Privacy Policy

This policy explains how Helm collects, uses, shares, protects and retains personal information across our website, accounts, platform, communications and support services.

Last updated: 29 July 2026 notifications@helmhq.co.uk

We use data to provide Helm

This includes accounts, security, subscriptions, records, documents, workflows, support and service communications.

Customers control workspace content

A customer organisation is normally the controller for personal information it enters into its Helm workspace.

We do not sell personal data

We do not sell personal information or use customer workspace content for third-party advertising.

01

About this policy

This Privacy Policy applies to the Helm website at helmhq.co.uk, the Helm software platform and related services, including account registration, authentication, subscriptions, customer workspaces, support, bug reporting, update requests, notifications and other communications.

In this policy, Helm, we, us and our refer to [INSERT LEGAL ENTITY NAME], which operates the Helm service under the Helm trading name.

This policy is intended to comply with applicable UK data protection and privacy law, including the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and relevant amendments made by the Data (Use and Access) Act 2025.

This policy does not replace a customer's own privacy notice. Customer organisations remain responsible for explaining how they use personal information within their transport operation.

02

Our role and your organisation's role

When Helm is the controller

Helm is normally the data controller for personal information used for our own purposes, including:

  • operating the public website;
  • creating and administering Helm accounts;
  • authentication, security and fraud prevention;
  • subscriptions, billing and account management;
  • support requests, contact enquiries and bug reports;
  • service messages, product updates and permitted marketing;
  • platform analytics, service improvement and legal compliance;
  • managing our suppliers, advisers and business operations.

When Helm is a processor

Customer organisations decide why and how personal information is entered into their Helm workspace. For that customer-controlled workspace content, the customer is normally the controller and Helm acts as its processor.

This can include information about company contacts, employees, drivers, vehicle users, incident participants, document subjects, task owners and recipients of update requests. We process that information to provide the service, maintain security, support authorised users and follow the customer's documented instructions.

Requests about customer-controlled workspace content should normally be directed to the relevant customer organisation first. We will assist customers with valid rights requests as required by law and our contractual obligations.

03

Information we collect

Account and identity information

Name, email address, profile details, organisation, role, account identifiers, authentication provider, login status, access permissions and password-reset information.

Subscription and transaction information

Plan, subscription status, billing contact details, payment status, invoices, transaction references and customer-service correspondence. Full card details are handled by payment providers and are not intended to be stored by Helm.

Contact and support information

Information included in contact forms, support conversations, bug reports, screenshots, attachments, browser and device details, page URLs and the steps needed to reproduce an issue.

Technical and usage information

IP address, browser, device, operating system, timestamps, session events, request logs, security events, error reports, navigation activity, cookie preferences and similar technical information.

Workspace records

Customer-controlled records such as companies, contacts, drivers, vehicles, tasks, incidents, notes, compliance dates, update requests, audit history and relationships between records.

Documents and files

Document names, types, linked records, expiry dates, storage references and uploaded files such as licences, certificates, compliance evidence, reports, images and PDFs.

Public update request information

Recipient name and email, secure token, requested fields, pre-filled values, expiry date, submitted updates, submission time and relevant security or diagnostic information.

Communications and preferences

Email preferences, subscription choices, unsubscribe status, messages sent to or from Helm and records required to honour communication preferences.

Special category and criminal offence information

Helm does not require customers to enter special category information or criminal offence information unless it is genuinely necessary for their lawful operational purpose. Customers must avoid uploading excessive or irrelevant sensitive information and must identify their own lawful basis and any additional legal condition before doing so.

If sensitive information is included in a support request or other communication to Helm, we will limit its use to what is necessary to handle the request, protect the service, comply with law or establish, exercise or defend legal claims.

04

Where information comes from

We may receive personal information:

  • directly from you when you register, subscribe or contact us;
  • from your employer or the organisation providing your access;
  • from authorised users entering or importing workspace records;
  • from linked identity providers, including Google OAuth;
  • from payment and subscription providers;
  • automatically from browsers, devices, logs and security systems;
  • from integrations or services connected at a customer's direction;
  • from public or regulatory sources where this is lawful, proportionate and relevant to the purpose.

Where a customer supplies information about another person, that customer is responsible for ensuring it has authority to provide the information and gives any privacy information required by law.

05

How and why we use information

The lawful basis depends on the purpose and the relationship we have with you. The table below describes the main processing activities for which Helm acts as controller.

PurposeInformation commonly usedMain lawful basis
Create and administer accountsIdentity, organisation, role, authentication and contact detailsContract; steps before entering a contract; legitimate interests
Provide subscriptions and paid servicesPlan, billing, transaction, account and support informationContract; legal obligation; legitimate interests
Authenticate users and protect the platformAccount identifiers, login events, IP, device, logs and security eventsContract; legitimate interests; legal obligation; recognised legitimate interests where applicable
Operate platform features and customer workflowsAccount details, permissions, workspace activity and customer instructionsContract; legitimate interests
Provide contact, support and bug-report servicesContact details, messages, screenshots, diagnostics and attachmentsContract; steps before a contract; legitimate interests
Send service and security communicationsEmail, account, subscription, incident and preference informationContract; legal obligation; legitimate interests
Improve reliability, usability and performanceUsage, error, diagnostic, support and aggregated informationLegitimate interests; consent where required for non-essential tracking
Prevent fraud, abuse and unauthorised accessIdentity, account, technical, transaction and security informationLegitimate interests; legal obligation; recognised legitimate interests where applicable
Send permitted product news or marketingContact details, customer relationship, preferences and engagementConsent or legitimate interests, subject to PECR
Comply with law and handle disputesRelevant account, transaction, communication, workspace and audit informationLegal obligation; legitimate interests; recognised legitimate interests where applicable

Where we rely on legitimate interests, those interests may include providing and improving a secure business service, supporting customers, preventing misuse, managing commercial relationships and establishing or defending legal rights. We consider necessity, proportionality and the effect on individuals before relying on this basis.

Where we rely on consent, you may withdraw it at any time. This does not affect processing carried out before withdrawal.

06

Customer workspace data

Helm is designed to help transport operators organise operational records and compliance activity. A workspace may contain information about contacts, drivers, vehicles, incidents, tasks, documents, update requests and audit history.

For customer-controlled workspace data:

  • the customer decides what information is entered and why;
  • the customer controls user access and record permissions;
  • Helm processes the information to provide and secure the service;
  • Helm may use sub-processors under contractual protections to host, transmit, support or back up the service;
  • Helm does not use customer workspace content for third-party advertising or sell it as personal data;
  • the customer remains responsible for accuracy, transparency, lawful collection, retention and responding to individuals.

Documents

Documents may contain more information than is visible in their filename or metadata. Customers should check files before upload, limit access to authorised users and remove documents that are no longer required.

Audit logs

Helm may record actions such as record creation, updates, status changes, links, requests and deletions. Audit history supports accountability, investigation and compliance. It may therefore be retained for longer than an editable field where justified by the customer's requirements, contractual terms or legal obligations.

Update requests

A customer may send a secure update link to a recipient. The link may contain a time-limited token and show selected pre-filled fields. Recipients should not forward the link. Helm may log information needed to validate the request, prevent misuse and record the submitted update.

07

Who we share information with

We share personal information only where reasonably necessary for the purposes described in this policy, where a customer instructs us to do so, or where law permits or requires it.

Customer organisations and authorised users

Workspace information is available to the customer organisation and users authorised by that customer. Administrators may be able to view account activity, records, documents, requests and audit history within their workspace.

Service providers and sub-processors

Helm uses specialist providers to deliver the platform. Depending on the service in use, these may include:

  • Webflow for public website hosting and delivery;
  • Memberstack for membership, authentication and subscription functions;
  • Google where a user chooses Google OAuth sign-in;
  • Xano for backend, API and database services;
  • Wized for front-end application orchestration;
  • Cloudflare for private file storage, delivery, security and network services;
  • Stripe for payment processing and transaction services;
  • Microsoft 365 for email and business communications;
  • Zapier for authorised workflow automation and notifications.

Providers may change as the service develops. We require processors to handle personal information under appropriate contracts, confidentiality obligations, security requirements and our instructions, unless law requires otherwise.

Other permitted recipients

We may also disclose relevant information to:

  • professional advisers, auditors, insurers and accountants;
  • regulators, courts, law enforcement or public authorities;
  • a buyer, investor or successor in connection with a proposed or completed sale, financing, merger or reorganisation;
  • another party where you or the relevant customer has directed or authorised the disclosure.

We do not sell personal information to data brokers or permit service providers to use customer workspace content for their own advertising.

08

International transfers

Some service providers or their sub-processors may store, access or support personal information outside the United Kingdom. This can constitute an international or restricted transfer under UK data protection law.

Where required, we use a lawful transfer mechanism and appropriate safeguards. Depending on the destination and circumstances, these may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission's Standard Contractual Clauses;
  • another safeguard or permitted exception available under law.

We also assess the nature of the information, destination, provider, security measures and any supplementary protections reasonably required. You may contact notifications@helmhq.co.uk for further information about safeguards relevant to your data.

09

How long we retain information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including contractual, legal, accounting, security and dispute-resolution requirements.

Account and profile information

For the life of the account and normally for up to six years after closure where needed for contracts, disputes, fraud prevention or legal records.

Subscription and billing records

Normally for up to six years after the relevant transaction or financial period, or longer where law requires.

Contact, support and bug reports

Normally for up to 24 months after the request is closed, unless the record is needed for an active issue, security incident, legal claim or recurring technical problem.

Customer workspace data

For the subscription term and any return, export or deletion period stated in the customer agreement or documented instructions, subject to backups and legal holds.

Security and audit logs

For a limited period proportionate to security, accountability and investigation needs. Relevant records may be kept longer where an incident, dispute or legal duty requires it.

Marketing preferences

Until you unsubscribe or we stop the relevant activity. We may retain a minimal suppression record to ensure we continue to respect an opt-out.

Backup copies may remain for a limited rolling period after deletion and are protected from ordinary use. Information may also be retained where deletion is suspended by law, litigation, regulatory investigation or another valid legal hold.

10

Cookies and similar technologies

Helm and its providers may use cookies, local storage, scripts, pixels and similar storage or access technologies for:

  • sign-in, authentication and session security;
  • remembering account, interface and privacy preferences;
  • fraud prevention, load balancing and service reliability;
  • measuring performance, errors and use of the website;
  • analytics or other optional purposes where permitted.

Technologies that are strictly necessary, or fall within another applicable legal exemption, may operate without consent. Non-essential technologies that require consent will not be used until the required choice has been made.

You can manage available preferences through the cookie controls provided on the website and through browser settings. Blocking essential technologies may prevent account or platform features from working correctly. Further details should be provided in Helm's separate Cookie Policy.

11

Service and marketing communications

Service communications

We may send messages needed to operate the account or service, including authentication codes, password resets, security alerts, billing notices, update-request notifications, material service changes and support replies. These are not optional marketing messages where they are necessary to provide or secure Helm.

Product news and marketing

We may send product news, platform updates, educational content or offers where you have consented, or where another lawful route is available under UK data protection law and PECR. Marketing will include a clear way to unsubscribe.

You can opt out using the unsubscribe control in a message or by emailing notifications@helmhq.co.uk . An opt-out from marketing does not stop necessary service or security communications.

12

Security

We use technical and organisational measures intended to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. Measures may include:

  • authenticated access and role-based permissions;
  • encrypted network connections;
  • private document storage and controlled file delivery;
  • security logging, monitoring and incident investigation;
  • supplier due diligence and data-processing contracts;
  • access limitation, confidentiality and secure administration;
  • backup, recovery and service-continuity arrangements.

No internet or storage system can be guaranteed completely secure. Users must protect login credentials, use secure devices, avoid sharing update links and notify Helm promptly of suspected unauthorised access.

Where a personal data breach occurs, we assess the risk and notify affected customers, individuals or the Information Commissioner's Office where required by law.

13

Automated processing

Helm may automatically calculate operational indicators such as due-soon status, critical dates, health scores, record counts and priority summaries using information held in a workspace.

These outputs are decision-support tools. They do not by themselves make decisions that produce legal or similarly significant effects on an individual. Customers remain responsible for reviewing source records, exercising professional judgement and making operational or compliance decisions.

If this position changes and Helm begins using solely automated processing for a decision that has legal or similarly significant effects, we will provide the required information and safeguards.

14

Your data protection rights

Depending on the circumstances and applicable exemptions, you may have the right to:

Be informed

Receive clear information about how personal data is used.

Access

Request a copy of personal information held about you.

Rectification

Ask for inaccurate or incomplete information to be corrected.

Erasure

Ask for deletion where there is no lawful reason to continue processing.

Restriction

Ask us to limit use of information in specified circumstances.

Data portability

Receive certain information in a structured, commonly used format.

Object

Object to direct marketing or certain processing based on legitimate interests.

Withdraw consent

Withdraw consent at any time where consent is the lawful basis.

Automated decisions

Receive safeguards where a significant decision is made solely by automated means.

To exercise a right, email notifications@helmhq.co.uk with enough information for us to understand the request. We may need to verify identity or authority before disclosing or changing personal information.

Rights are not absolute. We may refuse or limit a request where a legal exemption applies, the request relates to another person's rights, or the request is manifestly unfounded or excessive. We will explain the applicable reason where required.

Where Helm is acting as a processor for customer workspace data, we may refer the request to the relevant customer controller and support that customer in responding.

15

Data protection complaints

You can complain to Helm if you believe we have handled personal information unfairly, unlawfully, insecurely or without respecting your rights.

How to complain to Helm

Email notifications@helmhq.co.uk with the subject Data protection complaint. Explain what happened, the information involved, when it occurred and the outcome you are seeking.

  1. We will acknowledge receipt within 30 days of receiving the complaint.
  2. We will take appropriate steps to investigate without undue delay.
  3. We will keep you informed where the investigation takes time.
  4. We will explain the outcome and any action taken without undue delay.

Information Commissioner's Office

You also have the right to complain to the Information Commissioner's Office, the UK's independent data protection regulator. The ICO generally expects you to raise the issue with the organisation first so it has an opportunity to respond.

Website: ico.org.uk/make-a-complaint

16

Children's information

Helm is a business service for transport operators and is not directed at children. Individuals must be at least 18 years old to create their own commercial Helm account unless an organisation has established another lawful arrangement.

Customers must not enter children's personal information into Helm unless it is necessary, lawful, proportionate and subject to appropriate protections. Contact notifications@helmhq.co.uk if you believe children's information has been entered inappropriately.

17

Changes to this policy

We may update this policy to reflect changes to Helm, our suppliers, legal requirements or data-protection practices. The current version will be published on this page with a revised last-updated date.

Where a change is material, we may also notify account holders by email, through the platform or by another appropriate method.

18

Contact us

Controller[INSERT LEGAL ENTITY NAME]
Trading nameHelm
Privacy requests and complaints notifications@helmhq.co.uk
Postal address[INSERT REGISTERED OR BUSINESS ADDRESS]
ICO registration number[INSERT IF APPLICABLE]
Back to top