Legal · privacy

Privacy Policy

What we collect, why we collect it, how long we keep it, and what we never do with it.

Last updated: 2026-08-26

Draft — pending legal review. This text is published for transparency while counsel reviews it. It is not yet a binding agreement. Ask us for the executed version before relying on it in a procurement or audit process.

1. Who we are

Helix ([REGISTERED ADDRESS — to be confirmed]) is the controller for the personal data described here. Contact: privacy@helixcrypto.io.

2. Account data

To create an account we store your email address, your organisation name and your role. We use email solely to send magic-link sign-in messages, service notices and billing receipts. Authentication is passwordless — we never store a password.

Lawful basis: performance of a contract (providing the service) and legitimate interest (securing accounts).

3. Screening data

When you screen an address we store the address, the chain, the verdict, the signals behind it and the timestamp — scoped to your organisation. This record is the audit trail: it is what lets you show a bank or a regulator what you knew and when.

Blockchain addresses are public data. They may nevertheless relate to an identifiable person, so we treat screening records as personal data and protect them accordingly.

4. What we never do

  • We do not sell your data.
  • We do not expose which organisation screened which address to any other customer.
  • We do not use your screening history to train models sold to third parties.
  • The public flagged-wallet feed is anonymised at the API layer: addresses are truncated, organisation identifiers are never emitted, and repeated flags are de-duplicated.

5. Retention

Screening records are retained for the life of your account so that your audit trail stays intact, and for a period afterwards where record-keeping obligations apply to you or to us. Account data is deleted within 30 days of account closure, except where we must retain billing records for tax purposes. You can request an export or an erasure at privacy@helixcrypto.io.

6. Sub-processors

We use a small set of infrastructure providers to run the service: hosting and managed Postgres, a transactional email provider for sign-in links, and a payment processor for subscriptions. Each processes data only on our instructions. The current list is available on request at privacy@helixcrypto.io.

7. Sanctions and label sources

Sanctions labels come from published government lists. Where a label identifies a person, that identification is the publishing authority's — not ours. If an authority removes an entry, our daily ingest retires the corresponding label rather than continuing to assert a listing that no longer exists.

8. Your rights

Depending on where you are, you may have rights to access, correct, export, restrict or erase your personal data, and to object to processing. Write to privacy@helixcrypto.io and we will respond within the period your law requires. You may also complain to your local data protection authority.

9. Security

Data is encrypted in transit. Sign-in tokens are stored hashed, never in plaintext, and are single-use with a short expiry. API keys are stored as hashes; the plaintext key is shown once at creation and cannot be recovered afterwards. Access to production data is limited to personnel who need it to operate the service.

10. Changes

We will post material changes to this policy on this page and, where the change affects you, notify account contacts by email.