Privacy Policy
What we collect, why we collect it, how long we keep it, and what we never do with it.
Last updated: 2026-08-26
1. Who we are
Helix ([REGISTERED ADDRESS — to be confirmed]) is the controller for the personal data described here. Contact: privacy@helixcrypto.io.
2. Account data
To create an account we store your email address, your organisation name and your role. We use email solely to send magic-link sign-in messages, service notices and billing receipts. Authentication is passwordless — we never store a password.
Lawful basis: performance of a contract (providing the service) and legitimate interest (securing accounts).
3. Screening data
When you screen an address we store the address, the chain, the verdict, the signals behind it and the timestamp — scoped to your organisation. This record is the audit trail: it is what lets you show a bank or a regulator what you knew and when.
Blockchain addresses are public data. They may nevertheless relate to an identifiable person, so we treat screening records as personal data and protect them accordingly.
4. What we never do
- We do not sell your data.
- We do not expose which organisation screened which address to any other customer.
- We do not use your screening history to train models sold to third parties.
- The public flagged-wallet feed is anonymised at the API layer: addresses are truncated, organisation identifiers are never emitted, and repeated flags are de-duplicated.
5. Retention
Screening records are retained for the life of your account so that your audit trail stays intact, and for a period afterwards where record-keeping obligations apply to you or to us. Account data is deleted within 30 days of account closure, except where we must retain billing records for tax purposes. You can request an export or an erasure at privacy@helixcrypto.io.
6. Sub-processors
We use a small set of infrastructure providers to run the service: hosting and managed Postgres, a transactional email provider for sign-in links, and a payment processor for subscriptions. Each processes data only on our instructions. The current list is available on request at privacy@helixcrypto.io.
7. Sanctions and label sources
Sanctions labels come from published government lists. Where a label identifies a person, that identification is the publishing authority's — not ours. If an authority removes an entry, our daily ingest retires the corresponding label rather than continuing to assert a listing that no longer exists.
8. Your rights
Depending on where you are, you may have rights to access, correct, export, restrict or erase your personal data, and to object to processing. Write to privacy@helixcrypto.io and we will respond within the period your law requires. You may also complain to your local data protection authority.
9. Security
Data is encrypted in transit. Sign-in tokens are stored hashed, never in plaintext, and are single-use with a short expiry. API keys are stored as hashes; the plaintext key is shown once at creation and cannot be recovered afterwards. Access to production data is limited to personnel who need it to operate the service.
10. Changes
We will post material changes to this policy on this page and, where the change affects you, notify account contacts by email.