Skip to main content

Privacy Policy

This policy explains what personal data Helpwing collects, why we hold it, who else ever sees it, and what you can ask us to do with it. It covers helpwing.app, the dashboard, the chat widget and the API.

Effective

1. Terms and definitions

  • “Help & Wing”, “we” and “us” — Help & Wing, the company established in Auckland, New Zealand that operates Helpwing and, for the data described in clause 3, the controller of it.
  • “Personal data” — any information relating to an identified or identifiable person.
  • “Processing” — anything done with personal data: collecting, storing, organizing, using, disclosing, erasing.
  • “User” — a person with a Helpwing account: an owner, an administrator or an agent of an organization.
  • “End user” — a person who writes to a support address or opens a chat widget belonging to one of our users. Their data reaches us because our user sent it.
  • “Cookie” — a small file a site stores in the browser, used here to keep a session signed in and to remember interface preferences.
  • “IP address” — the network address a request arrives from, recorded as part of ordinary server logging.

2. General provisions

Using the site or the service means you have read this policy and consent to the processing it describes. If you do not, do not use the service.

This policy applies to Helpwing only. Pages and services we link to — a payment network explorer, a hosting provider’s status page, a customer’s own site — have policies of their own, and we are not responsible for them.

We do not verify the accuracy of what you tell us, and we assume you are entitled to provide it. Keeping your details current is your part of the arrangement.

3. What this policy covers

We keep collection deliberately narrow. For a user of the service, that is:

  • Account data — name, email address and password hash. We never store a password in a readable form.
  • Organization data — the workspace name, its members and their roles, project settings, custom support domains and API keys.
  • Billing data — the plan on the organization, its deposit address and the on-chain transfers credited to it. Blockchain payments carry no card details, so we hold none.
  • Session and security data — sign-in times, browser and device description, IP address and the audit trail of administrative actions, so that a compromised account can be recognized and reviewed.
  • Support correspondence — what you write to us when you ask for help.
  • Technical logs — request metadata, error reports and aggregate product usage, kept to keep the service working and to find faults.

Cookies are necessary for signed-in access: without them there is no session to authorize. IP addresses are recorded for diagnostics, rate limiting and the prevention of abuse and fraud, not to profile you.

4. Why we collect personal information

We process the data above in order to:

  • Identify you and create and maintain your account.
  • Give you access to the parts of the service your role and plan allow.
  • Deliver the service itself — receive email, run the chat widget, store tickets, send replies.
  • Process payments and keep an accurate record of what your organization owes and has paid.
  • Answer your support requests and give you technical assistance.
  • Send service messages you cannot opt out of while you hold an account: security alerts, billing notices and material changes to these documents.
  • Detect, investigate and prevent abuse, fraud, spam and attempts to reach data belonging to another organization.
  • Understand in aggregate which parts of the product are used, so we can improve them.
  • Meet legal, accounting and tax obligations.
  • Send product news and offers — only if you have asked for them, and every such message carries a way to stop.

We do not sell personal data, we do not rent it to advertisers, and we do not use the contents of your tickets to train models.

5. How we process and share it

Processing is done by automated means on servers we operate or rent, with access limited to the people who need it to do their job and logged when it happens.

Personal data is disclosed to third parties only where it is needed to run the service. Those recipients act on our instructions, are bound to confidentiality, and may not use the data for their own purposes:

  • Postwing, which delivers outbound email on our behalf.
  • Our hosting, storage and content-delivery providers.
  • Error-monitoring and infrastructure-metrics providers.
  • Public blockchain networks, when a payment is settled. A transaction and the deposit address it went to are public by design; we publish nothing else to them.
  • Professional advisors, and a successor entity in the event of a merger or sale, on the same terms as this policy.
  • Competent state authorities, where a lawful and properly issued request requires it.

We are established in Auckland, New Zealand, and some of the providers above operate elsewhere, so your data will in the ordinary course be processed outside your own country. Where it crosses a border we rely on a lawful transfer mechanism and on contractual protections with the provider that hold it to standards comparable to those in this policy.

We keep data for as long as the account exists. After an organization is closed, its data is deleted within ninety (90) days, except records we are required to keep for accounting and tax purposes, which are held for the period the law prescribes. Backups age out on their own schedule and are not indefinite.

If a breach affecting your personal data occurs, we will notify you and, where required, the relevant supervisory authority, without undue delay and with what we know at the time.

6. Cookies and local storage

The dashboard sets what it needs to work and nothing more: a session cookie to keep you signed in, and browser storage for interface preferences such as theme and dismissed notices.

The chat widget stores a conversation identifier in the visitor’s browser so a returning visitor sees the thread they already started. It sets no advertising cookies and does not track visitors across sites.

Blocking these will sign you out and reset your preferences; the service cannot be used signed-in without them.

7. Data you send us about your end users

When your end users write to you, their messages, email addresses, attachments, names and any attributes you attach to them pass through Helpwing and are stored in your project.

For that data we are a processor and you are the controller. We hold it on your instructions, use it only to run your inbox, and do not contact your end users on our own account. Deciding what is collected, informing those people and holding the lawful basis for it is yours.

You can export or delete an end user’s data from the dashboard at any time. A deletion you make there is carried through our live systems; requests that reach us directly from one of your end users are passed to you rather than acted on unilaterally.

8. Your rights and choices

For the data described in clause 3 you may ask us to give you a copy of it, correct it, delete it, restrict or object to its processing, or provide it in a portable form. Most of it you can change yourself from the profile and organization settings screens.

Requests go to contact@helpwing.app and are answered within thirty (30) days. We may ask you to confirm your identity before acting — it is your protection as much as ours. If you believe we have handled your data badly, you may also complain to a supervisory authority: the Office of the Privacy Commissioner in New Zealand, or the one for the country you live in.

Deleting data we are legally required to retain, or that would break the integrity of an audit record, may be refused; where it is, we will say so and explain why.

9. Obligations of the parties

You undertake to provide the personal data the service needs, to keep it current, and not to send us personal data you have no right to send — including special categories of data, which the service is not built to hold and should not be put into tickets.

We undertake to use the data only for the purposes named in clause 4, to keep it confidential, not to disclose it beyond clause 5, and to take reasonable measures to protect it from loss and unauthorized access.

10. Liability

We are liable for losses caused by our unlawful use or disclosure of personal data, except where the information was already public, was received from a third party before we began processing it, was disclosed with your consent, or was exposed through credentials you failed to keep safe.

The limitations of liability in the Terms of Service apply to this policy as well.

11. Dispute resolution

A complaint about this policy is to be raised with us first. Send it in writing to contact@helpwing.app; we will answer within thirty (30) days of receiving it. Only after that period may a claim be taken further, under the law of New Zealand, which governs this policy as it does the Terms of Service.

12. Changes to this policy

We may update this policy as the service changes. The current version is always the one at this address, and the date it took effect is shown at the top of the page.

Where a change materially affects how we handle your data, we will tell you by email or in the dashboard before it takes effect. Continuing to use the service after that date means you accept the updated policy.