usehelps.com

Data Processing Agreement

Version 1.1 — 8 September 2026

Current version · Stable address of this document: https://www.usehelps.com/legale/en/dpa

This is a courtesy translation of a document written in Italian. In case of any divergence between the two versions, the Italian text prevails.

This agreement supplements the Helps Terms of Service and governs the processing of personal data that we carry out on behalf of the Customer, pursuant to article 28 of Regulation (EU) 2016/679 ("GDPR").

It applies whenever the Customer, by using Helps, entrusts us with personal data of third parties — typically the people they speak to during video calls.

1. The parties

Data controller: the Customer, that is the company or professional who uses Helps.

Data processor: Giuseppe Cristiano Assennato, Contrada Canicassè, 93100 Caltanissetta (CL), Italia — hereinafter "Helps".

The Customer decides which calls to transcribe, what information to enter and for what purposes. Helps carries it out.

2. Subject matter and duration

Subject matter: the provision of the Helps service, as described in the Terms of Service.

Duration: the agreement lasts as long as the contractual relationship between the parties, and remains effective until the data is deleted or returned.

Nature and purpose of the processing: transcription of the audio of video calls, automatic generation of suggestions from the material supplied by the Customer, storage of transcripts and notes so that they can be consulted.

3. What data is involved

Categories of data subjects

Types of data

Special categories of data

Helps is not designed to process data belonging to the special categories provided for by article 9 of the GDPR — health, political opinions, religious beliefs, trade union membership, biometric data, sex life and sexual orientation.

However, since the transcript reproduces the content of a conversation, the Customer acknowledges that such data could emerge in it. It is the Customer's responsibility not to activate Helps on calls where it is foreseeable that data of this kind will be processed, or to put in place the safeguards required by law.

4. Our obligations

Helps undertakes to:

Process only on instruction. We process personal data solely in order to provide the service and in accordance with the Customer's documented instructions. The Terms of Service and the configuration chosen by the Customer constitute those instructions. If we believe that an instruction infringes the law, we say so.

Ensure confidentiality. Anyone with access to the data is bound by confidentiality. Today administrative access is restricted to the founder.

Adopt adequate security measures, described in article 7.

Assist the Customer in responding to requests from data subjects exercising their rights, and with obligations relating to security, breach notification and impact assessments.

Report breaches without undue delay from the moment we become aware of them, providing the information available.

Delete or return the data at the end of the relationship, according to the Customer's choice, save for what the law requires us to keep.

Make available the information necessary to demonstrate compliance with these obligations.

5. The Customer's obligations

The Customer:

On the separation between the members of a team — what the person who leads a team does not see and what they do see — see article 7. It is an organisational measure on which the Customer can rely when assessing their own obligations towards the people who work for them.

6. Sub-processors

The Customer authorises Helps to use the sub-processors listed below, which are necessary for the operation of the service.

Sub-processorWhat it doesWhere it processes the dataBasis of transfer
Supabase (on Amazon Web Services infrastructure)hosts the databaseEuropean Union — Frankfurtno transfer outside the EU
AssemblyAItranscribes the audio of the callsUnited Statesadheres to the EU-US Data Privacy Framework
Anthropicgenerates the suggestions from the textUnited Statesstandard contractual clauses under art. 46 GDPR
Stripehandles paymentsUnited States and European Unionadheres to the EU-US Data Privacy Framework
Brevosends the service emailsEuropean Unionno transfer outside the EU
Vercel, Cloudflarehost the website and the return pagesdistributed networkdo not receive personal data processed on behalf of the Customer: only the browsing traffic of the website

On AssemblyAI the opt-out from the use of data for model training is active, and the retention of audio and transcripts is limited to 24 hours. Anthropic does not use the data of commercial customers to train its models and keeps it for up to 30 days.

If we intend to add or replace a sub-processor we notify the Customer with at least 30 days' notice. The Customer may object on reasonable grounds and, if no solution is found, withdraw from the contract.

We remain responsible for the conduct of the sub-processors.

7. Security measures

Pursuant to article 32 of the GDPR, we adopt the following measures:

Encryption. The data travels over encrypted channels. User passwords are stored only in encrypted form.

Access control. The database applies row-level controls that restrict each account to its own data. Administrative access is restricted to the founder, with two-factor authentication on the services that support it.

Minimisation. We do not keep the audio on our systems: it passes through to the transcription service, which keeps it for a maximum of 24 hours. On our systems only the text remains.

Credential management. The access keys for third-party services are kept in a secret store and rotated periodically.

Location. The database is hosted in the European Union, in the Frankfurt region.

Separation between the members of a team. The person who leads a team has no access to the transcripts of the calls of individual members, to their consumption — hours, runs, sessions — or to assessments, scores, per-person statistics or comparisons between users: Helps produces none of these. The separation is enforced by the row-level access controls of the database, and it is not a setting that the Customer or the team leader can change.

What the team leader sees is what a member chooses to share. Whoever shares an objection/answer pair on the Board makes it visible to the whole team, including the leader, with their own name, the date and the provenance — that is, whether the answer comes from a deal. That text may contain a sentence spoken by someone on a call, and it is not subject to the transcript retention periods set out in the privacy policy. The difference between the two halves is who decides: transcripts, consumption and assessments are what the service collects by itself; a share is an act of the member.

The choice of the transcript retention period is also per individual account: the person who leads a team cannot impose it on the members.

8. Transfers outside the European Union

Transfers to the United States sub-processors take place on the basis of the safeguards indicated in the table in article 6:

AssemblyAI and Stripe adhere to the EU-US Data Privacy Framework, the adequacy framework adopted by the European Commission in July 2023. No further safeguards are required towards certified entities.

Anthropic does not adhere to the Data Privacy Framework and bases transfers on standard contractual clauses pursuant to article 46 of the GDPR, incorporated into its own data processing agreement.

9. Audits

The Customer may ask us for the information necessary to verify compliance with this agreement.

More in-depth audits are to be agreed in advance, carried out during working hours and without interfering with the service. The Customer bears the cost of them, unless the audit reveals a breach on our part.

10. What happens at the end

At the end of the relationship, at the Customer's request, we delete or return the personal data processed on their behalf.

The Customer may at any time export their own data from the application independently, in a readable format.

We keep only what the law requires us to keep.

11. Liability and governing law

The limitations of liability provided for by the Terms of Service apply, to the extent permitted by law.

The agreement is governed by Italian law.

12. Changes to this agreement

We may change this agreement. We tell you with at least 30 days' notice, using the same mechanism that article 6 provides for sub-processors: within that period you may object on reasonable grounds and, if no solution is found, withdraw from the contract.

Version 1.1 of this agreement is notified with that notice period, and comes into force on its expiry.

13. Contacts

privacy@usehelps.com