HELION

Data protection

Privacy Policy

What HELION does with your data, why it is allowed to, how long it keeps it and what you can ask of us. HELION is a processing service, so most of what we hold is what you upload, together with the few facts your files carry and the record of the work you have had done on them.

Version of September 5, 2026

  1. 01

    Who is responsible

    The controller for the processing described here is Andreas Möller, a sole proprietor, Ernst-Reinke-Str. 3, 10369 Berlin, Germany, reachable at info@helion1.com. The business is small enough that no data protection officer has to be appointed under Article 37 GDPR and section 38 of the German Federal Data Protection Act, so every question about your data goes to that address and is answered by the operator personally.

  2. 02

    What we process

    Everything below is either given by you or carried in the files you upload. We ask for no more than the service needs, and nothing about you is inferred, bought or added from other sources. What the list names is what is typical of each kind, not every single field, because a service like this one grows new functions over time.

    • Your account: the email address you sign up with, whether it has been verified, when the account was created and the settings you choose for it. Your password is set and checked by our identity provider and never reaches us in readable form.
    • Your projects: what you name them, and what you enter so that your files can be processed, such as the date and the place the pictures were taken and the settings you choose for the result.
    • Your files: the files themselves, their names and sizes, a preview made from them, and the technical facts their metadata carries, such as the camera, the exposure and the lens. We read the facts the processing needs and leave the rest of the metadata alone.
    • The work you have done: which plan it ran under, whether it is waiting, running, finished or failed, when it ran and how long it took, anything that went wrong, and the files it produced.
    • Your payments: the record that something was paid for, and the reference of the transaction. Name, address, country and payment details are entered on the payment provider's own pages and stay with it. We never see a card number.
    • Server logs: when a page or an interface is requested, our hosting provider records the IP address, the time, what was requested, the status and the browser identification. That happens for every website, and it is what makes a fault or an attack traceable.
  3. 03

    Why we process it

    To give you an account and keep it safe, to store what you upload and process it as you ask, to keep the results available to you for as long as your plan covers, to write to you about your account and about the work you have had done, to take payment and to keep the books the tax law asks us to keep, and to keep the service reachable and free of abuse. That is the whole list. We do not profile you, we do not advertise to you, and we do not use what you upload, or what comes out of it, to train anything.

  4. 04

    On what legal basis

    Your account, what you upload, the work you have processed and the emails about them are processed to perform the contract you enter into with us, under Article 6 (1) (b) GDPR. Invoices and the records behind them are kept because tax and commercial law require it, under Article 6 (1) (c) GDPR. Server logs, backups and the measures that keep the service standing rest on our legitimate interest in a working and secure service, under Article 6 (1) (f) GDPR. Where anything ever needs your consent we ask for it first, and you can withdraw it at any time with effect for the future.

  5. 05

    Maps and place search

    Wherever this site shows a map or lets you search for a place, that map is delivered by Google Maps and your browser loads it directly from Google. Your IP address, what you type into the search box and the piece of the map you look at reach Google Ireland Limited, and may be processed by Google LLC in the United States, which relies on the EU-US Data Privacy Framework and on standard contractual clauses for that transfer. A map is loaded only on a page that shows one and only once you open it, never in the background and never as a way of recognizing you. Where a map is there to help you pick an observing site, you can type the coordinates by hand instead, and what we store afterwards is the same either way: the coordinates and the elevation of the place, and nothing about how you found it.

  6. 06

    Cookies and browser storage

    There is no consent banner on this site because there is nothing here that would need consent. The only cookies we set are the ones a page needs in order to work, such as the one that remembers the language you read the site in. When you are signed in, your browser keeps the sign-in tokens in its own storage so that a reload does not sign you out. All of it is strictly necessary for the functions you asked for, in the sense of section 25 (2) of the German Telecommunications Digital Services Data Protection Act. There is no analytics, no tracking pixel and no advertising network anywhere on this site, and the only third-party content it loads at all is the map described above.

  7. 07

    Who else sees your data

    Nobody buys it and nobody is given it for their own purposes. The service runs on infrastructure operated by others, and those others process your data on our instructions, under a data processing agreement, unless the list says otherwise. If we ever have to change a provider, this list changes with it and we tell you before it takes effect.

    • Our hosting provider, Amazon Web Services EMEA SARL, runs the service for us: the website, the sign-in, the storage your files land in, the database, the processing itself and the mail delivery. It runs in a data center in the European Union.
    • Google Ireland Limited delivers the maps and the place search, and is reached only on a page that shows a map, as described above.
    • Our payment provider, Paddle, sells the plans as merchant of record. It is its own controller for the payment data you enter on its pages, and its own privacy policy applies to that step. We receive the confirmation that something is paid for, not the payment details.
    • Email about your account and about the work you have had done goes out through our hosting provider's mail service, to the address on your account.
  8. 08

    Where your data is

    What you upload, the results, your account and the record of your work are stored and processed in the European Union. The two exceptions are the map, which reaches Google as described above, and the payment, which reaches our payment provider. Both rely on the adequacy decision for the EU-US Data Privacy Framework and on standard contractual clauses where the framework does not cover a case.

  9. 09

    How long we keep it

    What you upload, and the results that come out of it, stay until you delete them yourself, or until the period that comes with the plan they were processed under has run out. The pricing page states that period for each plan, and when it ends they are deleted automatically, so download what you want to keep before then. Your account data stays until you close the account. Invoices and the records that belong to them are kept for as long as tax and commercial law require, and they are then only kept, not otherwise used. Server logs are discarded after a short while, and backups are overwritten on a rolling basis.

  10. 10

    What we do not do with your files

    What you upload, and the results made from it, are yours. We store them, process them as you ask and keep them available to you, and nothing else. We do not publish them, we do not show them anywhere of our own, we do not use them in advertising and we do not train models on them. If we ever want to show a picture of yours, we ask you first, and we need your permission in writing for that particular picture.

  11. 11

    How it is kept safe

    Everything travels over an encrypted connection. What you upload goes straight from your browser into private storage over a link that expires, it is never public, and every file you download is handed over the same way. Passwords are held only by our identity provider, hashed, and a new one has to meet a length and a mix of characters that make guessing impractical. Everything stored is bound to the account that owns it, and the interface refuses anything asked for on behalf of another account.

  12. 12

    Your rights

    Under the GDPR you have the rights below, and exercising them is free and asks for nothing more than an email to info@helion1.com from the address on your account.

    • Access, Article 15: a copy of what we hold about you and an explanation of what we do with it.
    • Rectification, Article 16: anything wrong about you put right.
    • Erasure, Article 17: your data deleted, except where we still have to keep it for the tax records named above.
    • Restriction, Article 18: processing frozen while a question about your data is being settled.
    • Portability, Article 20: what you gave us handed over in a machine-readable form, or sent on to somebody else.
    • Objection, Article 21: an objection to any processing we base on our legitimate interest, with reasons that come from your situation.
    • Complaint, Article 77: a complaint to a supervisory authority, for us the Berlin Commissioner for Data Protection and Freedom of Information, or the authority where you live.
  13. 13

    Deleting your data yourself

    You do not have to write to us to get rid of something. What you have uploaded, what came out of it, and the account itself can each be deleted from your account area, and deleting something takes what belongs to it with it. Deletion is meant to be final: once something is gone it cannot be recovered, so keep your own copy of everything you upload.

  14. 14

    Changes to this policy

    We update this policy when the service or the law changes, and the version date at the top says which version you are reading. If a change matters to you, for instance a new recipient or a new purpose, we tell you by email before it takes effect. Reading this page again from time to time is worth it in any case.