Privacy policy
This policy explains which personal data PaxHelm processes, why, on what legal basis, and what rights you have over it.
Draft. This text is pending legal review and is not yet binding. The identity of the responsible company, the processors and the retention periods will be added before the final version.
Working version of .
Data controller
For privacy questions, write to [email protected].
What data we process
- Account: name, email address and password, stored only as a hash. If you sign in with a Microsoft account, that account's identifier.
- Content you create in the service: tasks, projects and their documents, reminders, follow-ups, captures, ideas, notes and contacts.
- Accounts you choose to connect: synced mail messages and calendar events, and the credentials for those accounts, encrypted at rest.
- Obsidian notes, if you turn on sync: the vault's files and their revision history.
- Devices: notification subscriptions and the tokens of devices you pair.
- Technical data: access and error logs, needed for security and troubleshooting.
- Billing, once payment is available: the data needed to issue invoices.
Why we use the data and on what basis
- To provide the service you signed up for, including service emails (account verification, invitations, access recovery): performance of a contract, GDPR Article 6(1)(b).
- To keep the service secure, prevent abuse and troubleshoot faults: legitimate interest, Article 6(1)(f).
- To meet legal obligations such as tax and invoicing: legal obligation, Article 6(1)(c).
We do not sell personal data or use it for advertising.
Artificial intelligence
AI features are optional. By default they run on your own computer through the local agent: processing happens there and the text is not sent to any AI provider. Cloud AI works only if it is turned on; then the text each request needs, such as a capture to sort, is sent to the cloud AI provider, acting as a processor.
AI suggestions are never applied without your confirmation. We make no solely automated decisions that have legal effects on you.
Processors
We use processors to host the service, deliver service emails and, once they are turned on, for cloud AI and payments, under contracts that bind them to process data only on our instructions.
Microsoft and Google accounts, IMAP and SMTP servers and Obsidian are services you choose to connect; their own terms and policies apply.
Transfers outside the European Economic Area
If a processor handles data outside the European Economic Area, the transfer relies on a European Commission adequacy decision or on standard contractual clauses, and the list of processors says so.
How long we keep data
- While your account is active, we keep the data needed to provide the service.
- Billing data is kept for as long as tax law requires.
Your rights
At any time you can ask to access, correct or erase your data, object to or restrict its processing, and receive it in a structured format. The full export is available in the settings.
To exercise these rights, write to [email protected]. We reply within one month.
You can also lodge a complaint with the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt.
Security
Credentials for connected accounts are encrypted at rest, connections use HTTPS, and each workspace is isolated from the others. If a data breach affects you, we notify the CNPD and, where the law requires it, the people affected, within the GDPR deadlines.
Changes to this policy
If we change this policy in a meaningful way, we will tell you by email or in the app before the change takes effect.