Privacy Policy
Last updated: 14 September 2026
1. Who is the data controller?
The data controller for your personal data is Nira Wealth Ltd, trading as Helix (the "Company", "we", "us"), registered in England and Wales under company number 17098405.
Contact: hello@helix.money. Data Protection Officer: legal@helix.money.
2. What data we collect
Depending on how you use Helix, we collect:
- Wallet address(es) you provide to view your claim history.
- Claim metadata you submit: amount, recipient phone (if you choose to provide one), recipient name, optional note, your sender wallet address.
- On-chain data that is publicly visible on Base: your sender address, recipient address, transaction hashes, timestamps, amounts. We read this from public RPC endpoints.
- Local-only data stored in your browser (localStorage) when you opt to "remember" your wallet address on the dashboard. We do not see this data; it stays on your device.
- Server logs (IP address, user agent, request path) for security and abuse prevention, retained for up to 30 days.
- Cookie-equivalent data for session continuity. We do not use third-party tracking cookies or pixels.
We do not collect: name, address, government ID, date of birth, biometric data, or financial account credentials. For fiat ramps, those data are collected directly by our regulated partner (BVNK Limited) under their own privacy policy.
3. How we use your data
We use the data we collect to:
- Operate the Service: create claim links, broadcast on-chain transfers, read public blockchain state, display your claim history.
- Prevent abuse: rate-limit API requests, detect anomalies, block Prohibited-Use activity.
- Comply with law: respond to lawful requests from UK authorities, law enforcement, and regulators.
- Improve the Service: aggregate, de-identified analytics (e.g., "X claims created today") — never tied to a wallet address.
We do not sell, rent, or share your personal data with marketers, data brokers, or advertisers.
4. Lawful basis (UK GDPR)
Under the UK GDPR / Data Protection Act 2018, we rely on the following lawful bases:
- Contract (Art. 6(1)(b)) — to provide the Service you have requested.
- Legitimate interests (Art. 6(1)(f)) — to keep the Service secure and prevent fraud.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law (e.g., responding to NCA requests).
- Consent (Art. 6(1)(a)) — only if you opt into optional features (e.g., newsletter).
5. Data sharing
We share data only with:
- Supabase Inc. — our database host (claims, notifications). Data is stored in the EU/UK region (us-east-1 / eu-west-2 depending on plan). Supabase acts as a data processor under our written instructions.
- Cloudflare, Inc. — our hosting and edge provider. They process server logs and TLS metadata.
- Alchemy, Inc. — our Base blockchain RPC provider. They see our public node queries; the queried wallet addresses are not personally identifying on their own.
- Regulated partners (currently BVNK Limited) — when you initiate a fiat ramp, your data is shared with them only to the extent needed to complete the ramp.
- Law enforcement or regulators — when required by valid legal process, or to report suspected sanctions evasion or money laundering.
We never sell your data, and we do not share it with marketing networks or analytics resellers.
6. International transfers
Some of our processors (Supabase, Cloudflare, Alchemy) may store or process data outside the UK/EEA. Where this happens, we rely on:
- Standard Contractual Clauses (SCCs) for transfers from the UK/EEA to third countries.
- The UK International Data Transfer Agreement (IDTA) where the recipient is in a non-adequate country.
- Processor commitments to equivalent security measures (encryption at rest, encryption in transit, access controls).
7. Data retention
We keep data only as long as we need it for the purposes described, or as required by law. Specifically:
- Claim records: 7 years from creation (UK statutory retention for financial records).
- Server logs: 30 days, then deleted.
- Backups: 30 days rolling.
- On-chain data: retained by the Base blockchain indefinitely (we cannot delete it).
8. Your rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate data.
- Erasure ("right to be forgotten") in some circumstances.
- Restriction of processing in some circumstances.
- Data portability — receive your data in a machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, email legal@helix.money with a description of your request. We will respond within 30 days. Note that some rights are limited where we have a legal obligation to retain data (e.g., 7-year financial records retention).
9. Security
We protect your data with industry-standard measures: encryption in transit (TLS 1.2+), encryption at rest in our database, role-based access controls on the server side, no client-side access to sensitive data, regular dependency updates, and infrastructure-level DDoS protection via Cloudflare.
You are responsible for the security of your own wallet, browser, and devices. We cannot recover your funds if your private key is stolen, leaked, or lost.
10. Cookies and similar
The Service uses only strictly-necessary localStorage entries (e.g., to remember your last-viewed wallet address on the dashboard) and no tracking cookies. We do not embed third-party analytics, advertising, or social-media scripts that would set cookies.
11. Children
The Service is not directed at children under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a child has used the Service, contact us and we will delete any data we hold.
12. Changes to this policy
We may update this policy. Material changes will be announced via the Service or by email. The "Last updated" date above will change when we do.
13. Contact and complaints
For any privacy question, email legal@helix.money.
You can also complain to the UK Information Commissioner's Office: ico.org.uk/make-a-complaint.
This privacy policy is a draft and has not been reviewed by a qualified lawyer. It is provided for transparency. Do not rely on this text as legal advice.