{% extends "base.html" %} {% block title %}How we handle your data — {{ site_name }}{% endblock %} {% block content %}
Short version: we keep the minimum needed to run a confidential document portal, and we are direct about the one thing people are usually not told — we log what you read.
| Data | Why |
|---|---|
| Email address and password hash | Your helexa account, shared with helexa.ai. We never store the password itself. |
| Which documents you open, and when | This material is confidential and commercially sensitive. Knowing which named account read which version of a document is how we look after it — and how we can tell you what you were shown if a question comes up later. |
| IP address and browser user-agent | Recorded alongside access events, to spot credential sharing or misuse. |
| Anything you send us in the interest form | So a human can respond to you. |
Access records are kept for {{ retention_months }} months and then deleted automatically. Your account lasts until you ask us to remove it.
{{ brand_name }} — {{ entity_note }} — and nobody else. We do not use analytics services, advertising trackers, or third-party fonts or scripts — this portal loads nothing from anyone else’s servers, which you can verify in your browser’s network tab.
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete your account, by writing to {{ contact_email }}. If we delete your account we keep the access record itself, with your account reference removed, because it is a record of how confidential material was handled.
The data controller is {{ entity_name }}, trading as {{ brand_name }}.