Privacy Policy
The short version
- We collect what you send us through the site, plus standard analytics about how the site is used.
- We use it to answer you, to deliver work, and to improve the site. Nothing else.
- We never sell your data, and we never share it for advertising.
- Where we hold data for a client, that client controls it and their notice applies, not this one.
- You can ask to see, correct or delete your data at any time by emailing hello@helix-growth.com.
01About this policy
Helix Growth respects your privacy and takes the protection of personal data seriously. This policy explains what we collect, why we collect it, how long we keep it and what rights you have over it.
It applies to:
- Visitors to helix-growth.com
- People who contact us, request an audit or enquire about our services
- Subscribers to our emails
- Client and prospective client contacts we deal with in the course of business
- Candidates who apply to work with us
It does not cover personal data we process on behalf of a client under a services agreement. Where we do that, the client is the controller and their own privacy notice applies. Section 3 explains how that distinction works.
02Who we are
Helix Growth is a standalone business providing data, marketing performance and business operations consultancy. References to we, us and our mean Helix Growth.
For the personal data described in this policy, Helix Growth is the controller, which means we decide what is collected and why.
- Privacy contact
hello@helix-growth.com - Based in
Johannesburg and Cape Town, South Africa - Markets served
South Africa, the United Kingdom, the European Union, the United States and the wider EMEA region
03When we are a controller, and when we are a processor
This distinction matters, because our obligations differ.
- Controller. For our own website, marketing, enquiries, recruitment and business administration, we decide what data is collected and why. This policy governs that data.
- Processor. During a client engagement we often build, connect and operate systems that hold our client's data, which can include personal data about their customers or staff. In that work we act only on our client's documented instructions. The client remains the controller, their privacy notice applies to those individuals, and our handling is governed by the data processing terms in our services agreement rather than by this policy.
If a client of ours holds your data and you want it accessed or deleted, contact that organisation directly. If you contact us instead, we will refer your request to them and tell you we have done so.
04Personal information we collect
Information you give us
Collected when you complete a form, email or call us, subscribe to our emails, request support, or apply for a role.
- Name
- Work email address
- Company name
- Job title
- Phone number
- Professional details, including what you tell us about your systems, teams and the problem you want solved
- Any other content you choose to include in a message to us
Information we collect automatically
Collected by our servers and by the analytics tools described in section 6.
- IP address, approximate location derived from it, browser type, operating system and device type
- Pages viewed, time on page, referring URL and outbound clicks
- Interactions such as scroll depth, form starts and form submissions
- Cookie and similar identifiers
Information from third parties
- If you authenticate through a service such as Google, we receive the profile data you permit that service to share
- If you interact with us on a platform such as LinkedIn, we may receive limited data from that platform
- We may use publicly available business sources to verify or complete company details
What we do not collect
- We do not seek special category data such as health, race, religion, political opinion or biometric data, and we ask that you do not send it to us
- We do not collect payment card details through this website
- We do not knowingly collect data from children. See section 12
05How we use your data, and our lawful basis
We only process personal data where we have a lawful basis to do so. Under the GDPR and UK GDPR those bases are set out in Article 6. POPIA and the CCPA use different language for a similar idea.
| What we do | Why | Lawful basis |
|---|---|---|
| Respond to an enquiry or audit request | To answer you and assess whether we can help | Legitimate interests, or steps towards a contract |
| Deliver services and manage the engagement | To do the work we were engaged for | Performance of a contract |
| Send marketing emails | To share relevant thinking and offers | Consent, or legitimate interests for existing business contacts |
| Measure and improve the website | To understand what is useful and fix what is not | Consent for non essential cookies, otherwise legitimate interests |
| Keep business, tax and accounting records | Because we are required to | Legal obligation |
| Consider a job application | To assess suitability for a role | Legitimate interests, or steps towards a contract |
| Protect the site and investigate misuse | Security and fraud prevention | Legitimate interests |
We do not sell your personal data, and we do not share it for cross context behavioural advertising as those terms are defined by United States privacy law.
06Cookies and similar technologies
Cookies are small files stored on your device. We use them in three categories.
- Strictly necessary. Needed for the site to work, for example remembering a form submission or a consent choice. These cannot be switched off.
- Analytics. Used to understand which pages are read and where people drop out, so we can improve the site. This includes Google Analytics and Google Tag Manager where enabled.
- Marketing. Used to measure campaign performance and, where relevant, to show you our advertising. This may include tags from advertising platforms and our CRM.
How to control them
- Where a consent banner is shown, analytics and marketing cookies are only set after you accept them, and you can change your choice at any time
- Your browser settings let you block or delete cookies. Blocking strictly necessary cookies may stop parts of the site working
- Browser level controls such as Global Privacy Control are respected where they are sent
07Who we share data with
We share personal data only where there is a reason to, and only with organisations bound to protect it. A data processing agreement is in place with each of them.
- Customer relationship management. HubSpot, holding enquiry and client contact records
- Analytics and tag management. Google, for website measurement
- Email and productivity. Our email, calendar and document providers
- Hosting and infrastructure. The providers who run this website and our internal systems
- Professional advisers. Accountants, auditors and lawyers, where necessary
- Authorities. Where we are legally required to disclose, or to establish or defend legal claims
Each of these organisations operates under its own privacy policy for data it controls in its own right. We do not give anyone permission to use your data for their own marketing.
If our business is ever sold or restructured, personal data may transfer as part of that transaction. You would be told before it happened and this policy would continue to apply.
08International transfers
We operate from South Africa and work with clients and suppliers in other countries, so your data may be processed outside the country where you live.
Where data moves out of the European Economic Area, the United Kingdom or South Africa, we rely on one of the following:
- An adequacy decision, where the destination country is recognised as offering equivalent protection
- Standard Contractual Clauses, or the UK International Data Transfer Agreement or Addendum
- The transfer conditions permitted by section 72 of POPIA
You can ask us which safeguard applies to a specific transfer by emailing hello@helix-growth.com.
09How long we keep data
We keep personal data only as long as we need it, then delete or anonymise it. We review what we hold every six months.
| Type of data | Kept for |
|---|---|
| Enquiries that do not become clients | 24 months from last contact |
| Client contact and engagement records | Duration of the engagement, then 7 years for tax and legal purposes |
| Marketing subscribers | Until you unsubscribe, then up to 12 months to honour the suppression |
| Website analytics | Up to 14 months, in line with our analytics configuration |
| Job applications | 12 months from the decision, unless you ask us to keep them longer |
| Server and security logs | Up to 12 months |
Where a longer period is required by law, or where data is needed for a live legal claim, we keep it for as long as necessary and no longer.
10How we protect data
We are a data consultancy, so we hold ourselves to the standard we set for clients. Our measures include:
- Encryption in transit for the website and our internal systems
- Access on a least privilege basis, so people can reach only the data their role requires
- Multi factor authentication on business accounts
- Separation between client environments, so one engagement cannot reach another
- Vendor review before a new processor is introduced
- Regular review of accounts, permissions and what we still need to hold
No system is completely secure. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant regulator within the timeframes the law requires.
11Your rights
Depending on where you live, you have some or all of the following rights.
- Access. A copy of the personal data we hold about you
- Correction. Fix data that is wrong or incomplete
- Deletion. Have data erased where we no longer have a reason to keep it
- Restriction. Ask us to pause processing while a matter is resolved
- Objection. Object to processing based on legitimate interests, and to direct marketing at any time
- Portability. Receive your data in a structured, machine readable format
- Withdraw consent. Where processing relies on consent, withdraw it without affecting what was lawful beforehand
- Non discrimination. Exercise these rights without being treated differently or receiving a worse service
How to exercise them
- Email hello@helix-growth.com and tell us which right you want to use
- We may ask for information to confirm your identity, so we do not disclose data to the wrong person
- We respond within one month. If a request is complex we may extend that by a further two months and will tell you why
- There is no fee, unless a request is excessive or repetitive
- To unsubscribe from marketing, use the link in any email or write to us
12Children
Our services are sold to businesses and our site is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, email hello@helix-growth.com and we will delete it.
13Automated decision making
We do not make decisions about you by wholly automated means that have a legal or similarly significant effect. Where we use automation in the work we do for clients, a person remains accountable for decisions that affect individuals.
14Third party links
Our site links to other websites, including our clients, our partners and platforms such as LinkedIn. We do not control those sites and we are not responsible for their content or their privacy practices. Read their policies before giving them your data.
15Region specific terms
European Union and United Kingdom
We comply with the GDPR and the UK GDPR. Our lawful bases are set out in section 5. You have the rights in section 11, and you can complain to your national data protection authority. In the United Kingdom that is the Information Commissioner's Office.
South Africa
We comply with the Protection of Personal Information Act. You can complain to the Information Regulator of South Africa. Where we act as an operator for a client, we process personal information only with that client's knowledge and authorisation, and we treat it as confidential.
United States, including California
We do not sell personal information and we do not share it for cross context behavioural advertising. California residents may request to know the categories and specific pieces of personal information collected, request deletion or correction, and are entitled to non discriminatory treatment for exercising those rights. Requests can be made to hello@helix-growth.com. You may use an authorised agent, and we will verify the authorisation.
16Changes to this policy
We update this policy when our practices change or when the law requires it. The current version is always published here with a revised last updated date. Where a change materially affects how we use your data, we will tell you directly if we hold your contact details.
17How to contact us
For any privacy question, request or complaint:
- Email hello@helix-growth.com
- Subject line put "Privacy request" in it so we route it quickly
We would rather resolve a concern with you directly, so please come to us first. You keep the right to complain to your data protection authority either way.