Last updated · July 2026
Privacy Policy
This page describes how Helixir (‘we’, ‘us’) processes information on behalf of the healthcare organizations that use our platform. This page is maintained by Helixir; it is not a substitute for independent legal review, and it is not a certification.
Who this policy is for
Helixir is a business-to-business platform used by clinicians, hospital administrators, pharmacies, diagnostic labs, and payers. We do not offer Helixir directly to patients. Individuals seeking their own health information should contact their healthcare provider.
What data we process
Operational data supplied by the customer organization, including clinician profiles, workspace configuration, audit events, and text or transcripts that authorized users choose to submit into the platform. Helixir does not require, and does not seek, protected health information (PHI) at signup.
How PHI is handled in AI workflows
When a user submits clinical text to an AI workflow, Helixir applies a server-side redaction layer that removes obvious identifiers (names in the form of MRN references, phone numbers, email addresses, dates of birth, addresses, and payment identifiers) before the prompt leaves our infrastructure. Redaction is a defense-in-depth control, not a substitute for the customer’s own minimum-necessary review.
Third-party model providers
Helixir uses model providers reached through an aggregator (OpenRouter). Model responses are generated at request time; Helixir does not permit model providers to train on customer prompts. Customers requiring a signed BAA or DPA with a specific model provider should contact us before enabling that workflow.
Retention
Audit records are retained for the life of the customer’s subscription. AI prompts and completions are stored only as long as needed to render the response and to write the audit event; they are not retained for training or analytics.
Access, deletion, and portability
Administrators of a customer organization can view audit history, remove users, and request deletion of their organization’s data at any time by contacting info@nevika.co.
Security
Helixir enforces row-level security on every table, per-organization scoping via database policies, immutable audit logging of AI activity, and rate limits on model calls. This is a description of enabled controls, not an independent certification.
Contact
Questions about this policy: info@nevika.co.