Skip to content

Data processing agreement

Draft data processing agreement for the planned Helmar.AI service. Customer workspaces are not open yet; processing terms and providers will be confirmed before launch.

Version 2 · 24 September 2026

In short

  • You are the controller; we act only on your instructions given through the workspace.
  • EU sub-processors, listed and announced 30 days ahead; you may object.
  • Breaches reported to you within 48 hours of us becoming aware; an export and deletion 90 days after you close.

1. Parties and roles

This agreement is part of the Terms of use between the contractor holding the workspace (“Controller”, “you”) and MB Helmar, company code 304242987, Šaltoniškių g. 2, Vilnius, Lithuania (“Processor”, “Helmar.AI”, “we”). You determine the purposes and means of processing your customers’ personal data; we process it on your behalf. It is concluded under Article 28(3) of Regulation (EU) 2016/679 (GDPR) and the Lithuanian Law on Legal Protection of Personal Data.

2. Subject matter, nature and purpose

We store, display, send, record and back up the personal data you enter or that your customers enter on the pages you send them, for the purpose of preparing estimates and proposals, recording acceptances, issuing invoices and receipts, matching payments, sending the messages you approved and keeping the documents as the record of what was agreed. The processing lasts for the term of your subscription and the 90-day export period after it.

3. Data subjects and categories of data

Data subjects: your customers and their representatives, the people at your customers’ properties, your users and crew, your subcontractors and suppliers.

Categories: identification and contact details; property addresses; the content of estimates, change orders, invoices, receipts and other documents; acceptance evidence (name, time, one-time code, document hash, IP address); message content and delivery records; payment references; site photos; time records of your crew. No special categories of data are intended; do not enter health or similar data about customers.

4. Your instructions

We process personal data only on your documented instructions, which are the settings and actions in the workspace, these terms and any written instruction you send to info@helmar.lt. If we believe an instruction infringes the GDPR or other law, we tell you before acting. We do not use your customers’ personal data for our own purposes.

5. Confidentiality

Every person we authorise to process personal data is bound by confidentiality by contract or law, has access only to what their task requires, and that access is time-limited and logged with a reason.

6. Security measures

Taking into account the state of the art and the risks, we maintain at least: encryption in transit and at rest; logical separation of workspaces; two-factor authentication; role-based access with an audit trail that cannot be edited; daily encrypted backups in the EU with tested restoration; monitoring, vulnerability management and patching; secure development practices and code review; an incident response procedure; and a yearly review of these measures. A summary of the current measures is available on request.

7. Sub-processors

You give general authorisation for the sub-processors we use to deliver the service: email delivery; SMS, WhatsApp and Viber delivery; hosting, database and file storage; card payments; the read-only bank connection; accounting synchronisation (Rivilė) when you enable it. All are established in the European Union and bound by written terms that give the same level of protection as this agreement. The current list with names and locations is in the workspace settings and available on request.

We tell you at least 30 days before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot offer an alternative, you may cancel the affected part of the service and receive a refund for the unused prepaid period.

8. Assistance and breach notification

  • Data subject requests: if a customer sends a request to us, we forward it to you within 2 working days and help you answer within the 30 days the GDPR allows.
  • Impact assessments and consultations with the supervisory authority: we provide the information about our processing that you reasonably need.
  • Personal data breaches: we inform you without undue delay and at the latest 48 hours after becoming aware, with what we know about the nature, the data and people concerned, the likely consequences and the measures taken, and we keep you updated. You notify the State Data Protection Inspectorate and your customers where the GDPR requires it.

9. International transfers

Personal data is processed in the European Union. Any transfer to a country outside the EU or EEA happens only with your prior authorisation and on the basis of an adequacy decision or the European Commission’s standard contractual clauses, with supplementary measures where needed.

10. Audits

Once a year we provide a summary of our controls and any independent assessment we hold. You may audit our compliance with this agreement, yourself or through an auditor bound by confidentiality, once in any 12-month period, on 30 days’ written notice, during working hours, without disrupting the service and at your cost, unless a supervisory authority or a breach requires an earlier audit.

11. Return and deletion

During the subscription you can export all personal data at any time. When the workspace closes we keep the export available for 90 days and then delete the personal data from live systems and, within a further 90 days, from backups, except what Lithuanian accounting and tax law requires you or us to keep (documents and payment records, 10 years), which we then keep restricted and delete when the period ends.

12. Liability

Each party is responsible for its own compliance with the GDPR. The limitations of liability in the Terms of use apply to this agreement, except where the GDPR makes a party liable to data subjects for damage caused by processing that infringes it.

13. Term and precedence

This agreement applies for as long as we process personal data for you and prevails over the Terms of use on matters of data protection. If any provision is invalid, the rest remains in force and the invalid provision is replaced by one that comes closest to its purpose.

14. Contact

Data protection matters: info@helmar.lt with “DPA” in the subject line. MB Helmar · Šaltoniškių g. 2, Vilnius, Lithuania · +370 693 33 057.

Questions about this document? Write to info@helmar.lt — a person answers within one working day.