Home›Privacy Policy

Privacy Policy (Helios Pro)

This policy covers Helios - Solar Energy Management Platform, the installer-facing product we call Helios Pro. Solar system owners who use the customer portal should read the customer privacy policy instead.

Last updated: 13 August 2026

1. Introduction

Helios Pro (“Helios Pro”, “we”) provides solar installation business tools to installer organizations. This policy covers personal data we process about installer-org users (admins, employees) and the customers managed inside an installer’s account. The data controller is Helios Energy Management Solutions, Nicosia, Cyprus.

2. Data We Collect

  • Account information: name, email, phone, role
  • Organization data: company name, VAT, billing identity, customer roster
  • Operational data: proposals, invoices, leads, calendar entries
  • Billing details: subscription plan, payment information
  • Usage data: access logs, audit trail, platform interactions
  • Mailbox data, only if you connect a mailbox — see section 4

3. Purpose of Processing

We process your data to operate the Helios Pro installer platform: managing your customer roster, sending proposals and invoices, processing subscription payments, and providing technical support and legal compliance.

4. Google Account Data (Gmail and Microsoft 365 Integration)

Helios Pro includes a shared inbox. A member of your team may choose to connect their own Gmail or Microsoft 365 mailbox so that incoming customer email is filed against the matching lead, customer or service ticket inside Helios. This integration is optional and is off until someone connects a mailbox.

What we request

  • We request a single Google scope, gmail.readonly (https://www.googleapis.com/auth/gmail.readonly). It grants read access only. Helios cannot send, delete, or modify anything in your Gmail account.
  • We request it because the shared inbox has no other way to see the customer replies it is built to organize. Nothing else in Helios uses Gmail access.

What we do with it

  • Helios checks the connected mailbox roughly every five minutes for new messages, using an incremental cursor so only new mail is fetched.
  • Message sender, subject, body and timestamps are stored in your organization’s inbox so the thread can be shown against the matching record. Unmatched messages are either surfaced in your support inbox or logged and discarded, depending on a setting you control.
  • Access and refresh tokens are encrypted at rest (AES-256-GCM) and are decrypted only at the moment a request is made to Google.
  • Mailbox data is confined to your organization. Multi-tenant isolation means no other Helios customer can query it.

What we never do with it

  • We do not sell Google user data, and we do not transfer it to data brokers or to anyone for advertising purposes.
  • We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
  • Our staff do not read your mail. Humans access Google user data only where you have given explicit consent for a specific support request, where it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

Third parties

  • Google user data is stored on our infrastructure and is not shared with third parties, with one exception: if your plan includes the optional AI reply-drafting feature and a user asks for a draft, the messages in that one thread are passed through a personal-data scrubber and then sent to Anthropic’s API to generate the suggested reply. Anthropic processes the request and does not train models on it. No mailbox data leaves Helios for any other reason.

Retention and revoking access

  • Any connected mailbox can be paused or disconnected at any time from Settings. Disconnecting revokes our OAuth token with Google immediately and stops all further access.
  • You can also revoke access yourself at myaccount.google.com/permissions.
  • On disconnection we delete the stored tokens. Messages already filed against your records are business records of your organization and follow the retention rules in section 5; you can delete them from Helios at any time.

Limited Use disclosure. Helios’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data Retention

Operational data is retained for the duration of your subscription. After account deletion, personal data is anonymized within 30 days. Anonymized aggregate data may be retained for analytical purposes.

6. Your Rights

  • Right to access your data
  • Right to rectification
  • Right to erasure (right to be forgotten)
  • Right to data portability
  • Right to withdraw consent

7. Contact

For questions about your data, or to exercise any of the rights above:

Email: contact@helios-energy.app
Helios Energy Management Solutions, Nicosia 2547, Cyprus

Terms of Service · Back to home