Skip to content

Trust Center

Privacy

HelmXP processes data on behalf of the hub (the credit union or other institution). This page documents what data we hold, how long we hold it, and how to exercise your rights under GDPR, CCPA, and applicable state law.

For the full legal text, see the Privacy Policy and Data Processing Agreement on the main site.

Data residency

All production data is stored in the regions listed below. Data does not leave these regions except for processing by the subprocessors listed on the Subprocessors page.

US East (Virginia)

Current

Azure Database for PostgreSQL, Azure Blob Storage, Azure Service Bus, Azure Application Insights, Azure Key Vault

EU West (Netherlands)

Planned — Wave B1

Azure Database for PostgreSQL (replica), Azure Blob Storage (replica)

What data is stored

The table below lists each category of data HelmXP processes, the retention period during an active subscription, and the deletion timeline after the subscription ends.

CategoryExamplesRetentionDeletion
Account and seat dataEmail address, display name, seat position, role label, MFA enrollment statusDuration of the hub subscriptionDeleted within 30 days of subscription termination
Briefing contentSection text, AI drafts, attachments, comments, sign-off timestampsDuration of the hub subscriptionDeleted within 30 days of subscription termination; export available on request before deletion
Logbook entriesApproved courses, Cycle records, examiner access grantsDuration of the hub subscriptionDeleted within 30 days of subscription termination
Financial data (read from integrations)NCUA 5300 data, GL trial balance figures pulled from Plansmith or similarCached for the duration of a Cycle; purged at Cycle closePurged at Cycle close; full deletion within 30 days of subscription termination
Authentication and session dataHashed passwords, session tokens, MFA TOTP secrets, audit logsSession tokens: 8 hours (configurable). Audit logs: 7 years for complianceSession tokens expire automatically. Audit logs retained 7 years per regulatory convention; contact support to discuss earlier deletion.
Usage and observability dataAzure Application Insights telemetry, anonymised event counts90 days in Application Insights (default)90 days rolling; telemetry never attaches default PII (Sentry sendDefaultPii is off) and is configured not to include hub-identifiable payloads

Exercising your rights

Hub administrators hold most self-service controls. Individual seat holders may contact privacy@helmxp.com for any right that is not available in the product UI.

Access

Hub administrators can export a full data extract from institution settings. Individual seat holders can contact privacy@helmxp.com.

Response: Self-service: immediate. Email request: within 30 days.

Rectification

Most account data can be updated by the seat holder in their profile. For records the product does not expose, email privacy@helmxp.com.

Response: Self-service: immediate. Email request: within 30 days.

Erasure (right to be forgotten)

Hub administrators can initiate account deletion for individual seats. Full hub deletion is initiated by the account owner via institution settings or by contacting support.

Response: Within 30 days of request confirmation.

Data portability

Hub administrators can download a full data export in JSON format from institution settings.

Response: Self-service: available on demand.

Objection to processing

Contact privacy@helmxp.com with the specific processing activity.

Response: Response within 30 days.

Privacy inquiries

For any privacy question not answered here, contact privacy@helmxp.com. We acknowledge all requests within 5 business days and provide a substantive response within 30 days.