This policy explains what personal information HELIX Sensors Inc. collects through the Helix dashboard, why we collect it, who we share it with, and the choices and rights you have. We have tried to write it in plain language, and to describe only what the product actually does.
In short
- Helix is a business tool: your employer (our client) asks us to create your account. We collect the minimum needed to run it — your work email, an optional name, your role and company, and a password we never store in readable form.
- There are no advertising, analytics, or tracking technologies anywhere in the Helix dashboard, and we never sell personal information. Our public demo site counts page views so we know whether the demo is being used; it sets no cookies, tells us nothing that identifies anyone, and runs nowhere near your account (see the demo site below).
- We use one essential sign-in cookie. Your browser also keeps a few things on your own device — your display preferences, remembered panel sizes, and (only while you are setting a password from an emailed link) that link’s one-time token. None of it is advertising, analytics, or tracking, and we never read these values back out of your browser. (Your preferences are separately saved to your account when you change them in Settings; that copy is described below.) The Cookie Policy lists every one by name.
- The sensor and scan data the dashboard displays is industrial telemetry (pipe wall-thickness measurements). It contains no personal information and does not record which individual performed a scan.
Who this policy covers
It covers everyone with a Helix account — personnel of our client companies and our own administrators — plus visitors to our public demo site (see the demo site below). It does not cover the industrial measurement data our clients own (that is governed by our service agreement with each client), and it does not cover your employer’s own privacy practices.
Personal information we collect
Your account
- Work email address — your sign-in identifier. We usually receive it from your employer when they ask us to set up your account.
- Name (optional) — a first and last name, if provided when your account was set up or when you completed your invitation.
- Role and company — whether the account is a client or administrator account, and which client company it belongs to. This is what scopes you to your own company’s data.
- Password — never stored in readable form. We keep only a salted Argon2id hash, which is additionally encrypted with a separate server-held key.
- Last sign-in time and a revocation counter that lets you sign out of every device at once.
- Display preferences — theme, timezone, date and number formatting, and similar settings you choose in Settings.
Security and operations
- IP address — used to limit repeated sign-in attempts and request rates. Held only in server memory for a rolling window of about five minutes; not written to our database.
- Server logs — security-relevant events (a sign-in succeeding or failing, an account being created or deleted) are logged and can include your email address and account identifier. Logs are captured by our hosting platform and retained for 1 Year.
- One-time links — when you are invited or reset your password, we email you a one-time link. We store only a cryptographic hash of it, its expiry (30 minutes for a password reset; up to 30 days for an invitation), and when it was used.
Content you provide
- Points of interest — administrators can pin notes to a scan (a title, a comment, an optional PDF attachment such as an inspection report). We store this content as provided; if an author includes personal information in it, that information is stored with it.
- Feedback reports — if you use the in-app feedback tool (when available), we receive your note plus technical context: the page you were on, the element you clicked, your screen size, and your browser’s user-agent string. If you are signed in, the report also identifies your account (your name and email address) so we can follow up; a report sent from a signed-out page is marked as such instead.
What we deliberately do not collect
- No advertising, analytics, or tracking technologies in the dashboard itself, first- or third-party. Signed-in pages carry no analytics script at all. (The separate public demo site counts anonymous page views, described under the demo site.)
- No profiling and no automated decision-making about individuals.
- No marketing emails — the only emails we send are invitations and password resets.
- No personal information in scan data — measurements are attributed to sensors and gateways, not to people, and nothing records which individual operated a scan.
- We never sell or rent personal information. There are no exceptions.
Why we use your information
- To create your account, authenticate you, and keep your session signed in.
- To scope what you see to your own company’s sites, assets, and scans.
- To secure the service — rate limiting, revoking stolen or stale sessions.
- To send the transactional emails described above (invitations, password resets).
- To apply your display preferences.
- To respond to feedback and fix problems you report.
We do not use your information for any other purpose without asking you first.
Consent
The limited collection described above is integral to providing an authenticated portal — it is a condition of the service, and by signing in and using Helix you consent to it. If we ever want to use your information for a new purpose, we will ask separately before doing so. You may withdraw consent at any time by asking your company’s administrator to close your account, or by contacting us (withdrawing consent for the data the service cannot run without means closing the account).
Who we share it with
We share personal information only with the service providers that host and operate the product, listed below. Each processes it on our behalf; we remain responsible for it.
| Provider | What they do for us | What they hold |
|---|---|---|
| Aiven (managed database) | Hosts our database | Account records described above |
| Cloudflare R2 (file storage) | Stores 3-D models, scan imagery, and point-of-interest PDF attachments | Uploaded documents (which may contain personal information their author added) |
| Vercel | Runs the dashboard and captures server logs; also counts page views on our public demo site only (Vercel Web Analytics — no cookies, no cross-site tracking, and not enabled on the signed-in dashboard) | Log entries that can include email addresses and IP addresses. For the demo site: page paths, referrer, and a country and device type derived from the request. Repeat visitors are counted by Vercel from a short-lived hash of the request rather than a stored IP address; we receive only the aggregate counts |
| Delivers invitation and password-reset emails | Your email address and the message contents | |
| Discord (feedback only) | Receives in-app feedback reports so our team can act on them | The feedback contents described above |
Beyond service providers: we will disclose personal information if required by law (for example a court order), and if Helix is ever part of a merger or sale of the business, this policy would continue to apply to the information transferred with it. Your company’s administrators can see the accounts (email, name, role) that belong to their company.
Where it is stored
Our service providers may store and process personal information outside Canada, including in the United States. While it is there, it is subject to the laws of that jurisdiction, and may be accessible to that jurisdiction’s courts, law enforcement, and national security authorities. We use contractual and technical safeguards with each provider regardless of where the data lives. If you have questions about our cross-border practices, contact our privacy officer (below).
How long we keep it
- Account information — for as long as your account exists. When an account is deleted, the deletion is permanent (we use hard deletes, not archival flags).
- Database backups — deleted records may persist in our database provider’s automated backups for up to 30 days (depending on the provider) before rotating out.
- Server logs — per our hosting platform’s retention (1 Year).
- Sign-in rate-limit data (IP addresses) — about five minutes, in server memory only.
- One-time link records — links expire on their own (30 minutes to 30 days) and records of consumed links are cleared when superseded.
How we protect it
- All traffic is encrypted in transit (TLS).
- Your session lives in an httpOnly cookie that page scripts cannot read; sessions expire after 24 hours and can be revoked instantly on every device (“Sign out everywhere” in Settings).
- Passwords: salted Argon2id hashes, additionally encrypted with a server-held key.
- One-time links are stored only as cryptographic hashes.
- When you open a one-time link, we take its token straight back out of the web address so it is not left in your address bar, your browser history, or the referrer sent to any later request. While you finish setting your password the tab holds it in session storage instead — it is erased when you close the tab, never reaches another tab, and is deleted the moment the link is used.
- Every request is re-checked server-side against your current role and company — hiding things in the browser is never the security boundary.
- Files are served through short-lived signed URLs (minutes to one hour), never public links.
No online service can promise perfect security, but we design so that the blast radius of any failure is as small as we can make it.
Your rights
You can ask us to confirm what personal information we hold about you, to access it, to correct it, or to delete it. Write to our privacy officer (below); we will verify your identity, respond within 30 days, and explain anything we cannot do (for example, deleting the account of a colleague — that request has to come from your company’s administrator). Your display name and email can also be corrected by your company’s administrator directly.
If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376). Quebec residents can also contact the Commission d’accès à l’information (cai.gouv.qc.ca).
For Quebec residents
- The person in charge of the protection of personal information at Helix is Cohen Van Kalsbeek - CTO and Co-founder, reachable at the contact below.
- The sign-in cookie is a technology that identifies you (it keeps your session tied to your account). It cannot be deactivated because the service cannot function without it — see the Cookie Policy for exactly what it does.
- There are no privacy-affecting settings that default to sharing: the dashboard collects no optional personal information, and every configurable setting is a display preference.
- On the public demo site only, page-view counting is active by default. We chose a form of it that stores nothing on your device and hands us nothing that identifies you, so there is nothing held on your device to switch off — but you are entitled to know it is on rather than off: see the demo site. It is not present on the dashboard, so it never applies to an account holder’s use of the product.
- You have the rights of access, rectification, deletion, and data portability described above, and the right to withdraw consent.
Privacy officer
Questions, requests, and complaints about personal information go to: Cohen Van Kalsbeek - CTO and Co-founder, info@helixsensors.com, 1774 Billington Rd, Bowen Island, BC, Canada - V0N 1G2.
If something goes wrong
If a breach of our safeguards creates a real risk of significant harm to you, we will notify you and report it to the Privacy Commissioner of Canada (and, for Quebec residents, the Commission d’accès à l’information) as required by law, and we keep a record of every security incident.
The demo site
Our public demo (demo.helixsensors.com) signs every visitor into a single shared, read-only demonstration account automatically — the cookie it sets identifies that shared demo account, not you. We collect no personal information from demo visitors beyond ordinary server logs, and anything you submit through the feedback tool there.
The demo site is also the only place in the product where we measure traffic. It runs Vercel Web Analytics, which counts page views so we can tell whether the demo is worth maintaining. It sets no cookies and stores nothing in your browser. What it records is the page path, the referring site, and a country and device type derived from your request. Counting repeat visitors happens on Vercel’s side, not ours: they state that they derive a short-lived hash from the request instead of storing your IP address, and that it cannot be used to identify you or follow you between sites — their documentation is the authority on that, not this page. What reaches us is aggregate counts: never an IP address, never a list of visitors, and nothing we could tie to a Helix account.
None of this runs on the dashboard itself. The analytics script is loaded only when the site is running as the demo; on app.helixsensors.com no analytics code is served at all, so nothing about how you or your colleagues use the product is measured by a third party. If that ever changes we will say so here, and on the notice, before it ships.
Our marketing site at helixsensors.com is a separate site, outside this policy, and it counts page views the same cookieless way — see its own privacy notice. It has no access to any Helix account and cannot see anything in the dashboard.
Changes to this policy
When we change this policy we will update the date at the top; for material changes we will also announce it in the portal before it takes effect. Earlier versions are available on request.