Candidate for legal review

Privacy Notice

Version 1.0 · Effective: 14 August 2026

This Privacy Notice explains how Helena Bioinformatics EOOD processes personal data when acting as a controller for its websites, accounts, communications and business operations. It also explains the separate situation in which Helena processes clinical or genomic data on documented instructions from a customer that acts as controller.

This Notice is information under Articles 13 and 14 GDPR. Acknowledging it does not create consent and does not replace a Data Processing Agreement or a specific consent where consent is the applicable legal basis.

1. Controller and privacy contact

For controller activities, the controller is Helena Bioinformatics EOOD, UIC 208673837, 14 Tsar Ivan Asen II Street, floor 1, apartment 1, 1142 Sofia, Bulgaria. Contact: privacy@helena.bio.

The privacy email is Helena’s data-protection contact. It should not be interpreted as a formal designation of a data protection officer unless Helena separately publishes such a designation.

2. Our roles

Helena acts as controller for account registration, identity and access management, legal acceptance evidence, security records, support, demo and contact requests, website operation, product communications, billing administration and its own legal compliance.

A laboratory, healthcare provider, researcher or other customer normally acts as controller for patient, sample, phenotype, genomic and case data submitted to a private workspace. Helena acts as processor for that data under the customer’s documented instructions and the applicable DPA. Data subjects should normally direct requests about such data to the relevant customer.

3. Data we process as controller

Identity and account data: name, professional and organizational affiliation, role, email, language, account profile, organization relationships, status and password hash. Helena does not store the account password in readable form.

Contract and compliance data: accepted legal-document version and digest, acceptance time and source, contracts, approvals, communications and records needed to establish or defend legal claims.

Security and technical data: IP address where logged by infrastructure, device and browser information, session and token identifiers, timestamps, request identifiers, authentication events, audit events, error and diagnostic data.

Communication and business data: contact, demo, support and partnership requests; correspondence; scheduling information; billing contact, customer and subscription identifiers when paid billing is enabled. Payment-card details are collected by Stripe and are not stored by Helena.

Public-service interaction data: public search requests and bounded questions sent to the public AI assistant. Users must not submit patient identifiers or confidential case information to public features.

Optional integration data: when a user deliberately links a supported external account, Helena may process the identifier and encrypted connection state needed for that integration. The product will identify the integration and may require additional notice before activation.

4. Customer-controlled clinical and genomic data

Depending on customer configuration, processor data may include pseudonymized sample identifiers, VCF and other variant data, phenotype terms, family relationships, analysis parameters, clinical notes supplied by the customer, generated evidence and reports, provenance and access records.

Genetic and health data are special-category data. The customer, not Helena, determines the applicable Article 6 and Article 9 GDPR bases and must ensure that direct identifiers are not uploaded unless expressly agreed. Helena processes this data only under documented instructions, except where Union or Member State law requires otherwise.

5. Purposes and legal bases for controller processing

Contract and pre-contract steps (Article 6(1)(b)): create and operate accounts, provide requested services, authenticate users, handle support and administer subscriptions.

Legal obligations (Article 6(1)(c)): tax and accounting records, legally required security or breach actions, regulatory cooperation and responses to lawful requests.

Legitimate interests (Article 6(1)(f)): secure the Service, prevent abuse, maintain auditability, diagnose faults, improve reliability, respond to business contacts and establish or defend legal claims. Helena balances these interests against individual rights and applies minimization and access controls.

Consent (Article 6(1)(a)): non-essential analytics or marketing communications where consent is required. Consent is optional, may be withdrawn at any time and does not affect earlier lawful processing. Essential authentication and security processing is not based on consent.

6. Sources and required information

We receive data directly from you, from an organization that invites or administers you, from a distributor or laboratory establishing an approved relationship, from service providers operating on our behalf, and automatically from devices and systems when the Service is used.

Information marked as required is necessary to create and secure an account or perform a contract. Without it, Helena may be unable to provide the requested account or feature. Optional analytics and marketing choices do not affect essential access.

7. Recipients and service providers

Hetzner Online GmbH provides EU server and infrastructure hosting. Vercel Inc. provides delivery and hosting for public websites and frontend applications and may receive network and usage metadata, but is not intended to receive private genomic case content.

Resend provides transactional email delivery and receives recipient email, message content and delivery metadata. Google services may process consent-based website analytics and information needed to handle contact requests or schedule demonstrations. OpenAI processes bounded public assistant content; the public assistant is not intended for patient or private case data and provider storage is disabled in Helena’s configured request.

Stripe will process billing identity, transaction and payment information as an independent controller and/or processor under its own terms when paid billing is enabled. Payment-card data is entered into Stripe-hosted surfaces. MEGA or another user-selected integration processes data only when the user enables that integration.

Professional advisers, auditors, insurers, public authorities and courts may receive data where necessary and lawful. We do not sell personal data. A current provider register should be reviewed together with this Notice because providers and legal entities may change.

8. International transfers

Private genomic workloads are designed to run on Helena-controlled infrastructure in the European Economic Area. Public website, email, analytics, support, payment and public-AI providers may process limited personal data outside the EEA.

Where a recipient is outside the EEA and no adequacy decision applies, Helena uses an applicable transfer mechanism such as the European Commission’s Standard Contractual Clauses together with supplementary measures where required. You may request information about the relevant safeguards at privacy@helena.bio. No customer-controlled clinical data is sent to an external AI provider unless the customer agreement, product mode, DPA and required safeguards expressly allow it.

9. Retention

Account and organization data is kept while the account is active and afterwards only for the period necessary for closure, security, legal, tax and claims purposes. Verification and abandoned pending-account data is removed or anonymized according to an operational retention schedule.

Legal acceptance and contract evidence is retained for the applicable limitation period and any additional period required to establish compliance, subject to access restrictions and applicable erasure rights. Security, audit and diagnostic records are retained according to risk-based schedules and are not represented as having a fixed period unless that schedule is operationally enforced.

Customer-controlled clinical and genomic data is retained for the period selected in the applicable order or DPA. Deletion from active systems and backup expiry follow documented technical procedures. Helena will not promise automatic permanent deletion within a particular period unless that period is configured and supported for the relevant service.

Provider records may remain under the provider’s lawful retention rules. Helena periodically reviews retention and documents any legal hold.

10. Security

Helena applies risk-appropriate technical and organizational measures, including access control, least privilege, credential hashing, encryption in transit, network restrictions, logging, monitoring, backup and recovery controls, vulnerability management and incident procedures. The precise measures applicable to customer-controlled data are stated in the DPA and may evolve without reducing the overall level of protection.

No system is completely secure. Users must protect their credentials and promptly report suspected compromise. Helena will notify controllers and individuals of personal-data breaches where and within the periods required by law and contract.

11. Cookies and similar technologies

Authenticated services use strictly necessary storage for security, authentication, language and session continuity. Public websites may use consent-based analytics. Non-essential analytics is disabled until the visitor chooses to allow it, and the choice can be changed through the analytics settings.

We do not intentionally send genomic search expressions, variant coordinates, patient data, authenticated case content or result URL parameters to website analytics.

12. Automated processing

Helena uses automated analysis and prioritization to support qualified users. Helena does not use controller-side account data to make a solely automated decision that produces legal or similarly significant effects on an individual. Clinical users remain responsible for review and decisions based on analysis outputs.

If this changes, Helena will provide the information and safeguards required by Articles 13, 14 and 22 GDPR before the processing begins.

13. Your rights

Subject to applicable conditions, you may request access, correction, erasure, restriction, portability or objection, and may withdraw consent where processing is based on consent. You may also complain to the Bulgarian Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria, or another competent supervisory authority.

Send controller-side requests to privacy@helena.bio. Helena may verify identity and normally responds within one month, subject to lawful extensions. For patient or customer-workspace data, contact the relevant laboratory or customer as controller; Helena will assist it under the DPA.

14. Children

The account Service is not directed to children and account holders must be at least 18. Patient data concerning children may be processed only when submitted by an authorized controller with an appropriate legal basis and safeguards.

15. Changes and versioning

Each version of this Notice is identified by version, language and effective date and is preserved in an immutable archive. Material changes are communicated to registered users. Where acknowledgement is required, Helena records the exact document version and digest presented to the user.

A new Notice does not retroactively alter the lawfulness of earlier processing. If a new purpose requires consent or another action, Helena will obtain it separately before that processing.

16. Contact

Questions, requests and requests for transfer-safeguard information may be sent to privacy@helena.bio or by post to the registered address above.

Helena Bioinformatics EOOD · UIC 208673837

14 Tsar Ivan Asen II Street, floor 1, apartment 1, 1142 Sofia, Bulgaria

legal@helena.bio · privacy@helena.bio