TENDER
Sign inStart free
A white leather folio with a rose-gold clasp on a yacht saloon table in sunlight
Legal

Privacy Policy.

Plain English wherever we can manage it. Operated by AI Compass Pty Ltd, ABN 51 673 500 868. Last updated 16 September 2026.

Helm is operated by AI Compass Pty Ltd (ABN 51 673 500 868), an Australian company. This policy explains what personal information we collect across Helm Tender and Helm Grants, why we collect it, who receives it and the choices you have. We run Helm in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). The short version: we collect only what the service needs, we use it only to run Helm for you, we sell nothing to anyone, and your data lives in Australia.

Dealing with us without identifying yourself

You can read Helm's public pages, guides, tender listings and award records without an account and without telling us who you are, and you can use a pseudonym when you send us a general question through the contact form. An account is different: billing, security and the law require us to know who holds it, so creating one needs your real name and a working email address.

What we collect

  • Account details: your name, email address and, if you verify it, your mobile number.
  • Business profile: company details, capability statements, past projects, preferences and any documents or records you add so Helm can score opportunities and help you respond.
  • Usage: which opportunities you view and track, the times you open and use your dashboard, and how the product is used, measured by our own first-party analytics so dashboards, reminders and the product itself work and improve.
  • Support: messages and screenshots you send us through tickets.
  • Billing: handled by Stripe. We never see or store your card number.
  • Security and technical data: sign-in events, two-factor enrolment, and the IP address, browser and device information your connection sends, used to protect accounts, keep the service running and investigate misuse.

We collect this directly from you, from your use of the product, and from public sources: government procurement and grant listings sometimes contain the published contact details of agency officers, which we index as part of the public notice they appear in.

If we receive personal information we did not ask for and do not need to run Helm, we destroy or de-identify it as soon as practicable, where it is lawful to do so.

What we use it for

One purpose: running Helm for you. Your profile is used to score tenders and grant rounds against your business, power the tools you use, and send the digests and reminders you turn on. We use aggregated, de-identified usage statistics to improve the product. We do not sell personal information, we do not share it with advertisers, and we do not use your data to train AI models. Marketing email is only sent with an unsubscribe control in every message, as the Spam Act 2003 (Cth) requires.

Who receives your data: our service providers

We share personal information only with the service providers that run Helm, each limited to its purpose, and with no one else unless the law requires it. Those purposes are: database, authentication and file storage; payment processing; email delivery; mobile verification; and AI processing of the text you ask Helm to score, read or draft. The providers behind them today, and where each processes your data:

  • Supabase: database, authentication and file storage. Australia (Sydney).
  • Stripe: payments and billing. United States.
  • Resend: transactional email delivery. United States.
  • Twilio: one-time codes for mobile verification. United States.
  • OpenAI and Anthropic: AI processing of the text you ask Helm to score, read or draft. United States, under terms that prohibit training on it.

This is the current list. If a provider changes, we update it here in the same release, and the purposes above remain the operative statement. If our business is ever sold or restructured, your data may transfer to the successor under this same policy. We may disclose information where a law, court or regulator validly requires it.

Overseas disclosure

Your account data and business profile are stored in Australia (Sydney). Some of the providers above process data outside Australia, including in the United States: payment processing, email delivery, mobile verification and AI processing involve data passing to them for those purposes. We rely on contractual safeguards with each provider, and our AI providers process text under terms that prohibit training on it. We store no personal information overseas ourselves.

Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access or disclosure. Every connection to Helm is encrypted, and our database and document storage are encrypted at rest. Access to the systems that run Helm is limited to the people who operate it. Every account sets up two-factor sign-in within seven days of opening. Backups are taken nightly and kept in Australia. More detail is on our security page. If a data breach happens that is likely to result in serious harm, we will notify you and the OAIC as the Notifiable Data Breaches scheme requires.

Retention

  • Documents you upload into a workspace are deleted 90 days after their tender or round is decided (won, lost or withdrawn), never before, and no later than twelve months after it closes, or immediately when you delete them or your account. You receive one email fourteen days before deletion listing the files.
  • For grant rounds still undecided at twelve months, the pre-purge email arrives fourteen days before deletion; download the bid archive if you need it.
  • Support-ticket screenshots are deleted 90 days after the ticket closes.
  • Account and profile data is kept while your account exists. Ask us to delete your account and we action it within 30 days, keeping only what tax, accounting or other law requires us to keep.
  • Security and server logs are kept for a limited rolling period to protect the service, then deleted.
  • Backups roll over: information deleted from Helm leaves our nightly backups within 21 days. A periodic encrypted archive kept away from the server for disaster recovery is held longer, used only to restore the service, and kept only as long as disaster recovery needs it.
  • We may keep de-identified statistics that no longer relate to anyone.

Access, correction and your choices

You can access and correct almost everything Helm holds about you directly in the product. For anything else - a copy of your data, a correction we have missed, or deletion of your account - use the contact form and we will respond within 30 days without charge. We may need to confirm your identity before we act on a request. If we refuse access or a correction, we will tell you why in writing and how to complain; if we do not agree to correct something, you can ask us to attach a statement that you believe it is wrong. Every marketing and digest email carries an unsubscribe control, and notification settings live in the product.

Cookies and browser storage

Helm uses no third-party tracking cookies, no advertising pixels and no external analytics trackers, which is why there is no cookie banner: there is nothing to consent to. Every cookie below is our own and is needed for the part of Helm it serves.

CookieWhat it doesHow long it lasts
sb-…-auth-tokenKeeps you signed in. It may be split into numbered parts.Up to 400 days, cleared when you sign out
helm_signed_inTells public pages you are signed in, so the right menu shows.30 days
helm_worldRemembers whether you are working on the tenders or the grants side.1 year
helm_faceRemembers which of Helm Tender or Helm Grants you arrived through, so a new account starts on that side.30 days
helm_seat_returnBrings an invited team member back to their invitation after signing in.24 hours
helm_tdRemembers a device you chose to trust for two-factor sign-in.30 days, or 24 hours after a backup-code sign-in
helm_bcHolds new two-factor backup codes while they are shown to you once.10 minutes
helm_internalSet only in Helm staff browsers, so our own visits are left out of usage statistics.1 year

Stripe's checkout page is Stripe's own site and sets its own cookies under Stripe's privacy policy while you pay.

Browser storage

Helm also keeps a few small items in your browser's local storage, which never leave your device unless noted:

  • helm.touch: the page you first landed on, the site that referred you and any campaign tags in the link, kept for 30 days, so that if you sign up we can record which channel brought you. It is read when you create an account.
  • helm.sidebarPinned and helm.navMoreOpen: whether you keep the dashboard sidebar pinned and its extra tools open.

Session storage, which your browser clears when you close the tab, holds a guard that stops a page reloading in a loop after an update, and whether you have dismissed the small-screen note. You can clear cookies and browser storage in your browser settings at any time; blocking cookies will prevent signing in, since the session cookie is how Helm knows you.

Helm links to government portals, source listings and other sites so you can act on an opportunity at its source. Those sites are not ours; their own privacy policies apply once you are there.

Children

Helm is a service for businesses and organisations. Accounts are for people aged 18 or over, and we do not knowingly collect personal information from children.

Complaints

If you think we have mishandled your personal information, tell us first through the contact form or our Privacy Officer, below. We will acknowledge your complaint within 5 business days, investigate, and aim to respond in full within 30 days. If we cannot resolve your concern, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Privacy Officer, AI Compass Pty Ltd, M3-158, 123 Parkyn Parade, Mooloolaba QLD 4557, Australia. Email our contact page with "Privacy" in the subject line.

Changes to this policy

When this policy changes materially we will tell you by email or in the product before the change takes effect. The date at the top of this page always states the current version.