Terms of Service

PLEASE READ THIS PRIVACY POLICY CAREFULLY. This Privacy Policy explains how HAVOK Consulting LLC, doing business through the HELIX brand (collectively, “HAVOK,” “HELIX,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects Personal Information in connection with our websites, software platform, subscriptions, communications, professional services, and related offerings (collectively, the “Services”).

1. Scope and Incorporation

This Data Processing Addendum (the “DPA”) forms part of the HELIX Master Services Agreement, the HELIX Platform Terms of Service, any applicable statement of work, invoice, order form, or other written agreement between HAVOK Consulting LLC, a Florida limited liability company doing business as HELIX (“HELIX,” “Processor,” “Service Provider,” “Contractor,” “we,” “us,” or “our”), and the customer identified in the applicable agreement (“Customer,” “Controller,” “Business,” “you,” or “your”).

This DPA applies only to the extent HELIX Processes Personal Data on behalf of Customer in connection with the Services. If there is a conflict between this DPA and the HELIX Master Services Agreement concerning Personal Data processing, this DPA controls solely with respect to that conflict. All other terms remain governed by the HELIX Master Services Agreement.

Where HELIX Processes Personal Data for its own independent business purposes, such as account administration, billing, security, fraud prevention, service analytics, legal compliance, and direct business communications, HELIX acts as an independent Controller or Business, as applicable, and the HELIX Privacy Policy governs that processing.

2. Definitions

Capitalized terms not defined in this DPA have the meanings given in the HELIX Master Services Agreement or applicable Data Protection Laws. For this DPA:

“Applicable Data Protection Laws” means laws and regulations applicable to the Processing of Personal Data under this DPA, including, where applicable, the GDPR, UK GDPR, Swiss data protection law, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and other U.S. state privacy laws.

“Controller” means the entity that determines the purposes and means of Processing Personal Data.

“Customer Personal Data” means Personal Data contained in Customer Data that HELIX Processes on behalf of Customer to provide the Services.

“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

“GDPR” means Regulation (EU) 2016/679.

“Personal Data” means information relating to an identified or identifiable natural person, household, or device, or information otherwise defined as personal data, personal information, or a similar term under Applicable Data Protection Laws.

“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

“Process,” “Processed,” or “Processing” means any operation performed on Personal Data, whether automated or not.

“Processor” means an entity that Processes Personal Data on behalf of a Controller.

“Restricted Transfer” means a transfer of Personal Data requiring an approved transfer mechanism under Applicable Data Protection Laws.

“Subprocessor” means a third party engaged by HELIX to Process Customer Personal Data on behalf of Customer.

“Supervisory Authority” means an independent public authority responsible for monitoring compliance with Applicable Data Protection Laws.

3. Roles of the Parties

3.1 Customer Role. Customer is the Controller or Business of Customer Personal Data, unless Customer acts as a Processor on behalf of another Controller. Customer determines the purposes and essential means of Processing and is responsible for the lawfulness, fairness, transparency, accuracy, and scope of Customer Personal Data.

3.2 HELIX Role. HELIX is the Processor, Service Provider, or Contractor with respect to Customer Personal Data and will Process it only to provide the Services, comply with documented Customer instructions, protect the Services, and meet legal obligations.

3.3 Customer as Processor. If Customer is itself a Processor, Customer represents that its instructions and appointment of HELIX are authorized by the applicable Controller. References to Customer obligations as Controller apply to Customer to the extent relevant to its role as Processor.

4. Processing Instructions

4.1 Documented Instructions. Customer instructs HELIX to Process Customer Personal Data as necessary to provide, configure, secure, maintain, support, troubleshoot, improve, and operate the Services; to prevent fraud, abuse, and security threats; to comply with applicable law; and as otherwise documented in the HELIX Master Services Agreement, this DPA, Customer account configuration, support requests, or written instructions accepted by HELIX.

4.2 Unlawful Instructions. HELIX will promptly inform Customer if, in HELIX’s reasonable opinion, a Customer instruction violates Applicable Data Protection Laws, unless legally prohibited. HELIX may suspend the affected Processing until the parties resolve the issue.

4.3 No Sale or Sharing. To the extent CCPA/CPRA applies, HELIX will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer, or combine it with Personal Data received from another source, except as permitted by

applicable law and reasonably necessary to provide the Services.

5. Customer Obligations

Provide lawful, documented instructions and ensure a valid legal basis for all Processing.

Provide required privacy notices and obtain all permissions, consents, and authorizations required for Customer’s collection and use of Customer Personal Data.

Configure the Services, permissions, retention settings, communications features, and integrations in compliance with Applicable Data Protection Laws.

Avoid submitting sensitive, special-category, biometric, health, financial-account, government-identification, children’s, criminal-history, or other highly regulated data unless HELIX has expressly agreed in writing and appropriate safeguards are implemented.

Respond to Data Subjects and Supervisory Authorities regarding Customer’s Processing activities.

Maintain independent backups or exports where legally or operationally required.

6. Confidentiality and Personnel

HELIX will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations, receive appropriate privacy and security training, and access Customer Personal Data only as necessary for their duties. HELIX will apply access controls based on role, business need, and least-privilege principles where reasonably available.

7. Security Measures

7.1 Safeguards. HELIX will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature, scope, context, and purposes of Processing and the risks to Data Subjects.

7.2 Security Program. Measures may include, as appropriate and commercially reasonable:

Access controls, unique user credentials, role-based permissions, and multi-factor authentication where supported.

Encryption in transit and, where supported by the applicable provider, encryption at rest.

Logging, monitoring, vulnerability management, malware protection, and incident-response procedures.

Business continuity, backup, recovery, and availability measures appropriate to the Services.

Vendor due diligence and contractual safeguards for Subprocessors.

Periodic review and improvement of security measures based on risk, technology, and service changes.

7.3 Customer Security Responsibilities. Customer is responsible for secure configuration of its account, user permissions, endpoint security, credential protection, multi-factor authentication, and promptly removing access for former or unauthorized users.

8. Subprocessors

8.1 General Authorization. Customer grants HELIX general written authorization to engage Subprocessors to provide the Services. Subprocessors may include platform providers, hosting providers, communications carriers, email providers, payment processors, analytics providers, artificial intelligence providers, support providers, and integration vendors.

8.2 Safeguards. HELIX will impose data protection obligations on each Subprocessor that are materially consistent with the applicable obligations in this DPA, taking into account the services performed by that Subprocessor. HELIX remains responsible for its Subprocessors’ performance of those obligations to the extent required by Applicable Data Protection Laws.

8.3 Changes. HELIX may update its Subprocessor list from time to time. Where legally required, HELIX will provide reasonable notice of a new Subprocessor. Customer may object on reasonable data-protection grounds within ten business days after notice. The parties will work in good faith to address the objection. If no reasonable alternative is available, HELIX may terminate the affected Service without liability other than refunding prepaid fees for the unused terminated portion, if any.

8.4 Customer-Directed Integrations. Third-party services enabled or connected by Customer are not HELIX Subprocessors unless HELIX separately engages them to Process Customer Personal Data on Customer’s behalf. Customer is responsible for reviewing and accepting the terms and privacy practices of Customer-directed integrations.

9. Data Subject Requests

Taking into account the nature of the Processing, HELIX will provide commercially reasonable assistance to Customer through appropriate technical and organizational measures to help Customer respond to verified requests from Data Subjects. If HELIX receives a request relating to Customer Personal Data, HELIX will direct the requester to Customer or notify Customer, unless prohibited by law. Customer is responsible for responding to the request and determining whether it is valid.

Assistance requiring material engineering, legal review, custom exports, or work outside standard platform functionality may be charged at HELIX’s then-current professional-services rates, unless prohibited by applicable law.

10. Personal Data Breach

10.1 Notice. HELIX will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. Notice may be delivered to Customer’s designated account, security, privacy, or administrative contact.

10.2 Information. To the extent reasonably available, the notice will describe the nature of the breach, categories of affected data and Data Subjects, likely consequences, measures taken or proposed, and a contact for follow-up. HELIX may provide information in phases as the investigation continues.

10.3 Cooperation. HELIX will take reasonable steps to contain, investigate, mitigate, and remediate the breach. Customer is responsible for determining whether notification to Data Subjects, regulators, or others is required and for issuing those notices, except where HELIX has an independent legal obligation.

10.4 No Admission. Notification of a Personal Data Breach does not constitute an admission of fault or liability by HELIX.

11. Assistance with Compliance

Taking into account the nature of the Processing and information available to HELIX, HELIX will provide commercially reasonable assistance with Customer’s obligations regarding security, breach notifications, data protection impact assessments, prior consultations, and regulator inquiries. Customer remains responsible for its compliance decisions and filings. Extensive or custom assistance may be subject to additional fees.

12. Audits and Information Rights

12.1 Information. Upon reasonable written request, HELIX will provide information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, policies, completed questionnaires, certifications, or third-party audit reports where available and subject to confidentiality restrictions.

12.2 Audits. If the information provided is insufficient to meet a legally required audit obligation, Customer may request an audit no more than once annually, except after a confirmed Personal Data Breach or where required by a Supervisory Authority. Audits must be conducted during normal business hours, with at least thirty days’ notice, in a manner that does not disrupt operations or compromise other customers, security, confidentiality, or privileged information.

12.3 Costs and Confidentiality. Customer bears its audit costs and HELIX’s reasonable costs arising from non-standard audit assistance. Auditors must be independent, qualified, non-competitive with HELIX, and bound by written confidentiality obligations. Audit reports are HELIX Confidential Information.

13. International Transfers

13.1 Transfer Mechanisms. HELIX and its Subprocessors may Process Customer Personal Data in the United States and other countries where they operate. For Restricted Transfers, the parties will rely on a lawful transfer mechanism, which may include an adequacy decision, certification framework, binding corporate rules, or the applicable Standard Contractual Clauses adopted by the European Commission.

13.2 EU Standard Contractual Clauses. Where the 2021 EU Standard Contractual Clauses are required and no other valid mechanism applies, they are incorporated by reference as follows: Module Two applies to Controller-to-Processor transfers; Module Three applies to Processor-to-Processor transfers; Clause 7 applies; the optional language in Clause 11 does not apply unless required by Customer in writing; the competent supervisory authority and governing law will be determined under the SCCs based on the exporter’s establishment; and the forum will be the courts specified by the SCCs.

13.3 UK and Switzerland. For transfers subject to UK or Swiss law, the SCCs apply with the modifications required by the applicable UK transfer addendum, UK international data transfer agreement, or Swiss law, as appropriate.

13.4 Supplementary Measures. HELIX will provide reasonable cooperation regarding transfer-impact assessments and supplementary measures, subject to confidentiality, security, legal restrictions, and reasonable fees for material custom work.

14. Government and Legal Requests

If HELIX receives a legally binding request for Customer Personal Data from a government authority, HELIX will, where legally permitted, notify Customer before disclosure and limit disclosure to what is legally required. HELIX may challenge requests it reasonably believes are unlawful or overbroad, but is not required to pursue litigation or incur material unreimbursed expense.

15. Return and Deletion

15.1 During the Term. Customer may access and export Customer Personal Data using available platform functionality, subject to the HELIX Master Services Agreement, account status, technical limitations, and applicable fees for custom assistance.

15.2 Following Termination. After termination or expiration, HELIX will delete or return Customer Personal Data in accordance with the HELIX Master Services Agreement, applicable retention settings, platform capabilities, and legal obligations. Customer should export required data before access ends.

15.3 Exceptions. HELIX may retain Customer Personal Data where required by law, needed to establish or defend legal claims, maintained in secure backups pending ordinary deletion cycles, or retained in aggregated or de-identified form. Retained Personal Data remains subject to this DPA until deleted or no longer Personal Data.

16. Special Categories and Regulated Data

Customer will not use the Services to Process protected health information subject to HIPAA, payment-card data outside approved payment fields, biometric identifiers, precise geolocation, government identification numbers, credentials, highly sensitive financial information, children’s data, or other specially regulated Personal Data unless HELIX has expressly agreed in writing and the parties have implemented any required additional agreement, configuration, or safeguards. HELIX does not act as a HIPAA business associate unless it signs a separate business associate agreement.

17. U.S. State Privacy Terms

To the extent HELIX Processes Customer Personal Data as a Service Provider or Contractor under U.S. state privacy laws:

HELIX will Process Customer Personal Data only for the limited and specified purposes described in this DPA and the Agreement.

HELIX will comply with applicable obligations imposed on Service Providers or Contractors and provide the same level of privacy protection required by applicable law.

Customer may take reasonable and appropriate steps to help ensure HELIX uses Customer Personal Data consistently with Customer’s obligations.

HELIX will notify Customer if it determines it can no longer meet applicable legal obligations and Customer may take reasonable steps to stop and remediate unauthorized use.

HELIX will not use Customer Personal Data for targeted advertising, cross-context behavioral advertising, sale, or sharing except where expressly permitted by applicable law and Customer instruction.

18. Liability and Indemnification

The limitations of liability, exclusions of damages, indemnification obligations, claim procedures, and dispute-resolution provisions in the HELIX Master Services Agreement apply to this DPA to the fullest extent permitted by law. Nothing in this DPA limits liability that cannot lawfully be limited under Applicable Data Protection Laws.

19. Term and Survival

This DPA begins when Customer accepts the Agreement or when HELIX first Processes Customer Personal Data on Customer’s behalf, whichever occurs first, and continues while HELIX Processes Customer Personal Data. Provisions concerning confidentiality, security, deletion, audit reports, international transfers, liability, and legal compliance survive as necessary to give them effect.

20. Changes and Order of Precedence

HELIX may update this DPA to reflect changes in law, regulatory guidance, the Services, or Processing practices. Material changes will be communicated as required by law or the Agreement. If a signed amendment expressly modifies this DPA, the signed amendment controls. Otherwise, the order of precedence is: (1) applicable mandatory Standard Contractual Clauses; (2) this DPA; (3) the HELIX Master Services Agreement; (4) the HELIX Platform Terms of Service; and (5) other incorporated policies.

Schedule 1 - Processing Details

Item

Description

Subject matter

Provision of the HELIX platform and related CRM, communications, website, automation, integration, support, implementation, analytics, and AI-enabled services.

Duration

For the term of the Agreement and any legally permitted retention period.

Nature and purpose

Collection, recording, organization, storage, hosting, retrieval, use, transmission, display, analysis, support, troubleshooting, security, deletion, and other Processing necessary to provide the Services.

Data Subjects

Customer personnel, users, prospects, leads, customers, vendors, website visitors, communication recipients, and other individuals whose data Customer submits to the Services.

Personal Data categories

Names, contact details, account identifiers, business information, communications, appointment data, CRM records, form submissions, transaction metadata, IP/device data, usage data, uploaded files, and other Customer-configured fields.

Sensitive data

Not intended unless expressly agreed in writing and appropriately configured.

Frequency

Continuous or as initiated by Customer and its users.

Retention

According to the Agreement, Customer configuration, platform capabilities, backup cycles, and legal requirements.

Schedule 2 - Minimum Security Measures

Logical access controls and authentication safeguards appropriate to the Services.

Role-based or need-to-know access to production systems and Customer Personal Data.

Encryption in transit using industry-standard protocols and encryption at rest where supported by the underlying platform or hosting provider.

Security monitoring, logging, incident handling, and escalation processes.

Patch, vulnerability, malware, and endpoint-management practices appropriate to the relevant environment.

Backup, continuity, and recovery practices appropriate to service criticality and platform capabilities.

Personnel confidentiality obligations and security awareness training.

Subprocessor diligence and contractual data-protection requirements.

Periodic review of security controls and risk-based improvements.

Schedule 3 - Subprocessor Categories

HELIX may use Subprocessors in the following categories. A current named list may be maintained separately and updated from time to time:

Core CRM and platform infrastructure providers.

Cloud hosting, storage, database, and content-delivery providers.

Telecommunications, voice, SMS, MMS, and email-delivery providers.

Payment, billing, and fraud-prevention providers.

Artificial intelligence and machine-learning service providers.

Analytics, monitoring, error-tracking, and security providers.

Customer-support, collaboration, productivity, and document-management providers.

Integration and API providers selected by Customer or required for enabled features.

Acceptance

Services after clear notice that this DPA applies where legally permissible. Payment of an invoice acknowledges the applicable billing notice but does not replace affirmative acceptance procedures where such procedures are required.

COMPANY

CUSTOMER CARE

Get Started

Copyright 2026. HAVOK Consulting LLC. All Rights Reserved.