1. Scope
This Privacy Policy explains how we collect, use, disclose, protect, retain, and delete personal data when you visit our website, contact us, create or use a HelmMind account, or connect an authorized third-party service. It also explains the choices and rights available to you.
This policy applies to the HelmMind marketing website and application identified at helmmind.ai. A customer agreement or Data Processing Addendum may provide additional terms where HelmMind processes personal data on behalf of an organization.
2. Information we collect
The information we collect depends on how you use HelmMind and which integrations your organization enables.
- Account and profile data: name, work email, organization, role, account identifiers, language, time zone, and account preferences.
- Authentication and security data: login events, MFA enrollment and verification records, device or browser information, IP address, session data, and security alerts. We do not store MFA one-time codes in readable form.
- Authorized advertising data: account, campaign, ad set, ad, budget, spend, delivery, conversion, attribution, and performance data that an authorized user allows HelmMind to access through an integration or approved import.
- Authorization data: OAuth tokens, granted scopes, connection status, and platform identifiers. We do not ask you to provide your advertising-platform password.
- Workspace and decision data: alerts, recommendations, comments, approvals, edits, rejection reasons, assignments, templates, exports, and audit records.
- Support and sales data: information submitted through demo, contact, support, privacy, security, or partnership requests and related communications.
- Billing data: subscription, invoice, and transaction information. Full payment-card details are handled by the payment processor identified at checkout and are not stored by HelmMind unless expressly stated.
- Website and usage data: pages viewed, feature interactions, referral information, diagnostics, error logs, and cookie or similar technology data described below.
3. How we use information
We use information to:
- Provide, secure, maintain, and troubleshoot the website and service.
- Connect authorized data sources and display dashboards, matrices, alerts, recommendations, data-health context, reports, and exports.
- Authenticate users, enforce role-based access and mandatory MFA, and investigate suspicious activity.
- Generate explainable recommendations and preserve the evidence, human decision, and follow-up outcome associated with them.
- Send operational messages, including account, security, support, email, and Feishu Webhook notifications configured by the customer.
- Respond to demo, sales, support, privacy, security, and partnership requests.
- Measure product performance and improve reliability, usability, recommendation quality, rules, and templates.
- Process billing, enforce agreements, comply with law, and protect the rights and safety of HelmMind, customers, users, and others.
4. Legal bases where applicable
Where data-protection law requires a legal basis, we process personal data as necessary to perform a contract, comply with legal obligations, protect legitimate interests that are not overridden by your rights, protect vital interests, or act with your consent. You may withdraw consent where processing is based on consent, without affecting earlier lawful processing.
5. How we disclose information
We do not sell personal data. We may disclose information in limited circumstances:
- To the organization that controls your HelmMind workspace, including its authorized administrators.
- To service providers supporting hosting, identity, communications, analytics, payments, monitoring, customer support, and AI processing under contractual restrictions.
- To advertising and integration providers when an authorized user requests a connection, data retrieval, export, or supported action.
- To professional advisers, auditors, insurers, or potential transaction counterparties subject to confidentiality obligations.
- When required by law, legal process, or a valid government request, or reasonably necessary to protect rights, safety, and service integrity.
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable notice and protection requirements.
6. Advertising platform integrations
HelmMind accesses connected advertising data only after an authorized user completes the provider's authorization flow or supplies an approved import. Access depends on the scopes granted and the provider's API availability. You can disconnect an integration from HelmMind or revoke access through the provider.
HelmMind's use of data received from Meta, Google, TikTok, or another provider is also subject to applicable provider terms and developer policies. HelmMind does not use one customer's private advertising data to expose that customer's campaigns, strategy, or account-level results to another customer.
7. AI processing and product improvement
Data categories
Category A — Platform Business Data. Ad account configurations, campaign settings, spend, ROAS, conversion metrics, and approval/adjustment records generated by the Customer through the Service. Category A data is operational in nature and generally does not constitute personal information.
Category B — Account and Contact Data. Registration, identity, and contact information of the Customer’s personnel. Category B data constitutes personal information, is governed by this Privacy Policy, and will not be used for model training.
Category C — Audience and Retargeting Data. Audience lists, customer files, and remarketing data uploaded or synchronized by the Customer, which may contain personal information of end users. Category C data will not be used for model training. Any processing beyond service delivery requires the Customer’s explicit, separate consent.
Training authorization and principles
By creating an account and affirmatively checking the consent box during registration, the Customer expressly agrees that Category A data may be used by HelmMind for training, optimization, and improvement of HelmMind models and algorithms. Where applicable law requires separate consent, it will be obtained through a dedicated mechanism.
- De-identification: training data will be de-identified and, where feasible, aggregated so it cannot reasonably be linked back to a Customer or individual.
- Sole purpose: data is used only to improve product capabilities, model accuracy, and service quality.
- No sale: HelmMind does not sell Customer data to a third party.
- No identifiable disclosure: HelmMind does not disclose identifiable Customer data except as described here or required by law.
Cross-border processing and model services
The Service routes tasks to third-party foundation model providers through a model gateway, based on task type, data classification, and the Customer’s account configuration. Customer-identifying data (including account IDs, spend details, and Customer names) is processed only by model providers within mainland China. De-identified tasks, such as English ad-copy generation and market-level intelligence analysis, may be processed by overseas model providers including Anthropic, OpenAI, and Google through HelmMind’s Hong Kong entity.
Enterprise training exemption
Enterprise customers may apply in writing to be excluded from model training. A Training Exemption takes effect within thirty (30) days of HelmMind’s confirmation and does not affect models already trained before its effective date. Electing an exemption does not affect use of the Service.
HelmMind applies industry-standard technical and organizational measures to protect Customer data. Upon account termination, Customer data will be deleted within a reasonable period, except anonymized or aggregated data that can no longer be associated with the Customer and data required to be retained by applicable law. HelmMind will provide at least thirty (30) days’ advance notice of material changes to these terms via email or in-product notification.
9. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including providing the service, maintaining security and audit records, resolving disputes, enforcing agreements, and meeting legal obligations. Retention periods vary by data type and customer instructions.
10. International Transfers
HelmMind and its service providers may process personal data in Hong Kong and in other jurisdictions where our cloud hosting, communications, analytics, support, advertising integration, and AI service providers operate.
When personal data is transferred across borders, HelmMind implements safeguards appropriate to the transfer and required by applicable law. These safeguards may include data processing agreements, recognized contractual clauses, transfer assessments, access controls, encryption, and vendor security reviews.
You may contact service@helmmind.ai to request further information about the safeguards applicable to a particular transfer.
11. Security
We use administrative, technical, and organizational measures designed to protect information. Confirmed controls include role-based access, mandatory MFA, controlled integrations, decision logs, and data-health visibility. No method of transmission or storage is completely secure. See our Security page for current controls and responsible disclosure instructions.
12. Your choices and rights
Depending on your location and relationship with HelmMind, you may have the right to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and to lodge a complaint with a supervisory authority. Some rights are subject to legal exceptions.
If your account is provided by an organization, that organization may need to handle or authorize your request as the controller. Submit a request through the Data Deletion page or contact service@helmmind.ai. We may verify your identity and authority before acting.
13. Children's privacy
HelmMind is a business service and is not directed to children. You must be at least 18 years old, or the age of legal majority in your jurisdiction, to create an account. If we learn that we collected personal data from a child contrary to applicable law, we will take appropriate steps to delete it.
14. Changes to this policy
We may update this policy to reflect changes to the service, law, or our data practices. We will post the updated effective date and provide additional notice where required. Material changes will not be applied retroactively where prohibited by law.
15. Contact
For privacy questions or requests, contact service@helmmind.ai, use the Contact page, or submit a verified request through Data Deletion.
BlueStart Technology Limited ("HelmMind," "we," "us," or "our") provides the HelmMind website and paid media operations platform.