Home / DPA

Data Processing Agreement (DPA)

How we process data on behalf of our clients, under GDPR — in plain terms.

This Data Processing Agreement ("DPA") supplements our Terms of Useand applies where Helix Technologies processes personal data on behalf of a client (e.g. your customers' data inside a website, e-shop or platform we build/host), under Regulation (EU) 2016/679 (GDPR).

1. Roles

The client acts as Data Controller and Helix Technologies as Data Processor. Helix processes data only on the client's documented instructions and to provide the services.

2. Subject matter & duration

Processing covers the data handled by the service we provide (forms, user accounts, orders) and lasts for the duration of our engagement.

3. Helix (Processor) obligations

  • Process only on the client's instructions.
  • Confidentiality for everyone with access to the data.
  • Appropriate technical & organisational security (encryption, backups, access control).
  • Assist the client with data-subject requests and compliance (DPIA, security).
  • Return or delete the data at the end of the engagement, at the client's choice.

4. Sub-processors

We use trusted providers (hosting, email, AI tools, consent-based analytics) bound by equivalent GDPR obligations, and notify the client of material sub-processor changes.

5. Security & breaches

We apply risk-appropriate measures (SSL, encryption, backups, least-privilege). On a data breach we notify the client without undue delay so they can meet GDPR deadlines.

6. International transfers

Data is preferably hosted within the EU/EEA. Any transfer outside the EEA uses appropriate safeguards (e.g. Standard Contractual Clauses).

7. Data-subject rights

We help the client respond to access, rectification, erasure, restriction and portability requests. See also our Privacy Policy.

To sign a formal DPA for your project: [email protected]. Last updated: July 27, 2026.