Privacy Policy

PLEASE READ THIS PRIVACY POLICY CAREFULLY. This Privacy Policy explains how HAVOK Consulting LLC, doing business through the HELIX brand (collectively, “HAVOK,” “HELIX,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects Personal Information in connection with our websites, software platform, subscriptions, communications, professional services, and related offerings (collectively, the “Services”).

This Privacy Policy applies to information for which HAVOK determines the purposes and means of processing. When a HELIX customer submits or manages information about its own contacts, leads, customers, employees, or other individuals through the Platform, that customer generally acts as the data controller or business, and HAVOK generally acts as a service provider or processor on the customer’s behalf. In those circumstances, the customer’s privacy notice and instructions govern the processing, subject to the applicable agreement with HAVOK.

1. Scope and Relationship to Other Agreements

This Privacy Policy applies to the Services and to websites or digital properties that link to it. It does not apply to third-party websites, applications, or services that maintain their own privacy notices.

The HELIX Master Services Agreement (“MSA”), HELIX Platform Terms of Service (“Terms”), and any applicable Data Processing Addendum (“DPA”) are incorporated by reference where applicable. If a signed DPA conflicts with this Privacy Policy regarding Customer Data processed on behalf of a customer, the DPA controls for that processing.

2. Definitions

“Customer Data” means information submitted to or processed through the Services by or on behalf of a HELIX customer, as defined in the MSA.

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual or household. The term includes “personal data” and similar terms under applicable privacy laws.

“Sensitive Personal Information” means information treated as sensitive under applicable law, such as precise geolocation, government identifiers, financial account credentials, certain health information, racial or ethnic origin, religious beliefs, biometric information used for identification, or the contents of private communications where protected by law.

3. Information We Collect

3.1 Information You Provide Directly

Account and identity information, including name, business name, job title, username, email address, telephone number, mailing address, and account credentials.

Billing and transaction information, including billing contact details, subscription selections, invoice history, tax information, and limited payment-related information. Full payment-card data is generally processed by our payment processors rather than stored by HELIX.

Communications and support information, including messages, support tickets, call recordings where enabled and lawful, meeting notes, survey responses, and feedback.

Professional-services information, including onboarding details, business requirements, content, brand assets, integration credentials, configuration instructions, and project materials.

Customer Data entered, uploaded, imported, synchronized, or generated through the Platform.

3.2 Information Collected Automatically

Device and browser information, such as IP address, browser type, operating system, device identifiers, language, and approximate location derived from IP address.

Usage and diagnostic information, such as login activity, pages and features used, clicks, timestamps, session duration, referring URLs, error logs, performance data, and security events.

Cookie and similar-technology information, including information collected through cookies, pixels, local storage, software development kits, and similar technologies.

Communications metadata, such as delivery status, routing data, message timestamps, telephone numbers, email addresses, and engagement data associated with communications sent through the Services.

3.3 Information From Third Parties

Information from service providers and integration partners, including authentication providers, payment processors, telecommunications providers, analytics providers, advertising platforms, and connected applications.

Information from publicly available sources, business directories, social media, referral partners, or other lawful sources.

Information provided by a HELIX customer about its users, employees, contractors, contacts, leads, or customers.

4. How We Use Personal Information

We may use Personal Information to:

Provide, operate, configure, maintain, secure, and improve the Services.

Create and administer accounts, authenticate users, and manage permissions.

Process payments, subscriptions, invoices, taxes, credits, disputes, and collections.

Provide onboarding, implementation, migration, consulting, training, customer support, and technical assistance.

Enable communications, automation, analytics, integrations, artificial intelligence features, and other Platform functionality requested or configured by users.

Communicate about the Services, including transactional messages, service notices, security alerts, product updates, and marketing communications where permitted by law.

Detect, investigate, prevent, and respond to fraud, abuse, security incidents, unlawful activity, policy violations, and technical problems.

Comply with legal obligations, enforce agreements, establish or defend legal claims, and protect the rights, safety, and property of HAVOK, our customers, users, and others.

Conduct research, analytics, quality assurance, and product development, including use of aggregated or deidentified information where permitted by law.

Carry out other purposes disclosed at the time of collection or with consent.

5. Customer Data and Our Role as Processor

Customers determine what Customer Data is submitted to the Platform and how it is used. Customers are responsible for providing legally required privacy notices, obtaining legally required consents, honoring individual rights, and ensuring that their instructions to HAVOK comply with applicable law.

HAVOK processes Customer Data to provide the Services, follow documented customer instructions, maintain security, prevent abuse, provide support, comply with law, and perform other activities permitted by the MSA or DPA. Individuals seeking to exercise rights concerning Customer Data should generally contact the relevant HELIX customer first. We may forward a request to that customer or assist the customer in responding, as required by contract or law.

6. Artificial Intelligence Features

Certain Services may use artificial intelligence, machine learning, or automated technologies supplied by HAVOK or third parties. Depending on the feature and customer configuration, prompts, inputs, Customer Data, and outputs may be transmitted to an AI service provider for processing.

We do not intentionally use Customer Data submitted to paid HELIX accounts to train generalized public AI models unless the applicable customer has authorized that use or the relevant service terms expressly permit it. AI features may produce inaccurate or unsuitable results, and users are responsible for reviewing outputs before use. Additional rules may be stated in the HELIX Artificial Intelligence Usage Policy.

7. How We Disclose Personal Information

We may disclose Personal Information to the following categories of recipients:

Service providers and subprocessors that provide hosting, cloud infrastructure, customer support, analytics, communications, email delivery, telephony, payments, security, identity verification, artificial intelligence, software integrations, document management, and professional services.

Connected services and integration partners at the direction of a customer or user.

Professional advisers, including attorneys, accountants, auditors, insurers, and consultants.

Government authorities, courts, law enforcement, regulators, or other parties when disclosure is required or permitted by law or reasonably necessary to protect rights, safety, or security.

Parties to a business transaction or due-diligence process involving a merger, financing, acquisition, reorganization, sale of assets, or transfer of the HELIX business.

Other parties with consent or at the direction of the individual or customer.

HELIX does not sell Personal Information for money. We do not knowingly sell or share Personal Information of individuals under 16 years of age. Certain advertising or analytics activities may be considered “sharing,” “targeted advertising,” or a “sale” under some state laws even when no money is exchanged. Where applicable, we provide a method to opt out.

8. Cookies, Analytics, and Advertising Technologies

We and our service providers may use cookies and similar technologies to keep users signed in, remember preferences, secure the Services, measure performance, understand usage, troubleshoot issues, and support marketing. Some cookies are necessary for the Services to function; others may be optional depending on applicable law and available consent tools.

Browser settings and consent-management tools may allow you to control cookies. Blocking cookies may affect functionality. Where required, we recognize legally valid browser-based opt-out preference signals, such as Global Privacy Control, for the browser or device sending the signal.

9. Legal Bases for Processing

Where European Economic Area, United Kingdom, or similar law applies, we process Personal Information under one or more of the following legal bases: performance of a contract; legitimate interests that are not overridden by individual rights; compliance with legal obligations; protection of vital interests; and consent. Where processing relies on consent, consent may be withdrawn at any time without affecting processing that occurred before withdrawal.

10. Data Retention

We retain Personal Information for as long as reasonably necessary to provide the Services, maintain business and legal records, resolve disputes, enforce agreements, meet contractual commitments, protect security, and comply with law. Retention periods vary based on the type of information, the purpose of processing, account status, customer instructions, technical requirements, backup cycles, and legal obligations.

After account termination, Customer Data may remain available for a limited period to support export, recovery, legal compliance, fraud prevention, or backup restoration. Data in backups may be deleted through ordinary backup-rotation cycles. Aggregated or deidentified information may be retained where it can no longer reasonably identify an individual.

11. Security

We maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Information. These safeguards may include access controls, authentication, encryption in transit where supported, logging, monitoring, vendor-management practices, backups, and incident-response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Users are responsible for protecting credentials, limiting user access, enabling available security features, maintaining secure devices and networks, and promptly notifying us of suspected unauthorized access.

12. International Data Transfers

The Services may be provided using personnel, systems, and service providers located in the United States and other countries. Personal Information may therefore be transferred to, stored in, or processed in jurisdictions with privacy laws different from those in the individual’s location. Where required, we use recognized safeguards, which may include standard contractual clauses, data-processing agreements, adequacy decisions, or other lawful transfer mechanisms.

13. Privacy Rights and Choices

Depending on location and applicable law, individuals may have rights to:

Know or confirm whether we process Personal Information and obtain access to it.

Correct inaccurate Personal Information.

Delete Personal Information, subject to legal exceptions.

Obtain a portable copy of certain Personal Information.

Opt out of sale, sharing, targeted advertising, or certain profiling where applicable.

Limit certain uses or disclosures of Sensitive Personal Information where applicable.

Object to or restrict certain processing.

Withdraw consent where processing is based on consent.

Appeal a denial of a privacy request where applicable.

Not be discriminated against for exercising applicable privacy rights.

To submit a request concerning information controlled by HAVOK, email [email protected] with the subject line “Privacy Request.” We may need to verify identity and authority before completing a request. Authorized agents may submit requests where permitted by law, but we may require proof of authorization and direct verification with the individual.

Requests involving Customer Data should generally be directed to the HELIX customer that collected or controls the information. We will assist that customer as required by applicable law and contract.

14. U.S. State Privacy Disclosures

14.1 Categories of Personal Information

During the preceding 12 months, we may have collected the categories described in Section 3, including identifiers; customer records; commercial information; internet or electronic network activity; geolocation information; audio, electronic, or communications information; professional information; inferences; and Sensitive Personal Information when supplied or enabled by a user. We collect, use, retain, and disclose these categories for the purposes described in this Privacy Policy.

14.2 Sale, Sharing, and Targeted Advertising

We do not sell Personal Information for money. If our use of certain advertising or analytics technologies is deemed a sale, sharing, or targeted advertising under applicable law, eligible individuals may opt out by using an available cookie or privacy-preference tool or by contacting [email protected]. We do not use Sensitive Personal Information to infer characteristics except as permitted by law.

14.3 Appeals

Where applicable law provides an appeal right, you may appeal a denied request by replying to our decision or emailing [email protected] with the subject line “Privacy Appeal.”

15. Marketing Communications

You may opt out of promotional emails by using the unsubscribe link in the message. You may opt out of promotional text messages by following the instructions in the message, such as replying STOP. Opting out of marketing does not prevent us from sending transactional, account, billing, security, or service communications.

16. Children’s Privacy

The Services are intended for business users and are not directed to children under 13. We do not knowingly collect Personal Information directly from children under 13 without legally required authorization. If you believe a child has provided Personal Information to us in violation of law, contact [email protected].

17. Third-Party Services and Links

The Services may link to or integrate with third-party services. Their privacy practices are governed by their own notices, not this Privacy Policy. Customers and users should review the privacy terms of each connected service before enabling an integration or submitting information.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, vendors, features, or business practices. The “Last Updated” date identifies the current version. We will provide additional notice of material changes where required by law. Continued use of the Services after the effective date of an updated policy constitutes acknowledgment of the update to the extent permitted by law.

19. Contact Information

Privacy requests and questions may be sent to:

HAVOK Consulting LLC

Attn: Privacy / Legal Department

1032 E Brandon Blvd, #7286

Brandon, Florida 33511

Email: [email protected]

General support: [email protected]

20. Document Governance and Change Log

This Privacy Policy is part of the integrated HELIX legal framework. Whenever this document or a related document is created, amended, renamed, or retired, HAVOK will review related legal documents for consistent definitions, cross-references, hierarchy, URLs, contact information, and legal positions.

COMPANY

CUSTOMER CARE

Get Started

Copyright 2026. HAVOK Consulting LLC. All Rights Reserved.