GDPR & UK GDPR Notice
This notice supplements our Privacy Policy for individuals in the European Economic Area (EEA), United Kingdom, and Switzerland.
Last updated: July 28, 2026
This GDPR & UK GDPR Notice explains how NoteHelix processes personal data in connection with NoteHelix Cloud and our public website when EU/EEA, UK, or Swiss data protection law applies. It should be read together with our Privacy Policy and Terms of Service.
If there is a conflict between this notice and the Privacy Policy on a topic specific to GDPR/UK GDPR rights, this notice controls for those individuals.
1. Controllers and roles
1.1 NoteHelix as controller
NoteHelix is the controller for personal data related to account registration, billing identity, website analytics necessary for the service, security logs, and communications you send to us.
1.2 NoteHelix as processor
For Customer Content stored in workspaces (notes, tasks, chat, and similar collaboration data), NoteHelix generally acts as a processor (or service provider) on behalf of the customer organization or account owner that controls the workspace. That customer determines the purposes of processing Customer Content. If you are an end user in someone else’s workspace, contact that workspace’s administrator for many data-subject requests related to workspace content; we will assist administrators as required.
2. Categories of personal data
Depending on how you use the Cloud Service, we may process:
- Identity and contact data (name, email)
- Account and authentication data
- Workspace content and collaboration metadata
- Usage, device, and log data
- Billing and subscription metadata via Stripe
- Support correspondence
Details appear in the Privacy Policy.
3. Purposes and legal bases
We process personal data on one or more of the following bases:
- Contract — to provide the Cloud Service you request, including account management, sync, collaboration, and paid subscriptions
- Legitimate interests — to secure and improve the service, prevent abuse, understand product usage in a privacy-aware way, and communicate important service messages, balanced against your rights
- Legal obligation — to comply with applicable laws, respond to lawful requests, and keep required financial records
- Consent — where we rely on consent (for example, for certain optional communications). You may withdraw consent at any time without affecting prior lawful processing
4. International transfers
Personal data may be processed in the United States and other countries outside your country of residence. Where GDPR/UK GDPR requires safeguards for transfers to countries without an adequacy decision, we use appropriate mechanisms such as the European Commission’s Standard Contractual Clauses (and UK addenda where applicable), together with supplementary measures as needed.
5. Retention
We keep personal data only as long as needed for the purposes described, including providing the service, resolving disputes, enforcing agreements, and meeting legal retention requirements. See the retention section of our Privacy Policy for more detail.
6. Your rights under GDPR / UK GDPR
Subject to legal limits, you may have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Erase personal data (“right to be forgotten”)
- Restrict processing
- Data portability
- Object to processing based on legitimate interests
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority in your country of residence or workplace
To exercise these rights with NoteHelix as controller, email contact@notehelix.com. We may ask for information to verify your identity and will respond within the timelines required by law (generally one month, extendable where permitted for complex requests).
If your request relates to Customer Content controlled by a workspace administrator, we may redirect you to that administrator or require their authorization before acting.
7. Automated decision-making
We do not use personal data for automated decision-making that produces legal or similarly significant effects about you without human involvement.
8. Children
The Cloud Service is not directed to children under 16. We do not knowingly process children’s data in violation of GDPR age-of-consent rules. Contact contact@notehelix.com if you believe we have collected such data in error.
9. Subprocessors
We use carefully selected subprocessors for hosting, databases, email delivery, monitoring, and payment processing (including Stripe). We remain responsible for subprocessors we engage for the Cloud Service and require appropriate data-protection terms.
10. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and monitoring. No system is perfectly secure; please protect your credentials and report suspected incidents to contact@notehelix.com.
11. Data Protection Officer / privacy contact
For GDPR/UK GDPR inquiries, data-subject requests, or transfer questions, contact us by email only at contact@notehelix.com. We do not provide a telephone contact for privacy matters at this time, and we do not publish a postal address in this notice.
12. Changes
We may update this notice periodically. The “Last updated” date will change when we do. Material updates may also be announced by email or in-product notice.