Skip to content

Your estimates, your customers, your money. Kept the way a contractor would keep them.

Planned security approach for Helmar.AI. Customer workspaces are not open yet. The controls below describe the intended product and must be implemented and verified before launch; they are not a certification or a claim that every control is already operating.

Product preview. Helmar.AI is in development. The features shown are planned; accounts and integrations are not open yet.

  • Hosted in the EUsub-processors in the EU only
  • Two-factor for every accountrecommended for everyone who signs in
  • Export any timeand for 90 days after you cancel

How data is protected

The controls, in plain words.

The same list is written into the data processing agreement. This is the readable version.

Encrypted in transit and at rest

TLS on every connection; data at rest is encrypted. Card numbers are handled by the payment partner and never reach Helmar.AI.

One workspace per contractor

Workspaces are logically separated. Your data is never visible to another company, and your customers see only their own page.

Two-factor authentication

Available for every account and recommended for everyone who signs in. The workspace owner decides who is invited and with which role.

An audit trail that cannot be edited

Prices, versions, acceptances, documents, payments and role changes are kept in a trail nobody can edit, with who and when.

Staff access is time-limited and logged

When our staff need to look into your workspace, the access is limited in time and recorded with a reason.

Daily encrypted backups, tested

Backups are taken daily, encrypted, kept in the EU, and restoration is tested. Monitoring, vulnerability management and patching run continuously.

Who can see what

Roles that match a building company.

The office answers customers without seeing margins. The crew sees the work and never a price. The accountant reads everything and changes nothing.

Can they…OwnerEstimatorOfficeReply handlerCrewSubcontractorBusinessAccountantBusinessCustomer
Approve prices and proposalsEach confirmed price keeps who set it and when
See margins and job costsCost, price and margin per line
Send proposalsOnly versions an owner or estimator approved
Record payments with evidenceCash receipts, manual matches
Approve refundsRecorded with the reason
Answer replies and book visitsWithout seeing prices or margins
Today’s jobs, checklists and photos1In the crew app, also offline
See the amount due at the handover2To show a QR code on site
See every invoice and payment3Documents also go to Rivilė every night
Their own proposal and job pageNo account, no app
Manage roles and billingWho is invited, with which role
  • Yes
  • No
  • Limited
  1. 1 Subcontractors see their days, their scope and the address.
  2. 2 Only a crew lead with the Collect payments permission.
  3. 3 Read-only.

Where data lives

In the European Union, with EU sub-processors.

Personal data is processed in the EU. Any transfer outside the EU or EEA would need your prior authorisation and an adequacy decision or the standard contractual clauses.

Hosting, database and file storage

In the EU. Daily encrypted backups with tested restoration.

Email, SMS, WhatsApp and Viber delivery

EU providers bound by written terms under GDPR Article 28.

Card payments and the read-only bank connection

Licensed EU partners. Helmar.AI never holds or moves your money and never sees card numbers.

Accounting sync

Rivilė, only when you enable it.

Changes announced 30 days ahead

A new or replaced sub-processor is announced at least 30 days before. You may object on data protection grounds.

Breaches reported within 48 hours

If a personal data breach affects your workspace, you are told within 48 hours of us becoming aware, with what happened and what to do.

If something happens

Two timelines, written down in advance.

What happens on a bad day, and what happens on your last day. Both are in the data processing agreement.

A personal data breach

  1. 1
    We become awareThrough monitoring, a partner’s notice, or a report to info@helmar.lt.
  2. 2
    Within 48 hoursYou are told what happened, which data was affected, and what to do.
  3. 3
    Authorities and customersYou notify the State Data Protection Inspectorate and your customers where the GDPR requires it. We provide the information you need.

You close the workspace

  1. 1
    Cancel in the workspaceAccess ends at the end of the paid period and the workspace becomes read-only.
  2. 2
    90 days of exportEvery document as a PDF, photos, and every record as CSV.
  3. 3
    DeletionFrom live systems, and within a further 90 days from backups, except what the law requires to be kept for 10 years, which stays restricted.

What we never do

Written into the terms, not a campaign.

Never

  • Hold or move your customers’ money
  • Send AI drafts without your approval
  • Use your customers’ data for our own purposes
  • Edit an issued document or an audit trail entry
  • Track where the crew is
  • Sell, share or train on your data

Always

  • Record what the bank confirms, nothing else
  • Send only templates you approved, from your own address
  • Act as your processor on your instructions, under a written agreement
  • Correct with credit notes and voids that keep the history
  • Record hours per job, never a location
  • Return an export and delete after 90 days when you leave

Signatures & evidence

Accepted with a name, a time and a hash.

Email code

A 6-digit code sent to the customer’s address. A simple electronic signature under the eIDAS Regulation and the Lithuanian Law on Electronic Identification.

Smart-ID and Mobile-ID

Qualified signatures, offered per proposal on Business, for larger or business work.

The evidence record

Name, time, the exact version and the document hash, plus the signed PDF for both sides. Sent, opened, questions, versions and the acceptance kept in order.

How long data is kept

As long as the law needs, and no longer.

After you close the workspace the export stays available for 90 days; then data is deleted from live systems and, within a further 90 days, from backups, except what the law requires to be kept.

Estimates, acceptances, invoices and payment records
10 years, as Lithuanian accounting rules require
Messages and delivery logs
5 years
Site photos
5 years after the job
Leads that never became an estimate
12 months
Website server logs
90 days
After you close the workspace
90 days to export, then deleted

Found a problem?

Tell us directly.

If you believe you have found a security issue in Helmar.AI, write to us before anyone else. A person reads it the same working day and you will hear back within one.

info@helmar.lt

Questions

Straight answers.

Who owns the data?
You. You own your estimates, documents and customer data; Helmar.AI processes your customers’ data only on your instructions under a data processing agreement.
Is there two-factor authentication?
Yes, for every account.
Is there an audit trail?
Every important change is kept in an audit trail that cannot be edited, and each confirmed price keeps who set it and when.
Do you see card numbers?
No. Card numbers are handled by the payment partner and never reach Helmar.AI.
What if a customer asks about their data?
We forward the request to you within 2 working days and help you answer within 30 days.
Can I audit you?
Each year we provide a summary of our controls and any independent assessment we hold. You may audit our compliance with the agreement, yourself or through an auditor bound by confidentiality, once in any 12 months on reasonable notice.
Is there an uptime commitment?
We aim for 99.9% monthly availability and announce planned maintenance in the workspace.

See the preview

Keep the record. Keep control of it.

Explore the product preview in a 20-minute demo. Accounts are not open yet. No card, no obligation.