One moment.
One moment.
How HelmXP collects, uses, and protects personal data on behalf of credit union customers.
Last updated: May 2026. The authoritative version is managed by HelmXP staff. The text below is a placeholder until the first published version is available.
HelmXP is operated by HelmXP (“we”, “us”). This policy describes how we handle personal data when you use the HelmXP platform. Our contact for privacy matters is privacy@helmxp.com.
We process data that Customer institutions provide when signing up and using the Service: institution name, NCUA charter number, executive names and email addresses, and board briefing content authored on the platform. We also process usage and audit log data (IP addresses, session identifiers, action timestamps) required for security and regulatory purposes.
We do not sell personal data. We do not use Customer briefing content to train AI models.
Processing is based on the performance of our contract with the Customer institution (delivering the Service), our legitimate interests in security and fraud prevention, and compliance with applicable law (including NCUA cybersecurity guidance). Where GDPR applies, the Customer institution is the data controller and HelmXP is the data processor; our obligations are set out in the Data Processing Agreement.
All data is stored encrypted at rest (AES-256, AWS KMS-managed) in the United States. Data in transit is protected by TLS 1.3 with HSTS enforced. Each Customer's data is isolated using PostgreSQL Row-Level Security — no query can read another Customer's data. Audit logs are append-only and retained for 7 years.
HelmXP uses a limited set of subprocessors to deliver the Service: Amazon Web Services (hosting, storage, email), Stripe (payment processing — no card data is stored by HelmXP), and Anthropic (AI drafting — content is sent to Anthropic only for the purpose of generating drafts on behalf of the Customer and is governed by Anthropic's data processing terms).
If you are covered by GDPR, CCPA, or similar legislation, you have rights to access, rectify, erase, and export your personal data. Submit requests to privacy@helmxp.com. We will respond within 30 days. Note: requests for deletion of briefing content that forms part of the institution's regulatory record may need to be reviewed by the Customer institution's compliance officer.
The HelmXP platform sets a single session cookie (HttpOnly, Secure, SameSite=Lax) necessary to maintain your authenticated session. We do not use advertising cookies or third-party tracking on the platform. The public marketing site (helmxp.com) may set minimal analytics cookies; see the Cookie Policy for details.
For privacy questions: privacy@helmxp.com. For data breach notifications or DPA matters, see the Data Processing Agreement.