Privacy Policy
HELM Managed Services Ltd · Company No. 17265994 · Last updated: October 2026
1. Who we are and what this covers
HELM Managed Services Ltd (“HELM”, “we”, “us”, “our”) is a company incorporated in England and Wales under company number 17265994. Our registered address is:
14 Riverholme Drive
Epsom
Surrey KT19 9TQ
United Kingdom
We provide managed IT services, cybersecurity consultancy and related technology services to business clients.
This policy covers all three of our online services:
- helmm.io, our website, including its quote tools;
- onboarding.helmm.io, the portal where a new client, and the IT provider they are leaving, give us the information we need to take over their IT;
- asset.helmm.io, the page behind the QR code on the asset tags we fix to devices we manage.
We are the data controller for the personal data described here, except where we say we handle it on behalf of a client. We can be contacted at [email protected].
2. What data we collect and why
On our website
- Enquiries and quote requests: name, work email address, company name. We use this to respond to your enquiry and to send you relevant information about our services. Lawful basis: legitimate interests. Before our quote tools open, our server checks that the email address belongs to a business by looking up the mail records for its domain; only the domain (the part after the “@”) is sent for this check, to Google’s public DNS service (or Cloudflare’s, if Google’s is unavailable). We then email you a link to confirm the address is yours, and the quote tools open once you have clicked it. To do this we keep your name, company, email address and a scrambled copy of the link for 24 hours. Your details go into our CRM only once you have confirmed.
- Invoice comparison (“Beat my invoice”): if you upload an invoice, the text is extracted in your browser and sent through our server to Anthropic, whose AI model reads it and matches its lines to our services to produce an estimate. An invoice may contain personal data, such as a named contact or address. We do not keep a copy of the invoice or its text: our server passes it on and records only technical information such as how long the request took. Anthropic processes it on our behalf under its commercial terms. We recommend removing anything we don’t need, such as bank details, before uploading. Lawful basis: legitimate interests (responding to your request for an estimate).
- Discovery calls: contact details, role, and business information needed to scope our services. Lawful basis: steps taken at your request before entering into a contract.
- Website analytics: we use Plausible Analytics to count visits to our website: which pages are viewed, which site or link referred the visit, and the visitor’s browser, operating system, device type and country. Plausible uses no cookies and stores nothing on your device. Your IP address is used only briefly to tell visits apart and to work out your country; it is not stored, and the anonymous visitor count it produces changes every day, so you cannot be followed from one day to the next or across other websites. We see only totals, never individuals. Lawful basis: legitimate interests (understanding how our website is used, so we can improve it). Any server-level logging is retained for no longer than 30 days.
In the onboarding portal
- Invitations: access is by invitation only. Whoever invites you, whether someone at HELM or at your organisation, gives us your work email address, and we email you a link. We record when that invitation was sent, and who sent it.
- Signing in: you sign in with your Google or Microsoft 365 work account. There is no password. That provider tells us your name and email address, and your profile picture if you have one. We use them to check you have been invited and to show who did what in the portal.
- What you tell us: the information the portal asks for about your organisation’s IT, such as its systems, licences, suppliers, sites and the people who use them, and any documents you upload. We use it to plan and carry out the handover of your IT to us. Where it concerns your colleagues, we handle it on your organisation’s behalf under its agreement with us.
- A record of changes: the portal keeps a log of who changed what, and when, so both sides can see what is outstanding. It cannot be edited, and is deleted with the rest of the onboarding.
- Your preferences: which notification emails you want, and the language you view the portal in.
Lawful basis: performing the agreement between HELM and your organisation, or steps towards one, and our legitimate interest in running the handover properly and keeping an accurate record of it.
On asset tags
- Scanning a tag: the page collects nothing from you, and shows nothing about the device, its owner or its user. It tells you the device is managed by HELM and how to report it found.
- Reporting a found device: if you email [email protected], we use your name, contact details and anything you tell us, such as where you found it, to arrange the device’s return to its owner. Lawful basis: legitimate interests, returning our client’s property.
Before the asset register opens to signed-in users, and before we add a form for reporting a found device or start recording scans, we will update this policy to say what they collect.
When we look after your IT
- Service delivery: we may process personal data held within systems we manage on your behalf. In this capacity we act as a data processor and our obligations are governed by the relevant Data Processing Agreement with your organisation.
3. How we use your data
We use the data described above to:
- Respond to your enquiry or request for a quote.
- Onboard your organisation as a client and deliver our services to it.
- Send you the emails the onboarding portal needs to, such as invitations and, if you choose, notifications.
- Return a lost device to its owner.
- Send you information about our services that may be relevant to your business (you can unsubscribe at any time).
We do not sell your data to third parties. We do not use your data for automated decision-making that produces legal or similarly significant effects.
4. Who we share data with
We may share your data with:
- HubSpot CRM (HubSpot Inc., USA): for managing leads and client relationships. HubSpot is certified under the EU–US Data Privacy Framework.
- Anthropic (Anthropic PBC, USA): provides the AI model behind the invoice comparison, which processes the text of any invoice you upload in order to produce your estimate.
- Amazon Web Services (in the London region): hosts our website and the onboarding portal, including the portal’s database and the documents uploaded to it, and sends the portal’s emails and the website’s confirmation emails.
- Cloudflare (Cloudflare Inc., USA): delivers and protects our website and hosts the asset tag page, so it handles the connection of every visitor to them, including your IP address. It also provides the backup DNS lookup described in section 2.
- Plausible Analytics (Plausible Insights OÜ, Estonia, EU): provides the website analytics described in section 2, hosted in the EU.
- Google (Google LLC, USA): provides our business email, including [email protected], the calendar you can book a discovery call through, the fonts our website displays, and the DNS lookup described in section 2. If you sign in to the onboarding portal with a Google account, Google confirms who you are.
- Microsoft (Microsoft Corporation, USA): if you sign in to the onboarding portal with a Microsoft 365 account, Microsoft confirms who you are.
- The other side of your onboarding: everyone invited to an onboarding can see what has been entered in it, including your name next to what you changed. That is usually your colleagues and the IT provider you are leaving.
- A device’s owner: if you report a found device, we may pass your details to its owner so they can collect it, if you agree.
- Our subcontractors and engineers, strictly on a need-to-know basis and subject to equivalent confidentiality obligations.
- Regulatory authorities, where required by law.
All data sharing is subject to appropriate safeguards under UK GDPR. Where a provider is based outside the UK, the transfer is made under an approved mechanism such as the UK Extension to the EU–US Data Privacy Framework or the UK International Data Transfer Addendum.
5. Data retention
- Email confirmation records (your name, company, email address and a scrambled copy of the link we sent): 24 hours.
- Enquiry data (where no contract is entered into): 12 months from last contact.
- Onboarding portal: everything in an onboarding, including the documents uploaded to it and its log of changes, is deleted from the portal 90 days after we close the onboarding at the end of the handover. Your sign-in details (name, email address and profile picture) are deleted at the same time as the last onboarding you belong to.
- Found-device reports: 90 days after the device is returned or the report is closed.
- Client data: 7 years from the end of the engagement (in line with standard accounting obligations). If we keep a copy of a completed onboarding as part of our records for your organisation, it is held for this period.
You may request deletion at any time (subject to any legal retention requirements).
6. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have data erased (in certain circumstances).
- Object to processing based on legitimate interests.
- Portability of data provided to us electronically.
- Withdraw consent where processing is consent-based.
Where we handle data on a client’s behalf, we will pass your request to that client and help them respond.
To exercise any of these rights, email us at [email protected]. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
7. Cookies and your browser
Our website uses no advertising or tracking technologies. It sets two cookies of its own, both only when you use the quote tools. The first holds a random reference that lets the page notice when you have clicked the confirmation link we emailed you, and lasts an hour. The second remembers that you have confirmed your email address, so you don’t have to do it again for 30 days; it holds your name, company and email address. Both are signed so they can’t be altered, can’t be read by scripts on the page, and are not used to track you or shared with anyone. Its analytics (Plausible, described in section 2) are cookieless and store nothing on your device. The only exception is Cloudflare, which protects the site: if it needs to check that a visitor is a person rather than an automated attack, it may set a short-lived security cookie. That cookie is strictly necessary and is not used to track you. The website may also store a single item in your browser’s local storage (“helm-tweaks”) to remember display preferences, which stays on your device.
The onboarding portal sets only the cookies it needs to work: one that keeps you signed in, others that protect sign-in against forged requests and bring you back to the right page afterwards, one that remembers an invitation link for an hour while you sign in, and one that remembers the language you chose. HELM staff also have one that remembers which side of an onboarding they are viewing it as. None of them are used to track you, and none are shared with anyone.
The asset tag page sets no cookies.
When a page on our website loads, your browser fetches some of its components (fonts, and the code libraries the site is built with) from third-party providers, including Google and public code-delivery networks. As with any web request, those providers receive your IP address in order to send the file back. They do not receive anything you type into the website.
8. Security
We take reasonable technical and organisational measures to protect personal data from unauthorised access, loss or disclosure. The onboarding portal is encrypted in transit and at rest, and you sign in with your own work account rather than a password we hold. As a managed security provider, security is core to everything we do.
9. Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects when it was last revised. Continued use of our services after a material change constitutes acceptance.
10. Contact
Questions or requests relating to this policy should be directed to:
[email protected]
HELM Managed Services Ltd, 14 Riverholme Drive, Epsom, KT19 9TQ.