Privacy Policy
This policy explains what data Pixhelm LTD, trading as Helpdash ("Helpdash", "we", "us") collects when you use helpdash.io or any Helpdash-hosted workspace, why we collect it, how long we keep it, and the rights you have over it. We aim for plain English — if anything below is unclear, email privacy@helpdash.io and a human will respond within one business day.
1. Who the controller is
For the marketing site (helpdash.io), Pixhelm LTD (company number 17389527), trading as Helpdash, registered in England & Wales, is the data controller. For data inside a customer’s workspace, the customer is the controller and Helpdash is the data processor under the Data Processing Addendum signed at account creation.
2. What we collect
On the marketing site we collect minimal anonymised analytics (page path, referrer, country at the country level, device class) using a first-party endpoint — no third-party trackers, no cross-site cookies. We do not run advertising pixels.
When you contact us we receive the data you put in the form (name, email, company, the message itself) plus a timestamp and the originating IP. When you create an account we collect your name, email, password (hashed with bcrypt), workspace slug, and any optional billing details. Inside a workspace, we store the operational data your team enters — tickets, replies, attachments, articles, audit events, automation rules, CSAT responses.
3. Why we use it
Marketing analytics: to understand which pages help and which don’t. Contact form: to reply. Account data: to authenticate you, scope your workspace, and bill you. Workspace data: to run the helpdesk product on your team’s behalf as a processor.
4. Lawful bases (GDPR)
Performance of contract (running the product you signed up for), legitimate interests (basic analytics and product improvement, minimised and anonymised), and consent (for non-essential cookies and the marketing newsletter — both opt-in, both withdrawable from any page footer).
5. Where data is hosted
Marketing site: Cloudflare CDN, EU edge. Production workspaces: AWS Frankfurt (eu-central-1) by default. UK (London) and US (Virginia) regions are available on Pro and above; dedicated single-tenant deployments on Enterprise can run in customer-supplied VPC, including on-prem.
6. How long we keep it
Marketing analytics: 13 months, then aggregated. Contact-form messages: 24 months from last reply. Workspace data: as long as the workspace is active, plus 30 days after cancellation for export. After 30 days, data is permanently deleted unless a longer retention is requested in writing. Audit logs are retained 13 months by default and can be streamed to your own S3 bucket for longer retention.
7. Sub-processors
We use AWS (hosting), Cloudflare (CDN + WAF), Resend (transactional email), Stripe (payments), and Sentry (error reporting, EU region, PII scrubbed). The current sub-processor list with regions and DPAs is at trust.helpdash.io. We notify customers 30 days before adding or replacing any sub-processor.
8. Your rights
You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. Marketing-site requests: email privacy@helpdash.io. Workspace data: contact the workspace admin (we’re the processor; they’re the controller). We respond within 30 days, usually within 7.
9. Security
Transport is TLS 1.3 (HTTPS-only, HSTS). Data at rest is AES-256. Passwords are bcrypt-hashed. Access to production is SSO-only with MFA enforced. Every privileged action is recorded in a tamper-evident audit log. Independent penetration tests run yearly; reports available under NDA from trust.helpdash.io.
10. AI connectors (MCP)
A workspace admin can connect an external AI assistant to Helpdash over the Model Context Protocol, from Settings → AI connectors. This is off by default and nothing is shared until an admin creates a token or completes an OAuth authorisation.
Once connected, the assistant reads and writes workspace data on behalf of the operator who issued the credential, limited to the scopes granted. It acts with that operator’s own permissions — a connector can never reach data the operator could not open in the app, and never reaches another workspace. Scopes are read-only unless write access is ticked explicitly. Values that hold passwords or secret keys are masked before they leave the server and cannot be read over a connector at all.
The receiving AI provider is chosen by you, not by us. When a connector is active, the data the assistant requests is transmitted to that provider and is then governed by their privacy terms; Helpdash sends nothing to any model provider of its own accord. Review the provider’s terms before granting write scopes.
We store only a SHA-256 hash of a connector token — the key itself is displayed once at creation and cannot be recovered by us. Every connector call is written to the workspace audit log with the operator, the tool and the outcome. Revoking a token in Settings → AI connectors takes effect on the assistant’s very next request.
11. Changes to this policy
We notify active workspace admins by email 30 days before any material change. The previous version stays accessible at /legal/privacy/archive.
12. Contact
Pixhelm LTD, Suite 11114, 5 Brayford Square, London, United Kingdom, E1 0SG. Privacy: privacy@helpdash.io. Lead supervisory authority: the UK Information Commissioner’s Office (ICO).