Helia HR

Privacy Policy

Last updated 2026-07-23 · See also Terms of Service

1. Who is the controller?

For data you upload about your employees and contractors, your organization (the tenant) is the data controller. Helia HR is the data processor, acting on documented instructions captured in your subscription. For the data we collect about your admins to operate the service (sign-in email, IP, audit-log actor), we are the controller. Contact: hello@heliahr.com.

2. What we collect

  • Account identifiers — your work email, display name, and tenant role.
  • Authentication metadata — magic-link tokens (single-use, 24-hour expiry), OAuth provider IDs if you use SSO, and last sign-in timestamps.
  • Session devices — for each active sign-in we store your browser/operating-system (from the User-Agent) and a last-active time, shown only to you under Account → Security so you can recognise and revoke your own sessions. No IP or location is stored for this; the record is deleted when the session expires or is revoked.
  • Tenant data — anything your HR team enters: employee records, projects and assignments, time-off, onboarding, reviews. Treated as your customer data.
  • Audit log — actor, IP, action, target row id, timestamp. Required for GDPR Article 30 records of processing.
  • Operational telemetry — error rates, request latency, feature state. Aggregated; not used to profile individuals.

3. What we DO NOT collect

  • No third-party analytics or session-replay tools.
  • No advertising trackers. We don't sell, share, or rent personal data — ever.
  • No biometric data, no precise geolocation, no behavioural fingerprinting.

4. Where data lives

Production data is hosted in the EU — the database in Frankfurt (Supabase) and the application in Frankfurt (Vercel, fra1). Backups stay in the same region. We do not transfer personal data outside the EU/EEA; if that ever changes we'll rely on Standard Contractual Clauses and tell you first.

5. How long we keep it

  • Active tenant data — for the lifetime of your subscription.
  • Backups — encrypted, 30 days rolling.
  • Audit log — up to 7 years (statutory record-keeping in most EU jurisdictions).
  • Magic-link tokens— deleted on use, or after 24 hours.
  • Sessions — expire after 7 days.

6. Your rights (GDPR)

EU/UK residents have the right to access, rectify, erase, restrict, port, and object to processing of their personal data. Employees of a Helia HR tenant should direct these requests to their organization (the controller). For data Helia HR holds as controller — your operator account — email hello@heliahr.com. We respond within 30 days.

7. Self-service exports

You can export your own data from the Account page at any time. Owners and admins can export the full tenant bundle, and a per-employee Article 15 export is available from each employee's detail page. Exports are operator-driven, audit-logged, and rate-limited.

8. Subprocessors

  • Supabase (Frankfurt, EU) — primary database + storage.
  • Vercel (Frankfurt, EU) — application hosting + serverless functions.
  • Resend (EU) — transactional email (magic links, invitations, notifications).
  • Cloudflare — DNS and inbound email routing for our domain.
  • Google — identity provider, only if you choose to sign in with Google SSO.
  • Paddle (EU) — billing + VAT, activated only when paid plans launch and you choose to upgrade.
  • OpenAI (US) — powers the optional AI features (see section 9). Only the specific fields needed for a given AI action are sent, under a no-training agreement (your data is not used to train models), and only when you invoke an AI feature.

9. AI features

Helia AI is assistive, not autonomous: it drafts and summarises to save time, and a person always reviews, edits, and owns the result. Helia AI never makes an automated decision about a person (no automated hiring, firing, rating, or pay decisions — GDPR Art. 22), and never takes an irreversible action on its own.

  • What is sent:only the fields relevant to the feature you invoke (e.g. a growth plan sends the employee's grade criteria, goals, and pooled anonymous feedback). We never send salary/pay into AI prompts.
  • Anonymity is preserved: AI summaries of anonymous feedback (e.g. eNPS) stay aggregate and never re-identify a respondent.
  • Processor + no training: AI runs server-side via OpenAI under a no-training agreement; prompts are not used to train models.
  • Optional: AI features run only when a permitted user clicks to use them; they can be left unused.

Full detail: How Helia AI works.

10. Security

  • TLS 1.2+ in transit; AES-256 disk-level encryption at rest.
  • Row-level security on every table — tenants are isolated at the database layer, not just in the app.
  • Sensitive fields (e.g. compensation, dependants) are restricted to HR/owner roles and every access is recorded in the audit log. Dedicated field-level encryption for salary and national-id is on our roadmap.
  • Secret-scanning in CI, dependency monitoring, rate limiting, a locked-down Content-Security-Policy, and an internal security review. Independent penetration testing is planned as we grow.

11. Changes to this policy

Material changes are announced in-app and by email at least 14 days before they take effect. Archived versions are available on request.

Questions, a data-subject request, or any data-protection matter? Email hello@heliahr.com — we respond within 30 days.