Trust Center
Privacy
HelmXP processes data on behalf of the hub (the credit union or other institution). This page documents what data we hold, how long we hold it, and how to exercise your rights under GDPR, CCPA, and applicable state law.
For the full legal text, see the Privacy Policy and Data Processing Agreement on the main site.
Data residency
All production data is stored in the regions listed below. Data does not leave these regions except for processing by the subprocessors listed on the Subprocessors page.
US East (Virginia)
CurrentAzure Database for PostgreSQL, Azure Blob Storage, Azure Service Bus, Azure Application Insights, Azure Key Vault
EU West (Netherlands)
Planned — Wave B1Azure Database for PostgreSQL (replica), Azure Blob Storage (replica)
What data is stored
The table below lists each category of data HelmXP processes, the retention period during an active subscription, and the deletion timeline after the subscription ends.
| Category | Examples | Retention | Deletion |
|---|---|---|---|
| Account and seat data | Email address, display name, seat position, role label, MFA enrollment status | Duration of the hub subscription | Deleted within 30 days of subscription termination |
| Briefing content | Section text, AI drafts, attachments, comments, sign-off timestamps | Duration of the hub subscription | Deleted within 30 days of subscription termination; export available on request before deletion |
| Logbook entries | Approved courses, Cycle records, examiner access grants | Duration of the hub subscription | Deleted within 30 days of subscription termination |
| Financial data (read from integrations) | NCUA 5300 data, GL trial balance figures pulled from Plansmith or similar | Cached for the duration of a Cycle; purged at Cycle close | Purged at Cycle close; full deletion within 30 days of subscription termination |
| Authentication and session data | Hashed passwords, session tokens, MFA TOTP secrets, audit logs | Session tokens: 8 hours (configurable). Audit logs: 7 years for compliance | Session tokens expire automatically. Audit logs retained 7 years per regulatory convention; contact support to discuss earlier deletion. |
| Usage and observability data | Azure Application Insights telemetry, anonymised event counts | 90 days in Application Insights (default) | 90 days rolling; telemetry never attaches default PII (Sentry sendDefaultPii is off) and is configured not to include hub-identifiable payloads |
Exercising your rights
Hub administrators hold most self-service controls. Individual seat holders may contact privacy@helmxp.com for any right that is not available in the product UI.
Access
Hub administrators can export a full data extract from institution settings. Individual seat holders can contact privacy@helmxp.com.
Response: Self-service: immediate. Email request: within 30 days.
Rectification
Most account data can be updated by the seat holder in their profile. For records the product does not expose, email privacy@helmxp.com.
Response: Self-service: immediate. Email request: within 30 days.
Erasure (right to be forgotten)
Hub administrators can initiate account deletion for individual seats. Full hub deletion is initiated by the account owner via institution settings or by contacting support.
Response: Within 30 days of request confirmation.
Data portability
Hub administrators can download a full data export in JSON format from institution settings.
Response: Self-service: available on demand.
Objection to processing
Contact privacy@helmxp.com with the specific processing activity.
Response: Response within 30 days.
Privacy inquiries
For any privacy question not answered here, contact privacy@helmxp.com. We acknowledge all requests within 5 business days and provide a substantive response within 30 days.