1. Who we are and the scope of this policy
Helix DB, Inc., a Delaware corporation ("HelixDB", "we", "us", or "our") provides HelixDB database software, managed cloud infrastructure, developer tools, websites, documentation, and related support (collectively, the "Services").
For personal information used to operate accounts, billing, our websites, and our business, HelixDB acts as a controller or business. When we process personal information contained in a customer's database or other Customer Data solely to provide the Services, HelixDB generally acts as that customer's processor or service provider. The customer controls that data and is responsible for its own notices, permissions, and lawful basis.
Questions and privacy requests may be sent to founders@helix-db.com.
2. Information we collect
The information we collect depends on how you use the Services. It can include:
- Account and identity information. GitHub user ID, username, display name, email address, and avatar. GitHub provides this information when you sign in after authorizing the requested
read:useranduser:emailpermissions. - Workspace and team information. Workspace names, URL slugs, icons, membership roles, invitations, and the email address or GitHub identity used to invite a team member.
- Project and service configuration. Project and cluster names, deployment region and size, build configuration, customer-supplied source and query files, environment variables, API-key names and identifiers, and cluster configuration. Secret keys may be shown when created; stored credentials are protected or hashed as appropriate to their function.
- Customer Data. Graph, vector, text, and other data submitted to a managed cluster, together with schemas, queries, and query results. Customers decide what Customer Data to submit.
- Usage, diagnostics, and audit information. Request volume, compute, memory and storage consumption, timestamps, latency, status and error information, deployment and runtime logs, query names and diagnostic findings, administrative actions, and identifiers for the user, workspace, project, or cluster involved.
- Billing information. Billing contact name and email, credit balance, metered usage, charges, invoice and payment status, and limited payment-method details such as brand and last four digits. Payment card numbers are collected and processed by Stripe rather than stored by HelixDB.
- AI-assisted query optimisation information. If this optional database feature is made available and you choose to use it, we process your prompts, recent chat messages, relevant schema and query context, generated queries, and error responses needed to generate and retry a response. The feature may query your cluster using the credential you provide. HelixDB does not provide a standalone AI service.
- Website and device information. Requested pages, referring page, approximate location derived from IP address, browser and device details, timestamps, and performance or engagement events collected through our hosting platform.
- Communications. Information you send when requesting support, booking a demo, completing a security or Trust Center request, or otherwise contacting us.
We obtain information from you, your organization, GitHub, payment and infrastructure providers, and automatically from the Services. Please do not provide sensitive personal information in support tickets, environment variables, AI prompts, or Customer Data unless it is necessary, authorized, and appropriately protected.
Account identity and configuration information is required to create and operate an account and managed resources. If you do not provide it, we may be unable to provide the requested Services. Our hosting platform collects aggregate website traffic and performance information without using advertising cookies.
3. How and why we use information
| Purpose | Typical information | UK/EEA lawful basis |
|---|---|---|
| Provide, secure, and administer the Services | Account, workspace, configuration, Customer Data, credentials, logs, and usage | Contract; legitimate interests; legal obligations |
| Authenticate users and manage permissions | GitHub identity, session and security information | Contract; legitimate interests in preventing misuse |
| Deploy, operate, back up, and troubleshoot clusters | Configuration, source files, Customer Data, telemetry, and diagnostics | Contract; legitimate interests in reliable operations |
| Meter usage, manage credits, invoice, and collect payment | Workspace, usage, billing contact, and payment metadata | Contract; legal obligations; legitimate interests |
| Provide optional AI-assisted query optimisation | Prompts, schema context, generated queries, and errors | Contract or steps taken at your request |
| Improve performance, reliability, and user experience | Aggregated usage, diagnostics, feedback, and analytics | Legitimate interests in improving the Services |
| Communicate and respond to requests | Contact, support, demo, and Trust Center information | Contract; legitimate interests; consent where applicable |
| Comply with law and protect rights and safety | Relevant account, transaction, security, and audit records | Legal obligations; legitimate interests |
We do not make decisions that produce legal or similarly significant effects about individuals using solely automated processing.
4. Customer Data
Customers retain their rights in Customer Data. We process Customer Data to provide, secure, support, and maintain the Services, comply with documented customer instructions and applicable law, and enforce the agreement governing the Services. We do not use Customer Data to train AI models. We may use aggregated or de-identified operational information that does not reasonably identify a customer or individual to understand and improve the Services.
A customer's organization administrator may access and control its workspace, members, projects, clusters, logs, and Customer Data. If your account is managed by an organization, direct requests about that organization's Customer Data to the organization first.
6. International transfers
HelixDB and its providers may process information in the United Kingdom, United States, European Economic Area, and other locations where they operate. Where data-protection law requires a transfer mechanism, we use an applicable adequacy decision, approved standard contractual clauses or the UK International Data Transfer Addendum, or another lawful safeguard. Customers may select from available cluster regions; control-plane, support, billing, security, and diagnostic information may still be processed outside the selected data region.
7. Retention and deletion
We retain information only for as long as reasonably needed for the purposes described above, including to provide an active account, meet contractual commitments, maintain security and audit records, resolve disputes, and satisfy tax, accounting, and legal requirements. Retention depends on the type of record, the customer's configuration, and applicable law.
- Authentication session cookies expire after seven days, and the temporary GitHub OAuth state cookie expires after ten minutes.
- Detailed enterprise node CPU and memory measurements are configured to be pruned after 14 days.
- Workspace, project, and cluster records generally remain while the relevant resource or account is active.
- Deleting a supported workspace, project, or cluster initiates deletion of its active resources and associated control-plane records. Some audit events, billing records, logs, and residual backup copies may remain for the periods required for security, recovery, or law before they expire or are overwritten.
- Enterprise backup retention can depend on the schedule selected for the cluster. Certain storage-measurement snapshots are configured to be pruned after 180 days.
The dashboard does not currently provide self-service deletion for a personal workspace. To request account or personal-information deletion, email founders@helix-db.com. We may need to verify your identity and coordinate with the relevant workspace administrator.
8. Security
We use technical and organizational measures intended to protect information, including access controls, scoped credentials, encrypted network connections, hashed enterprise API keys, audit logging, monitoring, backups, and restricted administrative access. More information about our security program is available in the Trust Center. No system is completely secure, so customers are responsible for protecting their credentials, configuring access appropriately, and notifying us promptly of suspected misuse.
10. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to request access, correction, deletion, restriction, portability, or objection; to withdraw consent; to limit certain uses of sensitive personal information; and to appeal a decision about a request. HelixDB does not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. You may also have a right not to receive discriminatory treatment for exercising a privacy right.
Submit a request to founders@helix-db.com. Tell us the right you wish to exercise and the account or workspace involved. We may ask for information needed to verify your identity and authority. An authorized agent may submit a request where local law permits, but we may require proof of authorization.
UK residents may complain to the Information Commissioner's Office. EEA residents may contact their local supervisory authority. You may contact us first so we have an opportunity to address the issue.
11. Children
The Services are designed for adults and may be used only by people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information to us, contact us so we can investigate and delete it where appropriate.
12. Changes and contact
We may update this policy as the Services or legal requirements change. We will post the revised policy here, update its effective date, and provide additional notice when required by law.
For privacy questions or requests, contact Helix DB, Inc. at founders@helix-db.com.