Privacy Policy

Version: 1.3·Last updated: September 11, 2026

Helmsted, Inc. ("Helmsted," "we," "our," or "us") is a Delaware corporation committed to protecting the privacy and security of the information entrusted to us. This Privacy Policy describes how we collect, use, store, and share information in connection with our platform and services (the "Services").

Helmsted supports information management and collaboration among clients and professionals in independent wealth management. We process information to provide authorized services, operate and secure accounts and integrations, and meet applicable obligations. Our role depends on the service. Separate client services do not automatically expand rights in information received for a firm.

1.Scope of This Policy

This Privacy Policy applies to:

  • Financial advisors and firms using Helmsted
  • Other professionals and firms participating in authorized services
  • End clients of those advisors whose data may be processed through Helmsted, including clients who hold their own Helmsted account for the client portal
  • Visitors to our website and users of our platform

Our role depends on the service and the activity. We process firm information under the applicable DPA and provide separately authorized services only within the necessary rights and source restrictions. A firm-created record does not itself establish client acceptance.

2.Information We Collect

The categories below depend on the services used and integrations enabled. Optional or planned capabilities are not available in every account.

A.Information Provided Directly

  • Name, email address, phone number, and professional credentials
  • Firm name, CRD number, and professional affiliation
  • Account login credentials
  • Communications processed through the platform (messages, emails, meeting notes, call transcripts)
  • Documents uploaded to the platform (e.g., tax returns, estate documents, financial statements, insurance policies)

B.Financial and Planning Data

  • Assets, liabilities, income, and expenses
  • Investment holdings and custodial account data
  • Insurance, estate, and trust documentation
  • Account balances, holdings, and transactions retrieved from financial institutions a client chooses to connect through account aggregation (see Section 15)
  • Other financial information provided by advisors or their clients for planning purposes

C.Communication and Recording Data

  • Audio recordings of calls and meetings conducted through or connected to the platform
  • Transcriptions generated from recorded calls and meetings
  • Automated meeting summaries, action items, and follow-up recommendations
  • Email content and metadata processed through integrated email accounts

Each party is responsible for obtaining the notices and consents required for its recording and communications activities before processing begins.

D.Automatically Collected Information

  • Device and browser information
  • IP address and approximate location data
  • Usage data (features used, interactions, session duration, and activity patterns)

E.AI-Derived Data

  • Structured data extracted from uploaded documents
  • Summaries, insights, and planning considerations generated by AI systems
  • Metadata and contextual relationships identified across financial data points
  • Proactive alerts based on regulatory changes, market conditions, or client-specific triggers

3.How We Use Information

We use technical information and other permitted data to maintain and improve services within our agreements and source restrictions. We do not sell client information or use it to train AI models. Professional business information may support network administration and development; client information embedded in it remains protected.

Permitted purposes include organizing financial information; generating requested analyses and professional workflow materials; facilitating authorized communications and integrations; maintaining records and security; and meeting applicable legal duties. Usage Data, Structural Knowledge, and De-identified Aggregated Data remain subject to DPA section 2.4. Account content from Plaid or custodial feeds, including derived account content, is excluded from de-identified aggregation.

Helmsted provides technology and informational assistance, not investment or other professional advice. Each professional remains responsible for its services and for reviewing and approving professional advice and materials before release to the client. Informational tools, including spending and budgeting assistance, may respond directly to clients. AI outputs may contain errors.

4.Data Minimization and Access Controls

We limit access and processing to authorized purposes. Supported text paths mask detected sensitive identifiers before AI submission. Images may contain unmasked identifiers, and masking does not remove all personal information.

5.AI Processing and Zero Data Retention

We do not use adviser or client information to train or fine-tune AI models. AI-provider processing is subject to the applicable no-training and zero-retention commitments. Helmsted separately retains service records under the applicable retention terms.

AI providers must operate under verified arrangements prohibiting model training and providing zero retention of customer inputs and outputs for the services used, as required by the DPA. See helmsted.ai/security/subprocessors.

6.Professional Relationships and Client Accounts

Independent professionals serve you under their own engagements. Your authorization does not override rights in other people's information, protected firm materials, or restricted feeds. You may withdraw authorization for future sharing by contacting privacy@helmsted.ai or using available controls. Lawfully received copies may remain subject to the recipient's retention duties.

Where available under separately accepted service terms, an account may support continuing services and other authorized professional relationships. Ending one relationship does not itself terminate another valid relationship. Retention and further use still require the applicable rights and a valid service or preservation basis. This does not promise uninterrupted access or a future feature.

Clients may exercise applicable rights directly with Helmsted or through their professional. A separate client relationship does not expand rights in information received for another firm.

7.Sharing of Information

We do not sell personal information.

We may share information in the following limited circumstances:

A.Authorized Professional Recipients

We share designated records with firms, personnel, and independently engaged professionals authorized for the relevant services, including advisers, accountants, attorneys, and insurance professionals. Authorization remains subject to applicable law and source restrictions.

B.Service Providers

Technology providers processing on our behalf are subject to applicable contractual protections. Our versioned Subprocessor list is at helmsted.ai/security/subprocessors. Independent professionals receiving records for their own engagements are separate recipients. Participation alone is not a guarantee of their services.

C.Legal and Regulatory Requirements

We may disclose information to comply with applicable laws, regulations, subpoenas, court orders, or legal processes, and to support RIA regulatory obligations including SEC and state recordkeeping requirements.

D.Business Transfers

In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will provide notice of any such transfer and any choices you may have regarding your information.

8.Data Retention

We retain information for authorized services and applicable preservation duties, which may continue after an engagement ends. Eligible active-system data is deleted within the applicable contractual or legal period, subject to lawful exceptions. Restricted backups expire under the applicable schedule, with deletions reapplied if restored.

For firm requests, the DPA preserves the applicable 30-day return-or-delete election, subject to lawful preservation and authorized continuity. Contract-covered audit and processing records have a minimum five-year retention period from creation, with the first two immediately accessible; longer periods and different legal starting events apply where required. Continuing client records require a valid service or preservation basis.

9.Data Portability and Exit

You may contact privacy@helmsted.ai to request access, correction, an eligible export, deletion, or an explanation of retained information. We verify authority without undue delay, protect other people's records, and respond within applicable legal deadlines. An export does not transfer account credentials or data-provider permissions.

Firms may request an export in a standard, machine-readable format. Clients may request eligible records in their account. We work with affected users on an orderly transition, subject to source rights and required preservation.

10.Data Security

We implement industry-standard administrative, technical, and physical safeguards to protect information, including:

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Role-based access controls and individual credentials
  • Activity logging and monitoring
  • Security assessments and remediation
  • Written security policies; see helmsted.ai/security for current audit status

No system can be guaranteed to be completely secure. In the event of a data breach that affects your personal information, we will notify affected parties in accordance with applicable law.

11.Your Rights and Choices

Depending on your jurisdiction, you may have the right to:

  • Access your personal data held by us
  • Request correction of inaccurate or incomplete data
  • Request deletion of your data (subject to regulatory retention requirements)
  • Restrict or object to certain processing activities
  • Receive your data in a portable format

Use the request process in section 9. Preservation duties may continue after a professional engagement ends; we explain any applicable retained information.

If you are an advisor or firm, contact us at privacy@helmsted.ai to exercise your rights.

California Residents (CCPA)

Applicable rights may include access, correction, deletion, and limits on certain uses, sale, or sharing of personal information, subject to legal exceptions. We do not sell personal information or discriminate for exercising applicable rights. Contact privacy@helmsted.ai to submit a request.

12.AI and Automated Processing

We maintain safeguards appropriate to the information and services, including access controls, encryption, and activity monitoring. Significant platform events and AI-processing metadata support oversight and troubleshooting; available records vary by workflow. Supported document workflows maintain revision history. See our security disclosures for current practices and audit status.

Informational tools may respond directly to clients. Professionals review and approve professional advice and materials they release. AI outputs may contain errors.

13.Communication Recording Disclosures

Recording, automated communications, connections, and other sensitive features require the notices and consents applicable to the activity. General account acceptance does not replace them.

When authorized recording features are used, recordings and transcriptions receive the applicable safeguards and retention treatment. Each party remains responsible for its own communications and recording obligations.

14.Cookies and Tracking Technologies

We may use cookies and similar technologies to:

  • Maintain sessions and authentication state
  • Analyze platform usage and performance
  • Improve user experience

We do not use cookies for third-party advertising. You can manage cookie preferences through your browser settings.

15.Account Aggregation and Third-Party Integrations

A.Account Aggregation

Optional account connections use Plaid Inc. and require the applicable data-access and sharing authorizations. Review Plaid’s terms and privacy policy at plaid.com/legal. Helmsted does not store your financial-institution password through the connection service. Account information may include balances, holdings, transactions, and identifiers.

Connections retrieve information only while the applicable authorization and provider arrangement remain valid. Disconnecting stops future retrieval; deletion of prior data follows applicable law and provider terms. Keeping history does not automatically authorize refresh or access by a new professional.

You may request disconnection or deletion through available controls or privacy@helmsted.ai. Account content is never used for model training and is excluded from de-identified aggregation. Financial-institution restrictions and required deletion obligations continue to apply.

B.Other Integrations

Helmsted may also integrate with third-party systems, including email providers, custodians, calendar services, and other financial technology platforms. Data shared with these integrations is governed by their respective privacy policies. We encourage you to review the privacy practices of any third-party services you connect to Helmsted.

16.Children's Privacy

The service is intended for adults and authorized representatives. Records they provide may include information about dependents or beneficiaries, subject to the same protections.

Children are not invited to create accounts or use the service independently.

17.Changes to This Policy

We identify policy versions, give advance notice of material changes, and obtain additional consent where required before new uses begin. Posting a policy does not retroactively expand rights in previously collected information.

Material changes are notified in advance by email or through the service, subject to the applicable agreement and notice period. Versions and change history are retained.

18.Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact:

Helmsted, Inc.

Registered in Delaware

privacy@helmsted.ai