One moment.
One moment.
Last updated: May 25, 2026
HelmXP's EU Data Processing Agreement (DPA) describes how HelmXP acts as a data processor on behalf of your Hub when processing personal data governed by the General Data Protection Regulation (GDPR).
The DPA is based on the standard clauses published by the European Commission and is accepted electronically at signup.
The DPA applies to any Hub located in the European Economic Area (EEA), or to any Hub outside the EEA that processes personal data of EEA individuals.
If you selected EU data residency at signup, your DPA was presented during onboarding and your acceptance is recorded in your Hub's legal log.
The DPA covers:
HelmXP uses a limited set of sub-processors. The current list and their roles are published on the Trust Center subprocessors page. You will receive 30 days' notice before any new sub-processor is added.
Your current DPA acceptance — including the template version, IP address, and timestamp — is recorded in your Hub's legal log under Manage > Legal. If you need a signed copy for your records, contact support.
If your procurement process requires changes to the standard DPA, contact your account manager. Legal review for redlines is handled on a per-customer basis and typically involves a two-week turnaround.