If you run a nonprofit, a ministry, or a small business, the sensible first question about AI is "where does my data actually go?" This page answers it plainly. It is the page we would want to read before hiring someone like us.
Building a workflow means connecting to systems you already run — an inbox, a CRM, a forms tool, a document store. We prefer scoped credentials or service accounts limited to exactly the records the workflow touches, rather than full administrative access. Where a platform cannot scope access that finely, we will say so before you grant it.
At the end of an engagement, we ask you to revoke our access. If we hold copies of anything for testing, we delete them.
Workflows we build send data to third-party AI model providers to do their work — classifying an email, drafting a reply, extracting a field from a document. Two things matter here:
CONFIRM: name the model providers you actually use, and link their enterprise/API data terms
We do not ship fully autonomous workflows for decisions that are expensive to get wrong. Anything that sends external communication, moves money, changes a record of record, or touches a person's case file gets a review step by default. You can choose to remove it; we will tell you what you are accepting if you do.
Some of the work we do sits near sensitive data — donor records, beneficiary information, member details. Where an engagement involves data subject to specific regimes, we scope it explicitly in the agreement rather than relying on this page.
CONFIRM: state whether you will sign a BAA, handle PII/PHI, or work with regulated data — and what you will decline
Every workflow we deliver comes with written documentation: what it touches, what it decides, where the human steps are, and how to switch it off. If you end the relationship, you keep that document.
If you are evaluating us and need detail this page does not cover, ask — hello@helmico.ai. We would rather answer a hard question early than discover a mismatch mid-build.