Legal
Privacy notice
What Helix NMS+ collects, why it collects it, and which of the two very different relationships you are in. Last updated 8 September 2026.
Who we are
Helix NMS+ is a network management and ISP billing system published by Helix Cloud Solutions, based in Kenya. This notice covers this website (helixnms.com) and the console at cloud.helixnms.com.
Questions, or a request about your own data: [email protected].
Two relationships, and most of this page is about the first
The distinction below decides who you should ask about your data, so it comes before everything else.
1. You use this website, or you hold a Helix account
We are the controller. We decide what is collected and why, and this notice describes it.
2. You are a subscriber of an ISP that runs Helix
We are a processor. Your internet provider is the controller: they decide what subscriber records exist, and we hold and process those records on their instructions so they can operate the network and bill for it.
If you are an ISP subscriber, ask your provider, not us. We cannot lawfully act on a request about their records without their instruction — including a request to see or delete them. Send it to your provider and they can reach us.
What this website collects
This site has no sign-up, no contact form and no comments. It collects one thing: Google Analytics 4 (measurement ID G-QY6F0GQLW1), which records page views, the page you arrived from, approximate location derived from your IP address, and basic device and browser information.
Analytics sets cookies (_ga and similar) on .helixnms.com. We use this to understand which pages are read. We do not run advertising cookies, we do not track you across other websites, and we do not sell or share this data with data brokers.
The console uses a separate analytics property from this site, so console activity is never mixed into public website reporting.
What your Helix account holds
If you have a console account, we store:
- your email address — required, and the identifier for the account;
- your name, if you give one, and a profile picture URL if you signed in with Google;
- a hash of your password if you set one. We never store the password itself and cannot recover it — a reset sets a new one;
- your role, whether the account is suspended, and the organisations you belong to;
- security metadata: when the account was created, when the password last changed, and a marker used to sign every device out at once.
Signing in sets a session cookie for the console host only. It is not readable by other sites.
Signing in with Google
Google sign-in is optional. If you use it, Google tells us your email address, your name and your profile picture. We never receive your Google password, and we ask Google for nothing beyond your basic profile and email.
One deliberate safety property is worth stating: a Google identity is not automatically merged into an existing Helix account that happens to share the same email address. Automatic linking is a known account-takeover route and is switched off.
What the product records while it runs
Operating a network produces operational data: device status and telemetry, configuration and command history, syslog from managed routers, and an audit record of which account performed which action. Where an ISP uses the billing side, that extends to customer records, subscriptions, invoices and payment references.
Most of this belongs to the ISP as controller. We hold it to run the service, to investigate faults, and because an audit trail is part of what the product is for.
How long it is kept
Operational data is pruned automatically, on windows that depend on the customer’s plan:
- device and portal logs — 7, 30 or 45 days;
- service-quality metrics such as latency and packet loss — 3, 7 or 15 days;
- device telemetry — from 7 days, by plan.
Account records are kept while the account exists. Billing records are kept for as long as the ISP needs them for accounting and tax, which is their decision as controller.
Who else is involved
- Google — analytics on this site, and sign-in if you choose it.
- Our hosting and network providers, who run the servers the service is delivered from.
- Payment providers, where an ISP customer has enabled one, to process the payments their subscribers make.
Some of these operate outside Kenya, so data may be processed abroad. We do not sell personal data to anyone, and we do not share it for advertising.
Your rights
Under Kenya’s Data Protection Act 2019 you may ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, and object to how it is used. You may also complain to the Office of the Data Protection Commissioner.
To exercise any of these, write to [email protected] — and see the routing note above if you are an ISP’s subscriber rather than our own account holder.
You can refuse analytics cookies through your browser’s settings or Google’s own opt-out. Nothing on this site requires them.
Security, and what we say if something goes wrong
Passwords are stored hashed. Device credentials and tunnel keys are encrypted at rest. Access to a customer’s data is scoped to their organisation and every refusal is recorded.
If a breach affects personal data we hold, we will inform the affected customers, and the regulator where the law requires it, and tell them what we know rather than waiting until we know everything.
Changes
If this notice changes materially we will update the date at the top and, where the change affects account holders, tell them directly. This page was last updated on 8 September 2026.
See also our terms of service, and the console if you are signing in.