Last updated: July 3, 2026
This Data Processing Agreement ("DPA") is incorporated into and forms part of the Helion Terms of Service between Helion Labs, operated by Lalit Shrotriya ("Helion", "we", "us"), and the customer ("Controller", "you"). It applies where Helion processes personal data on your behalf as part of the Helion Cloud service.
1. Definitions
- GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council.
- DPDP Act means India's Digital Personal Data Protection Act, 2023.
- Controller means you, the customer, who determines the purposes and means of processing Your visitors' data.
- Processor means Helion, who processes data on your behalf.
- Personal Data, Processing, and Data Subject carry the meanings given to them under the GDPR and/or the DPDP Act, as applicable to your location.
- Sub-processor means any third party engaged by Helion to process Personal Data in connection with the Service.
2. Our Approach to Privacy
Helion is built to minimize personal data collection by design. We do not use cookies for analytics tracking, and We do not store IP addresses. Instead, We generate an anonymous identifier from a hash of the visitor's IP address, user agent, and project ID, combined with a rotating salt. The raw IP address is discarded immediately, and the identifier cannot be linked back to an individual once the salt rotates.
The data We store per event is:
- Page URL and referrer
- Browser name and version
- Operating system name and version
- Device type, brand, and model
- City, country, and region (derived from IP at request time; IP then discarded)
- Custom event properties You choose to send
No persistent identifiers, no cookies, no cross-site tracking.
Session replay (optional feature)
Helion optionally supports session replay, which must be explicitly enabled by You. When enabled, it records DOM snapshots and user interactions (mouse movements, clicks, scrolls) on Your website using rrweb. This may incidentally capture personal data visible on the page. Text content and form inputs are masked by default. You are responsible for ensuring Your use of session replay complies with applicable privacy law, including giving Your own end users appropriate notice.
AI features
Helion's codebase includes optional AI features (natural-language queries over analytics data, anomaly insights, AI-assisted reports). These are not currently enabled on this deployment, and no data is sent to any AI/LLM provider today. If We enable these features in the future, We will update this DPA and this Section in advance, naming the provider used and the safeguards in place.
3. Scope and Roles
Helion acts as a Processor when processing data on Your behalf. You act as the Controller for the analytics data collected from visitors to Your websites and applications.
4. Processor Obligations
We commit to:
- Process Personal Data only on Your documented instructions and for no other purpose.
- Ensure personnel with access to Personal Data are bound by confidentiality obligations.
- Implement and maintain the technical and organizational measures described in Section 7.
- Not engage a Sub-processor without informing You in advance, and flow down equivalent data protection obligations to any Sub-processor.
- Assist You, where reasonably possible, in responding to requests from Your data subjects to exercise their rights.
- Notify You without undue delay (and no later than 72 hours) upon becoming aware of a Personal Data breach affecting Your data.
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
- At Your choice, delete or return Personal Data upon termination of the Service.
5. Your Obligations as Controller
You confirm that:
- You have a lawful basis for the processing described in this DPA.
- You have provided appropriate privacy notices to Your own end users.
- You are responsible for the accuracy and lawfulness of the data You instruct Helion to process.
6. Sub-processors
We use a small number of third-party sub-processors to deliver the Service — currently limited to cloud infrastructure hosting and transactional email delivery. For security reasons, We do not publish the specific identity or location of Our infrastructure provider in this public document. If You require this information for Your own records of processing activities (for example, for an EU customer's Article 30 records), contact Us and We will provide it directly along with the relevant safeguards in place (such as Standard Contractual Clauses, where applicable).
We do not currently use any billing provider or AI/LLM sub-processor — both exist as optional, currently-disabled integrations in Helion's codebase. We will inform You of any intended change to Our sub-processors, including any new addition, with reasonable advance notice, and You will have the opportunity to object.
7. Technical and Organizational Measures
Data minimization and anonymization
- IP addresses are never stored; they are used only to derive geolocation and generate an anonymous identifier, then discarded.
- Rotating cryptographic salts ensure visitor identifiers cannot be reversed or linked to individuals once the salt rotates.
- No cookies or persistent cross-device identifiers are used for analytics.
Access control
- Dashboard access is protected by authentication and role-based access control.
- Production systems are accessible only to authorized personnel.
Encryption and transport security
- All data is transmitted over HTTPS (TLS).
Incident response
- We maintain procedures for detecting, reporting, and investigating Personal Data breaches, and will notify You within 72 hours of becoming aware of one affecting Your data.
Open source
- Helion's codebase is publicly available, allowing independent review of Our data handling practices.
8. International Data Transfers
Where Personal Data is transferred outside Your country or the EEA to one of Our sub-processors, such transfers are governed by the safeguards available under applicable law, including Standard Contractual Clauses (Commission Decision (EU) 2021/914) where applicable to EEA-originating data.
9. Data Retention and Deletion
Analytics events are retained for as long as Your account is active; We do not currently enforce a maximum retention period. Session replays, if enabled, are retained for 30 days and then permanently deleted. You can delete individual projects, all associated data, or Your entire account at any time from the dashboard. On termination, We delete Your data within 30 days unless legally required to retain it longer.
10. Governing Law
This DPA is governed by the laws of India, and the courts of Mumbai, Maharashtra shall have exclusive jurisdiction over any dispute arising from it, without prejudice to any mandatory rights You may have under the GDPR or the DPDP Act as applicable to You.
11. How to Execute This DPA
Using Helion Cloud constitutes acceptance of this DPA as part of Our Terms of Service. If Your organization requires a signed copy for its own compliance records, You can download a pre-signed version below and countersign it — no need to send it back to Us.
Contact
- Email: hello@helionlabs.dev
- Operated by: Lalit Shrotriya, Mumbai, Maharashtra, India