Last updated · July 2026
Data Processing Addendum
This DPA describes how Helixir processes personal data on behalf of customer organizations subject to the EU GDPR, UK GDPR, or equivalent regimes. Customers requiring a signed DPA should request one at info@nevika.co.
Roles
The customer is the controller. Helixir is the processor. Helixir processes personal data only on documented instructions from the customer, as reflected in the platform’s configuration and this page.
Categories of data
Clinician identifiers, workspace configuration, audit events, and free-text prompts and completions submitted through AI workflows.
Categories of data subjects
Customer personnel using Helixir and, incidentally, patients referenced in text a user submits into an AI workflow. Helixir applies a server-side identifier-redaction step before sending prompts to model providers.
Sub-processors
Helixir uses Supabase (managed Postgres, authentication, storage) and OpenRouter (LLM aggregator) as sub-processors. Helixir will provide reasonable notice of any material change to this list.
International transfers
Where personal data is transferred outside of the EEA/UK, Helixir relies on Standard Contractual Clauses or equivalent transfer mechanisms with sub-processors.
Security measures
Row-level security on all tables, per-organization scoping, immutable audit logging, encryption of data in transit, and rate limits on AI calls. Access to production data is restricted to authorized Helixir personnel on a need-to-know basis.
Assistance
Helixir will reasonably assist the customer with data subject requests, DPIAs, and consultation with supervisory authorities.
Return or deletion
On termination or written request, Helixir will delete or return customer personal data within a reasonable window, subject to legal retention requirements.