HelixHelixBack to the platform ↗

TRUST & RESPONSIBILITY

Privacy Policy

How information moves through our platform, who can access it, and the choices people have.

Questions or privacy requests? support@identitycore.io

Draft for review · Not yet effective

Company details, data practices, contact channels, and legal review must be completed before adoption. This is a proposed document, not a finalized notice or accepted contract.

In this document
01Scope and responsibility02Information we collect03Sources of information04Purposes of processing05Workspace, agency, and support access06AI processing and external AI clients07Cookies, browser storage, and measurement08Recipients and disclosures09Audience licensing, sale, and sharing10Retention and deletion11Security and incidents12Rights and request process13U.S. state privacy disclosures14International processing15Children and restricted information16Communications, changes, and contact

01Scope and responsibility

This proposed Privacy Policy describes how the operator of Helix (Company, we, us) handles personal information through its websites, workspaces, audience tools, campaign and content tools, knowledge features, Ask Intelligence, APIs, and MCP integrations (Services). It covers visitors, account users, business contacts, and people whose information is processed through the Services. Contact us at support@identitycore.io. The legal operator name remains to be confirmed before adoption.

We determine the purposes of processing for account administration, security, support, and our business operations. When processing customer content and contact lists solely under customer instructions, we generally act on that customer’s behalf. An agency may act for its client. The actual processing and applicable agreement determine each party’s role; a label does not override the law. White-label branding does not change the service operator or an agency’s responsibilities.

A customer’s privacy notice governs its collection and marketing activities. External data suppliers and destinations may independently control information under their own notices. This Policy does not replace those notices or remove obligations we independently have.

02Information we collect

Account and business information includes names, work email addresses, organization and workspace details, roles, invitations, preferences, authentication and verification records, and support communications. Passkey authentication uses public credentials; your device’s biometric unlock information is not the passkey credential sent to our service.

Customer content includes imported contacts, names, emails, telephone numbers, postal addresses, identifiers, custom fields, permission and suppression records, audience definitions, saved previews, channel header bundles, campaign and workflow settings, creative assets, and knowledge documents. Fields vary by source, feature, permissions, and customer instructions.

Audience information includes selected categories, interests, geographic and demographic filters, aggregate counts, and supported breakdowns. Where enabled and authorized, connected systems may process contact identifiers and delivery or engagement events. Inferred interests and demographics can be approximate, incomplete, or incorrect; they are not verified facts about a person.

AI and integration information includes prompts, messages, saved drafts, conversation history, selected knowledge passages, generated content, tool requests and results, approvals, credentials, and execution records. Do not paste credentials into chats or knowledge documents. Technical information includes IP addresses, browser and device characteristics, timestamps, interactions, errors, security events, and usage.

Commercial information may include billing contacts, orders, balances, invoices, payment status, and transaction records. Payment information collected directly by an external payment provider is also subject to that provider’s notice. This draft does not assert that we store full payment-card details.

03Sources of information

Information comes from you; your organization, agency, and authorized users; uploaded files and content; configured integrations and data suppliers; and automatic collection during service use. Public geographic reference data can support ZIP, city, radius, and DMA targeting. Public availability, a licensed source, or a selectable field does not establish consent to marketing or permission for every use.

04Purposes of processing

We process information to authenticate users, administer accounts and permissions, import and organize data, build and save audiences, provide requested analytics, store and retrieve content, operate requested AI assistance, execute authorized integrations and delivery, provide support, administer orders, and communicate about the Services.

We also process information to secure systems, prevent fraud and misuse, troubleshoot failures, measure service usage, maintain reliability, meet legal obligations, enforce agreements, and resolve disputes. Service improvement must remain consistent with applicable notices, contracts, and legal purpose limits. Uploading customer personal information does not grant an unrestricted right to reuse it for unrelated purposes.

05Workspace, agency, and support access

Workspace records are accessible to users and integrations according to permissions. Organization or agency administrators may manage access and business records within their authorized scope. Their own policies govern how they supervise users. Leaving an organization can end access to records created during that relationship.

Private AI conversations have access controls separate from ordinary workspace records. Actions initiated in a conversation can create shared business records and audit events. Deleting a conversation does not automatically delete independently created audiences, campaigns, exported copies, or audit records. Authorized personnel may access information as necessary for support, security, or legal purposes under applicable controls; we do not promise that no personnel can ever access stored information.

06AI processing and external AI clients

Requested AI features may send prompts, conversation context, selected documents or passages, and permitted tool results to hosted AI providers. Knowledge processing may involve text extraction, embeddings, retrieval, and generated responses. The current application uses hosted cloud and model services. The final provider inventory and contractual restrictions must be confirmed before this notice is adopted.

AI output can be inaccurate, incomplete, biased, or unsuitable. Review it before using it for campaigns or decisions. Do not submit unnecessary personal or sensitive information. Certain contact results are presented outside the model context, but personal information you type or attach may enter model processing. This draft makes no unverified promise that every provider has zero retention or never uses information for model training.

An external MCP client, AI application, or integration can receive information its credentials and grants authorize. Its own processing, storage, retention, and security practices apply to received copies. Revoking a key prevents future authorized access but cannot recall information already transferred.

07Cookies, browser storage, and measurement

The Services use cookies or similar mechanisms for authentication, session security, and operation. Browser storage may retain interface preferences such as theme, motion, and navigation state. Technical requests create logs. Blocking essential storage can prevent sign-in or disrupt functionality.

Embedded maps, media, or other enabled third-party services may receive network information when loaded. Customer campaign tracking, where enabled, may use identifiers, pixels, or event records and requires appropriate customer notices and permissions. Offering advertising tools does not itself mean that our own website uses advertising trackers.

Before publishing this notice, inventory any nonessential analytics or advertising technologies deployed on our properties and document their purposes, providers, and consent controls. Do not infer that a cookie banner or opt-out preference handler is implemented merely from this policy draft.

08Recipients and disclosures

Information may be disclosed to service providers supporting hosting, storage, authentication, AI, communications, security, support, and billing under appropriate obligations. Customer information is disclosed to authorized workspace members, agencies, clients, destinations, and integration operators as directed and permitted by the customer.

We may make disclosures required by law or valid legal process, or reasonably necessary to investigate misuse, protect people and systems, or establish or defend legal rights. Professional advisers and parties to an actual or proposed financing, merger, acquisition, or business transfer may receive information subject to appropriate safeguards. Information may also be disclosed at your direction or with valid consent. None of these categories overrides applicable purpose limitations or opt-outs.

09Audience licensing, sale, and sharing

We sell audience-level data. The specific fields, permitted uses, and license restrictions depend on the applicable offering and agreement. Licensing audience data, making personal information available to customers, or transferring identifiers to advertising destinations can qualify as a sale, sharing, or targeted advertising under privacy law, even without a separate monetary payment for a particular transfer. Classification depends on actual practices and contracts. Hashed identifiers are not necessarily anonymous.

The finalized notice must state the actual categories of information sold or shared, recipient categories, purposes, and opt-out mechanisms—or affirmatively state that such activities do not occur if verified. This draft does not assert that the Company never sells or shares personal information, nor that all audience information is anonymous.

A count, segment, inferred interest, export, or delivery capability does not establish consent to contact an individual. Supplier restrictions, objections, deletion obligations, channel consent, and suppression requirements continue to apply. Reidentification of aggregate results and attempts to defeat access limits are not authorized.

10Retention and deletion

Retention depends on the purpose, account activity, service delivery, legal and contractual obligations, security needs, disputes, and information sensitivity. Saved audience definitions and preview snapshots are business records, separate from short-lived query caches. Chat history and drafts may remain until deletion. Archiving is not necessarily permanent deletion.

Deleting a thread, source, or account does not necessarily delete independent business records, sent communications, customer exports, or required audit and transaction records. Backups may persist under their lifecycle and are not ordinarily available for continued business use. Limited suppression information may be retained where lawful to prevent renewed contact or reimport.

Customers are responsible for downloaded and downstream copies. Processing on behalf of a customer may require that customer’s deletion instruction, subject to independent legal duties. Operational retention periods, backup deadlines, source-deletion propagation, and account-deletion procedures must be verified before publication. We will explain applicable exceptions instead of promising immediate universal deletion.

11Security and incidents

We use administrative, technical, and organizational safeguards designed to protect information, including access controls appropriate to the Services. No transmission or storage system is completely secure. Customers must protect devices, authentication factors, API keys, destination credentials, and exported files, review access, and promptly report suspected compromise to support@identitycore.io.

We will provide notifications of qualifying security incidents where required by applicable law or contract. These duties vary by jurisdiction and circumstances. Security controls do not replace customer obligations, and this draft does not claim an unverified certification or guarantee absolute security.

12Rights and request process

Depending on applicable law, individuals may have rights to confirm processing; access or obtain a portable copy; correct inaccuracies; request deletion; object to or restrict certain processing; withdraw consent; and opt out of sale, sharing, targeted advertising, or certain profiling. Rights concerning sensitive information and automated decisions may also apply. Legal conditions and exceptions apply; the Terms do not waive mandatory privacy rights.

Submit privacy requests to support@identitycore.io with the subject Privacy Request. Explain your relationship and request without sending passwords, full government identifiers, or unnecessary sensitive documents. Identity verification and authorized-agent checks will be proportionate to the request and risk. We will respond within applicable legal deadlines, explain permitted denials and appeal options, and will not unlawfully discriminate for exercising rights.

For information controlled by a customer, contacting that customer may be the fastest route. If contacted, we will assess our role and assist or route the request appropriately without avoiding independent obligations. You may complain to the competent privacy regulator or other authority where permitted. An account is not a prerequisite for exercising a legally available privacy right.

13U.S. state privacy disclosures

The information described above can include identifiers, business and account records, commercial information, internet and network activity, geography, professional and demographic information, and inferences. Sources, purposes, recipient categories, and retention criteria appear above. Actual collection and disclosure vary by feature and relationship. The final notice requires a verified preceding-twelve-month collection and disclosure inventory.

Where California or another state privacy law applies, rights may include access, deletion, correction, portability, opt-outs, and limits on certain sensitive-information uses. Covered opt-out preference signals, such as Global Privacy Control, must be handled through an implemented mechanism where legally required. This draft does not represent that signal handling or a Do Not Sell or Share workflow is already deployed.

Where an appeal right applies, a denied request can be appealed through the designated privacy contact; the outcome and applicable regulator complaint channel will be explained. Charges are limited to circumstances permitted by law. Data-broker registration and centralized deletion requirements, including California DROP where applicable, must be assessed against the actual business model. This draft is not evidence of registration or operational compliance.

14International processing

Where European or UK law applies to processing for which we are a controller, a legal basis may include performance of a contract with the individual, legal obligations, consent for a specific purpose, or legitimate interests such as security and business administration where not overridden by individual rights. A customer contract alone is not a lawful basis for every person in an uploaded list. Special-category processing requires an additional condition and is not authorized by default.

Processing on a customer’s behalf is subject to documented instructions and an applicable data processing agreement. Cross-border transfers require safeguards where applicable, potentially including standard contractual clauses and supplementary measures. This draft does not claim executed transfer instruments, a particular adequacy arrangement, or appointed regional representatives. Confirm applicable jurisdictions, hosting locations, representatives, and transfer mechanisms before international launch.

15Children and restricted information

The Services are intended for adult business users, not children. Do not create audiences of known minors or upload children’s data. Do not provide medical records, government identifiers, passwords, payment authentication details, biometric identifiers, sensitive precise-location histories, or similarly restricted information without a separate signed agreement expressly authorizing lawful processing and appropriate protections. The Terms contain additional restrictions on sensitive targeting and harmful uses.

Contact support@identitycore.io if you believe prohibited information or children’s data has been supplied. Customer promises do not substitute for legal duties imposed on the Company.

16Communications, changes, and contact

Use the instructions in our promotional messages to opt out. Necessary security, legal, billing, and service communications may continue. For customer marketing, use the sender’s unsubscribe or preference mechanism; we assist where we operate that mechanism. Opting out of one sender does not necessarily modify unrelated organizations’ lists.

The final Policy will state its effective date and be updated as practices change, with notice and additional consent where legally required. Prior versions should remain available. Continued use is not a substitute for consent where the law requires it.

For privacy, support, or suspected misuse, contact support@identitycore.io. No mailing address has been provided for this draft. Publication remains pending the legal company name, any required notice address, the precise categories and recipients of audience data sold or shared, operational retention and rights procedures, and any required regional representatives. Until completed, this is a review draft rather than a finalized privacy notice.

Back to top ↑
Helix
Privacy PolicyTerms & ConditionsFor vendors