Legal
Privacy Policy
Effective 9 September 2026
1. Who we are
HelixID is a product of Dgverse Infotech LLP, a limited liability partnership registered in India at DWARAKA, Kattayikonam P.O, Thiruvananthapuram 695584, Kerala, India. For anything in this policy, contact hello@dgverse.in.
2. Data we collect
Account data. When you create a HelixID account we store your email address, a salted password hash (only if you set a password), your email-verification status, and the optional company name and field of operation you provide at sign-up.
Google Sign-In data. If you choose “Continue with Google”, Google sends us only the basic profile information covered by the scopes you approve — typically your email address, name, profile picture, and Google account identifier. We use it solely to create and authenticate your HelixID account. We do not request access to Gmail, Drive, Calendar, Contacts, or any other Google service, and we never receive your Google password.
Service data. Data you create while using the console: agent identifiers and metadata, issuer DIDs, verifiable credentials you issue or verify, authorization policies, API keys, and the tamper-evident audit records those actions produce.
Technical data. Server logs containing IP address, browser user-agent, request paths, and timestamps, retained for security, abuse prevention, and debugging.
Enquiry data. If you submit the demo or enterprise contact form, we store the name, email, company, and message you send so we can reply.
3. How we use it
- To create, authenticate, and secure your account.
- To provide the HelixID service — issuing, verifying, and revoking credentials, and maintaining your audit trail.
- To send transactional email: verification, password reset, security notices, and material service changes.
- To respond to sales, support, and design-partner enquiries you initiate.
- To detect, investigate, and prevent abuse, fraud, and security incidents.
- To meet legal, accounting, and regulatory obligations.
We do not sell personal data, we do not share it with advertisers, and we do not use it to train machine-learning models.
4. Legal bases
Where the GDPR or comparable law applies, we rely on: performance of a contract (operating your account and the service), legitimate interests (security, abuse prevention, and responding to enquiries you send us), consent (where you give it, such as optional marketing email — withdrawable at any time), and legal obligation (tax and statutory record-keeping).
5. Google user data — limited use
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through Google Sign-In is used only to provide and improve the HelixID console’s authentication features, is never sold or transferred to third parties except as required for that purpose or by law, and is never used for advertising or for training generalized AI/ML models. You can disconnect HelixID from your Google Account at any time at myaccount.google.com/permissions.
6. Sub-processors and sharing
We share personal data only with service providers who process it on our instructions under written terms: cloud hosting and database providers for running the service, an email delivery provider for transactional and enquiry email, and Google LLC where you choose Google Sign-In. We also disclose data where we are legally compelled to, or to protect our rights and the safety of our users.
7. International transfers
We are established in India and our providers may process data in other jurisdictions, including the European Union and the United States. Where personal data of EU/UK residents is transferred outside those regions, we rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
8. Retention
Account data is retained for as long as your account is active and for up to 90 days after deletion, so the account can be restored if the deletion was a mistake. Audit records are retained for the period stated in your plan or contract, because their value is that they cannot be quietly removed. Server logs are retained for up to 12 months. Enquiry data is retained for up to 24 months.
9. Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Passwords are stored only as salted hashes. Private keys used for credential signing are held in the deployment’s configured key store, and access to production systems is restricted to the people who need it. No system is perfectly secure; if a breach affects your data, we will notify you and any relevant regulator as required by law.
10. Your rights
Subject to your local law, you may request access to your personal data, correction, deletion, a portable copy, restriction of processing, or object to processing based on legitimate interests. You may also withdraw consent where processing rests on it. Email hello@dgverse.in and we will respond within 30 days. If you are in the EEA or UK you may also complain to your local supervisory authority.
11. Cookies
helixid.dev sets no advertising or cross-site tracking cookies. The hosted console stores authentication tokens in your browser strictly to keep you signed in; clearing them signs you out.
12. Children
HelixID is a developer and enterprise product and is not directed at anyone under 18. We do not knowingly collect data from children.
13. Changes
We will update the effective date above when this policy changes and, for material changes, notify account holders by email before the change takes effect.
14. Contact
Dgverse Infotech LLP, DWARAKA, Kattayikonam P.O, Thiruvananthapuram 695584, Kerala, India — hello@dgverse.in. See also our Terms of Service.