GDPR
Last updated: December 29, 2025
Our Commitment to Data Protection and Individual Rights
At Helvo, protecting personal data and respecting the privacy rights of individuals is a core principle of how we build and operate our CRM platform. We are committed to transparency, accountability, and security in the way personal data is collected, processed, and stored.
This page explains how Helvo complies with the General Data Protection Regulation (GDPR) and how we support our customers in meeting their own data protection obligations.
What Is GDPR?
The General Data Protection Regulation (GDPR) is a European Union regulation designed to strengthen data protection and privacy for individuals within the EU. It applies to any organization that processes personal data of EU residents, regardless of where the organization is located.
GDPR enhances individual rights, promotes transparency, and establishes clear responsibilities for organizations handling personal data.
Does GDPR Apply to You?
GDPR applies if you or your organization:
- Are located in the European Union, or
- Offer goods or services to individuals in the EU, or
- Process or store personal data of EU residents
Non-compliance may result in significant penalties, including fines of up to €20 million or 4% of annual global turnover, whichever is higher.
Helvo’s GDPR Commitment
Helvo processes personal data in accordance with GDPR principles, including:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
Our internal policies, security practices, and product architecture are designed to support these principles.
Roles Under GDPR
Depending on the context:
- Helvo acts as a Data Processorwhen processing Customer Data on behalf of our customers.
- Helvo acts as a Data Controllerfor personal data related to website visitors, account owners, and billing contacts.
Data Processing and Security Measures
Helvo implements appropriate technical and organizational measures to protect personal data, including:
- Encrypted data storage and transmission
- Access controls and authentication mechanisms
- Regular security reviews and monitoring
- Secure cloud infrastructure provided by trusted vendors
Payment data is processed exclusively by certified third-party payment providers. Helvo does not store full payment card details.
Data Processing Addendum (DPA)
Helvo offers a Data Processing Addendum (DPA) that forms part of our Terms of Service. The DPA outlines:
- The scope and purpose of data processing
- Security measures and confidentiality obligations
- Sub-processor commitments
- Data transfer safeguards
Customers may request a copy of the DPA by contacting us.
Privacy by Design and by Default
Helvo follows privacy by design and privacy by default principles across product development and operations. This means:
- Data protection is considered from the earliest design stages
- Only the necessary personal data is processed by default
- Access to personal data is restricted to authorized users
Individual Rights Under GDPR
Helvo supports the following GDPR rights:
- Right of access – Obtain confirmation and access to personal data
- Right to rectification – Correct inaccurate or incomplete data
- Right to erasure (Right to be forgotten)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent, where applicable
Data Deletion and Export Features
Helvo provides tools and processes to help customers fulfill data subject requests:
Right to Be Forgotten
Authorized account administrators can permanently delete contact, lead, or user data from the system. Once deleted, the data is removed from active systems and scheduled for secure removal from backups in accordance with our retention policies.
Data Export
Customers can export personal data stored within Helvo in a commonly used, machine-readable format upon request.
All deletion and export requests are subject to identity verification and authorization checks.
Assisting Customers With Data Subject Requests
Helvo assists customers in responding to GDPR data subject access requests (DSARs) related to customer data processed through the services.
Requests should be submitted through the account administrator or by contacting our support team.
International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), Helvo ensures appropriate safeguards are in place, such as standard contractual clauses or equivalent legal mechanisms.
Accountability and Governance
Helvo maintains internal data protection policies, employee training, and operational procedures to ensure ongoing GDPR compliance and accountability.
We regularly review and improve our privacy and security practices to adapt to regulatory and technological developments.
Contact Information
If you have questions regarding GDPR compliance or wish to exercise your data protection rights, please contact us:
Email: privacy@helvo.io
Website: helvo.io