Last updated 14 August 2026
This Privacy Policy explains how Helio SEO ("we", "us") handles personal data. For content and data you put into the Service, you are the data controller and we act as your processor; for the data we collect to run our business and provide the Service to you, we are the controller.
Account and billing data (name, email, company; payment details are taken and held by Stripe, not by us). The public content of websites you connect, which we scan to plan and write articles. Publishing credentials you provide (for example an API key for your website platform), used only to deliver articles to your site. Usage data (logins, actions, IP address). Communications you send to us.
To provide and operate the Service (performance of our contract with you). To secure, maintain and improve the Service and prevent abuse (legitimate interests). To bill you and keep records (contract and legal obligation). To send service messages and, where permitted, marketing messages (legitimate interests or consent, which you can withdraw).
Articles are written with the help of third-party AI models. The material sent for that processing is the public content of your website, your brief and settings, and research gathered for the article. We do not send your payment details or publishing credentials to AI providers.
We share data with vetted sub-processors who help us run the Service: cloud hosting, Stripe for payments, our email delivery provider, and AI providers for article writing. We require them to protect data to standards consistent with this policy. A current list is available on request. We do not sell personal data.
Where data is transferred outside the UK or EEA, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.
We keep personal data for as long as your account is active and as needed to provide the Service, then for any period required to meet legal, accounting or reporting obligations, after which it is deleted or anonymised.
We use technical and organisational measures including encryption in transit, access controls, and per-account isolation. Publishing credentials are held server-side, are never exposed back to the browser once saved, and are used only to deliver articles to your own site.
Subject to applicable law you may request access to, correction or deletion of your personal data, object to or restrict certain processing, and request portability. To exercise your rights, contact hello@helioseo.io. You also have the right to complain to the Information Commissioner's Office (ICO).
We use strictly necessary cookies to keep you signed in and to operate the Service. We do not run third-party advertising or tracking cookies on the Service.
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from children.
We may update this policy and will post the current version here with the date it last changed.
For any privacy question or request, contact hello@helioseo.io.