Helfzen Privacy Policy
Last updated: July 28, 2026
See also: Terms of Service
1. Who we are and what this covers#
Helfzen provides a collections workspace for home care agencies — software that helps an agency follow up on billed claims and reconcile the payments it receives. Our customers are organizations: home care agencies and the billing teams that work for them. The people who use Helfzen are those organizations' staff.
This policy explains what information Helfzen collects, why, who it is shared with, how long it is kept, and what rights you have.
Two different kinds of data, and the distinction matters throughout:
| Agency data | Account data | |
|---|---|---|
| What it is | The billing records an agency puts into Helfzen — invoices, payments, remittances, bank transactions, and the patient and payer details that appear on them | Information about the individual people who use Helfzen: name, work email, password, role |
| Whose it is | The agency's. Helfzen processes it on the agency's instructions and does not own it | The individual's, held so they can sign in and so their actions are attributable |
| Who decides | The agency decides what to put in, what to correct, and what to delete. We act on its instruction | The agency's administrator manages membership; the individual manages their own credentials |
If you are an employee of an agency that uses Helfzen and you want your information corrected or deleted, contact your agency — they control that data, and we act on their instruction. See §8.
Helfzen is a business tool. It is not directed to consumers, and it is not directed to children (§11).
2. Information we collect#
2.1 Account information
Name, work email address, a password (stored only as a bcrypt hash — we never hold your password itself), organization membership, and role. If your agency uses "Sign in with Google", we receive your Google account's basic profile and email so we can identify you; we do not receive your Google password.
2.2 Agency billing data
Whatever the agency puts into Helfzen or connects it to, which typically includes: invoices and invoice lines; payments and how they were applied; batches, contracts, and payers; electronic remittance advice (X12 835) files from payers; and workflow content the agency's staff create — notes, follow-ups, and activity history.
This data can include information about the agency's patients — commonly a name, address, date of birth, and admission identifier carried on an invoice. See §12 for our position on healthcare data.
2.3 Bank transaction data
If an agency connects a bank account or its accounting system, we receive and store, for that account: transaction amounts, posted dates, the bank's own description or memo text, check numbers, ACH or wire trace references, and the last four digits of the account.
What we never receive or store:
- Your bank username or password. There is no part of Helfzen that accepts, transmits, or stores bank login credentials. You enter them into Plaid (§4.1), not into Helfzen.
- A full bank account number. Only the last four digits are ever kept, and that limit is enforced in our code at each place a statement or feed is read.
Bank memo text is free text written by a bank, and it can incidentally contain a person's name — for example on a private-pay check. We store the memo as the bank wrote it, because it is what lets a deposit be matched to a payment; we do not attempt to enrich or interpret it.
2.4 Cookies and similar technologies
Helfzen sets one cookie: a session cookie that keeps you signed in. It is httpOnly (not readable by scripts in your browser), secure (sent only over HTTPS), and expires after 8 hours.
We do not use advertising cookies, analytics cookies, tracking pixels, session recording, or third-party trackers of any kind. There is no advertising network, no analytics vendor, and no data broker in our system. We do not track you across other websites, and there is nothing here to opt out of.
2.5 Logs
Our hosting provider records ordinary server logs (request times, status codes, error traces) and our database provider records operational metrics. Within the application we keep an audit record of security-relevant actions — signing in and out, connecting or disconnecting a bank provider, changing bank accounts or reconciliation rules, changes to organization settings and membership — and a run log of each data import or sync. These records contain no passwords, no access tokens, and no full account numbers.
2.6 Email
If an agency uses Helfzen to send collections email, we process the message content and recipient addresses to send it, and we record that it was sent. Delivery happens either through that user's own Google account (with their authorization) or through an SMTP server the agency configures.
3. Why we use it, and on what basis#
| Purpose | What it covers | Basis |
|---|---|---|
| Providing the service | Storing and displaying billing records, matching payments to invoices, reconciling deposits, sending collections email | Performance of our contract with the agency |
| Authentication and security | Signing you in, enforcing roles, keeping the audit record, investigating incidents | Contract; our legitimate interest in operating a secure service |
| Support | Investigating a problem an agency reports | Contract; legitimate interest |
| Legal and compliance | Responding to lawful requests; meeting obligations that apply to us | Legal obligation |
We do not use agency data to train machine-learning models, to build products for other customers, or for advertising or profiling of any kind. Helfzen has no artificial-intelligence feature that processes customer data, and no such feature is present in the service.
4. Bank connectivity, and the role of Plaid#
Bank connectivity in Helfzen is provided by Plaid Inc. ("Plaid"). This is worth reading carefully, because it determines who holds what.
4.1 Your bank credentials go to Plaid, never to us. When an agency administrator connects a bank account, they do so inside Plaid Link, a component operated by Plaid. The bank username, password, and any one-time code are entered into Plaid's interface and are transmitted to Plaid — Helfzen never receives them, never transmits them, and never stores them. What Helfzen receives back is an access token that permits reading transactions from that account, and that token is encrypted before it is stored.
4.2 What Plaid receives about you. Plaid receives the credentials you enter, the institution you selected, and an identifier for the connecting organization. Plaid's handling of that information is governed by Plaid's own end user privacy policy — https://plaid.com/legal/#end-user-privacy-policy — which you should read, and by the consent Plaid presents to you inside Plaid Link before the connection is made.
4.3 What we ask Plaid for. Transaction data only. Helfzen requests no payment-initiation, transfer, identity, income, or asset product, and there is no code anywhere in Helfzen that can move money. The most a Helfzen bank connection can do is read the transactions of the account it was connected to.
4.4 Disconnecting. When an agency disconnects a bank provider, we delete the stored access token and ask Plaid to remove the connection. See §7.3 for what happens to the transaction history.
4.5 QuickBooks. If an agency connects QuickBooks Online, the authorization happens on Intuit's own page under the agency's Intuit credentials; we receive an access token for that company and read recorded deposits. We never receive Intuit login credentials.
5. Who we share information with#
We do not sell your information. See §6.
We share information only with the service providers below, each of which processes it on our behalf to provide the service, and only to the extent needed for their role.
| Provider | Role | What it can see |
|---|---|---|
| Vercel Inc. | Application hosting | Requests and responses in transit through the platform; server logs |
| Neon Inc. | Managed PostgreSQL database | All stored data, at rest |
| Plaid Inc. | Bank connectivity | Your bank credentials (entered into Plaid, §4), the institution, and the transactions of the connected account |
| Intuit Inc. | QuickBooks Online integration (optional) | The QuickBooks company an agency authorizes, and the deposits we read from it |
| Google LLC | "Sign in with Google" (optional) and sending email through a user's own Gmail account (optional) | Sign-in assertions for users who choose Google login; the content and recipients of email sent through that user's Gmail authorization |
An agency that uses neither Google sign-in nor Gmail sending, and connects no bank or accounting system, shares nothing with Plaid, Intuit, or Google.
We also share information when we are legally required to — in response to a lawful subpoena, court order, or governmental demand — and when necessary to protect the rights, safety, or property of Helfzen, our customers, or the public. Where we are permitted to notify the affected agency of such a request, we will.
In a merger, acquisition, or sale of assets, information may transfer to the successor, which would remain bound by this policy or a policy at least as protective, and affected agencies would be notified.
Our source code is hosted with GitHub, Inc., which holds no customer data.
6. We do not sell your data#
Helfzen does not sell, rent, license, or trade your information — including bank transaction data obtained through Plaid — to anyone, for any purpose. We do not share it with advertisers or data brokers. We do not monetize it in aggregated or anonymized form. There is no exception to this, and no product of ours depends on one.
7. How long we keep it, and how it is deleted#
7.1 The default. We keep an agency's data for as long as the agency's account is active, because the agency needs those records. We do not set your record-retention floor — an agency's own payer contracts and applicable state and federal rules determine how long it must keep billing records, and that is the agency's decision, not ours.
7.1a A small amount of operational data is deleted automatically, on a schedule. Two kinds of record have a fixed lifetime and are removed by an automated nightly job:
| What | Kept for |
|---|---|
| Data-import and sync run logs — one entry per file upload or provider sync, holding counts, timings and error text, not your billing records | 400 days |
| Notifications you have already read — the in-app alerts about mentions, assignments and status changes | 180 days |
Neither is a business record: a run log is operating telemetry, and a read notification is a copy of an event whose original (the message, task or invoice it pointed at) we keep. Everything else — invoices, payments, bank transactions, remittances, your team's notes and the audit log — is kept for the life of your account and removed when your organization is deleted, per §7.2.
7.2 Deletion on request or termination. An agency administrator may ask us to delete the agency's data at any time. We will:
- Acknowledge the request within 5 business days;
- Offer an export of the data first, and allow 30 days to take it;
- Delete within 30 days of that window closing — or immediately, if the agency declines the export;
- Confirm in writing what was deleted.
Deleting an organization removes its records across the system, including invoices, payments, bank transactions, integrations and audit records.
This is a feature of the product, not a manual database operation. An administrator of your organization can, from Settings, download a complete export of the organization's data and schedule its deletion. Scheduling starts the 30-day window in §7.2 step 2 — during which your workspace keeps working normally and the schedule can be cancelled — after which the same administrator can perform the permanent deletion. Every step is recorded, and the record of a deletion is deliberately kept outside the deleted organization so we can confirm to you what was removed and when.
7.3 Disconnecting a bank provider is not a deletion request, and we will not treat it as one. Disconnecting deletes the stored access token immediately and ends the data flow. The transactions already imported are kept, because they are the agency's own financial history and because a reconciliation someone performed should not be erased by a change of configuration. If you want that history deleted, ask us under §7.2 and we will delete it.
7.4 Backups. Deleting data from our live systems does not immediately remove it from our database provider's backups and point-in-time restore window. It ages out of those as that window passes. We say this rather than promising an instant, irreversible erasure we cannot perform.
7.5 Session data is not stored on our servers at all — the session lives in your browser's cookie and expires after 8 hours.
7.6 Honest note on automation.
- Automatic: the two scheduled deletions in §7.1a run nightly without anyone asking. Disconnecting a bank, accounting, email or billing provider deletes that provider's stored credential immediately (§7.3).
- A person, deliberately: deleting an organization. It is available in the product as a scheduled action with a typed confirmation and a grace period, and it is performed by one of your own administrators or by us on your written instruction. No timer ever deletes an organization, and we do not intend to build one — a workspace disappearing while nobody is watching is not a feature.
- Still true: most of your data has no expiry date. It is kept while your account is active and removed when your organization is deleted, which is what §7.1 says.
8. Your rights and how to exercise them#
8.1 If you are our customer (an agency). You may request access to, correction of, export of, or deletion of your organization's data. Most of it you can already read, correct, and export inside the product; for anything else, contact us at info@helfzen.com from an address on your organization's membership. We respond as set out in §7.2.
8.2 If you are an individual whose information is in an agency's Helfzen account — a member of the agency's staff, or a person whose details appear on an agency's invoice — the agency controls that data and we act on its instruction. Contact the agency directly. If you contact us instead, we will refer your request to the agency and tell you we have done so; we will not act on it unilaterally, because doing so would mean altering the agency's records on the word of someone we cannot verify.
8.3 Depending on where you live, you may have rights to know what information is held, to have it corrected or deleted, to receive a copy, and not to be discriminated against for exercising those rights. Helfzen sells no data and engages in no targeted advertising, so there is nothing to opt out of on those grounds. Requests are handled through §8.1 or §8.2 according to which applies.
8.4 We do not charge for a reasonable request, and we do not require you to create an account to make one.
9. How we protect information#
No system is perfectly secure, and we do not claim to be. What we actually do:
- Encryption in transit. All connections use HTTPS/TLS. Our connection to our database uses TLS with full certificate verification (
sslmode=verify-full), pinned in code so a library default cannot weaken it. - Encryption at rest. Our database provider encrypts stored data at the storage layer. In addition, every credential we hold on your behalf — bank access tokens, QuickBooks tokens, Google tokens, SMTP passwords — is separately encrypted by Helfzen using AES-256-GCM with a per-secret random salt and initialization vector, under a dedicated encryption key that is not used for anything else.
- Access controls. Each user's permissions are scoped to their own organization and re-checked against live membership on every request. Actions that store a bank credential are restricted to organization administrators and are recorded in an audit log.
- Two-factor authentication on our own platform accounts. Every account that can reach our production systems — hosting, database, source control, and our Plaid, Intuit, and Google dashboards — has two-factor authentication enabled.
- Two-factor authentication in Helfzen itself, required of administrators. Signing in uses a password (stored as a bcrypt hash) plus a signed, http-only, 8-hour session cookie — and, for every organization administrator, a one-time code from an authenticator app before any session is issued. It is required of administrators in every organization and cannot be switched off by the organization; it is available to, and not required of, other roles, because those roles cannot store a credential or change your organization's configuration. You also receive single-use recovery codes, and an administrator can reset a colleague's second factor if a device is lost — never their own, and always recorded in the audit log.
- Independent review of code changes. Changes to our software cannot reach production without an approving review by someone other than the person who wrote them, enforced by a repository rule rather than by convention. That reviewer is engaged for that purpose and holds access to our source code only — no production system and no customer data.
- Automated security monitoring. A scheduled detector runs over our own audit trail, data-sync logs and provider connection state, and alerts us to repeated authentication failures, refusals by our authorization controls, failed data imports, provider connections in an error state, and bursts of server errors.
- We collect less. No bank credentials, no full account numbers, no raw remittance or statement files retained after processing.
- A written security program. Policies covering access control, asset inventory, vulnerability management, endpoint security, change management, vendor management, retention, training, and incident response, each with an owner and a review cadence.
Stated plainly so you are not misled: we do not offer hardware security keys, passkeys, or SMS codes as second factors, and there is no self-service password change in the product yet. Our monitoring is scheduled rather than continuous, and we operate no security information and event management platform. We also hold no SOC 2 report and have not commissioned an independent penetration test.
10. If something goes wrong#
If we confirm a security incident that has resulted in unauthorized access to an agency's data, we will notify that agency's administrators without undue delay and no later than 72 hours from confirmation, telling them what we know, what we do not yet know, and what we recommend they do. We will not delay a notification to make it more complete. Where the law requires notification to a regulator or to individuals, we will meet it.
11. Children#
Helfzen is a workplace tool sold to businesses. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we hold such information other than as part of an agency's own billing records for a patient, we will delete it. Where an agency's billing records concern a minor patient, that data is the agency's, handled under §1 and §12.
12. Healthcare data — our position, stated accurately#
Helfzen processes healthcare billing information. Invoices can carry a patient's name, address, and date of birth, and remittance files describe claims for care.
What we do not claim:
- We do not claim HIPAA compliance.
- We have no Business Associate Agreement in place with any customer as of the date of this policy.
What that means in practice. Handling protected health information as a business associate requires a signed Business Associate Agreement. If your agency intends to place protected health information into Helfzen, contact us first — a BAA must be in place before you do, and we will tell you honestly what our posture is. In pilot and demonstration environments, the data we use is de-identified.
We would rather state this and lose a deal than imply a compliance posture we do not hold.
13. Where data is stored, and international transfers#
Helfzen is operated from the United States, and our database is hosted in the United States (US East). Our hosting and service providers operate internationally and information may be processed by their personnel or systems outside the United States in the course of providing and supporting their services.
We do not currently offer data-residency guarantees. If you are subject to requirements that data remain in a particular jurisdiction, tell us before you begin, because we would rather say no than say yes inaccurately.
14. Changes to this policy#
We may update this policy. When we make a material change, we will update the "Last updated" date and notify agency administrators by email or in the product before the change takes effect. Prior versions are available on request.
15. Contact us#
| Company | Helfzen Enterprises LLC |
| Postal address | 7 Fringe Ct, Nanuet, NY 10954 |
| Email Privacy questions, access and deletion requests, and reports of a security issue or suspected vulnerability |
info@helfzen.com |
We aim to respond to any privacy enquiry within 5 business days.