Privacy Policy
Last updated: March 16, 2026
Helia ("we", "us", "our") operates the helia.tel website and the Helia SaaS platform (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service.
1. Information We Collect
We collect the following types of information:
- Account Information: When you register, we collect your email address and password (encrypted).
- Organization Data: Business name, address, phone number, timezone, and business type.
- Appointment Data: Customer names, phone numbers, email addresses, appointment dates and times, and service details.
- Calendar Data: When you connect Google Calendar, Microsoft Outlook, or CalDAV calendars, we access calendar events to check availability and sync appointments. We only read and write events related to your Helia bookings.
- Voice & Chat Data: When customers interact with the AI assistant via phone or chat, we process the conversation to fulfill booking requests. Voice calls are processed in real-time and are not permanently recorded.
- Usage Data: We collect anonymous analytics data (via Google Analytics) including pages visited, browser type, and device information.
2. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Process and manage appointment bookings
- Synchronize appointments with your connected calendars
- Send booking confirmations and reminders via email or SMS
- Improve the AI assistant's ability to handle booking requests
- Provide customer support
- Detect and prevent fraud or abuse
3. Third-Party Services
We use the following third-party services to operate Helia:
- Supabase: Database hosting and authentication (EU data center)
- Google Gemini: AI language model for voice and chat conversations
- Twilio: Phone call handling and SMS delivery
- Google Calendar API: Calendar synchronization (with your explicit consent via OAuth)
- Microsoft Graph API: Outlook calendar synchronization (with your explicit consent via OAuth)
- Fly.io: Application hosting (Frankfurt, Germany data center)
- Google Analytics: Anonymous usage statistics
- SendGrid: Transactional email delivery
- Stripe: Payment processing (we never store credit card numbers)
4. Google API Scopes
When you connect Google Calendar, Helia requests the following OAuth scopes:
https://www.googleapis.com/auth/calendar.events — To read and write calendar events for appointment synchronization.
Helia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Data Storage & Security
Your data is stored in EU-based data centers (Supabase in Zurich, Switzerland; Fly.io in Frankfurt, Germany). We use industry-standard encryption (TLS 1.2+) for all data in transit and encrypt sensitive data at rest. Access to production systems is restricted to authorized personnel only.
6. Data Retention
We retain your data for as long as your account is active. When you delete your account, we remove all associated data within 30 days. Calendar OAuth tokens are revoked immediately upon disconnection.
7. Your Rights (GDPR)
If you are located in the European Economic Area, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability
- Withdraw consent at any time
To exercise any of these rights, contact us at privacy@helia.tel.
8. Cookies
Helia uses essential cookies for authentication (session management) and Google Analytics cookies for anonymous usage tracking. You can disable analytics cookies in your browser settings without affecting the Service.
9. Children's Privacy
Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy, please contact us: