Privacy Policy
Effective Date: September 30, 2026 · Last Updated: September 30, 2026
This Privacy Policy explains how Covariant Systems LLC d/b/a HelixNodes ("HelixNodes," "Covariant Systems," "we," "us," or "our") collects, uses, discloses, and protects personal information.
This Privacy Policy applies to information we process in connection with:
- the HelixNodes website;
- customer accounts;
- billing;
- customer support;
- web-hosting services;
- virtual private servers;
- networking and infrastructure services; and
- other products and services we provide.
It does not necessarily govern personal information that a HelixNodes customer stores or processes through its hosted websites, applications, databases, or virtual servers on behalf of that customer's own users. See Customer-Hosted Data below.
1. Who We Are
HelixNodes is operated by:
Covariant Systems LLC
doing business as HelixNodes
A Wyoming limited liability company
United States
Contact information:
Mail: 30 N Gould St, Ste R, Sheridan, WY 82801
Privacy: support@helixnodes.com
Support: https://billing.helixnodes.com
2. Information We Collect
Depending on how you interact with us, we may collect the following categories of information.
A. Account Information
When you register or place an order, we may collect:
- name;
- company or organization name;
- email address;
- telephone number;
- billing address;
- physical address;
- username;
- account identifiers;
- account preferences; and
- other information you voluntarily provide.
B. Billing and Transaction Information
We may collect information about:
- products ordered;
- invoices;
- transaction amounts;
- payment status;
- refunds;
- credits;
- transaction identifiers;
- payment method type; and
- billing history.
Payment-card information may be collected directly by our payment processors rather than stored by HelixNodes.
Where possible, we avoid storing complete payment-card numbers ourselves.
C. Identity and Fraud-Prevention Information
To prevent fraud and abuse, we may process:
- IP addresses;
- device information;
- approximate geographic information derived from IP addresses;
- transaction patterns;
- account history;
- login activity;
- fraud-risk indicators; and
- information supplied by fraud-prevention or payment providers.
In higher-risk circumstances, we may request additional identity or business verification.
D. Service and Technical Information
When you use our Services, we may automatically collect technical information including:
- IP addresses;
- timestamps;
- service identifiers;
- server identifiers;
- bandwidth usage;
- resource utilization;
- network-flow information;
- routing information;
- system events;
- authentication events;
- monitoring data;
- error logs; and
- security telemetry.
The precise information collected depends on the Service.
E. Website Usage Information
When you visit our website, we may collect:
- IP address;
- browser type;
- operating system;
- pages viewed;
- referring pages;
- timestamps;
- session information;
- device identifiers; and
- cookie or similar technology information.
F. Communications
If you contact us, we may retain communications such as:
- support tickets;
- emails;
- live-chat messages;
- abuse reports;
- sales inquiries;
- account notes; and
- records of technical-support interactions.
G. Customer-Provided Content
When providing support, you may voluntarily provide:
- log excerpts;
- configuration files;
- screenshots;
- database information;
- software output;
- account credentials; or
- other technical information.
Do not provide passwords, private keys, or sensitive personal information unless reasonably necessary.
Where temporary credentials are required for support, you should rotate them after the support interaction.
3. Customer-Hosted Data
Customers may use HelixNodes Services to store or process data about their own users, customers, employees, or other individuals.
Examples include:
- website databases;
- ecommerce customer information;
- application-user records;
- email;
- uploaded files;
- analytics data; or
- personal information stored in a VPS.
For such information, the HelixNodes customer generally determines:
- what data is collected;
- why it is collected;
- how it is used;
- who may access it; and
- how long it is retained.
In such circumstances, the customer may be the data controller or equivalent entity under applicable privacy law, while HelixNodes may act as a processor or service provider.
If you are seeking to exercise privacy rights relating to information controlled by one of our customers, you should generally contact that customer directly.
We may assist our customers with legally required privacy requests where applicable.
4. How We Use Personal Information
We may use personal information to:
Provide the Services
Including to:
- create and administer accounts;
- provision servers;
- process orders;
- authenticate users;
- operate infrastructure;
- deliver support;
- send service notifications; and
- maintain customer relationships.
Process Payments
Including to:
- issue invoices;
- collect amounts due;
- process refunds;
- maintain transaction records; and
- investigate disputed transactions.
Maintain Security
Including to:
- detect account compromise;
- prevent unauthorized access;
- investigate attacks;
- detect malware;
- prevent fraud;
- analyze abuse;
- protect IP reputation; and
- protect our network and customers.
Prevent Abuse and Fraud
Including to:
- evaluate high-risk orders;
- detect duplicate or fraudulent accounts;
- respond to abuse complaints;
- identify malicious activity;
- enforce our Terms and AUP; and
- protect our payment and network providers.
Communicate With You
Including:
- support responses;
- invoices;
- maintenance notices;
- security alerts;
- abuse notices;
- policy changes;
- renewal information; and
- other account-related communications.
Improve the Services
Including to:
- diagnose technical problems;
- understand usage;
- forecast capacity;
- improve performance;
- analyze reliability;
- develop new features; and
- improve support processes.
Comply With Law
Including to:
- comply with legal obligations;
- respond to valid legal process;
- preserve records where required;
- enforce contractual rights; and
- protect the rights and safety of HelixNodes and others.
Marketing
Where permitted by law, we may use contact information to send information about HelixNodes products, services, or promotions.
You may opt out of marketing communications without affecting necessary transactional communications.
5. Legal Bases for Processing in the EEA, United Kingdom, and Similar Jurisdictions
Where applicable law requires a legal basis for processing, we rely on one or more of the following.
Contract
We process information where necessary to:
- create your account;
- provision Services;
- bill you;
- provide support; or
- otherwise perform our agreement with you.
Legitimate Interests
We may process information for legitimate business interests such as:
- securing our network;
- preventing abuse;
- preventing fraud;
- improving the Services;
- maintaining business records;
- defending legal claims; and
- communicating with customers.
Where required, we balance those interests against the rights and interests of affected individuals.
Legal Obligation
We may process information where necessary to comply with law, regulation, court orders, taxation requirements, or legally binding requests.
Consent
Where required, we may rely on consent, including for certain cookies or marketing communications.
Where consent is the legal basis, you may withdraw it as provided by applicable law.
6. Cookies and Similar Technologies
Our website may use cookies and similar technologies for purposes including:
- account authentication;
- security;
- maintaining sessions;
- remembering preferences;
- fraud prevention;
- analytics; and
- measuring website performance.
Some cookies may be necessary for the website or customer portal to function.
Where required by applicable law, we will request consent before placing non-essential cookies.
7. Analytics
We may use analytics services to understand how visitors use our website and Services.
Analytics providers may process information such as:
- IP addresses;
- device information;
- browser information;
- referring pages;
- page activity; and
- timestamps.
Where required by law, analytics technologies will be subject to applicable consent controls.
8. Payment Processors
We use third-party payment processors to process some transactions.
Payment processors may collect payment information directly from you and process it under their own privacy terms.
We may receive transaction status, payment identifiers, card type, limited card information, billing details, fraud indicators, and similar information without receiving the complete payment-card number.
9. Service Providers
We may disclose personal information to vendors and contractors that perform services on our behalf, such as:
- data-center providers;
- infrastructure providers;
- network carriers;
- payment processors;
- fraud-prevention providers;
- domain registrars;
- customer-support software providers;
- billing-platform providers;
- email providers;
- monitoring providers;
- analytics providers;
- security providers;
- professional advisers; and
- backup or storage providers.
We provide such parties only information reasonably necessary for their role and require appropriate safeguards where required by law.
10. Data Centers and Infrastructure Providers
HelixNodes operates or uses infrastructure that may be located in jurisdictions including:
- United States, including Ashburn, Virginia; and
- Netherlands, including Amsterdam.
A customer's selected server location ordinarily determines the primary location of data stored on that server.
However, account information, monitoring information, backups, billing information, operational metadata, support information, and similar information may be processed elsewhere.
11. International Data Transfers
Because HelixNodes operates internationally, personal information may be transferred to or processed in countries different from the country where the information was originally collected.
These countries may have different privacy laws.
Where required by applicable data-protection law, we will use legally recognized mechanisms for international transfers, which may include:
- adequacy decisions;
- Standard Contractual Clauses;
- contractual safeguards; or
- other lawful transfer mechanisms.
Customers requiring particular international-transfer arrangements should contact us concerning an applicable Data Processing Addendum.
12. When We Disclose Information
We may disclose personal information as described below.
Service Providers
We may disclose information to companies that perform services for us.
Customer-Authorized Disclosure
We may disclose information at your request or with your authorization.
Legal Requirements
We may disclose information if we reasonably believe disclosure is required by:
- applicable law;
- subpoena;
- warrant;
- court order;
- legally binding governmental request; or
- other valid legal process.
Where legally permitted and appropriate, we may attempt to notify the affected customer before disclosure.
Emergencies and Protection of Rights
We may disclose information where reasonably necessary to protect:
- life or physical safety;
- HelixNodes systems;
- customers;
- networks;
- property;
- legal rights; or
- others from significant harm.
Abuse and Security
We may share information reasonably necessary to investigate or prevent:
- spam;
- phishing;
- malware;
- denial-of-service attacks;
- fraud;
- network intrusion; or
- other malicious activity.
This can include communicating with network operators, abuse desks, security researchers, affected organizations, or relevant authorities.
Corporate Transactions
Information may be transferred as part of:
- a merger;
- acquisition;
- financing;
- reorganization;
- sale of assets; or
- sale or transfer of the HelixNodes business.
Any successor will remain subject to applicable privacy obligations regarding transferred personal information.
13. We Do Not Sell Personal Information for Money
HelixNodes does not sell customer personal information to data brokers in exchange for money.
If our practices change in a manner that qualifies as a "sale," "sharing," or similar regulated activity under an applicable privacy law, we will update this Policy and provide legally required rights or notices.
14. Advertising
We do not permit third-party advertisers to access Customer Content merely for the purpose of targeting advertisements.
If we use advertising or marketing measurement services on our public website, they may be subject to separate cookie controls or disclosures where required.
15. Data Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and for legitimate business and legal requirements.
Retention periods may depend on:
- whether your account remains active;
- contractual requirements;
- billing and taxation rules;
- fraud prevention;
- abuse history;
- security requirements;
- dispute resolution;
- backup cycles;
- legal holds; and
- applicable statutes of limitation.
We may retain some account, billing, security, abuse, and transaction records after account closure where reasonably necessary.
Operational logs are generally retained for shorter periods unless needed for security investigation, abuse handling, troubleshooting, or legal compliance.
16. Deletion of Customer Content
Following cancellation or termination of a Service, Customer Content may be deleted.
Deletion from active systems does not necessarily result in immediate deletion from every backup or disaster-recovery system.
Residual copies may remain until backup media are rotated or overwritten according to our ordinary retention processes.
We may preserve specific data where legally required.
Customers should retrieve required data before terminating Services.
17. Data Security
We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information we process.
Measures may include:
- access controls;
- authentication protections;
- network segmentation;
- monitoring;
- logging;
- encryption where appropriate;
- physical data-center controls;
- restricted administrative access;
- backups; and
- incident-response procedures.
No Internet service or storage system is completely secure, and we cannot guarantee absolute security.
You are responsible for securing the applications, systems, credentials, and data under your control.
18. Security Incidents
If we become aware of a security incident affecting personal information, we will investigate and take reasonable remedial action.
Where applicable law requires notification to affected individuals, customers, regulators, or other parties, we will provide such notification as required.
If an incident affects Customer Content for which HelixNodes acts as a processor, we will communicate with the affected customer as required by applicable law or contractual commitments.
19. Your Privacy Rights
Depending on where you live and the law applicable to the processing, you may have rights concerning your personal information.
These may include the right to:
- obtain access to personal information;
- request correction;
- request deletion;
- request restriction of processing;
- object to certain processing;
- obtain portable copies of certain information;
- withdraw consent;
- opt out of certain marketing;
- lodge a complaint with a data-protection authority; or
- appeal a decision concerning a privacy request.
These rights are not absolute and may be subject to legal exceptions.
20. Exercising Privacy Rights
To submit a privacy request, contact:
support@helixnodes.com
We may need to verify your identity before completing a request.
Verification information will be used for purposes related to processing the request.
Authorized agents may submit requests where permitted by law, although we may require evidence of authorization.
We will not unlawfully discriminate against you for exercising an applicable privacy right.
21. European Economic Area and United Kingdom Residents
Where the GDPR, UK GDPR, or comparable legislation applies, individuals may have rights including:
- access;
- rectification;
- erasure;
- restriction;
- objection;
- portability; and
- withdrawal of consent.
You may also have the right to complain to the data-protection authority responsible for your jurisdiction.
HelixNodes may act as either a controller or processor depending on the processing activity.
For Customer Content processed by HelixNodes on behalf of a customer, inquiries should generally first be directed to that customer.
22. Data Processing Addendum
Customers subject to GDPR or similar data-processing requirements may require a Data Processing Addendum ("DPA") governing HelixNodes' processing of Customer Content.
Where applicable, HelixNodes may make a DPA available that addresses matters including:
- processing instructions;
- confidentiality;
- security;
- sub-processors;
- assistance with data-subject requests;
- deletion or return of data;
- security incidents; and
- international data transfers.
23. Sub-Processors
Where HelixNodes acts as a processor, we may use third-party sub-processors to assist in providing the Services.
These may include providers for:
- data-center infrastructure;
- cloud infrastructure;
- support;
- monitoring;
- email;
- backups;
- security;
- billing; or
- network operations.
Where legally required, applicable contractual protections will be imposed upon sub-processors.
24. Children
HelixNodes Services are intended for business and technical users and are not directed to children under 13.
We do not knowingly collect personal information directly from children under 13 through account registration.
If you believe a child has provided us personal information in violation of applicable law, contact us at support@helixnodes.com.
Customers operating services directed toward children are responsible for complying with applicable children's privacy laws.
25. Customer Responsibilities
If you use HelixNodes to collect or process personal information from others, you are responsible for your own compliance with privacy law.
Depending on your activities, this may include:
- publishing a privacy policy;
- identifying lawful bases for processing;
- obtaining required consent;
- responding to privacy requests;
- implementing security measures;
- complying with children's privacy requirements;
- complying with cookie requirements; and
- entering into appropriate processor agreements.
HelixNodes does not become responsible for your privacy-law compliance merely because data is hosted on our infrastructure.
26. Law-Enforcement Requests
Government and law-enforcement requests for customer information should be directed to:
support@helixnodes.com
Requests should clearly identify:
- the requesting agency;
- the legal authority relied upon;
- the account or resource sought;
- the information requested; and
- appropriate contact information.
We reserve the right to seek clarification, challenge overbroad requests, or require formal legal process where appropriate.
27. Abuse Reports
Information submitted in an abuse report may be used to:
- investigate the report;
- communicate with the affected customer;
- prevent harm;
- enforce the AUP; or
- communicate with relevant providers or authorities.
We may share portions of an abuse complaint with the affected customer where reasonably necessary to allow them to investigate.
If disclosure of sensitive information could create a security or safety risk, please identify that concern when submitting the report.
28. Business Customers and Contact Information
If your employer or organization provides your contact information to us in connection with an account, we may use that information to administer the organization's Services and communicate with you in your professional capacity.
29. Third-Party Links
Our websites may contain links to websites or services operated by others.
Their privacy practices are governed by their own policies, not this Privacy Policy.
30. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
The "Last Updated" date identifies the latest revision.
If a change materially affects how we handle personal information, we will provide notice where required by applicable law.
31. Contact Us
Questions or requests concerning this Privacy Policy may be directed to:
Covariant Systems LLC d/b/a HelixNodes
30 N Gould St, Ste R, Sheridan, WY 82801
Wyoming, United States
Privacy: support@helixnodes.com
Legal: support@helixnodes.com
Support: https://billing.helixnodes.com