Helix.ID
Sign In

Privacy Notice

Last updated 17 September 2026 · Version 1.1

View as Markdown

H3lix AI Ltd., trading as Helix, is a company incorporated in Delaware, United States. This notice explains how we handle personal information, what we do with it, and what rights you have.

It covers the personal information for which Helix is the data controller. That is principally three things: information about the business customers who hold accounts with us and the people who work for them; information about visitors to helix.id; and the voice datasets we license or collect in order to build and test our machine-learning models.

It does not cover the age check itself. When a business integrates our technology and an end user completes a voice check, that business decides to run the check and acts on the result, so that business is the controller and Helix acts as its processor. What happens during a check is described in our End-User Processing Notice at https://helix.id/privacy/voice-check. The two notices are meant to be read together.

If you have any questions, write to us at privacy@helix.id.

1. Who we are, and who to contact

Helix. H3lix AI Ltd., 1301 N Broadway St, #32355, Los Angeles, CA 90012, United States. Telephone +1 213 340 6080. Email privacy@helix.id.

Our privacy contact. Email privacy@helix.id, or write to us at the address above marked for the attention of the Data Protection Responsible Person.

We have not appointed a statutory Data Protection Officer. We assessed the criteria in Article 37 UK GDPR and concluded that we are not required to designate one. Internal responsibility for data protection sits with our Data Protection Responsible Person, currently our Chief Technology Officer. This is an internal management role and we do not hold it out as a Data Protection Officer appointment.

Our UK and EU representative. Because Helix is established in the United States, we have appointed Prighter to act as our representative under Article 27 UK GDPR and Article 27 EU GDPR. You can contact them directly, and so can a supervisory authority.

For the EU: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria.

For the UK: Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom.

You can make a request to either through https://app.prighter.com/portal/helix. Please quote reference ID-19548739993 on any correspondence.

2. What we collect, and where it comes from

2.1 Information you give us

If you hold an account with us, or work for a business that does, we collect your name, business email address, job title, role and invitation status, and a record of actions you take in the customer dashboard. If you contact support, we hold the correspondence.

If you ask for access to our beta, we hold your name, work email address, company and role, the product you are interested in, and, if you give them, your monthly traffic range and a description of what you are trying to solve, together with the correspondence about that request. We use this to consider the request and to contact you about it.

If you meet with us, we may use Granola, a note-taking service, to transcribe the meeting and produce notes. Granola does not keep the audio: it transcribes in real time and the audio is discarded. We ask everyone on the call before transcription starts, and if anyone objects we do not use it. The transcript and notes are held as a record of the meeting.

If you buy from us, we hold billing history. Payment-card data is collected and processed directly by Braintree, a PayPal service, which acts as an independent controller for that data under its own privacy statement at https://www.braintreepayments.com/legal/braintree-privacy-policy. Helix does not receive or store full payment-card numbers.

2.2 Information we collect automatically

To show you a page on helix.id, your browser sends us your IP address and standard request information such as browser type and language. We use that only to serve the request. We do not store it in our own systems and we do not use analytics cookies, because we do not set any. We do use a cookie-free analytics service to understand how the site is used in aggregate. It sets nothing on your device, receives no IP address and no identifier for you, and cannot recognise you from one visit to the next.

The infrastructure providers that host and protect our service, Cloudflare and Amazon Web Services, retain standard request logs, including IP addresses, for their own security and operational purposes. We do not use those logs for analytics or to identify visitors. How long they keep those logs is set by their own published retention policies, which we do not control.

For the age-assurance service, no IP address, raw or hashed, is stored in the analytical event log or in the age-assurance analytics pipeline, and application logs are written without IP addresses.

2.3 Information we obtain from other sources, and voice data we collect for model development

This is the part most privacy notices get wrong, so we state it plainly. We do obtain personal information from third parties. There are two kinds, and one more we collect ourselves.

Voice datasets for model training. To build a system that can tell a child's voice from an adult's, we need recordings of both. We license voice corpora from specialist dataset providers. These include a children's speech corpus supplied by Nexdata, comprising recordings from roughly 219 speakers and around 9.2 hours of audio, together with synthetic corpora used for evaluation. The personal information in these datasets is the voice recording itself and associated metadata, principally the speaker's age and, for anti-spoofing work, whether a sample is genuine or artificial.

We did not collect these recordings from the speakers and we hold no contact details for them. The provider obtained consent at the point of collection for speech-technology development and onward licensing. That consent is not our lawful basis, because consent has to be given to the organisation relying on it. Our basis is legitimate interests, and the consent obtained at source is relevant to our assessment of whether that is fair, rather than a substitute for it. Section 4 sets out that assessment and Section 8 sets out what we do and do not do with the data.

Because we have no means of contacting the speakers, we do not send them individual notice under Article 14 UK GDPR, relying on the disproportionate-effort exemption at Article 14(5)(b). As the compensating measure for that reliance, we publish a training-data provenance statement describing every corpus we hold, its source and its licence terms, at https://helix.id/privacy/training-data.

Voice recordings we collect ourselves. We also collect a small number of recordings directly, from paid adult participants who take part in our own voice-data collection. Those participants are told what the recording is for, give their consent to us directly, and can withdraw it. Because we have a direct relationship with them, they receive full notice at the point of collection and can exercise all of their rights against us in the ordinary way. This collection is adults only by design, and it is also described in the provenance statement.

Business contact information for sales. We research organisations that may have a need for age assurance and identify the person within them whose role makes them the right contact. That means we hold names, job titles, employers and business email addresses obtained from professional networks and public professional sources. We do not buy contact lists, we do not enrich our records through data brokers, and we do not share prospect data with anyone.

2.4 Sensitive and biometric information

Voice is a personal characteristic, and some of the information we handle is treated as sensitive or as biometric information under one law or another. We would rather set out what we actually do than make a blanket denial.

Voice recordings in our training datasets. We hold these, they are personal information, and some of them are recordings of children. They are used to fit and test model parameters against age labels and anti-spoofing labels. We do not use them to identify anyone, we do not build a speaker gallery or a voiceprint from them, and we do not attempt to match them against any other recording. On that basis they are not special-category data under Article 9(1) UK GDPR, which turns on whether biometric data is processed for the purpose of uniquely identifying a person. They remain sensitive in the ordinary sense and we handle them accordingly.

The age check. When an end user completes a voice check, their voice is analysed on their own device to estimate an age band. No comparison against any stored reference happens, no voiceprint is created, and the audio is discarded after processing. Article 9(1) is not engaged by that processing either, for the same reason.

Voice matching, where a business uses it. Some businesses configure our technology so that a user must first be matched against a voice they set up earlier. That is biometric processing for the purpose of identifying a particular person, and Article 9(1) is engaged by it. The reference is created and held on the user's own device in encrypted form, and it is never transmitted to Helix. We never receive it, and we never receive the result of the comparison. The business deploying the feature is the controller for it and determines its own lawful basis and its own Article 9(2) condition. Our product is designed to support reliance on Article 9(2)(g) UK GDPR with paragraph 10 of Schedule 1 Part 2 of the Data Protection Act 2018, on the basis that the check exists to prevent circumvention of an age gate. Where the laws of Illinois, Texas, Washington or Quebec require consent before voice data is collected or a biometric template is generated, consent is obtained separately in accordance with those laws.

We do not process racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, health data or data about sex life or sexual orientation.

3. How we use your information

We use personal information to:

  • create and administer accounts, and let people log in to the customer dashboard;
  • deliver and support the service our customers have bought;
  • answer questions and resolve problems;
  • send service, security and administrative notices;
  • keep a record of meetings we hold with customers, prospects, partners and auditors;
  • keep an audit record of configuration changes made through the dashboard, which matters because those settings configure a certified service;
  • keep our systems secure and prevent automated abuse of the verification endpoint;
  • monitor, at population level, whether the age-assurance service is performing as expected;
  • train and evaluate our machine-learning models;
  • approach organisations that may need what we build, and respond to organisations that ask to see it; and
  • meet our own legal and regulatory obligations.

We do not use anything from an end user's age check for marketing, and we do not use marketing data for anything to do with age assurance. The two are kept apart by design.

5. Automated decision-making and our use of AI

Our product estimates a person's age from the sound of their voice using machine-learning models. It runs on the user's own device and produces a probability distribution across five age bands, from which a yes or no answer to a specific age threshold is derived. The model can also decline to answer where it is not confident enough, in which case no result is issued at all.

Helix does not make solely automated decisions about you that produce legal or similarly significant effects. For the age check, the business that asked for the check receives the result and decides what to do with it, including whether to grant access, and it is responsible for offering a route to have a decision reviewed by a person. If you were refused access after a voice check, that business is who to ask.

We also run two models that decide whether a voice sample is genuine rather than recorded or synthetic. These say something about the recording, not about who you are.

We do not use age-check results for profiling, advertising, scoring or any purpose other than answering the age question we were asked.

6. Cookies and storage on your device

We use a small number of cookies and similar storage items. Almost all of them are strictly necessary to provide the service you have asked for and to keep it secure, and those do not require your consent.

On our corporate site, helix.id, we set nothing at all. No cookies, no browser storage.

In the product, the necessary items keep you signed in, including inside a partner's embedded widget and for people who reach us through the Vercel marketplace; protect against cross-site request forgery; identify the verification attempt in progress so we can detect automated abuse; and remember where you have got to in setting up or verifying your account. They last anywhere from the life of a single browser tab to thirty days.

One item is not strictly necessary. We remember whether you chose the light or dark theme, because you chose it. You can clear it in your browser at any time.

We do not use analytics cookies, and session identifiers are removed before anything reaches our analytics.

Where a business uses voice matching, the voice reference is created and held on your own device in encrypted form. That is storage on your device too, and we mention it for completeness, though it exists only because you asked for that feature. Section 9 explains how to remove it.

We do not use cookies for advertising. We do not permit third parties to use tracking technologies on our site to target advertising at you, and we do not share information with advertising networks.

Our separate Cookie Notice lists every item by name, what it is for and how long it lasts: https://helix.id/privacy/cookies.

7. Who we share information with

We share personal information with service providers who process it on our instructions and cannot use it for their own purposes:

ProviderWhat it doesWhat it receives
Amazon Web ServicesHosting, storage, database, email delivery, dashboard authenticationAccount data, event log data, application logs
PostHogProduct and website analyticsPseudonymous event data. No IP address, no session identifier.
Cloudflare, Google and LeminAnti-bot checks at the point of a voice checkThe user's IP address, transiently, while the check is served
LinearSupport ticketing from the customer dashboardSupport correspondence
VercelMarketplace integration and sign-in for customers who install Helix through VercelAccount identity for those users, at sign-in
GranolaMeeting transcription and notesMeeting audio transiently, for transcription only, and not retained; the transcript, notes and attendee names. Our account is configured so that our meeting content is not used to train Granola's models.

Braintree is different. It acts as an independent controller for payment-card data under its own privacy statement, rather than as our processor.

Where we run our own voice-data collection, the provider that recruits and pays participants handles their identity and payment details as our processor and does not receive the recordings.

We do not sell personal information, and we do not disclose personal information to third parties for those parties' own purposes. The only exception is Braintree, described above, which is why we name it. No dataset we hold is sold, licensed out, shared for anyone else's marketing, or contributed to a data exchange. This is a commitment our internal assessments depend on, not a form of words.

We may disclose information where the law requires it, or in connection with a merger, acquisition or sale of the business, in which case we would tell you.

8. How long we keep information

We keep information only as long as we need it for the purpose it was collected for. Different purposes need different periods, so we do not apply a single rule.

WhatHow long
Customer account dataDeleted within 90 days of the account closing
Billing records6 years, for tax and accounting
The live age checkNothing is retained. The audio is discarded on the device after processing.
Age-assurance event log and outcome telemetry6 months
Our own infrastructure and application logs6 months
Request logs held by our infrastructure providers, Cloudflare and Amazon Web ServicesPer each provider's published retention policy. We do not control these periods.
Meeting transcripts and notes12 months from the meeting, then deleted. Notes we have acted on are kept as ordinary business records.
Voice training and evaluation datasets, licensed and directly collectedFor as long as they are needed to develop and evaluate our models, subject to a written purpose-linked retention policy and a documented review at least every 24 months. We do not keep children's voice data indefinitely. Recordings from participants who withdraw consent are removed from future training.
Certification and test records10 years, as required by New York 13 NYCRR Part 700.5(d)
Prospect and beta contact dataUntil you ask us to stop, or the record is pruned as stale. Suppression records are kept so we do not contact you again.
Requests to delete a voice referenceExecuted within 30 days, including propagation to backups

When we no longer need information we delete it or anonymise it. Where that is not immediately possible, for instance because it sits in a backup archive, we isolate it from further processing until it can be deleted.

9. Your rights

You have rights over your personal information, and they work differently depending on which information we are talking about. We would rather explain that than give you a list that turns out not to apply.

Your account information, and information about you as a business contact. All the usual rights are available and actionable. You can ask for a copy, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in portable form, and object to processing we carry out on the basis of legitimate interests. Write to privacy@helix.id and we will respond within one month, or tell you within one month if we need longer and why.

The age check. Nothing from a check is retained by us in a form that could be linked to you. There is no stored record of you here to find, correct or delete. Under Article 11 UK GDPR, where an organisation genuinely cannot identify a person from the data it holds, it is not required to collect extra information about them purely to make these rights actionable, and we are not going to start collecting identifying information in order to be able to answer requests about data we do not keep. If you want to raise something about a decision that was made after a voice check, the business that ran the check holds your account and made the decision, and it is the controller.

A voice reference, if a business uses voice matching. It is on your device, not ours. Clearing that site's data or removing the passkey you set up removes it, and once the key is gone what remains cannot be unlocked by anyone, including us. Because this processing does not rest on your consent, there is no consent to withdraw, but you can object under Article 21 and you can ask the business you are dealing with to delete the reference. Where we hold anything associated with such a request, we act on it within 30 days.

Voice recordings in our licensed training datasets. We want to be straightforward about the limits here. We cannot identify individual speakers in these corpora and we hold no contact details, so we cannot locate one person's recordings on request. If you believe a recording of you or your child is in a dataset we license, contact us at privacy@helix.id and we will work with the dataset provider to trace and remove it. You should also know that deleting a recording does not remove its influence from a model that has already been trained on it. Retraining is the only way to do that, and we would rather say so than imply otherwise.

Voice recordings you made for us as a participant. These are different. We know who you are, because you took part directly, so every right is actionable: you can ask for a copy, ask us to delete your recordings, and withdraw your consent at any time by writing to privacy@helix.id. If you withdraw, your recordings are removed from any future training. The same honest limit applies as above: a model already trained on them cannot be untrained except by retraining.

Objecting to legitimate interests. If you object, we stop unless we can demonstrate compelling grounds that override your interests, or we need the information for legal claims. For sales outreach, which the law treats as direct marketing, the right is absolute: tell us to stop and we stop, with no balancing exercise, and we add you to a suppression list so a later data source does not bring you back.

Withdrawing consent. We rely on your consent for one thing only: recordings you made for us as a paid participant. You can withdraw that at any time, as described above. For everything else we process as controller there is no consent to withdraw, and the right to object is the one that applies. Where a business has asked you to complete a voice check and obtained your consent under a law that requires it, that consent is the business's to manage and you should raise it with them.

Complaints. If you are in the UK you can complain to the Information Commissioner's Office. If you are in the EU you can complain to your national supervisory authority, and you can contact our EU representative. If you are in Switzerland you can contact the Federal Data Protection and Information Commissioner. We would rather hear from you first, but we are not going to pretend that is a condition.

To exercise any of this, email privacy@helix.id or write to the postal address in Section 1.

10. Children

Two different things are true here and it would be misleading to give only one of them.

We do not offer accounts to children and we do not market to them. helix.id is a business-to-business website and Helix does not knowingly create accounts for anyone under 18 through it. Our own voice-data collection is adults only by design.

Our technology exists to work out whether someone is a child, so children encounter it. When a business runs an age check, a child's voice is analysed on the child's own device and discarded, nothing is retained by us, and the result goes to the business, which is the controller and is responsible for its own lawful basis and for telling users and, where applicable, their parents what is happening. Our End-User Processing Notice at https://helix.id/privacy/voice-check describes this in plain terms.

We hold recordings of children's voices in our training datasets, deliberately. A model cannot learn to recognise a child's voice without hearing children's voices. These recordings are licensed from a specialist provider that obtained consent at the point of collection, they are held encrypted with restricted access, they are used only to build and test our age-estimation model, and they are never disclosed to our customers or anyone else. We do not keep them indefinitely: we operate a written retention policy tied to the purpose, with a scheduled review, consistent with the requirements of the US Children's Online Privacy Protection Act. Because these are children's recordings, they attract the specific protection that data protection law requires for children's data, and we weighed that carefully before deciding we could rely on legitimate interests. The ICO's Age Appropriate Design Code shapes how we handle children's data across the product, and this processing is assessed in full in our Data Protection Impact Assessment and our legitimate interests assessment.

If you are a parent or guardian and you have a question about this, write to privacy@helix.id.

11. International transfers

Our servers are in the United States, so information we hold as controller is processed there.

The most sensitive processing does not travel at all. The voice analysis in an age check runs on the user's own device, so the audio, the age estimate and any voice reference never reach our infrastructure, wherever the user is.

What does reach the United States is account and billing data, support correspondence, meeting transcripts and notes, website analytics, the outcome telemetry from the age-assurance service, and recordings from participants in our own voice-data collection. Our anti-bot providers also see a user's IP address while they serve a check.

For transfers from the United Kingdom we rely on the UK Extension to the EU-US Data Privacy Framework, known as the UK-US Data Bridge, where the recipient is certified under it. For transfers from the European Union we rely on the EU-US Data Privacy Framework on the same basis. Where a recipient is not certified, or where the framework ceases to be available, we use the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum as applicable, and we carry out a transfer risk assessment before relying on them. We keep the certification status of our recipients under review. Details are available on request.

12. Keeping information secure

We apply technical and organisational measures appropriate to the information we hold: encryption in transit and at rest, access controls, audit logging of privileged actions, redaction of personal data from application logs at the point they are written, and a restricted, access-controlled store for training datasets. The certified age-assurance service is built so that the sensitive material never leaves the user's device in the first place, which is a stronger protection than anything we could apply to it after the fact.

No system is perfectly secure and we are not going to claim otherwise. If something happens that affects your information and puts you at risk, we will tell you and we will tell the regulator, as the law requires.

13. Information for United States residents

If you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia, you have rights under your state's privacy law.

Categories of personal information we have collected in the past twelve months

CategoryExamplesCollectedNotes
A. IdentifiersName, email, IP address, online identifier, account nameYes
B. California Customer Records categoriesName, contact and financial informationYesBilling history. Card data is held by Braintree.
C. Protected classification characteristicsAge, date of birth, race, ethnicity, other demographic dataYesAge labels attached to voice recordings in our training datasets. We do not collect this from website visitors or account holders.
D. Commercial informationTransaction and payment informationYesBilling history for business accounts.
E. Biometric informationFingerprints and voiceprintsYesVoice recordings in our training datasets, licensed and directly collected. Where a business uses voice matching, a voice reference is created and stays on the user's own device; we do not receive or store it. We do not collect fingerprints.
F. Internet or other network activityBrowsing and usage of our website and servicesYes
G. Geolocation dataPrecise device locationNoWe do not collect precise geolocation.
H. Audio, electronic, sensory or similar informationAudio recordingsYesVoice recordings in our licensed training datasets and from consenting participants in our own collection. Audio from business meetings is transcribed in real time with attendees' agreement and is not retained. Audio from a live age check is processed on the user's device and never reaches us.
I. Professional or employment-related informationJob title, employer, professional backgroundYesBusiness contact information for our customers, for beta applicants and for sales prospecting.
J. Education informationStudent recordsNo
K. InferencesProfiles or summaries drawn from other informationYesAn estimated age band and the model's confidence are recorded against a short-lived random session identifier, which expires after an hour, and kept for up to six months so that we can monitor whether the service is working. We do not build profiles about individuals and we do not use this for any decision about anyone.
L. Sensitive personal informationSee belowYesVoice recordings, and age information attached to them, in our training datasets.

Sources

We collect information directly from you, automatically when you use our website and services, and from third parties. The third-party sources are specialist voice-dataset providers, from whom we license recordings used to train and evaluate our models, and professional networks and public professional sources, from which we obtain business contact information. Section 2.3 explains both, and describes the recordings we collect directly from participants.

Sale and sharing

We have not sold personal information, and we have not shared personal information for cross-context behavioural advertising, in the past twelve months. We do not do either of these things. We have disclosed identifiers and California Customer Records categories to service providers for business purposes, under written contracts, as described in Section 7.

Your rights

Depending on your state, you have the right to know whether we process your personal data, to access it, to get a copy, to correct inaccuracies, to have it deleted, and not to be discriminated against for exercising any of these. You may also have the right to opt out of targeted advertising, sale, or profiling that produces legal or similarly significant effects. We do not carry out targeted advertising, we do not sell personal data, and we do not profile people in that way, so there is nothing to opt out of, but the rights are yours regardless.

Depending on where you live you may also have the right to obtain a list of the categories or the specific third parties we have disclosed data to, to limit the use of sensitive personal information, and, in Florida, to opt out of the collection of personal data through the operation of a voice or facial recognition feature.

On that last one. Our technology is a voice feature, so it is worth being clear. If a business asks you to complete a voice age check, the business is the controller and its own notice should tell you what your choices are, including any alternative route it offers. Helix does not retain anything from the check. If you want to raise it with us directly, write to privacy@helix.id and we will tell you what we hold, which for a completed check is nothing.

To exercise any of these rights, email privacy@helix.id or use the postal address in Section 1. You may use an authorised agent, who will need to show they are authorised. We will verify your identity before we act, using only the information you give us for that purpose. We will respond within 45 days of receiving your request, and if we need longer we will tell you why within that period. If we refuse a request you may appeal by emailing privacy@helix.id, and we will explain our decision in writing. If we refuse the appeal you may complain to your state Attorney General.

California Shine the Light. We do not disclose personal information to third parties for their direct marketing purposes.

Do Not Track. There is still no agreed standard for how sites should respond to Do Not Track signals, so we do not respond to them. We will say so here if that changes.

14. Changes to this notice

We review this notice at least once a year, and whenever we make a material change to what we do with personal information or to the legal basis we rely on. Changes are approved before they are published. We keep every previous version of this notice, together with the record of its approval, and we will provide any earlier version on request so that you can see what applied when your information was collected. The version and date at the top of this notice tell you which one you are reading.

15. How to contact us

By email: privacy@helix.id

By post: H3lix AI Ltd. 1301 N Broadway St, #32355 Los Angeles, CA 90012 United States

By telephone: +1 213 340 6080

Our UK and EU representative:

Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria (EU)

Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom (UK)

Requests: https://app.prighter.com/portal/helix — quote ID-19548739993

Related notices: End-User Processing Notice https://helix.id/privacy/voice-check · Cookie Notice https://helix.id/privacy/cookies · Training Data Provenance Statement https://helix.id/privacy/training-data