Helm CFO Inc. ("Helm," "we," "us," or "our") provides an AI-powered financial operations platform for early-stage companies. This Privacy Policy explains how we collect, use, disclose, retain, and protect information in connection with our website at helmcfo.com (the "Website") and our software platform, applications, and related services (together, the "Service").
This Policy applies to information about our customers, the individual users authorized to access the Service on a customer's behalf, prospective customers, website visitors, and other individuals who interact with us.
Please read this Policy carefully. If you do not agree with it, do not use the Website or the Service.
Section 1Our Two Roles: Controller and Processor
The Service is a business-to-business product. It is important to understand that we handle two different kinds of information in two different capacities.
Account Information — we act as a controller. When you create an account, contact us, subscribe to communications, browse the Website, or communicate with our team, we determine how that information is used. This Policy governs that information in full.
Customer Data — we act as a processor (service provider). When a customer connects an accounting system, billing platform, or other data source, or uploads documents, we receive that customer's business and financial records ("Customer Data"). We process Customer Data only to provide the Service to that customer, on that customer's instructions, and as permitted by our Terms of Service and any applicable Data Processing Addendum ("DPA"). We do not determine the purposes for which Customer Data is processed.
If you are an individual whose personal information appears inside a customer's Customer Data — for example, as a vendor, contractor, employee, or contact in their accounting records — and you wish to exercise rights over that information, please contact the customer directly. They are the controller of that data. If you contact us, we will refer you to them or assist them in responding, as required by law and by our agreement with them.
Customers who require a DPA, including Standard Contractual Clauses where applicable, may request one at privacy@helmcfo.com.
Section 2Information We Collect
2.1 Information You Provide to Us
- Account and identity information. Name, business email address, telephone number, job title, company name, and password or federated login identifier.
- Company profile information. Entity type, jurisdiction of incorporation, fiscal year, industry, headcount, funding stage, and similar business attributes you enter to configure the Service.
- Billing information. Billing contact, billing address, subscription plan, and transaction history. We do not collect or store full payment card numbers. Card details are collected and processed directly by our payment processor.
- Communications and support content. Messages, support tickets, survey responses, call and meeting notes, and any attachments you send us.
- Content you upload. Documents, spreadsheets, financial models, contracts, invoices, receipts, and other files you choose to upload to the Service.
- Prompts and instructions. The questions, instructions, and context you submit to the Service's AI features.
2.2 Information We Collect From Connected Systems
With your explicit authorization, the Service connects to third-party systems you already use and retrieves data from them. Section 3 describes these connections in detail. Categories include accounting and general ledger data, billing and subscription revenue data, expense data, and bank and card account activity as recorded in your accounting system.
2.3 Information We Collect Automatically
- Device and connection information. IP address, browser type and version, operating system, device identifiers, language, and time zone.
- Usage information. Pages and screens viewed, features used, buttons clicked, session duration, referring URLs, timestamps, and error and diagnostic logs.
- Cookies and similar technologies. See Section 8.
2.4 Information We Receive From Third Parties
- Referral sources. Information from partners, accountants, investors, or existing customers who refer you to us.
- Authentication providers. Basic profile information from single sign-on providers when you choose to log in that way.
- Analytics partners. Aggregate and pseudonymous information about how visitors find and use the Website.
2.5 Sensitive Information
We do not seek and ask that you not submit government identification numbers, health information, biometric data, precise geolocation, or information about racial or ethnic origin, religious beliefs, sexual orientation, or union membership. Some of this information may nonetheless appear incidentally within accounting records or uploaded documents that a customer connects to the Service. Where it does, we treat it as confidential Customer Data, process it only to provide the Service, and do not use it for any independent purpose.
Section 3Connected Accounts and Third-Party Data Sources
The core function of the Service is to read a company's financial data from the systems where it already lives, analyze it, and present the results back to you. This section explains how those connections work.
3.1 How Connections Are Authorized
Connections are established by the customer through industry-standard authorization flows, most commonly OAuth 2.0. You are redirected to the third-party provider, you authenticate directly with that provider, and you grant Helm a scoped access token. We do not ask for, receive, or store your username and password for any connected system. Access tokens and refresh tokens are encrypted at rest and are accessible only to the systems and personnel that require them to operate the Service.
You may revoke any connection at any time. See Section 3.6.
3.2 Accounting Integrations (QuickBooks Online, Xero, and Puzzle)
If you connect an accounting platform — QuickBooks Online (via Intuit's APIs), Xero, or Puzzle — we access your company's accounting data under the authorization you grant. The categories are the same across providers; the exact records vary with each provider's data model. The data we read includes:
- Company profile information and fiscal year settings
- Chart of accounts and account balances
- Profit and loss and balance sheet report data, including the transaction-level detail behind them
- Invoices, sales receipts, credit memos, and payments
- Bills, bill payments, purchases, and vendor credits
- Customers as recorded in your accounting system
- Recurring transaction templates
How we use accounting data. We use it solely to provide the Service to you: to produce financial metrics, dashboards, forecasts, runway and burn analysis, anomaly and error detection, and the narrative explanations the Service generates for you and for your authorized users.
Read-only access. The Service is read-only with respect to your accounting system. We never create, modify, or delete records in QuickBooks, Xero, or Puzzle, and we never categorize or re-categorize your transactions. Your books remain exactly as your accounting system and your accountant maintain them; Helm only reads them.
Your use of each accounting platform is governed by your own agreement with its provider. In particular, your use of QuickBooks Online is governed by your agreement with Intuit, and Intuit's handling of your data under that relationship is described in Intuit's own privacy statement, not this one. The same is true of Xero and Puzzle under their respective agreements and privacy policies.
3.3 Billing and Subscription Revenue (Stripe)
If you connect Stripe, we read your Stripe account data under the authorization you grant: customers, subscriptions, products and prices, invoices, charges and payments, refunds, and payout records. We use this data to compute revenue metrics such as MRR, growth, churn, retention, and cohort analyses, and to power the same dashboards, forecasts, and narratives described above.
Stripe access is read-only in practice: we never create or modify records in your Stripe account, never charge your customers, and never move funds. We do not receive or store cardholder numbers; Stripe does not expose them.
3.4 What We Never Do With Connected Data
The following applies to all data we retrieve from any connected system — accounting, billing, or otherwise. We do not sell it. We do not rent, trade, or license it. We do not use it for advertising, marketing, targeting, or lead generation, whether directed at you or at anyone else. We do not use it to train, fine-tune, or improve any general-purpose or third-party machine learning model. We do not disclose it to any third party except the service providers listed in Section 6, each of which is bound by contract to process it only to deliver services to us, and except as required by law under Section 6.4.
3.5 Banking and Workspace Tools
Banking. The Service does not currently connect directly to banks or financial institutions. Bank and card account balances and activity reach the Service only as recorded in your connected accounting system. If we offer direct bank connections in the future, we will describe the data accessed at the time you enroll, and this section will be updated. We do not initiate payments, transfers, or any movement of funds, and we do not request or hold credentials or authority that would permit us to do so.
Workspace and communication tools (such as Slack, Gmail, and Google Meet). Where you enable them, we access only what the approved scopes cover, to deliver notifications, answer questions where you work, send messages you compose and approve, or process meeting transcripts you authorize.
Google user data (Limited Use). Helm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Helm accesses your Google Meet meeting transcripts (via the meetings.space.readonly scope) only to provide the in-product features you explicitly enable, letting you query and review your own meeting transcripts. Helm does not use this data for advertising; does not sell it; does not transfer it to others except as necessary to provide the feature (to service providers under confidentiality and data-processing obligations), to comply with applicable law, or as part of a merger or acquisition with comparable protections; and does not allow humans to read it except with your explicit consent, for security, abuse, or legal purposes, or where the data has been aggregated and anonymized. Helm does not use Google user data to develop, improve, or train generalized AI or machine learning models. You can delete ingested transcripts or disconnect Google Meet at any time, which revokes our access and permanently deletes the stored transcript data.
3.6 Disconnecting
You may disconnect any integration at any time:
- In the Service: open Settings → Integrations and select Disconnect for the relevant connection.
- For QuickBooks Online: you may also disconnect from within QuickBooks by going to Apps → My Apps and selecting Disconnect for Helm.
- By request: email support@helmcfo.com and we will disconnect it for you.
When a connection is disconnected, we immediately delete our stored access and refresh tokens, request revocation of the grant with the provider, and stop retrieving new data from that system. Data already retrieved is handled as described in Section 9. If you want that data deleted as well, you may request deletion under Section 9.3.
Section 4How We Use Information
To provide and operate the Service. Authenticate users, establish and maintain integrations, ingest and normalize financial data, run analyses, generate reports, forecasts, and recommendations, and deliver the features you have subscribed to.
To operate AI features. Process your prompts and the relevant Customer Data through our models and those of our AI subprocessors to produce output for you. See Section 5.
To support you. Respond to inquiries, troubleshoot, investigate errors, and provide onboarding and training.
To bill you. Process subscriptions, invoices, payments, and collections, and maintain financial records.
To secure the Service. Monitor for, detect, investigate, and prevent fraud, unauthorized access, abuse, and violations of our Terms of Service, and to protect our rights, our users, and the public.
To improve the Service. Analyze aggregate usage patterns, diagnose defects, measure feature performance, and develop new functionality. Where we use Customer Data for improvement, we use it in aggregated or de-identified form that does not identify you or your company, and subject to the model-training limits in Section 5.
To communicate with you. Send service notices, security alerts, billing messages, product updates, and — where permitted — marketing communications you can opt out of at any time.
To market and sell. Contact prospective customers, run campaigns, measure their effectiveness, and manage our sales pipeline. We do not use Customer Data for these purposes.
To comply with law. Meet tax, accounting, audit, and recordkeeping obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
Section 5Artificial Intelligence and Machine Learning
The Service uses large language models and other machine learning systems, some operated by us and some by third-party AI providers acting as our subprocessors.
How your data reaches these models. To answer a question or generate a report, the Service assembles the relevant context — which may include portions of your Customer Data — and submits it to a model for processing. Output is returned to you within the Service.
Our commitments.
- We do not use Customer Data to train, fine-tune, retrain, or otherwise improve any general-purpose or publicly available AI model.
- We contract with our AI providers on commercial terms under which they do not use data we submit to train or improve their models, and retain it only for limited operational purposes such as abuse prevention.
- We do not permit AI providers to use Customer Data for any purpose other than returning output to us.
- We may develop internal models and heuristics using aggregated or de-identified data that cannot reasonably be used to identify you, your company, or any individual. We do not re-identify such data.
Accuracy. AI-generated output is probabilistic and can be incomplete or wrong. It is not accounting, tax, legal, or investment advice, and it does not replace review by a qualified professional. Section 7 of our Terms of Service governs your responsibility to review output before relying on it.
Automated decision-making. We do not make decisions about you that produce legal effects or similarly significant effects concerning you based solely on automated processing without human involvement.
Section 6How We Disclose Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose information only as follows.
6.1 Within Your Organization
Information in your account, including Customer Data, is accessible to the users your organization's administrators authorize, according to the roles and permissions they assign. Administrators control who has access. We are not responsible for how authorized users within your organization use information they are permitted to see.
6.2 Service Providers and Subprocessors
We engage vendors to operate the Service. Each is bound by written agreement to process information only to provide services to us, to protect it appropriately, and not to use or disclose it for any other purpose. Categories include:
| Category | Purpose |
|---|---|
| Cloud infrastructure and hosting | Run the application and store data |
| Database and data warehouse providers | Store and query financial and account data |
| AI and machine learning providers | Generate analysis, narrative, and recommendations |
| Payment processing | Collect subscription fees |
| Email and messaging delivery | Send transactional and service communications |
| Error monitoring, logging, and observability | Detect and diagnose defects |
| Product and web analytics | Understand feature usage and Website traffic |
| Customer support and CRM | Manage support requests and customer relationships |
| Identity and authentication | Verify user identity and manage sessions |
| Professional advisors | Legal, accounting, audit, insurance, and tax services |
A current list of subprocessors that process Customer Data is available to customers on request at privacy@helmcfo.com. Customers with a DPA in place will receive advance notice of new subprocessors as specified in that DPA.
6.3 Business Transactions
If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, information may be disclosed to the counterparty and its advisors as part of due diligence and may be transferred as part of the transaction. Customer Data transferred in such a transaction remains subject to protections at least as protective as this Policy, and we will notify affected customers.
6.4 Legal and Safety
We may disclose information where we believe in good faith that doing so is required by applicable law, regulation, legal process, subpoena, court order, or governmental request; or is necessary to enforce our Terms of Service, to investigate suspected fraud or security incidents, or to protect the rights, property, or safety of Helm, our users, or the public. Where we are legally permitted to do so and it is practicable, we will notify the affected customer before disclosing Customer Data in response to a legal demand, so that the customer may seek protective relief.
6.5 With Your Direction
We disclose information to third parties when you instruct us to — for example, when you invite an outside accountant, bookkeeper, board member, or investor into your workspace, share a report, or enable an integration that transmits data to another system.
6.6 Aggregated and De-Identified Information
We may create and disclose aggregated or de-identified information — such as benchmarks, industry statistics, or anonymized trend data — that cannot reasonably be used to identify you, your company, or any individual. We will not attempt to re-identify such information and will require recipients not to do so.
Section 7International Transfers
We are based in the United States and our infrastructure is primarily located there. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and in other countries where our service providers operate. Data protection laws in those countries may differ from those in your own.
Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on an appropriate transfer mechanism, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision. Customers may request our transfer documentation at privacy@helmcfo.com.
Section 8Cookies and Tracking Technologies
We and our partners use cookies, pixels, tags, local storage, and similar technologies on the Website:
- Strictly necessary — authentication, session management, security, and load balancing. These cannot be disabled.
- Functional — remember your preferences and settings.
- Analytics — understand how the Website and the Service are used so we can improve them.
- Marketing — measure the effectiveness of our own campaigns on the Website. We do not run third-party advertising, and we do not use Customer Data for advertising.
You can control cookies through your browser settings and, where we present one, through the cookie preferences interface on the Website. Blocking some cookies will affect how the Website and the Service function.
Do Not Track. Browser Do Not Track signals are not yet supported by a uniform industry standard, and we do not currently respond to them.
Global Privacy Control. Where we detect an opt-out preference signal such as Global Privacy Control on the Website, we treat it as a valid request to opt out of sale and sharing for that browser.
Section 9Data Retention and Deletion
9.1 Retention Principles
We retain information only as long as necessary for the purposes described in this Policy, or as required by law.
| Information | Retention |
|---|---|
| Integration access and refresh tokens | Deleted immediately on disconnection or account closure |
| Customer Data | For the term of the customer's subscription, then deleted per Section 9.2 |
| Account and profile information | For the term of the relationship, then up to 24 months, unless deletion is requested sooner |
| Billing, invoicing, and tax records | Up to 7 years, as required by tax and accounting law |
| Support and communication records | Up to 3 years after the interaction |
| Security, audit, and access logs | At least 12 months, and as long as needed for security, audit, and compliance purposes |
| Website analytics and cookie data | Up to 13 months |
| Marketing contact records | Until you unsubscribe, then a suppression record only |
| Aggregated and de-identified data | Retained indefinitely; it is not personal information |
9.2 On Termination
When a subscription terminates, the customer has 30 days to export their Customer Data from the Service. After that window, we delete Customer Data from production systems within 30 days. Residual copies in encrypted backups are purged on our standard backup rotation, within 90 days of deletion from production. We may retain a minimal record of the account's existence and billing history as required by Section 9.1.
9.3 Deletion on Request
A customer may request deletion of Customer Data at any time by emailing privacy@helmcfo.com. We will confirm the request, action it within 30 days, and confirm completion. Deletion is irreversible. We may decline or delay a deletion request to the extent retention is required by law, necessary to resolve a billing dispute, or necessary to establish, exercise, or defend a legal claim, and we will tell you if that applies.
Section 10Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, and destruction. These include:
- Encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest
- Encrypted storage of integration credentials and access tokens (AES-256), with encryption keys held in a dedicated secrets management system
- Role-based access control and least-privilege provisioning, with access to production data limited to personnel who require it
- Multi-factor authentication on administrative and production systems
- Logging and monitoring of access to production environments
- Separation of production, staging, and development environments
- Confidentiality obligations and security training for personnel and contractors
- Vendor security review before engaging providers that process Customer Data
- A documented incident response process, with regular review
No system is perfectly secure. We cannot guarantee absolute security, and information you transmit to us over the internet is transmitted at your own risk. Please do not send sensitive information to us over unsecured channels.
Your responsibilities. Keep your credentials confidential, enable multi-factor authentication, review which users have access to your workspace, and notify us at security@helmcfo.com immediately if you suspect unauthorized access to your account.
Breach notification. If we become aware of a security incident affecting your personal information or Customer Data, we will notify you and any applicable regulator without undue delay, as and where required by applicable law and by our agreement with you.
Section 11Your Rights and Choices
11.1 All Users
- Access and correction. You may access and update your account and profile information in the Service, or ask us at privacy@helmcfo.com.
- Deletion. You may request deletion of your personal information or of Customer Data as described in Section 9.3.
- Marketing opt-out. Unsubscribe using the link in any marketing email, or email privacy@helmcfo.com. We will still send you transactional and service messages related to your account.
- Disconnect integrations. See Section 3.6.
- Cookies. See Section 8.
11.2 United States State Privacy Rights
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws may have the right to: confirm whether we process their personal information and access it; obtain a copy in a portable format; correct inaccuracies; request deletion; opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects; and not be discriminated against for exercising these rights.
We do not sell personal information and we do not share it for cross-context behavioral advertising or targeted advertising.
To exercise a right, email privacy@helmcfo.com with your name, the email address associated with you, and the right you wish to exercise. We will verify your identity before responding, which may require additional information. We respond within the timeframe required by applicable law, generally 45 days, extendable once where permitted. You may use an authorized agent, who must provide proof of authorization. If we deny your request, you may appeal by replying to our response with the word "Appeal"; we will respond to appeals within 45 days.
For the categories of personal information we collect, the sources, the purposes, and the categories of recipients, see Sections 2, 4, and 6, which together constitute our notice at collection.
California residents under 18. If you are a California resident under 18 and have posted content on the Website, you may request its removal by emailing privacy@helmcfo.com. Removal from public display does not necessarily remove content from our systems or backups.
California Shine the Light. California residents may request information about disclosures of personal information to third parties for their direct marketing purposes by emailing privacy@helmcfo.com.
11.3 EEA, UK, and Swiss Rights
Where the GDPR or UK GDPR applies to our processing as a controller, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent where processing is based on consent. Withdrawing consent does not affect the lawfulness of processing carried out beforehand.
Our legal bases for processing as a controller are:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service, administer your account, and bill you.
- Legitimate interests (Art. 6(1)(f)) — to secure and improve the Service, prevent fraud and abuse, market to businesses, and operate our business. We balance these against your rights and interests.
- Consent (Art. 6(1)(a)) — for non-essential cookies and certain marketing, where required.
- Legal obligation (Art. 6(1)(c)) — for tax, accounting, and compliance recordkeeping.
You may lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first at privacy@helmcfo.com.
Section 12Children's Privacy
The Service is a business tool intended solely for use by individuals 18 years of age or older. We do not knowingly collect personal information from children under 13, and we do not direct the Website or the Service to children. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child has provided us information, contact privacy@helmcfo.com.
Section 13Third-Party Websites and Services
The Website and the Service may link to or interoperate with websites and services we do not control, including QuickBooks Online and other integrations. This Policy does not apply to them. Their handling of your information is governed by their own privacy policies and by your own agreements with them. We encourage you to review those before connecting or sharing information.
Section 14Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Last Updated" date above. If we make material changes, we will use reasonable efforts to notify you in advance — by email to the address associated with your account, by notice within the Service, or by prominent notice on the Website — and, where required by law, obtain your consent. Changes take effect on the date posted unless stated otherwise. Your continued use of the Service after changes take effect constitutes acceptance.
Section 15How to Contact Us
Helm CFO Inc.
611 South DuPont Highway, Suite 102, Dover, Delaware 19901
- Privacy inquiries and rights requests: privacy@helmcfo.com
- Security matters: security@helmcfo.com
- Product support: support@helmcfo.com
- Legal notices: legal@helmcfo.com
We will respond to privacy inquiries within 30 days, and sooner where required by law.