Helix Data Processing Addendum

Data protection terms for Customer Data processed by Helix

Effective date: August 29, 2026

1. Parties and scope

This Data Processing Addendum ("DPA") is entered into between the Customer that has accepted or signed an agreement for the Service ("Customer") and the Helix entity identified in the applicable order form, account registration, or commercial agreement ("Helix"). This DPA forms part of the agreement between the parties (the "Agreement").

To the extent Helix processes Personal Data on behalf of Customer in connection with the Service, Customer acts as the controller or business and Helix acts as the processor or service provider, as those terms or analogous terms are defined under applicable data protection law. If Customer acts as a processor for another controller, Helix acts as Customer's subprocessor.

2. Definitions

3. Customer instructions

Helix will process Personal Data only on Customer's documented instructions, including instructions embodied in the Agreement, Customer's configuration and use of the Service, repository connections, support requests, and other documented directions, unless processing is required by applicable law. If law requires processing beyond Customer's instructions, Helix will inform Customer before processing unless prohibited by law.

4. Nature, purpose, and duration of processing

5. Customer responsibilities

Customer will ensure it has a lawful basis and all necessary rights, notices, and consents to provide Personal Data to Helix for processing under the Agreement.

Customer is responsible for determining whether the Service is appropriate for the categories of data and regulatory obligations applicable to Customer.

Customer will configure source-control permissions, repository access, user invitations, and administrative controls consistent with Customer's legal and security requirements.

Customer will not intentionally use the Service to process data subject to additional contractual or regulatory requirements unless the parties have agreed in writing to the necessary controls or additional terms.

6. Confidentiality

Helix will ensure that personnel authorized to process Personal Data are subject to confidentiality obligations and access Personal Data only as necessary to perform their responsibilities.

7. Security measures

Helix will maintain administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or disclosure. These safeguards include, as appropriate to the Service, authentication and authorization through approved identity or source-control providers, access restrictions, and security monitoring and logging.

Customer acknowledges that security is a shared responsibility and remains responsible for its own accounts, endpoints, credentials, tokens, source-control configuration, and user administration.

8. No model training

Helix will not use Customer Data, including source code, repository content, Personal Data, or derived architectural representations, to train Helix models or third-party models.

9. Model and cloud processing

The Service is primarily hosted on Google Cloud Platform. Lens primarily uses models hosted within Helix-controlled Google Cloud infrastructure. For selected tasks, Helix may use Google Cloud services such as Vertex AI to process Customer Data using third-party model infrastructure. Such processing is limited to providing the Service and is subject to Helix's applicable agreement with the provider and the restrictions in this DPA.

10. Subprocessors

Customer authorizes Helix to engage third-party service providers that process Personal Data on Helix's behalf in providing the Service (legally referred to as "subprocessors"). Helix's current subprocessors are identified in Schedule B to this DPA. Helix will require each subprocessor that processes Personal Data to protect the data under obligations materially consistent with the protections applicable to Helix under this DPA, as appropriate to the services performed.

Helix may add, replace, or remove subprocessors as the Service evolves. Where required by applicable law or a negotiated enterprise agreement, Helix will provide reasonable notice of a material new subprocessor and an opportunity for Customer to raise a good-faith data protection objection. If the parties cannot reasonably resolve an objection, either party may terminate the affected Service as provided in the applicable Agreement. The then-current version of this DPA will identify Helix's current subprocessors in Schedule B.

11. Data subject requests

Taking into account the nature of the processing, Helix will provide commercially reasonable assistance to Customer in responding to verified requests from individuals to exercise applicable privacy rights relating to Personal Data processed by Helix on Customer's behalf. If Helix receives such a request directly and can identify the relevant Customer, Helix will direct the requester to Customer or notify Customer, unless prohibited by law.

12. Security incidents

Helix will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data processed by Helix on Customer's behalf. The notice will include information reasonably available to Helix regarding the nature of the incident, affected data, likely consequences, and measures taken or proposed to address the incident. Helix's notification is not an admission of fault or liability.

13. Assistance and compliance information

Taking into account the nature of the processing and information available to Helix, Helix will provide commercially reasonable assistance with Customer's obligations relating to security, breach notification, privacy impact assessments, and regulator consultations where required by applicable law. Helix may satisfy audit or information requests by providing available security documentation, questionnaires, summaries, certifications, or independent assessment materials. On-site audits are subject to reasonable confidentiality, scope, scheduling, and cost requirements and are available only where required by applicable law or expressly agreed in writing.

14. Return and deletion

During the term, Customer may disconnect or unlink repositories using available Service controls. When an authorized user disconnects a repository, Helix deletes the repository source code and associated Lens-derived repository data from the active Helix environment. Upon termination of the Agreement, Helix will delete or return Personal Data as required by the Agreement and applicable law, unless retention is legally required. Data in backups, if any, will be removed in accordance with the applicable backup lifecycle and will remain protected until deleted.

15. International transfers

The standard Service is currently hosted in a U.S. Central Google Cloud region. If Personal Data is transferred from a jurisdiction that restricts international transfers, the parties will use a legally recognized transfer mechanism where required, which may include applicable standard contractual clauses or another valid mechanism. Enterprise deployment in another region or a customer-controlled cloud environment may be available by written agreement.

16. U.S. service-provider commitments

Where U.S. state privacy law applies and Helix acts as a service provider, processor, or contractor, Helix will process Personal Data only for the limited and specified purposes described in the Agreement; will not sell Personal Data; will not retain, use, or disclose Personal Data outside the direct business relationship with Customer except as permitted by applicable law; and will not combine Personal Data with personal information received from another person or collected from Helix's own interactions with an individual except as permitted by applicable law.

17. Order of precedence

If there is a conflict between this DPA and the Agreement regarding processing of Personal Data, this DPA controls to the extent of that conflict. A signed enterprise data protection addendum or security addendum may modify this DPA for the applicable Customer.

18. Contact and notices

Data protection notices to Helix may be sent to srinivas.palepu@gethelixworks.com. Customer notices will be sent to the administrative or legal contact associated with the Customer account or order form.

Schedule A - Current processing environment

Schedule B - Third-Party Service Providers

This schedule identifies third parties that may process Customer Personal Data on Helix's behalf in providing the Service. In data-protection law these providers may be referred to as “subprocessors.” Customer-selected source-control systems such as GitHub and GitLab are described separately because they primarily act as Customer-directed integrations and authentication/authorization sources rather than as Helix-selected processing vendors.

Customer-directed integrations. GitHub and GitLab are currently used for sign-in and repository authorization. They are selected or authorized by the Customer, and Lens is designed to respect the permissions made available through those systems together with Helix organization controls. They are not listed above as Helix-selected subprocessors solely because a Customer chooses to connect its account to those services.

Payment provider. No payment provider is currently included because Helix does not currently process payments through a third-party payment service. If a payment provider is enabled in the future, this Schedule will be updated before that provider processes Customer Personal Data on Helix's behalf.

Model-training restriction. No provider listed in this Schedule is authorized by Helix to use Customer Data to train Helix models, provider models, or other third-party models.

Schedule B last updated: August 29, 2026

Purpose: This DPA supplements the agreement governing the Customer's use of the Helix services. It applies where Helix processes personal data on behalf of Customer in connection with the Service.
TermMeaning
Customer DataData submitted to, stored in, or processed by the Service on Customer's behalf, including repository content, source code, metadata, derived architectural representations, and related account or usage data.
Personal DataInformation relating to an identified or identifiable natural person, or equivalent personal information protected by applicable data protection law, contained in Customer Data.
ProcessingAny operation performed on Personal Data, including collection, storage, access, analysis, transmission, generation, deletion, or other use.
SubprocessorA third party engaged by Helix to process Personal Data on Helix's behalf in providing the Service.
Security IncidentA confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Helix on Customer's behalf.
CategoryDescription
Subject matterProvision of Lens and related Helix software engineering services.
Nature and purposeHosting and processing authorized repositories; generating and maintaining architectural representations and related context; authenticating users; enforcing permissions; operating, securing, monitoring, supporting, and improving Service performance.
DurationFor the term of the Agreement and for the period necessary to complete deletion or comply with applicable legal obligations.
Data subjectsCustomer personnel, contractors, repository contributors, and other individuals whose Personal Data may appear in Customer Data.
Types of dataBusiness contact and account information; repository and source-code content; commit metadata; identifiers; access and permission information; usage, diagnostic, and security data; and any Personal Data a Customer chooses to include in a connected repository.
Sensitive dataThe Service is not designed to require special-category or highly regulated personal data. Customer should not intentionally place regulated personal data in repositories unless Customer has determined such processing is lawful and appropriate for the Service and has any required agreement with Helix.
Binding processing restriction: Helix will not use Customer Data, including source code, repository content, Personal Data, or derived architectural representations, to train Helix models or third-party models.
AreaCurrent posture
Primary hostingGoogle Cloud Platform (standard environment: U.S. Central region).
Primary model environmentModels hosted within Helix-controlled Google Cloud infrastructure.
Frontier model processingSelected tasks may use Google Cloud / Vertex AI under Helix's agreement with Google.
Authentication / repository authorizationCustomer-selected source-control and identity integrations, currently GitHub and GitLab; access is constrained by source-system permissions and Helix organization controls.
TrainingCustomer Data is not used to train Helix models or third-party models.
DeletionDisconnecting a repository deletes its source code and associated Lens-derived repository data from the active Helix environment.
Alternative deploymentAlternative regions or deployment in a customer-controlled cloud environment may be available through an enterprise agreement.
ProviderPurposeProcessing locationData involved
Google Cloud Platform (Google LLC / applicable Google contracting entity)Cloud hosting, storage, compute, networking, security monitoring, logging, analytics infrastructure, and operation of Helix-hosted models.United States (standard environment: U.S. Central); other regions may be available by agreement.Source code, repository content and metadata, derived architectural representations, account/usage data, logs, and other Customer Data necessary to provide the Service.
Google Cloud Vertex AI (Google LLC / applicable Google contracting entity)Selected frontier-model processing when a task requires model capabilities beyond Helix-hosted models.Google Cloud processing locations configured by Helix for the applicable Service; standard service is operated from the United States unless otherwise agreed.Only the Customer Data and context necessary for the selected model request. Customer Data is not authorized for model training.
Google Workspace / Google services (Google LLC / applicable Google contracting entity)Business email and service communications where Customer contact information or support communications are processed through Helix's Google-managed business services.United States and other locations used by Google in accordance with the applicable Google service terms.Business contact information and communications; not used as the primary repository-processing environment.