# Helix Privacy Policy

**Effective date:** 19 December 2025
**Last updated:** 19 December 2025

## 1. Key Facts — The quick read

| What we collect | Why we need it | How long we keep it |
|---|---|---|
| **Basic details** (name, email, phone) | To set up your HELIX account and contact you about your bookings | While your account is active and for up to 6 years after your last booking |
| **Travel essentials** (passport info, loyalty numbers, seat & meal prefs) | To book flights, hotels and other travel on your behalf | For 12 months after you close your account or you request for it to be deleted |
| **Dietary requirements and allergens** (e.g. "strict gluten-free", "no nuts", "avoid cross-contamination") | To fulfil bookings safely with airlines, hotels, restaurants and experience providers | Stored with your profile and the relevant booking; retained in line with booking records; you can request deletion where feasible |
| **Payment data** (card token, billing address) | To pay travel providers securely | 7 years for accounting & tax compliance |
| **Chat & concierge history** (the "HELIX memory") | Core part of the service — lets us remember your preferences and past trips so we can act without repeating questions | 2 years after last chat. Inferred memory is kept for 12 months after you close your account or you request for it to be deleted |

**Important:** Helix's AI memory is integral to providing you with hyper personalisation. You can delete individual messages, clear your whole conversation history and even delete everything we have inferred from your messages. However, doing so will impact Helix's ability to provide the best service.

**We never sell your data.** We share only the minimum details with trusted travel providers. All information is **encrypted in transit and at rest.**

## 2. Who we are

**Helix Technologies Limited** ("Helix Tech", "Helix", "we", "us", "our") operates HELIX, the AI concierge for travel, hotels, restaurants, and experiences. Helix Tech is registered in Jersey, Channel Islands (company no. 158737).

- **Registered office:** 30 Stopford Road, St Helier, JE2 4LZ
- **Contact:** [privacy@helix.je](mailto:privacy@helix.je)

Helix Tech is the primary **data controller** for personal data processed via the Services.

**Helix Intelligent Services Inc.** ("Helix Inc") is a wholly-owned Delaware subsidiary that supports payments and billing. Depending on context, Helix Inc may act as:

- a **processor** for Helix Tech (processing payment-related data on Helix Tech's instructions), and/or
- a **separate controller** for certain payment, fraud-prevention, tax, and regulatory compliance activities connected to taking payments.

## 3. The data we collect

We collect personal data that you provide, that is generated through your use of the Services, and that we receive from booking and payment partners.

### Identification and contact
- Full name, email address, phone number, postal address (where needed)

### Travel documentation and booking details
- Passport or ID number, visa information, date of birth, citizenship, travel itineraries, booking references
- Loyalty programme details (where provided)

### Booking preferences
- Seat and accessibility preferences
- Meal preferences and dietary requirements expressed as fulfilment instructions (e.g. "strict gluten-free", "no nuts", "dairy-free")

### Payments
- Billing details and transaction information (e.g. payment status, refunds, chargebacks, transaction IDs)
- Card payments are processed by our payment providers. We do not store full card numbers.

### Interaction data and HELIX memory
- Chat transcripts, support requests, in-app actions, and preferences you set
- Preferences inferred from your use of the Services (e.g. preferred airlines, hotel styles, cuisines, budget ranges)

### Technical data
- IP address, device and browser/app information, logs, diagnostic data, and analytics events

## 4. Mobile app-specific data

When you use our iOS or Android apps, we may also collect:

- **Device identifiers** (such as advertising ID or platform identifiers, where available and permitted)
- **App instance identifiers** and **crash/performance diagnostics**
- **Push notification tokens** (to deliver notifications to your device)
- **App settings** and feature usage events

**Permissions:** If you enable optional permissions (e.g. notifications, location), the app may process the related data. You can control permissions in your device settings.

## 5. Information about other people (travellers and guests)

You may provide information about other people, such as travel companions, hotel guests, or restaurant reservation guests (e.g. names, dates of birth, passport details, or dietary requirements).

You confirm that you have permission to provide this information for booking and fulfilment purposes. We use third-party traveller and guest data only to:

- search, reserve, and book requested services
- manage changes and provide support
- meet legal, accounting, and compliance obligations

## 6. Special category data

We ask you to provide **requirements** (e.g. "strict gluten-free") rather than medical diagnoses. If you choose to provide medical details, or if the information reveals health conditions, we will treat it as **special category data** and apply additional safeguards.

### Our approach
- We only ask for and use special category data when it is necessary to fulfil your request (e.g. ensuring an airline meal or restaurant booking accommodates an allergy).
- Where required, we will seek **explicit consent** in-product at the time you provide such information.
- You can remove or update these details at any time.

## 7. How we use your information

We use personal data to:

- Arrange travel, hotel stays, restaurant reservations, and experiences on your behalf
- Send service communications (confirmations, itinerary updates, changes, receipts, and security notices)
- Provide concierge support and resolve issues
- Store preferences and HELIX memory to personalise recommendations and speed up future bookings
- Process payments, refunds, and chargebacks
- Prevent fraud and misuse, and keep the Services secure
- Improve the Services (performance, analytics, debugging)
- Send marketing communications where permitted and in line with your preferences

## 8. Legal Bases (UK GDPR / GDPR where applicable, and Data Protection (Jersey) Law 2018)

Where applicable, we process personal data under one or more of these legal bases:

- **Contract:** necessary to provide the Services, including booking fulfilment and support
- **Legitimate interests:** to operate, secure, and improve the Services, prevent fraud, and maintain quality (balanced against your rights)
- **Consent:** where required (e.g. certain marketing communications, and special category data where applicable)
- **Legal obligation:** to comply with legal, tax, accounting, sanctions, or regulatory requirements

## 9. Service messages and marketing

### Service messages
We send essential communications such as booking confirmations, itinerary updates, receipts, customer support messages, and security notices. These are required to provide the Services.

### Marketing
Marketing emails (such as product updates, offers, or re-engagement messages) will include an unsubscribe option and can also be managed in-app where available. If you opt out, we will still send essential service messages.

## 10. Sharing and processors

We share only the minimum information needed to provide the Services.

### Booking and fulfilment partners and suppliers
We share relevant data with partners and suppliers to search, reserve, and book on your behalf, including airlines, hotels, restaurants, experience operators, and their intermediaries as required to fulfil bookings.

### Payments and billing
- **Helix Intelligent Services Inc.** (payments and billing operations)
- Payment providers such as **Stripe** and related fraud-prevention partners

### Infrastructure and communications
- Hosting and database providers, monitoring and logging providers, customer support tools
- Email and messaging providers for sending service communications

### Professional advisors and legal
- Accountants, auditors, insurers, legal advisors
- Regulators, courts, or law enforcement where required by law

## 11. Where we store data and international transfers

We host core production data in Frankfurt, Germany (EU). Some partners may process personal data outside Jersey, the UK, or the EEA. Where international transfers apply, we use appropriate safeguards such as Standard Contractual Clauses or other recognised transfer mechanisms.

## 12. Data security

We use technical and organisational measures designed to protect personal data, including access controls, multi-factor authentication for internal access, row level security, and encryption for sensitive data where appropriate. No system is completely secure, but we work to protect your data and reduce risk.

## 13. Retention

We keep personal data only as long as necessary for the purposes described above, then delete or anonymise it unless we must retain it for legal, tax, accounting, fraud-prevention, or dispute-resolution purposes.

Typical retention periods:

- **Bookings and invoices:** up to 6 years after your last booking, and up to 10 years where needed for accounting, audit, disputes, or regulatory requirements
- **Payment and accounting records:** up to 10 years
- **Security and operational logs:** typically 12 to 24 months unless needed for investigations
- **Chat history:** typically up to 24 months after last activity
- **Inferred preferences:** you can delete both explicit and inferred preferences; we do not retain them longer than necessary and they are not required to keep your account open

## 14. Your rights

Depending on your location and applicable law, you may have rights to access, rectify, erase, restrict, object, or port your data, and to withdraw consent where we rely on consent.

You can contact us at [privacy@helix.je](mailto:privacy@helix.je); we aim to answer within **one month**.

## 15. Cookies & similar technologies

We use essential cookies to keep you signed in and secure. Where we use analytics cookies, they are optional and managed through your preferences where required.

## 16. Automated decisions

HELIX uses AI to propose itineraries and recommendations. Bookings will not be made without your explicit confirmation.

## 17. Changes to this Policy

We may update this Policy from time to time. We will post updates on our website and update the effective date above. Where changes are material, we will provide additional notice.

**Last updated:** 19 December 2025
