Privacy policy
How the helmar.app website handles enquiries, demo requests and optional analytics. Contractor accounts and customer workspaces are not open yet; the product-related sections below describe the planned service.
In short
- For website visitors and demo enquiries, MB Helmar is the data controller.
- The website stores enquiries on its hosting server in Germany and sends them to our inbox through Resend.
- Google Analytics 4 loads only with your consent. Provider access outside the EU is described below.
1. Who we are
MB Helmar, company code 304242987, VAT code LT100020159311, registered at Šaltoniškių g. 2, Vilnius, Lithuania (“Helmar.AI”, “we”), operates the helmar.app website and is developing the Helmar.AI workspace, a planned service for construction contractors to prepare estimates, record acceptances, issue invoices and match payments.
For visitors of this website and for contractor accounts we are the data controller. For the customers of a contractor (the people who receive an estimate, accept it or pay an invoice) the contractor is the controller and we act as their processor under the Data processing agreement. Questions and requests: info@helmar.lt.
Contractor accounts, customer verification, invoicing and payment integrations are not available in this preview. Do not enter real customer information into the illustrative workspace.
2. What this policy covers
This policy covers three places where personal data is handled:
- the public website helmar.app, including the contact form and cookies;
- the workspace at the app address, used by contractors and their teams;
- the customer pages and documents that a contractor sends to their customers.
3. What we collect
Site visitors: technical data needed to serve the pages (IP address, browser and device type, pages visited, time stamps), the cookies described in the Cookie policy, and whatever you send through the contact form or a call request (name, company, email or phone, what you quote, your message and the call time you ask for).
Contractor accounts: name, email, phone, role in the workspace, company details (name, codes, address, bank account for documents), billing details and invoices for the subscription, sign-in records and two-factor settings, and the content you create: price book, measurements, estimates, versions, documents, photos, notes, messages and payment records.
Customers of contractors (processed on the contractor’s behalf): name, contact details, property address, the estimates, change orders, invoices and other documents addressed to them, the evidence of an acceptance (name, time, one-time code, document hash and technical data such as IP address), message delivery records, and payment references received from the bank or the card partner. Card numbers are handled by the payment partner and never reach Helmar.AI.
4. Why we use it and on what basis
- To provide the service you signed up for and to run the customer pages: performance of a contract (GDPR Article 6(1)(b)).
- To issue invoices, keep accounting records and answer lawful requests from authorities: legal obligation (Article 6(1)(c)), including the retention periods required by Lithuanian accounting and tax law.
- To keep the service secure, prevent fraud and abuse, keep audit trails and improve the product from aggregated usage: our legitimate interest (Article 6(1)(f)), balanced against your rights.
- Statistics cookies on the website and any marketing email: your consent (Article 6(1)(a)), which you can withdraw at any time.
We do not use personal data for automated decisions with legal effect, and we do not sell personal data.
5. Customers of contractors
When a contractor sends you an estimate, an invoice or a message through Helmar.AI, the contractor decides what is collected and why. We act on their instructions, keep the documents unchanged as the legal record of what was accepted, and never contact you for our own purposes. Requests about your data should go to the contractor named on the document; if you write to us, we forward your request to them within 2 working days and help them answer within 30 days.
6. Who we share it with
For this website we use Hostinger International Ltd (hosting on a server in Germany), Resend (Plus Five Five, Inc., delivering contact messages and call requests to our inbox), and, only after analytics consent, Google Ireland Ltd (Google Tag Manager and Google Analytics 4). Enquiries are also stored in our website database and mailbox. Provider processing outside the EU is described in the transfers section.
Customer workspaces, messaging integrations, payments, bank connections and accounting synchronisation are planned. Their providers and processing terms will be confirmed before those services open.
We disclose data to authorities when legally required. If the website changes ownership, we will notify affected people as required and explain any change to processing.
7. Where the data lives
The website enquiry database and its server backups are stored on our hosting server in Germany. Email delivery and analytics also involve other locations: Resend identifies its primary processing operations as being in the United States, and Google may process analytics data outside the EU or EEA. Resend’s data processing addendum incorporates the European Commission’s standard contractual clauses for relevant transfers. Google’s applicable processing and transfer terms govern its analytics service. This website does not promise that all provider processing stays in the EU.
Providers and transfer arrangements for future customer workspaces will be confirmed before that service opens.
8. How long we keep it
Website enquiries that have not become customers are eligible for deletion from our lead database after 12 months. The automatic cleanup runs when a new enquiry arrives or our team opens the leads area. Database backup copies are kept for 14 days, so a deleted enquiry can remain in a backup for up to 14 days more.
Email copies in our inbox are managed separately; deleting a database record does not delete the email. We must review and remove those copies as part of the same retention process. You can request deletion through the contact details below.
The previous product retention schedule for estimates, invoices, customer messages and workspace exports is a draft. Final periods, accounting obligations and provider retention will be confirmed before customer workspaces open. Cookies are described on the Cookie settings page.
9. How we protect it
The current website uses HTTPS, a password-protected admin area with hashed credentials and secure session cookies, access checks on admin operations, request limits and daily server backups. These are the controls implemented for website enquiries and posts.
Two-factor authentication, encryption at rest, separate customer workspaces, tamper-resistant audit trails and a tested incident and restoration process remain requirements for the planned product. They are not verified controls of the current website. We will describe the implemented measures before customer workspaces open.
We assess suspected personal data breaches and notify the relevant authority and affected people when the applicable law requires it.
10. Your rights
You can ask us to see and export your data, correct it, delete it where the law allows, restrict or object to its use, and move it to another provider. Where we rely on consent you can withdraw it at any time; where we rely on legitimate interest you can object and we will stop unless we have compelling grounds.
Write to info@helmar.lt. We answer within 30 days. You can also complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, Vilnius, vdai.lrv.lt) or to the authority of the EU country where you live.
11. Cookies
The website sets only the necessary cookies by default. Statistics cookies run only after you accept them in the banner, and you can change your choice at any time on the Cookie settings page. Customer pages set only the session cookie needed for the one-time code. Details, names and durations are in the Cookie policy.
12. Children
The service is for businesses and their adult customers. We do not knowingly collect data from anyone under 18; if you believe we have, write to info@helmar.lt and we will delete it.
13. Changes to this policy
We may update this policy when the service or the law changes. Material changes are announced in the workspace and by email 30 days before they apply; the version and date at the top of this page always show the current text.
14. Contact
MB Helmar · Šaltoniškių g. 2, Vilnius, Lithuania · info@helmar.lt · +370 693 33 057. Data protection questions: info@helmar.lt with “Privacy” in the subject line.
Questions about this document? Write to info@helmar.lt — a person answers within one working day.