Privacy policy
Last updated: 1 February 2026
26 Ventures SAPI de CV, operator of Helios, is responsible for the personal data described in this policy. It explains what we collect through www.usehelios.ai and through the Helios service, why, and what rights you have.
1. Our two roles
Controller: for data collected on this website and from prospective customers, we decide the purposes and means of processing.
Processor: when a customer deploys the service, conversations with that customer's end users are processed on the customer's instructions. In that case the customer is the controller and its own privacy notice applies; requests from end users are forwarded to the customer.
2. Data we collect
Contact data you submit: name, work email, phone, company, role and the content of your enquiry.
Usage data: pages viewed, referrer, approximate location derived from IP, device and browser type, collected through cookies and similar technologies subject to your choices.
Service data processed on behalf of customers: conversation transcripts, call recordings where enabled, contact identifiers and records retrieved from the customer's connected systems.
3. Why we use it
To respond to enquiries and demo requests, and to carry out our pre-contractual and contractual relationship with your organisation.
To operate, secure, support and improve the service, including troubleshooting and abuse prevention.
To send commercial communications where permitted, with an opt-out in every message.
To comply with legal, accounting and regulatory obligations.
4. Legal bases
Depending on your jurisdiction, we rely on the performance of a contract, our legitimate interest in operating and promoting a B2B service, your consent for non-essential cookies and marketing where required, and compliance with legal obligations.
5. Model training
We do not use customer conversations, customer records or personal data processed on behalf of a customer to train foundation models. Model providers used to deliver the service are engaged under terms that prohibit training on this data.
6. Sharing
We share personal data with service providers that host, secure, analyse or support the platform, with communication channel providers required to deliver a message, with professional advisers, and with authorities where legally required. Providers act under written agreements and may not use the data for their own purposes.
We do not sell personal data.
7. International transfers
Data may be processed in countries other than yours, including the United States and the European Union. Transfers are covered by appropriate safeguards such as standard contractual clauses. Data residency options can be agreed for enterprise deployments.
8. Retention
Website and contact data is kept for as long as needed for the purpose collected and for the period required by law. Service data is retained according to the configuration agreed with each customer and deleted or returned at the end of the engagement.
9. Security
We apply encryption in transit and at rest, role-based access control, least-privilege administration, logging and audit trails, and periodic review of our controls. No system is perfectly secure, and we ask you not to send sensitive data through unsecured channels.
10. Your rights
Subject to your jurisdiction, you may request access, rectification, deletion, objection, restriction, portability or withdrawal of consent, including the ARCO rights recognised under Mexican data protection law. Write to privacy@usehelios.ai and we will respond within the applicable legal period. You may also complain to your competent data protection authority.
11. Children
The website and the service are not directed to children and we do not knowingly collect their personal data.
12. Changes and contact
We may update this policy; the date above reflects the latest version. Questions: 26 Ventures SAPI de CV, privacy@usehelios.ai.
