Helvety Cloud Data Processing Addendum (metadata)
This Data Processing Addendum ("DPA") applies when a customer organization ("Customer") uses Helvety Cloud and Helvety by Rubin ("Helvety") processes personal data in account, authentication, invitation, policy-acceptance, or billing metadata on Customer's documented instructions. It does not apply to end-to-end encrypted workspace content Helvety cannot decrypt. Related: Privacy Policy, Terms of Service.
1. Roles
For the metadata in scope, Customer is the controller and Helvety is the processor under Art. 9 of the Swiss Federal Act on Data Protection (nDSG), to the extent Customer determines the purposes and means of that processing. Helvety remains controller of its own account operations where it alone determines purposes (for example product security logs and Helvety's own billing records), as described in the Privacy Policy. Helvety is not a processor of encrypted workspace plaintext it cannot access.
2. Scope of processing
Subject matter: operating Helvety Cloud for Customer's authorized users. Duration: while the relevant Cloud accounts and workspaces exist and for retention described in the Privacy Policy. Nature: storage, transmission, and support for metadata Helvety holds. Categories of data subjects: Customer's users and invitees. Categories of personal data: email addresses, authentication and membership metadata, policy acceptance records, invitation metadata, billing identity and subscription status, and technical logs reasonably needed to operate the Service. Not in scope: titles, bodies, filenames, file bytes, or other workspace plaintext that remains ciphertext.
3. Instructions
Helvety processes in-scope metadata only on Customer's documented instructions, including use of Helvety Cloud, the Terms, this DPA, and configuration in the product (for example invitations and billing). Helvety informs Customer if an instruction appears to violate Swiss data protection law. Helvety may process as required by Swiss law; Helvety will inform Customer of such a legal requirement unless prohibited.
4. Security
Helvety implements appropriate technical and organizational measures for the Service, including TLS in transit, access controls, separation of encryption unlock from session auth, and end-to-end encryption of workspace content on user devices. Helvety ensures persons authorized to process metadata are bound to confidentiality.
5. Subprocessors
Customer authorizes Helvety to engage the infrastructure processors listed in the Privacy Policy subprocessors section (including Supabase in Zurich, Vercel, Stripe, and email delivery used for auth). Helvety remains responsible for subprocessors under Art. 9 nDSG. Material changes to that list are published on the Privacy Policy page.
6. Assistance and breaches
Taking into account the nature of processing, Helvety assists Customer with data subject requests and security obligations for in-scope metadata Helvety holds. Helvety cannot produce encrypted workspace plaintext. Helvety notifies Customer without undue delay after becoming aware of a personal data breach affecting in-scope metadata, and cooperates on information reasonably needed for Customer's notification duties.
7. Return and deletion
On account closure or written request, Helvety deletes or returns in-scope metadata as described in the Privacy Policy and product deletion flows, except where Swiss law requires longer retention (for example accounting). Shared workspaces with remaining members are not wiped for those members when one user leaves or deletes their account.
8. Governing law
This DPA is governed by the substantive laws of Switzerland. Exclusive jurisdiction is Basel-Stadt, Switzerland, except where mandatory law provides otherwise. Questions: contact@helvety.com.