Privacy Compliance Framework

How Helix protects personal data worldwide

Safeguarding personal data is a priority for Helix. We have implemented a global Privacy Compliance Framework designed to support consistent, responsible and lawful processing of personal data across Helix and its affiliates worldwide.

What is the Privacy Compliance Framework?

The Privacy Compliance Framework sets out the privacy principles and requirements that Helix affiliates and personnel must follow when collecting, using, accessing, storing, disclosing, retaining or transferring personal data.

It applies when Helix processes personal data for its own business and employment purposes and when it processes personal data on behalf of customers.

The Framework covers personal data relating to employees, applicants, customers, users, resellers, business partners, suppliers, service providers and other individuals connected with Helix’s activities.

The Framework is designed to support:

  • lawful, fair and transparent processing; 
  • purpose limitation and data minimization; 
  • accuracy, retention and secure deletion; 
  • appropriate technical and organizational security measures; 
  • respect for individuals’ privacy rights; 
  • accountability, oversight, training and audit; and 
  • appropriate safeguards for international transfers of personal data. 

For further details, please refer to the full Privacy Compliance Framework

How does Helix protect customers and business data?

Helix uses privacy, contractual, organizational and technical controls to protect personal data. These controls are applied according to the nature of the processing, the services provided and the risks involved. 

  • access controls based on business need and least privilege; 
  • confidentiality obligations and privacy and security training; 
  • encryption and other safeguards for data in transit and at rest, where appropriate; 
  • incident response, business continuity and recovery processes; 
  • vendor and subprocessor due diligence and contractual protections; and 
  • periodic risk assessments, testing, audits and compliance reviews. 

Learn more about our security program and review our compliance certifications and attestations on our Trust Center.

How does Helix support customers’ privacy obligations?

When Helix processes personal data on behalf of a customer, the customer determines the purposes and means of the processing and BMC Helix processes the data in accordance with the customer’s documented instructions and the applicable agreement. 

The applicable Data Processing Addendum describes the parties’ data protection responsibilities, including requirements relating to confidentiality, security, subprocessors, individual rights, personal data breaches, audits, return or deletion of data and international transfers. 

For contractual details, review the DPA and the relevant service agreement or order.

How does BMC Helix protect international data transfers?

Data protection laws may restrict transfers of personal data to countries that are not recognized as providing an adequate level of protection.

Where required, BMC Helix uses legally recognized transfer mechanisms, including:

  • the European Commission’s Standard Contractual Clauses;
  • applicable UK international transfer provisions;
  • Brazilian Standard Contractual Clauses.

The Privacy Compliance Framework establishes BMC Helix’s global privacy standards, while the SCCs provide the relevant legal transfer mechanism where required. The Framework supplements the SCCs and does not modify their mandatory provisions. More details on data transfers are included in services agreements and orders, depending on the type of services.

BMC Helix affiliates

The Privacy Compliance Framework applies across BMC Helix affiliates worldwide. 

A complete and current list of participating entities and their jurisdictions is available on the BMC Helix Affiliates page. Each entity is required to comply with the applicable privacy and international transfer requirements.

Further information

For questions about the Helix’s privacy practices, please contact the BMC Helix Privacy Office at Privacy@helixops.ai. The Privacy Office will deal with the matter and, if necessary, involve appropriate persons or departments within Helix.

Explore related resources: