Privacy Policy

Last updated: August 2026

We, Helio Ltd. ("Helio", "we", "us", or "our"), welcome your use of our website at helio.so, our open-source MCP governance proxy, and any hosted services we provide ("Our Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our services, in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018. Personal data means any information relating to an identified or identifiable natural person, including your name and email address.

Helio is a governance proxy for Model Context Protocol ("MCP") tool calls. The open-source proxy is designed to be self-hosted. In that configuration, policy rules, tool-call traffic, and audit records stay on your infrastructure and are not transmitted to Helio. This Privacy Policy covers personal data we process when you visit our website, contact us, submit a design-partner enquiry, or use a hosted Helio service that we operate on your behalf.

1. Data Controller

The data controller responsible for your personal data is:

Helio Ltd.
128 City Road
London EC1V 2NX
United Kingdom

Email: hello@helio.so

2. Data We Collect Automatically

When you access our website, certain connection data is automatically transmitted to our web server, including:

  • Your IP address
  • Date and time of access
  • The URL of the requested resource
  • Browser type and version (user agent)
  • Referring URL

This data is processed to provide and secure our website. We do not use this data to identify you personally or merge it with other data sources, except where analytics tools are enabled with your consent as described below. The legal basis for this processing is our legitimate interest in providing a functional and secure website (Article 6(1)(f) UK GDPR).

3. Data You Provide to Us

You can browse our website and download or run the open-source software without providing personal data. Certain website features require you to provide information.

3.1 Email and other correspondence

If you contact us by email or through other channels listed on our website, we collect the information you choose to send us. This typically includes your email address and the content of your message.

Purpose: To respond to your enquiry and, where relevant, to discuss sales, partnerships, or support.

Legal basis: Our legitimate interest in communicating with you (Article 6(1)(f) UK GDPR) and, where you are exploring a commercial engagement, steps prior to entering a contract (Article 6(1)(b) UK GDPR).

Retention: Correspondence is retained for as long as needed to handle your enquiry and for a reasonable period afterwards for record-keeping, unless a longer period is required by law.

3.2 Design partner and product enquiries

If you request a design-partner conversation or otherwise ask us to follow up, we collect your email address and the details you choose to share about your agent setup. We use this to evaluate the request, reply, and, where relevant, discuss a commercial engagement.

Purpose: Handling design-partner and product enquiries.

Legal basis: Your consent (Article 6(1)(a) UK GDPR), steps prior to entering a contract (Article 6(1)(b) UK GDPR), and our legitimate interest in communicating with prospective users (Article 6(1)(f) UK GDPR).

Retention: Enquiry data is retained until you ask us to delete it, or until it is no longer needed for the purpose collected.

3.3 Hosted and Enterprise Services

If you use a Helio-hosted dashboard, incident log, SSO, or related enterprise service, we process account and operational data needed to provide that service. This may include names, work email addresses, organisation details, authentication identifiers, configuration metadata, and audit or incident records you choose to store with us.

Self-hosted deployments of the open-source proxy do not send tool-call payloads, policies, or audit trails to Helio. We do not receive that data unless you separately share it with us (for example, for support) or you subscribe to a hosted service that stores it.

Legal basis: Performance of a contract (Article 6(1)(b) UK GDPR) and our legitimate interest in operating and securing the service (Article 6(1)(f) UK GDPR).

4. Cookies and Similar Technologies

Our website uses cookies and similar technologies (such as local storage and scripts) to ensure functionality, improve user experience, analyse usage, and measure the effectiveness of our marketing. Cookies are small text files stored on your device.

4.1 Categories of Cookies

Strictly Necessary Cookies: These are essential for our website to function. They include:

  • Cookie-consent preference stored in local storage
  • Security cookies from our hosting provider (Vercel)

Legal basis: Performance of a contract (Article 6(1)(b) UK GDPR) and legitimate interest (Article 6(1)(f) UK GDPR).

Analytics Cookies: With your consent, we use analytics tools to understand how our website is used. These include:

  • Google Analytics (via Google Tag Manager)
  • Vercel Analytics and Speed Insights

These tools create pseudonymised usage profiles. IP addresses are anonymised where the provider supports it. Legal basis: Your consent (Article 6(1)(a) UK GDPR), provided via our cookie banner.

4.2 Managing Cookies

When you first visit our website, we display a cookie banner where you can accept or decline non-essential cookies. You can also configure your browser to reject or delete cookies, though this may affect functionality.

5. Third-Party Services

5.1 Hosting (Vercel)

Our website is hosted by Vercel Inc., 340 S Lemon Ave #3717, Walnut, CA 91789, USA. When you visit our website, Vercel processes your IP address to deliver content and protect against security threats. We also use Vercel Analytics and Speed Insights to understand site performance.

Legal basis: Legitimate interest (Article 6(1)(f) UK GDPR); analytics where consent is required (Article 6(1)(a) UK GDPR).

Vercel is certified under the EU-US Data Privacy Framework. For more information, see Vercel's privacy policy.

5.2 Google Analytics

We use Google Analytics to analyse website usage. Your IP address is anonymised before processing where supported. Google may transfer data to the USA under the EU-US Data Privacy Framework.

Legal basis: Your consent (Article 6(1)(a) UK GDPR).

5.3 Email Delivery (Resend)

We use Resend to send transactional emails related to design-partner and other website enquiries you submit.

Legal basis: Performance of a contract or steps prior to a contract (Article 6(1)(b) UK GDPR), and legitimate interest in responding to enquiries (Article 6(1)(f) UK GDPR).

6. International Data Transfers

Some of our service providers are located outside the UK. When we transfer your data internationally, we ensure appropriate safeguards are in place:

  • Adequacy decisions: Transfers to countries the UK has deemed to provide adequate protection
  • International Data Transfer Agreement (IDTA): The UK's standard contractual clauses for international transfers
  • UK Extension to EU SCCs: Where applicable, we use EU Standard Contractual Clauses with the UK Addendum

For transfers to the USA, we rely on the EU-US Data Privacy Framework where the recipient is certified, or appropriate contractual safeguards.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specific retention periods:

  • Contact and design-partner enquiries: For the duration of the enquiry plus a reasonable record-keeping period
  • Hosted-service account data: Duration of the account plus 30 days, unless a longer period is required by law or agreed in a customer contract
  • Analytics data: As per our analytics providers' policies (typically 14-26 months)

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include encryption, access controls, and regular security assessments.

The open-source Helio proxy is designed so that policy evaluation and audit storage happen on infrastructure you control. Helio does not phone home from self-hosted deployments.

9. Your Rights

Under UK data protection law, you have the following rights:

  • Right of access: Request a copy of your personal data
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your data in certain circumstances
  • Right to restrict processing: Request limitation of how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at hello@helio.so. We will respond within one month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority: ico.org.uk.

10. Right to Object

You have the right to object to processing of your personal data at any time where we rely on legitimate interests as the legal basis. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

For direct marketing, you can object at any time and we will stop processing your data for this purpose immediately.

11. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects. Policy decisions made by a Helio proxy you operate (allow, deny, hold for approval, and similar) are evaluations of tool calls against rules you configure, on infrastructure you control unless you have contracted a hosted service.

12. Children's Privacy

Our services are not directed at children under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a new "Last updated" date. We encourage you to review this policy periodically.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Helio Ltd.
128 City Road
London EC1V 2NX
United Kingdom

Email: hello@helio.so