We use data to provide Helm
This includes accounts, security, subscriptions, records, documents, workflows, support and service communications.
This policy explains how Helm collects, uses, shares, protects and retains personal information across our website, accounts, platform, communications and support services.
This includes accounts, security, subscriptions, records, documents, workflows, support and service communications.
A customer organisation is normally the controller for personal information it enters into its Helm workspace.
We do not sell personal information or use customer workspace content for third-party advertising.
This Privacy Policy applies to the Helm website at helmhq.co.uk, the Helm software platform and related services, including account registration, authentication, subscriptions, customer workspaces, support, bug reporting, update requests, notifications and other communications.
In this policy, Helm, we, us and our refer to [INSERT LEGAL ENTITY NAME], which operates the Helm service under the Helm trading name.
This policy is intended to comply with applicable UK data protection and privacy law, including the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and relevant amendments made by the Data (Use and Access) Act 2025.
This policy does not replace a customer's own privacy notice. Customer organisations remain responsible for explaining how they use personal information within their transport operation.
Helm is normally the data controller for personal information used for our own purposes, including:
Customer organisations decide why and how personal information is entered into their Helm workspace. For that customer-controlled workspace content, the customer is normally the controller and Helm acts as its processor.
This can include information about company contacts, employees, drivers, vehicle users, incident participants, document subjects, task owners and recipients of update requests. We process that information to provide the service, maintain security, support authorised users and follow the customer's documented instructions.
Requests about customer-controlled workspace content should normally be directed to the relevant customer organisation first. We will assist customers with valid rights requests as required by law and our contractual obligations.
Name, email address, profile details, organisation, role, account identifiers, authentication provider, login status, access permissions and password-reset information.
Plan, subscription status, billing contact details, payment status, invoices, transaction references and customer-service correspondence. Full card details are handled by payment providers and are not intended to be stored by Helm.
Information included in contact forms, support conversations, bug reports, screenshots, attachments, browser and device details, page URLs and the steps needed to reproduce an issue.
IP address, browser, device, operating system, timestamps, session events, request logs, security events, error reports, navigation activity, cookie preferences and similar technical information.
Customer-controlled records such as companies, contacts, drivers, vehicles, tasks, incidents, notes, compliance dates, update requests, audit history and relationships between records.
Document names, types, linked records, expiry dates, storage references and uploaded files such as licences, certificates, compliance evidence, reports, images and PDFs.
Recipient name and email, secure token, requested fields, pre-filled values, expiry date, submitted updates, submission time and relevant security or diagnostic information.
Email preferences, subscription choices, unsubscribe status, messages sent to or from Helm and records required to honour communication preferences.
Helm does not require customers to enter special category information or criminal offence information unless it is genuinely necessary for their lawful operational purpose. Customers must avoid uploading excessive or irrelevant sensitive information and must identify their own lawful basis and any additional legal condition before doing so.
If sensitive information is included in a support request or other communication to Helm, we will limit its use to what is necessary to handle the request, protect the service, comply with law or establish, exercise or defend legal claims.
We may receive personal information:
Where a customer supplies information about another person, that customer is responsible for ensuring it has authority to provide the information and gives any privacy information required by law.
The lawful basis depends on the purpose and the relationship we have with you. The table below describes the main processing activities for which Helm acts as controller.
| Purpose | Information commonly used | Main lawful basis |
|---|---|---|
| Create and administer accounts | Identity, organisation, role, authentication and contact details | Contract; steps before entering a contract; legitimate interests |
| Provide subscriptions and paid services | Plan, billing, transaction, account and support information | Contract; legal obligation; legitimate interests |
| Authenticate users and protect the platform | Account identifiers, login events, IP, device, logs and security events | Contract; legitimate interests; legal obligation; recognised legitimate interests where applicable |
| Operate platform features and customer workflows | Account details, permissions, workspace activity and customer instructions | Contract; legitimate interests |
| Provide contact, support and bug-report services | Contact details, messages, screenshots, diagnostics and attachments | Contract; steps before a contract; legitimate interests |
| Send service and security communications | Email, account, subscription, incident and preference information | Contract; legal obligation; legitimate interests |
| Improve reliability, usability and performance | Usage, error, diagnostic, support and aggregated information | Legitimate interests; consent where required for non-essential tracking |
| Prevent fraud, abuse and unauthorised access | Identity, account, technical, transaction and security information | Legitimate interests; legal obligation; recognised legitimate interests where applicable |
| Send permitted product news or marketing | Contact details, customer relationship, preferences and engagement | Consent or legitimate interests, subject to PECR |
| Comply with law and handle disputes | Relevant account, transaction, communication, workspace and audit information | Legal obligation; legitimate interests; recognised legitimate interests where applicable |
Where we rely on legitimate interests, those interests may include providing and improving a secure business service, supporting customers, preventing misuse, managing commercial relationships and establishing or defending legal rights. We consider necessity, proportionality and the effect on individuals before relying on this basis.
Where we rely on consent, you may withdraw it at any time. This does not affect processing carried out before withdrawal.
Helm is designed to help transport operators organise operational records and compliance activity. A workspace may contain information about contacts, drivers, vehicles, incidents, tasks, documents, update requests and audit history.
For customer-controlled workspace data:
Documents may contain more information than is visible in their filename or metadata. Customers should check files before upload, limit access to authorised users and remove documents that are no longer required.
Helm may record actions such as record creation, updates, status changes, links, requests and deletions. Audit history supports accountability, investigation and compliance. It may therefore be retained for longer than an editable field where justified by the customer's requirements, contractual terms or legal obligations.
A customer may send a secure update link to a recipient. The link may contain a time-limited token and show selected pre-filled fields. Recipients should not forward the link. Helm may log information needed to validate the request, prevent misuse and record the submitted update.
We share personal information only where reasonably necessary for the purposes described in this policy, where a customer instructs us to do so, or where law permits or requires it.
Workspace information is available to the customer organisation and users authorised by that customer. Administrators may be able to view account activity, records, documents, requests and audit history within their workspace.
Helm uses specialist providers to deliver the platform. Depending on the service in use, these may include:
Providers may change as the service develops. We require processors to handle personal information under appropriate contracts, confidentiality obligations, security requirements and our instructions, unless law requires otherwise.
We may also disclose relevant information to:
We do not sell personal information to data brokers or permit service providers to use customer workspace content for their own advertising.
Some service providers or their sub-processors may store, access or support personal information outside the United Kingdom. This can constitute an international or restricted transfer under UK data protection law.
Where required, we use a lawful transfer mechanism and appropriate safeguards. Depending on the destination and circumstances, these may include:
We also assess the nature of the information, destination, provider, security measures and any supplementary protections reasonably required. You may contact notifications@helmhq.co.uk for further information about safeguards relevant to your data.
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including contractual, legal, accounting, security and dispute-resolution requirements.
For the life of the account and normally for up to six years after closure where needed for contracts, disputes, fraud prevention or legal records.
Normally for up to six years after the relevant transaction or financial period, or longer where law requires.
Normally for up to 24 months after the request is closed, unless the record is needed for an active issue, security incident, legal claim or recurring technical problem.
For the subscription term and any return, export or deletion period stated in the customer agreement or documented instructions, subject to backups and legal holds.
For a limited period proportionate to security, accountability and investigation needs. Relevant records may be kept longer where an incident, dispute or legal duty requires it.
Until you unsubscribe or we stop the relevant activity. We may retain a minimal suppression record to ensure we continue to respect an opt-out.
Backup copies may remain for a limited rolling period after deletion and are protected from ordinary use. Information may also be retained where deletion is suspended by law, litigation, regulatory investigation or another valid legal hold.
Helm and its providers may use cookies, local storage, scripts, pixels and similar storage or access technologies for:
Technologies that are strictly necessary, or fall within another applicable legal exemption, may operate without consent. Non-essential technologies that require consent will not be used until the required choice has been made.
You can manage available preferences through the cookie controls provided on the website and through browser settings. Blocking essential technologies may prevent account or platform features from working correctly. Further details should be provided in Helm's separate Cookie Policy.
We may send messages needed to operate the account or service, including authentication codes, password resets, security alerts, billing notices, update-request notifications, material service changes and support replies. These are not optional marketing messages where they are necessary to provide or secure Helm.
We may send product news, platform updates, educational content or offers where you have consented, or where another lawful route is available under UK data protection law and PECR. Marketing will include a clear way to unsubscribe.
You can opt out using the unsubscribe control in a message or by emailing notifications@helmhq.co.uk . An opt-out from marketing does not stop necessary service or security communications.
We use technical and organisational measures intended to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. Measures may include:
No internet or storage system can be guaranteed completely secure. Users must protect login credentials, use secure devices, avoid sharing update links and notify Helm promptly of suspected unauthorised access.
Where a personal data breach occurs, we assess the risk and notify affected customers, individuals or the Information Commissioner's Office where required by law.
Helm may automatically calculate operational indicators such as due-soon status, critical dates, health scores, record counts and priority summaries using information held in a workspace.
These outputs are decision-support tools. They do not by themselves make decisions that produce legal or similarly significant effects on an individual. Customers remain responsible for reviewing source records, exercising professional judgement and making operational or compliance decisions.
If this position changes and Helm begins using solely automated processing for a decision that has legal or similarly significant effects, we will provide the required information and safeguards.
Depending on the circumstances and applicable exemptions, you may have the right to:
Receive clear information about how personal data is used.
Request a copy of personal information held about you.
Ask for inaccurate or incomplete information to be corrected.
Ask for deletion where there is no lawful reason to continue processing.
Ask us to limit use of information in specified circumstances.
Receive certain information in a structured, commonly used format.
Object to direct marketing or certain processing based on legitimate interests.
Withdraw consent at any time where consent is the lawful basis.
Receive safeguards where a significant decision is made solely by automated means.
To exercise a right, email notifications@helmhq.co.uk with enough information for us to understand the request. We may need to verify identity or authority before disclosing or changing personal information.
Rights are not absolute. We may refuse or limit a request where a legal exemption applies, the request relates to another person's rights, or the request is manifestly unfounded or excessive. We will explain the applicable reason where required.
Where Helm is acting as a processor for customer workspace data, we may refer the request to the relevant customer controller and support that customer in responding.
You can complain to Helm if you believe we have handled personal information unfairly, unlawfully, insecurely or without respecting your rights.
Email notifications@helmhq.co.uk with the subject Data protection complaint. Explain what happened, the information involved, when it occurred and the outcome you are seeking.
You also have the right to complain to the Information Commissioner's Office, the UK's independent data protection regulator. The ICO generally expects you to raise the issue with the organisation first so it has an opportunity to respond.
Website: ico.org.uk/make-a-complaint
Helm is a business service for transport operators and is not directed at children. Individuals must be at least 18 years old to create their own commercial Helm account unless an organisation has established another lawful arrangement.
Customers must not enter children's personal information into Helm unless it is necessary, lawful, proportionate and subject to appropriate protections. Contact notifications@helmhq.co.uk if you believe children's information has been entered inappropriately.
We may update this policy to reflect changes to Helm, our suppliers, legal requirements or data-protection practices. The current version will be published on this page with a revised last-updated date.
Where a change is material, we may also notify account holders by email, through the platform or by another appropriate method.