Privacy & Security

This page is maintained by the Helix team to answer common questions about how Helix handles client and staff data. It describes app controls and current practices — it is not an independent certification.

What Helix stores
  • Client records: name, date of birth, room, allergies, care notes.
  • Medications, prescriptions, MAR entries, PRN entries, topical applications and stock counts.
  • Staff profiles, roles and organisation membership.
  • An append-only audit log of every administration, receipt, count and void action.

Helix stores special category health data. The lawful basis relied on is generally UK GDPR Article 9(2)(h) — processing necessary for the provision of health or social care.

How it is secured
  • All data is stored in an encrypted managed PostgreSQL database.
  • Traffic between your device and the backend is encrypted in transit (HTTPS/TLS).
  • Row-Level Security is enforced at the database: users only see data belonging to organisations they are a member of.
  • Access is scoped by role — carer, manager, owner or auditor — inside each organisation.
  • Authentication is by email and password with session tokens; no anonymous access.
Who can see what
  • Carer — can record MAR/PRN/topical/counts and view their organisation's clinical records.
  • Manager — everything a carer can do, plus edit prescriptions, void MAR entries with a reason, and manage staff and PRN protocols.
  • Owner — full control of the organisation, including inviting auditors.
  • Auditor — read-only access for CQC or external audit purposes, time-boxed by invitation.
Retention

Retention periods are set by the care provider in line with CQC and NHS records management guidance (commonly 8 years for adult care records after the last date of care). Ask your manager for the specific retention schedule that applies to your service.

Data subject rights

Under UK GDPR, clients (or their legal representatives) and staff have rights of access, rectification, erasure and objection. Requests should be sent to your organisation's Data Protection lead, who can export or delete the relevant records through Helix, or to privacy@gethelix.cloud. You can also request account deletion.

Incidents & contact

Suspected data breaches must be reported to your Data Protection lead immediately so the incident can be assessed and, if required, reported to the ICO within 72 hours. Vulnerability reports about the Helix application itself should be sent to privacy@gethelix.cloud.

This page describes controls provided by Helix and practices adopted by the care provider. It does not constitute legal advice or an assurance of regulatory compliance. Back to home.