This Data Processing Agreement ("DPA") supplements our Terms of Useand applies where Helix Technologies processes personal data on behalf of a client (e.g. your customers' data inside a website, e-shop or platform we build/host), under Regulation (EU) 2016/679 (GDPR).
1. Roles
The client acts as Data Controller and Helix Technologies as Data Processor. Helix processes data only on the client's documented instructions and to provide the services.
2. Subject matter & duration
Processing covers the data handled by the service we provide (forms, user accounts, orders) and lasts for the duration of our engagement.
3. Helix (Processor) obligations
- Process only on the client's instructions.
- Confidentiality for everyone with access to the data.
- Appropriate technical & organisational security (encryption, backups, access control).
- Assist the client with data-subject requests and compliance (DPIA, security).
- Return or delete the data at the end of the engagement, at the client's choice.
4. Sub-processors
We use trusted providers (hosting, email, AI tools, consent-based analytics) bound by equivalent GDPR obligations, and notify the client of material sub-processor changes.
5. Security & breaches
We apply risk-appropriate measures (SSL, encryption, backups, least-privilege). On a data breach we notify the client without undue delay so they can meet GDPR deadlines.
6. International transfers
Data is preferably hosted within the EU/EEA. Any transfer outside the EEA uses appropriate safeguards (e.g. Standard Contractual Clauses).
7. Data-subject rights
We help the client respond to access, rectification, erasure, restriction and portability requests. See also our Privacy Policy.
To sign a formal DPA for your project: [email protected]. Last updated: July 27, 2026.