Skip to content

Legal

Privacy policy

Last updated

1. Who we are — link to this section

1.1

Helmpay Limited, trading as Helm, is the controller of the personal data described in this policy. We are a company registered in England and Wales with company number 16417022, whose registered office is at 2 Frederick Street, London, England, WC1X 0ND.

1.2

You can contact us about this policy or about your personal data at contact@helm.business, or by writing to us at our registered office.

2. What this policy covers — link to this section

2.1

This policy explains how we collect, use, share and protect personal data when you visit our website, apply for a Helm account, use the Helm platform, or communicate with us.

2.2

Our customers are businesses. The personal data we process therefore relates mainly to the individuals connected with those businesses, including directors, officers, beneficial owners, authorised signatories and team users, and to individuals connected with the counterparties our customers pay or are paid by.

3. The personal data we collect — link to this section

3.1

Identity data: name, date of birth, nationality, photograph or likeness from an identity document, identity document number and issuing details, and signature.

3.2

Contact data: email address, telephone number, business address, and residential address where required for verification.

3.3

Business data: role and position, shareholding and beneficial ownership details, directorship history, and information about the business you are connected with and its trading activity.

3.4

Verification and screening data: the results of identity verification and of sanctions, politically exposed person, adverse media and other screening checks, and information obtained from company registries, credit reference agencies and other third party sources.

3.5

Transaction data: details of payments made and received, including amounts, currencies, dates, references, counterparty and beneficiary details, and information you provide about the purpose of a transaction or the underlying commercial arrangement.

3.6

Technical data: IP address, device and browser information, operating system, log data, and information about how you interact with our website and platform.

3.7

Communications data: the content of and metadata relating to your correspondence with us, including emails and support enquiries.

3.8

We do not deliberately collect special category personal data. Where an identity document reveals information capable of indicating racial or ethnic origin, we process it only as incidental to identity verification and not for any separate purpose.

4. Where we obtain personal data — link to this section

4.1

From you, when you apply for an account, use the platform, give a payment instruction, respond to an information request or contact us.

4.2

From our customers, where you are a director, officer, beneficial owner, team user, counterparty or beneficiary of a business that uses Helm. In that case the business that provided your data will normally have obtained it from you.

4.3

From third parties, including identity verification providers, company registries and other public registers, credit reference agencies, sanctions and watchlist providers, adverse media sources, our banking and payment partners, and payment networks.

4.4

Automatically, through cookies and similar technologies when you use our website, as described in our Cookie Policy.

5. Why we use personal data, and our lawful basis — link to this section

Purpose
Assessing an application and deciding whether to open an account
Lawful basis
Performance of a contract, or steps taken at your request before entering into one; our legitimate interest in assessing business risk
Purpose
Verifying identity, ownership and control, and carrying out customer due diligence
Lawful basis
Compliance with a legal obligation; our legitimate interest in preventing financial crime
Purpose
Screening against sanctions, politically exposed person and watchlist sources
Lawful basis
Compliance with a legal obligation; substantial public interest in preventing or detecting unlawful acts
Purpose
Providing the account and executing payments
Lawful basis
Performance of a contract
Purpose
Monitoring transactions and detecting, investigating and preventing financial crime and fraud
Lawful basis
Compliance with a legal obligation; substantial public interest; our legitimate interest in protecting our business and our customers
Purpose
Making reports to regulators, law enforcement and other authorities
Lawful basis
Compliance with a legal obligation
Purpose
Providing support and responding to enquiries and complaints
Lawful basis
Performance of a contract; our legitimate interest in operating our business
Purpose
Maintaining records, accounting, audit and tax
Lawful basis
Compliance with a legal obligation; our legitimate interest in running our business
Purpose
Securing our systems and preventing misuse
Lawful basis
Our legitimate interest in protecting our platform and our customers
Purpose
Improving and developing our services
Lawful basis
Our legitimate interest in developing our business
Purpose
Sending marketing communications about our services
Lawful basis
Consent, or our legitimate interest in marketing to business customers
Purpose
Establishing, exercising or defending legal claims
Lawful basis
Our legitimate interest in protecting our legal position; establishment, exercise or defence of legal claims

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests, rights and freedoms. You may request further information about that assessment.

6. Automated processing — link to this section

6.1

We use automated processing in our verification and transaction screening. This includes automated matching against sanctions, watchlist and adverse media data, and automated rules that may cause a transaction to be held for review or an application to be flagged.

6.2

Automated processing may result in a payment being delayed or held, an application being referred for further review, or an account being restricted pending review.

6.3

Where automated processing produces an outcome that is adverse to you, a member of our team reviews that outcome before any decision to refuse an application, to close an account or to permanently reject a payment takes effect.

6.4

You may ask us to explain the general nature of the processing that led to an outcome, may express your point of view, and may contest an outcome by contacting us at contact@helm.business. There are circumstances in which we are prohibited by law from explaining the reason for an outcome, and in those cases we will tell you only what we are permitted to tell you.

7. Who we share personal data with — link to this section

7.1

Our banking, payment and technology partners, who provide elements of the service including account issuance, payment execution, custody and identity verification. These partners process personal data as controllers in their own right for their own compliance purposes, and their own privacy notices apply to that processing.

7.2

Payment networks and financial institutions involved in executing a payment, including intermediary banks and the recipient's bank. Payment messages typically carry the payer's and payee's details, and that information is visible to the institutions in the payment chain.

7.3

Verification and screening providers, company registries, credit reference agencies and fraud prevention agencies.

7.4

Professional advisers, including lawyers, accountants, auditors and insurers.

7.5

Regulators, law enforcement, tax authorities, courts and other public authorities, where we are required to disclose or where disclosure is necessary to protect our legal position.

7.6

Service providers who process personal data on our behalf, including hosting, infrastructure, communications and support providers. Those providers act on our instructions under a written contract and may not use the data for their own purposes.

7.7

A purchaser or prospective purchaser of our business or assets, subject to appropriate confidentiality protections.

7.8

We do not sell personal data.

8. International transfers — link to this section

8.1

Some of our partners and service providers are located outside the United Kingdom, including in the United States.

8.2

Where we transfer personal data outside the United Kingdom, we do so on the basis of one of the following:

(a)

the receiving country has been determined by the UK Government to provide an adequate level of protection;

(b)

the transfer is made under the International Data Transfer Agreement, or under the UK Addendum to the European Commission's Standard Contractual Clauses, supported by a transfer risk assessment; or

(c)

another lawful transfer mechanism or derogation applies, including where the transfer is necessary for the performance of a contract with you or in your interest, or is necessary for the establishment, exercise or defence of legal claims.

8.3

Where a payment is made to a jurisdiction outside the United Kingdom, information about that payment necessarily travels to that jurisdiction in order for the payment to be executed.

8.4

You may request further information about the safeguards applied to a particular transfer.

9. How long we keep personal data — link to this section

9.1

We keep personal data for as long as necessary for the purpose for which it was collected, and for as long as we are required to keep it by law.

9.2

Records relating to customer due diligence, and records relating to transactions, are retained for five years after the end of the business relationship or the date of the transaction, in accordance with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, and may be retained for longer where a regulator or law enforcement authority requires it.

9.3

Accounting and tax records are retained for six years from the end of the relevant accounting period.

9.4

Records relating to an application that did not proceed are retained for five years from the date of the application, so that we can evidence the basis on which the application was assessed.

9.5

General correspondence and support records are retained for three years from the date of the last communication, unless they form part of a record we are required to retain for longer.

9.6

Records relevant to an actual or anticipated legal claim are retained until the claim is resolved and any applicable limitation period has expired.

9.7

When personal data is no longer required, we delete it or anonymise it.

10. Your rights — link to this section

10.1

Under UK data protection law you have the right to:

(a)

be informed about how we use your personal data, which is the purpose of this policy;

(b)

access the personal data we hold about you and receive a copy of it;

(c)

have inaccurate personal data corrected and incomplete personal data completed;

(d)

have your personal data erased in certain circumstances;

(e)

restrict our processing in certain circumstances;

(f)

receive your personal data in a portable form, where processing is based on consent or on a contract and is carried out by automated means;

(g)

object to processing based on our legitimate interests, and to object at any time to processing for direct marketing; and

(h)

withdraw consent, where we rely on consent, at any time, without affecting the lawfulness of processing before withdrawal.

10.2

These rights are not absolute. In particular, we are frequently unable to erase or restrict personal data that we are required by law to retain, including customer due diligence and transaction records. We are also unable to disclose information where doing so would prejudice the prevention or detection of crime, or would amount to unlawfully alerting a person that a report has been made.

10.3

To exercise a right, contact us at contact@helm.business. We will respond within one month, which we may extend by a further two months where a request is complex or where we have received a number of requests from you. We may ask you to verify your identity before we act.

10.4

There is normally no charge. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive.

11. Complaints — link to this section

11.1

If you are unhappy with how we have handled your personal data, contact us first at contact@helm.business and we will try to resolve it.

11.2

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk, by telephone on 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

12. Security — link to this section

12.1

We maintain technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These include access controls, authentication requirements, encryption in transit and at rest, logging and monitoring, and restrictions on which of our personnel can access which data.

12.2

No system is entirely secure. You are responsible for keeping your own credentials confidential and for notifying us promptly if you suspect unauthorised access.

13. Children — link to this section

The services are provided to businesses and are not directed at children. We do not knowingly collect personal data relating to children.

14. Changes to this policy — link to this section

14.1

We may update this policy. The current version is always available at helm.business/legal/privacy, and the date shown on the page indicates when it was last updated.

14.2

Where a change is material, we will notify you by email or through the platform.

Helmpay Limited, company number 16417022, 2 Frederick Street, London, England, WC1X 0ND. contact@helm.business