Your data and our AI agents
Last updated: July 2026
This page answers the questions an IT lead, a data protection officer or a careful director asks before signing. It names our subprocessors, states where data is stored, says how long we keep it, and separates what we do from what we don't. What is not yet in place is written here too: a compliance page that only lists successes is not a compliance page.
Why this page exists
Questions about data always land at the same moment: just before signature, usually in writing, sometimes as a vendor questionnaire. Answering them case by case produces slightly different answers from one client to the next, which is the surest way to lose the trust you were trying to build. So this page fixes the answers once, publicly, with a date on them. The privacy policy describes what we do with your data when you browse this site; this page adds what we do with your customers' data when we build something for you, and those are not the same obligations.
Who is responsible for what
Two roles follow one another and they must not be confused. On this site, HelyOs Global is the controller: we decide why and how your data is used, and the privacy policy accounts for it. In an engagement the relationship inverts: you remain the controller of your customers', patients' or employees' data, and HelyOs Global becomes your processor under Article 28 GDPR. In practice that means we act only on your documented instructions, never decide on our own to put that data to a new use, and return or delete everything at the end of the contract, your choice. A third case exists and deserves naming: when an AI agent we deploy collects data itself from your visitors, you are still the controller, so it is your notice and your legal basis that must appear on the form or in the voice opening. We draft the wording, you approve it.
Where your data is stored
Persistent client-space data — accounts, messages, project records — is hosted on Supabase infrastructure in region eu-west-3, Paris. That is verifiable and it is the commitment we make: what gets written to a disk is written in France. The site itself is served by Vercel, whose delivery network replicates public pages worldwide — public pages, with no personal data in them. The server functions that handle a form or an assistant request run without writing anything: they receive, forward, answer and forget. We will not claim here that each of those functions physically executes in Europe until the execution region is pinned in the configuration: that work is pending, and announcing it before it is done would be exactly the kind of approximation this page exists to avoid.
Our subprocessors, by name
A subprocessor you cannot name is a subprocessor you cannot audit. Here are ours, with what each one sees and when. Vercel Inc. hosts and serves the site: it sees HTTP requests, therefore IP addresses, for the duration of a response. Supabase hosts the accounts, messages and projects of the client space, in Paris. Web3Forms delivers contact form submissions to our mailbox: it sees what you typed into the form. Resend sends the internal notifications that alert us to a new message: it sees the destination address and the notification body. Our language-model provider — Anthropic, OpenAI, Google or OpenRouter depending on the configuration in force — receives the text you write to the site assistant, for as long as it takes to produce an answer. ElevenLabs gives the voice agents speech and hearing: it processes call audio when you ask to be called back. The script for that voice widget is served by the unpkg CDN, backed by Cloudflare, and it loads only if you open the voice agent's cockpit — from the site assistant or from the page presenting that agent. Until you open it, nothing is requested from unpkg. When you do, unpkg sees your IP address and your browser, for as long as it takes to deliver a JavaScript file, and nothing else. Google's Gmail interface is called for the Iris agent demonstration, but only against a demo mailbox of our own: no visitor data passes through it. Upstash, or its Vercel KV equivalent, stores the anti-abuse counters: a technical identifier derived from your address, with no name and no content, automatically erased after twenty-six hours. Airtable receives the prospect records created in the sales-agent demonstration, and only those. Sentry, when enabled, collects the site's technical errors — stack trace, page, deployed version — with no personal data. Finally, Google Tag Manager and the Meta pixel load only after your explicit consent in the cookie banner, and nothing is requested from their servers until you click. Three channels commonly present elsewhere are absent here and therefore process nothing: Cal.com booking, WhatsApp and direct telephone are disabled on the site as of today.
How long we keep what
A retention period that is not written down is an unlimited one. Ours: a request sent through the contact form is kept as long as it takes to answer, then at most three years after our last exchange — the period the French data protection authority accepts for commercial prospecting. An email address left to receive a guide follows the same rule and is deleted immediately on request. A client-space account lives as long as the relationship, then is deleted at your request or after prolonged inactivity. Client-space messages and project records are kept for the duration of the follow-up, then archived with the file. Anti-abuse counters expire on their own after twenty-six hours. Invoices and accounting records are kept for ten years: not a choice, but Article L. 123-22 of the French Commercial Code. Conversations with the site assistant are kept nowhere at all, which is the subject of its own section below.
What we do not do
Your data trains no model — neither ours, since we train none, nor a provider's. Calls to language models go through business accounts whose terms exclude reuse of content for training; that is the point we document in writing in the processing agreement, naming the provider selected for your project. We neither sell nor rent any data. We do not cross one client's data with another's: each project has its own space, its own keys, and nothing travels between files. We run no advertising profiling, and the site drops no measurement cookie before you agree. Finally, no decision producing legal or similarly significant effects — a quote, a price, accepting a project — is made by a machine: Article 22 GDPR does not need to apply because there is nothing for it to apply to.
The site assistant: what it sees, what it forgets
This is the most frequent question and it deserves a technical answer rather than a promise. When you write to the assistant, your message travels to our server, which adds the current conversation context and sends it to the model provider. The answer comes back and is displayed. At no point does that server write the conversation to a database, a file or a log: the route handling these exchanges contains no write operation at all, and that is verifiable in the site's code. In practice, closing the tab erases the conversation. One limitation follows and you should know it: we cannot give you back the history of an exchange with the assistant, because we do not have it. The trade-off is that it exists nowhere and therefore cannot leak from anywhere. The client space works the other way round: the messages you exchange with the team there are kept, because that is precisely what they are for.
The EU AI Act: who carries which obligation
Regulation (EU) 2024/1689 allocates obligations by the role played, not by company size. When we design and configure an agent for you, HelyOs Global acts as the provider of that system under the regulation; when you operate it with your own customers, you are its deployer. The transparency obligations of Article 50 apply from 2 August 2026: a person talking to a machine must know it, and artificially generated content must be identifiable as such. That is why our conversational agents state their nature in the first message or the first second of a call, without being asked, and why we decline to ship an agent that would pass itself off as human. A transitional period runs to 2 December 2026 for the technical marking of synthetic content produced by systems already on the market. The heavy obligations attached to high-risk systems cover none of the services we sell: no recruitment, no educational assessment, no credit scoring, no biometrics. Should a project fall under Annex III, we would tell you before the quote, and the applicable timeline would be 2 December 2027. Finally, for every agent we deliver we commit to providing the technical documentation your own deployer compliance requires: purpose, input data, known limits, human handover points.
The data processing agreement, and why it is not a download
Article 28 GDPR requires a written contract between you and us as soon as an engagement puts us in contact with your customers' data. We provide it within forty-eight working hours of your request, and it is signed before any access, never after. It names the subject matter and duration of the processing, the categories of data subjects, the list of sub-processors actually involved in your project — not the theoretical list in the section above, the one that concerns you — the security measures, the fate of the data at the end of the contract and the incident notification deadline. We deliberately publish no blank template for download. A generic processing agreement, with its brackets to fill in and its empty annexes, gives the appearance of a compliance it does not produce: the legal value of that document rests entirely on its annexes, that is, on the detail of your particular processing. A document pre-filled at random would be signed unread, which is precisely the risk Article 28 exists to remove. Ask for it and you will get it filled in.
Security and incidents
The measures that matter fit in a few lines, which is rather a good sign. Exchanges with the site are encrypted in transit. Access keys for third-party services live server-side, never in the browser, and are not committed to version control. The client space relies on Supabase row level security: an authenticated user reaches only their own records, and the rule is enforced by the database itself rather than by the interface alone, which makes it immune to a coding mistake in the application. Routes that write are protected by an origin check and by rate ceilings. Technical monitoring reports errors without their personal content. In the event of a breach affecting us, we inform you without undue delay with what we know, including what we do not yet know, so that you can meet the seventy-two-hour deadline of Article 33 towards your supervisory authority. Every incident is logged, including those below the notification threshold: Article 33.5 requires that internal register, and it is also the only way to notice a drift.
Your contacts and your remedies
HelyOs Global has not appointed a data protection officer, and that is not an oversight: Article 37 makes appointment mandatory for public bodies, for those whose core activity involves large-scale systematic monitoring, and for those processing sensitive or criminal data at large scale. None of those three cases matches the studio's activity. Writing the opposite to reassure would be decorative. Your requests — access, rectification, erasure, portability, objection, withdrawal of consent — therefore go straight to contact@helyosglobal.com and receive an answer within one month, the deadline in Article 12.3, extendable by two months for a complex request, in which case we tell you before the deadline rather than after. If the answer does not satisfy you, the CNIL can be petitioned free of charge, online, at www.cnil.fr, without notifying us first. The day one of those three conditions changes — a large-scale project involving health data, for instance — an officer would be appointed and their name would appear here.
The questions that come up before signature
Does my data leave the European Union?
What is stored durably — client-space accounts, messages and projects — stays in Paris, in region eu-west-3. Some one-off processing goes through providers that may operate outside the Union: those flows are governed by the European Commission's standard contractual clauses, and the processing agreement tells you which ones are actually involved in your project.
Do you use our data to train a model?
No. We train no model, and the business accounts we use with providers exclude reuse of content for training purposes. It is written into the contract, naming the selected provider, rather than promised on a page.
Do you provide a data processing agreement, and why is it not downloadable?
We provide it within forty-eight working hours and sign it before any access to data. It is not a free download because its value rests on its annexes: a blank template, filled in at random, would be signed unread — the very risk Article 28 exists to remove.
What happens to a conversation with the site assistant?
Nothing: it is written nowhere. The route handling these exchanges contains no write to a database, a file or a log. Closing the tab is enough to erase it, and we therefore cannot give you back its history.
Which AI provider do you use?
The site is deliberately provider-agnostic: depending on the configuration in force, requests go to Anthropic, OpenAI, Google or OpenRouter. For a client project, the provider and the exact model are named in the contract, and a change is notified to you before it is applied.
Do you have a data protection officer?
No, and that is deliberate: none of the three conditions in Article 37 applies to the studio's activity. Your requests go straight to contact@helyosglobal.com, answered within one month. The day an appointment became mandatory, the officer's name would appear on this page.
What happens if you change subprocessor?
You are informed before the change, with a reasonable period to object, as Article 28.2 provides. A change of model provider in particular is never made silently: it is the one with the greatest consequences for where processing takes place.
What becomes of our data at the end of the contract?
You choose: return in a usable format, or deletion with a certificate. By default, absent instructions from you, we keep the data for thirty days then delete it, except accounting records subject to the ten-year legal retention.
Does the EU AI Act apply to my project?
The transparency obligations of Article 50 apply to every conversational agent from 2 August 2026, and our agents state their nature by default. High-risk obligations cover none of our current services; should your project fall under Annex III, we would tell you before the quote.
How long do you take to answer an erasure request?
One month, the deadline in Article 12.3, and in practice far less for a plain address left on a form. A complex request may be extended by two months, in which case we tell you before the deadline rather than after.