This Privacy Policy explains how MINTECH GmbH processes personal data when you use the Helgio website, browser extension, account, translation and learning features, document functions, support channels and related services.
MINTECH GmbH
Karl Heinrich Waggerl Gasse 1, 3013 Pressbaum, Austria
Commercial Register: FN 578433 m, Landesgericht St. Pölten
Email for privacy requests: privacy@helgio.io
General support: support@helgio.io
The extension is designed to process page or subtitle content when you actively use a Helgio function, for example when you select text, click a supported subtitle, request a translation, save vocabulary or use a document feature. We do not use Helgio to build an advertising profile of your general browsing activity.
For a translation or learning request, we may process the selected text and the surrounding context needed to provide the requested result. For document features, we process the file or extracted text needed to perform the requested conversion or translation.
If you separately consent to analytics, Helgio may send pseudonymous usage events, including the feature used and, where configured, the domain and path of the page on which you used Helgio. We do not describe this data as anonymous. Analytics is not activated before consent.
| Purpose | Data | Legal basis | Retention / criteria |
|---|---|---|---|
| Free quota and technical operation | Device or installation identifier, request counter, extension/app version, browser/OS data, IP address in server logs | Art. 6(1)(b) GDPR; Art. 6(1)(f) for abuse and security prevention | Operational identifiers are kept while needed to operate the quota and prevent abuse; server security logs are generally kept for a short operational period and may be retained longer for an active security or fraud investigation. |
| Account creation and login | Email address, account identifier, optional name, authentication-provider identifier if used, language and account settings | Art. 6(1)(b) | Until account deletion, subject to legally required records and backup rotation. |
| Translation and learning features | Selected text, context needed for the request, translation output, saved vocabulary, cards, learning progress | Art. 6(1)(b) | Transient request data is kept only as needed to deliver and troubleshoot the request; items you choose to save remain until you delete them or the account is deleted. |
| Document features | Uploaded document, extracted text, converted output and technical metadata needed for processing | Art. 6(1)(b) | Temporary conversion files are retained only as long as needed for processing and limited troubleshooting, then removed under lifecycle rules. Content you deliberately save in your account remains until deletion. |
| Subscription status and customer support for billing | Paddle customer/transaction identifiers, plan, subscription status and invoice references; MINTECH does not receive full payment-card data | Art. 6(1)(b); Art. 6(1)(c) where records are legally required | For the contract term and applicable statutory accounting / limitation periods. |
| Service and support communications | Email address, message content, relevant account and technical information | Art. 6(1)(b) or Art. 6(1)(f) | For as long as needed to resolve the request and for a limited period afterwards to document support and legal claims. |
| Security and fraud prevention | IP address, device/account identifiers, request patterns, technical logs | Art. 6(1)(f) | Normally short-term; longer only where needed for an active incident, abuse investigation or legal claim. |
| Optional analytics and surveys | Pseudonymous analytics identifier, feature events, browser/device data and, where configured, domain/path used with Helgio; survey responses | Art. 6(1)(a) consent; applicable ePrivacy/TKG rules for storage or access on the device | According to the configured analytics retention period, which we keep limited and review periodically. Consent records are retained as needed to demonstrate the choice. |
If you choose a third-party sign-in method such as Google Sign-In, the authentication provider supplies the identifiers necessary to sign you in, such as your name, email address and provider account identifier. We do not receive your provider password. The authentication provider also processes data under its own privacy terms.
Depending on the requested feature and current system configuration, Helgio may use third-party translation or AI providers such as DeepL, Google or OpenAI. We send only the content and technical data reasonably necessary to fulfil the request and do not intentionally attach your Helgio password or payment-card data to the text request.
Provider terms, data-location settings and retention options may change. We configure provider accounts and contractual safeguards with the aim of minimising retention and restricting provider use of request data. This policy will be updated if a material change affects users.
We use service providers only where needed to operate Helgio. Current categories and principal providers include:
| Provider / category | Purpose | Role and transfer approach |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, databases, storage and related infrastructure | Processor under contractual terms. We use EU-region infrastructure where configured. Transfers, if any, are protected through applicable contractual or adequacy mechanisms. |
| PostHog (EU Cloud, if analytics is enabled) | Consent-based product analytics and surveys | Processor. Analytics is loaded/sent only after consent. EU-hosted configuration is used where enabled. |
| DeepL / Google / OpenAI, depending on feature | Translation and AI-supported learning features | Processor or service provider under the applicable business/API terms. Where data is transferred outside the EEA, we rely on an applicable adequacy mechanism or Standard Contractual Clauses as required. |
| Document conversion provider, where used | Conversion of user-requested documents | Only the data needed for the requested conversion is sent. The provider and transfer safeguards must match the production configuration and are reviewed before deployment. |
| Paddle | Checkout, payments, invoicing, tax handling, subscription management, statutory withdrawal and refunds for web purchases | Paddle acts as an independent controller / authorised reseller for its transaction processing. The relevant Paddle entity depends on buyer location. |
We may also disclose data to professional advisers, courts, regulators or authorities where legally required or necessary to establish, exercise or defend legal claims.
We do not sell personal data and do not provide it to third parties for their independent advertising.
Helgio uses strictly necessary cookies or local storage to keep you signed in, remember interface choices, maintain security and record your privacy choices. These functions do not require analytics consent.
Optional analytics and survey technologies are activated only after an affirmative consent. Refusing analytics must be as easy as accepting it. Closing a consent dialog without accepting is treated as refusal. You can change the choice at any time through Cookie settings on the website and the relevant privacy/analytics setting in the extension.
The exact names and lifetimes of technical cookies or local-storage keys may change as the implementation evolves. We maintain the live consent interface and technical configuration so that optional analytics is not loaded or triggered before consent.
Helgio is not intended for account creation by children under 14. If we become aware that an account was created below the applicable minimum age without a valid legal basis, we will take appropriate steps, including deletion where required.
Subject to the GDPR and applicable law, you may have rights to access, rectify or erase your data, restrict processing, receive portable data, object to processing based on legitimate interests and withdraw consent at any time for future processing.
Send privacy requests to privacy@helgio.io. We may need to verify your identity before acting on a request.
You may also lodge a complaint with a competent supervisory authority. In Austria, the supervisory authority is the Österreichische Datenschutzbehörde (Austrian Data Protection Authority), https://www.dsb.gv.at/.
When an account is deleted, we delete or irreversibly separate account content from active production systems subject to technical processing time, legal retention duties and backup rotation. Backup copies are access-restricted and are overwritten according to the normal backup lifecycle rather than restored for ordinary product use.
We apply technical and organisational measures appropriate to the risk, including encrypted transport, access controls, credential protection, logging and software/infrastructure maintenance. No internet service can guarantee absolute security.
We update this Policy when our processing changes. Where a change is material for registered users, we will provide appropriate notice as required by law.