ensuring that users are finding what they are looking for easily.
  • Functionality cookies. These are used to recognise you when you return to our Website. This enables us to personalise our content for you, greet you by name and remember your preferences.
  • Targeting cookies. These cookies record your visit to our Website, the pages you have visited and the links you have followed.

You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

Cookie TitleProviderPurposeExpiry
__Secure-next-auth.callback-urlcal.comStrictly necessary cookie. Manages secure user login sessions and redirects users after authentication.Session
__Secure-next-auth.csrf-tokencal.comStrictly necessary cookie. Protects against Cross-Site Request Forgery (CSRF) attacks during authentication processes.Session
_gaGoogle AnalyticsAnalytical cookie. Used to distinguish users, track website performance, and visitor interactions, helping improve user experience.2 years
_ga_RX4HHQ613SGoogle AnalyticsAnalytical cookie. Collects detailed information on visitor behavior, website usage patterns, and helps identify areas for improvement.2 years
_gcl_auGoogle AdSenseTargeting cookie. Used by Google AdSense to measure advertisement efficiency and optimize ad targeting across websites using Google's advertising services.3 months

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the Website may become inaccessible or not function properly.

Where we store your personal data

The personal data that we collect from you may be transferred to, and stored within, countries outside the United Kingdom ("UK") and European Economic Area ("EEA").

Whenever we transfer your information internationally, we will take steps which are reasonably necessary to ensure that adequate safeguards are in place to protect your personal information and to make sure it is treated securely and in accordance with this privacy policy. In these cases, we rely on approved data transfer mechanisms (such as the EU "Standard Contractual Clauses" or UK "International Data Transfer Agreement" or "UK Addendum") to ensure your information is subject to adequate safeguards in the recipient country. If you are located in the UK or EEA, you may contact us for a copy of the safeguards which we have put in place to protect your personal information and privacy rights in these circumstances.

Your Rights

Helixia takes your privacy seriously and wants you to be aware of your rights, which subject to certain exceptions, are as follows:

  • you have the right to request (i) confirmation of whether we process your personal data and (ii) access to a copy of the personal data retained;
  • you have the right to have inaccurate personal data rectified, or completed if it is incomplete;
  • you have the right to have your personal data erased or transmitted directly to another company, where technically feasible;
  • where the processing of your personal data is based on your consent, you have the right to withdraw your consent at any time without impact to any data processing activities that have taken place before such withdrawal;
  • you have the right not to be subject to any decisions based solely on automated processing, including profiling, which has legal or other similarly significantly effects on you unless we have your consent, it is authorised by law or it is necessary for the performance of an agreement;
  • you have the right to restrict or object to our processing of personal data regarding you; and
  • the right to lodge complaints before a supervisory authority.

Before we can respond to a request to exercise one or more of the rights listed above, you may be required to verify your identity or your account details. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Please send us an email at mohamed@helixia.io if you would like to exercise any of your rights.

Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.

We take steps to ensure that your information is treated securely and in accordance with this policy. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, for example, by encryption or by using pseudonym, we cannot guarantee the security of your information transmitted via the internet; any transmission is at your own risk.

We have appropriate technical and organisational measures to ensure a level of security appropriate to the risk of varying likelihood and severity for the rights and freedoms of you and other individuals. We maintain these technical and organizational measures and will amend them from time to time to improve the overall security of our systems.

In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.

We will, from time to time, include links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any information to these websites.

How long we keep your personal data

We retain your information for as long as it is necessary for the purposes for which it was collected and processed. Where we do not need your information taking account of the purpose(s) for which it was collected, we retain it only for so long as we have a legitimate business purpose in keeping such data.

However, there are occasions where we are likely to keep this data for longer in accordance with our legal obligations, or where it is necessary for the establishment, exercise or defence of legal claims. Please note that this will be assessed on a case by case basis.

We may store your information in an aggregated and anonymised format.

Complaints

In the event that you wish to make a complaint about how we process your personal data, please contact us in the first instance at mohamed@helixia.io and we will endeavour to deal with your request as soon as possible.

This is without prejudice to your right to complain to a relevant supervisory authority in your habitual place of residence. If you are based in the UK, the relevant supervisory authority is the ICO. The ICO's address is:

Information Commissioner's Office,
Wycliffe House,
Water Lane,
Wilmslow,
Cheshire, SK9 5AF.

The ICO's helpline number is: 0303 123 1113, and its website is: https://www.ico.org.uk.

Changes

We will generally notify you of any material changes to this policy, through a notice provided via the Website or otherwise supplied to you. However, you should look at this policy regularly to check for any changes. We will also update the "Last Updated" date at the top of this policy, which reflects the effective date of such policy. Your continued engagement with us after the date of the updated policy constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you must stop your engagement with us.