One moment.
One moment.
Our data processor obligations under GDPR, CCPA, and related data protection law.
Last updated: May 2026. The authoritative DPA is managed by HelmXP staff and published here when in force. The text below is a placeholder until the first published version is available. Enterprise customers requiring a signed DPA should contact legal@helmxp.com.
This Data Processing Agreement (“DPA”) is between the Customer institution (“Controller”) and HelmXP (“Processor”). HelmXP processes personal data solely on the documented instructions of the Controller and for no other purpose.
Subject matter: delivery of the HelmXP executive workbench platform. Duration: the term of the subscription agreement. Nature: hosting, storage, AI drafting, authentication, audit logging. Types of personal data: names, email addresses, usage and audit data of the Controller's executive staff and board Captains.
HelmXP will: process data only on documented Controller instructions; ensure authorized personnel are bound by confidentiality; implement appropriate technical and organizational security measures (AES-256 at rest, TLS 1.3 in transit, RLS-enforced tenant isolation, SOC 2 Type 1 certification target); assist the Controller in responding to data subject requests within applicable timeframes; notify the Controller of a personal data breach within 72 hours of becoming aware of it.
Approved subprocessors: Amazon Web Services (hosting, US East region), Stripe (payment processing), Anthropic (AI drafting, content processed and discarded per Anthropic's API terms). HelmXP will notify the Controller at least 30 days before adding a new subprocessor. The Controller may object to a new subprocessor; if the objection cannot be resolved, the Controller may terminate the subscription.
Personal data is stored in the United States. Transfers to subprocessors outside the EEA are covered by Standard Contractual Clauses (SCCs, 2021/914/EU) or equivalent mechanisms. Documentation is available on request at legal@helmxp.com.
The Controller may audit HelmXP's compliance with this DPA no more than once per year, on 30 days' written notice, at the Controller's cost. HelmXP may satisfy the audit obligation by providing its current SOC 2 Type 2 report (when available).
On termination of the subscription, HelmXP will provide a full data export within 30 days and delete or anonymize all personal data within 90 days, unless retention is required by law. Audit logs required for NCUA examination purposes may be retained for up to 7 years.
Data protection enquiries: legal@helmxp.com. Enterprise customers requiring a separately signed DPA should contact their account manager.