Privacy Policy
What we collect, why we collect it, who it reaches, and how to get it removed.
1. Who is responsible
Helixtop, at TODO — building / door number and street, Thrissur, Kerala 679106, India, decides how and why personal data is processed on Helixtop and is the data fiduciary for the purposes of India’s Digital Personal Data Protection Act, 2023.
Where you use Helixtop to hold records about your own customers and staff, you decide what to collect and why. We process those records on your instructions, as a data processor.
2. What we collect
When you create an account:
- Your name, email address and phone number
- Your company name, business type and country
- A password, stored only as a cryptographic hash — we never see it
When you pay:
- Billing details and a record of transactions. Card and bank details are entered directly with our payment gateway and never reach our servers.
While you use the service:
- The business records you enter — customers, quotations, invoices, stock and so on
- An activity log of significant actions, with the account that performed them
- Technical logs: timestamps, error references and the approximate origin of a request
What we do not do:
- We do not use third-party advertising or analytics trackers.
- We do not sell or rent personal data to anyone.
- We do not read your business records except where you ask us to for support, or where the law requires it.
3. Why we process it
- To provide the service — creating your workspace, signing you in, storing your records. This is necessary to perform our contract with you.
- To take payment — billing, invoicing and recovering unpaid amounts.
- To support you — answering questions and investigating faults.
- To keep the platform secure — detecting misuse, and keeping an audit trail of who did what.
- To meet legal duties — tax and accounting records we are required to keep.
4. Cookies
We set a small number of strictly necessary cookies: one to keep you signed in, and one to remember interface preferences. They are not used for advertising or cross-site tracking, so no consent banner is required. Blocking them will prevent you from signing in.
5. Who else sees it
We use a small number of service providers, each with access limited to what their role requires:
- Amazon Web Services — hosting and storage. Your data is held in AWS’s Mumbai region, in India.
- Our payment gateway — processes card and bank payments and holds those details under its own privacy policy and PCI-DSS obligations.
We may also disclose data where the law compels us to, or to establish or defend a legal claim. If we are ever required to hand over a customer’s data, we will tell them unless prohibited from doing so.
6. Where it is stored
Personal data is stored in India. If that changes we will update this policy and notify account holders in advance.
7. How it is protected
- All traffic to the service is encrypted in transit using TLS.
- Stored data sits on encrypted disks, and backups are encrypted.
- Each customer’s business records live in a separate database, so one workspace cannot query another’s.
- Passwords are hashed and cannot be reversed. Stored system credentials are encrypted with AES-256-GCM.
- Administrative access by our staff is restricted and logged against the individual.
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board as the law requires.
8. How long we keep it
- Account and business records — for as long as your subscription is active.
- After you close an account — retained for 30 days so it can be restored if closed by mistake, then deleted.
- Invoices and tax records — kept for the period Indian tax law requires, currently eight years.
- Security and audit logs — up to 12 months.
9. Your rights
Under the Digital Personal Data Protection Act, 2023 you may:
- Ask what personal data we hold about you and get a copy
- Have inaccurate details corrected, or incomplete ones completed
- Ask us to erase data we no longer need for a lawful purpose
- Withdraw consent where we relied on it
- Nominate someone to exercise these rights if you die or become incapacitated
- Complain to the Data Protection Board of India
Write to info@helixtop.com and we will respond within 30 days. If your request concerns records held by a business that uses Helixtop, contact that business — we will point you to them.
10. Children
Helixtop is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.
11. Grievance Officer
As required by Indian law, complaints about the handling of personal data may be addressed to:
Ashiq
Helixtop
TODO — building / door number and street, Thrissur, Kerala 679106, India
info@helixtop.com
+91 62820 65969
We acknowledge complaints within 48 hours and aim to resolve them within 30 days.
12. Changes
We will post any update here and change the date at the foot of the page. If a change materially affects how we use your personal data we will email account holders before it takes effect.