Privacy Policy
1. About this policy
1.1 Who we are. Hipax is run by Helm Intelligence Pty Ltd (ACN 699 310 211, ABN 47 699 310 211) (Helm, we, us, our). This policy explains how we handle personal information when you use Hipax, our website or our support.
1.2 Our commitment. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1.3 How it fits with our Terms. This policy forms part of the Hipax Terms of Service. Words with capitals, such as Customer Data, User and Admin, have the meanings given in the Terms.
1.4 Effective date. This policy applies from 1 November 2026.
2. Two kinds of information we handle
2.1 Account information. This is information about the businesses that use Hipax and the people who use it: account holders, Admins, Team members and anyone who contacts us. We collect it to run your account, and we're responsible for it.
2.2 Customer Data. This is what our customers put into Hipax to run their business. It often includes personal information about their own customers, suppliers and staff, such as names, addresses, phone numbers and job details. The business that uploads it decides what goes in, and is responsible for collecting it lawfully and telling people how it's used. We store and process it to provide Hipax, and handle it as this policy describes.
2.3 If a Hipax customer holds your information. If you're a client of a business that uses Hipax, please contact that business first about your information. We'll help them respond where we can.
3. What we collect and how
3.1 What we collect. Depending on how you use Hipax, we collect:
| Kind | Examples |
|---|---|
| Contact and business details | Name, email, phone, business name, ABN and address |
| Account and login details | Role, login email, settings and security events such as sign-ins |
| Billing details | Plan, billing history and the last digits of your card. Stripe holds your full card details, not us |
| Usage information | Features used, actions taken, IP address, device and browser type, log data such as dates and times of access, and app performance data |
| Support and feedback | Messages, calls and feedback you send us |
| Customer Data | Jobs, quotes, invoices, schedules, photos, documents and customer records you put into Hipax or sync from Xero or Microsoft 365 |
3.2 How we collect it. Mostly directly from you: when you sign up, use Hipax, pay or contact us. Some comes from services you connect, such as Xero or Microsoft 365, within the permissions you grant. Usage information is collected automatically as you use Hipax.
3.3 Using Hipax without identifying yourself. You can browse our website without telling us who you are. To use Hipax, we need to know who you are and which business you represent.
4. How we use it
4.1 Account information. We use it to:
- set up and run your account, and verify sign-ups;
- bill you and keep financial records;
- provide support and respond to you;
- send notices about your account, the Terms and our prices;
- keep Hipax secure and prevent misuse; and
- understand how Hipax is used, so we can improve it.
4.2 Customer Data. We use it to provide Hipax to the business that uploaded it: storing it, showing it to the right Users, syncing it with connected services and producing AI outputs, insights and reports. We also use it in de-identified form, as section 5 explains. We don't sell Customer Data, and we don't use it to contact our customers' clients.
4.3 Other uses. We'll only use personal information for another purpose if you'd reasonably expect it, if you agree, or if the law allows or requires it.
5. AI and de-identified data
5.1 How Ask Hipax works. Ask Hipax and our other AI features run on Amazon Web Services in Sydney. We don't send any data to third-party AI model providers.
5.2 De-identified data. We combine and de-identify information to improve Hipax, develop and train our AI models, and produce industry benchmarks. De-identified data doesn't identify any business, User, customer or individual, and we take reasonable steps to stop it being re-identified. It isn't personal information, and we keep it permanently. If de-identified data is ever combined with personal information, we treat the result as personal information for as long as it stays combined.
5.3 An example. De-identified data might show how long a typical HVAC job takes from quote to invoice. It won't show whose job it was, who did it, or where.
6. Who we share it with
6.1 Service providers. We share personal information only as needed with:
- Amazon Web Services, which hosts Hipax, stores data and runs our AI processing in Sydney; and
- Stripe, which processes payments. Your card details go straight to Stripe, under its own terms and privacy policy.
6.2 Services you connect. When you connect a service such as Xero or Microsoft 365, Hipax reads and writes data in it within the permissions you grant. Emails drafted by Ask Hipax are sent from your own account, and only when a User sends or approves them. Those services handle data under their own terms.
6.3 Within your business. Admins can see all of your business's data in Hipax. Team members only see their own assigned jobs, schedule and the customer details for those jobs.
6.4 Other disclosures. We may disclose personal information if the law requires it, to protect people or Hipax from harm, or to a buyer of our business who agrees to handle it under this policy.
6.5 No selling. We don't sell personal information.
7. Where it is stored, and overseas
7.1 In Australia. We store and process Customer Data and account information in Australia, on Amazon Web Services in Sydney. That includes all AI processing.
7.2 Payments. We don't hold any data outside Australia. Payments are processed by Stripe, and your card details go straight to Stripe under its own privacy policy.
7.3 Services you connect. Data you send to a connected service, such as Xero or Microsoft 365, is held under that service's terms and may be stored outside Australia.
7.4 If this changes. If we start storing or processing Customer Data outside Australia, we'll update this policy and give customers at least 30 days' notice, as the Terms require.
8. How long we keep it
8.1 While you use Hipax. We keep your account information and Customer Data for as long as your Free Trial or Subscription is active.
8.2 After your account ends. We keep Customer Data after a Free Trial or Subscription ends, so you can pick up where you left off if you come back. After your account ends, we don't access or use your identifiable Customer Data, except to restore your account if you come back, or for security or legal reasons. We only use it in de-identified form, as section 5 describes. We also keep account and billing records for as long as tax and other laws require.
8.3 Asking us to delete information. You can ask us to delete or de-identify personal information we hold. We'll consider the request under the Privacy Act and tell you what we'll do, and why.
9. Sensitive information and children
9.1 Sensitive information. We don't ask for sensitive information, such as health information, racial or ethnic origin, or criminal records. Please don't put it into Hipax unless your business genuinely needs it and the law allows you to collect it.
9.2 Government identifiers. If you give us your ABN, we use it to identify your business. We don't collect tax file numbers.
9.3 Children. Hipax is for businesses, and account holders must be at least 18.
10. Security and data breaches
10.1 How we protect it. We take reasonable steps to protect personal information from misuse, loss and unauthorised access. Hipax uses multi-factor authentication, and our staff only access an account to provide support you've asked for, or for security or legal reasons.
10.2 Your part. Keep your logins secure, and tell us promptly at cybersecurity@helmintelligence.com.au if you think someone has accessed your account without permission.
10.3 Data breaches. If a data breach affects personal information we hold, we'll act quickly to contain it and tell affected customers without unreasonable delay. Where the Notifiable Data Breaches scheme applies, we'll notify affected individuals and the Office of the Australian Information Commissioner.
11. Marketing
11.1 What we send. We may email account holders about Hipax features, tips and offers.
11.2 Opting out. Every marketing email has an unsubscribe link, and you can opt out at any time. We'll still send notices about your account, billing and the Terms.
11.3 Customer Data isn't used for marketing. We never use Customer Data, such as your clients' details, to market to anyone.
12. Cookies and analytics
12.1 Cookies. Our website and web app use cookies and similar technologies to keep you signed in, remember your settings and keep Hipax secure.
12.2 Analytics. We use our own in-house analytics to understand how people use our website and Hipax, so we can improve them. We don't use third-party analytics tools. Error monitoring uses Amazon CloudWatch, and like the rest of Hipax it runs on Amazon Web Services in Sydney.
12.3 Your choices. You can block or delete cookies in your browser settings. Some parts of Hipax, such as staying signed in, may not work without them.
12.4 Cookies we use. These are the cookies Hipax sets. All are set by Hipax itself; we don't use third-party cookies.
| Cookie | Purpose | How long it lasts |
|---|---|---|
| sessionid | Keeps you signed in | 12 hours |
| csrftoken | Protects forms and sign-ins from misuse | 1 year |
| helm_td | Remembers a browser that has passed the sign-in code, so you aren't asked for one every time | 30 days |
| messages | Carries a one-off notice, such as "Saved", to the next page | Until that page shows it |
13. Access and correction
13.1 Seeing your information. You can ask for a copy of the personal information we hold about you. Admins can see and update most account details directly in Hipax.
13.2 Correcting it. If something is wrong or out of date, tell us and we'll correct it.
13.3 How we respond. We'll respond within 30 days. We may need to confirm who you are first. If we can't give access or make a correction, we'll explain why, as the Privacy Act allows. There's no charge for asking.
13.4 Information in a customer's account. If your information is in a Hipax customer's account, for example as one of their clients, please ask that business first. We'll help them respond.
14. Complaints
14.1 Tell us first. If you think we've mishandled your personal information, email us at support@helmintelligence.com.au with the details. We'll acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
14.2 If you're not satisfied. You can complain to the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.
15. Changes and contact
15.1 Changes to this policy. We'll update this policy when our practices or the law change, and show the new effective date at the top. If a change materially affects how we handle your information, we'll email the Account Contact before it applies.
15.2 Past versions. We keep past versions of this policy at www.helmintelligence.com.au.
15.3 Contact us. Helm Intelligence Pty Ltd, 49 Murriverie Road, North Bondi NSW 2026, Australia. Email support@helmintelligence.com.au, or cybersecurity@helmintelligence.com.au for security issues.