Skip to main content
Last updated: July 27, 2026 This Data Processing Agreement (“DPA”) is entered into between Gravity GTM, Inc. (“Gravity GTM,” “Processor,” “we,” or “us”), a company organized under the laws of Delaware with a registered address at 2995 55th Street, Unit 17033, Boulder, CO 80308, and the customer entity that has accepted the Helium Terms of Service (“Controller,” “Customer,” or “you”), in connection with Customer’s use of the Helium API, MCP server, Slack app, and/or Gmail/Calendar connection (collectively, “Helium” or the “Service”), operated by Gravity GTM and available at lite.gravitygtm.com (documentation at docs.gravitygtm.com/helium). This DPA supplements and is incorporated by reference into the Helium Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.

1. Definitions

1.1 “Applicable Data Protection Law” means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, where applicable, the EU/UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act as amended (“CCPA”), together with any successor or equivalent legislation. 1.2 “Controller,” “Processor,” “Data Subject,” “Personal Data,” and “Processing” (and their variants) have the meanings given in Applicable Data Protection Law. Where CCPA applies, “Controller” corresponds to “Business” and “Processor” corresponds to “Service Provider,” and this DPA should be read accordingly. 1.3 “Sub-processor” means any third party engaged by Gravity GTM to Process Personal Data on Gravity GTM’s behalf in connection with providing the Service. 1.4 “Customer Data” means the Personal Data submitted to, looked up through, or accessed via a connected Google account by or at the direction of Controller in the course of using Helium.

2. Subject Matter and Duration

2.1 This DPA governs Gravity GTM’s Processing of Personal Data on behalf of Controller in connection with Controller’s use of the Service. 2.2 Processing under this DPA will take place for as long as Controller maintains an active Helium account, plus any additional period during which Gravity GTM retains Customer Data in accordance with Section 9 (Deletion and Return of Data) or applicable law.

3. Nature and Purpose of Processing

3.1 Gravity GTM Processes Personal Data solely to provide the Service as directed by Controller — namely, to research, score, and return third-party investor/LP/company data in response to queries submitted by Controller, and to store Controller’s own fundraising profile and uploaded network data to power that research, each performed via the specific Sub-processors identified in Section 5. 3.2 Where Controller connects the Helium Slack app, Gravity GTM additionally Processes the conversational messages Controller’s workspace users send to the Helium Slack bot, for the purpose of interpreting the request and executing the corresponding research. 3.3 Where Controller connects a Google account, Gravity GTM Processes Gmail and Calendar data solely to send outreach Controller has approved, detect inbound replies to pause a sequence, and check calendar availability, as described in Section 5 (Google) and in the Helium Privacy Policy. 3.4 Gravity GTM Processes Personal Data only on Controller’s documented instructions, as reflected in Controller’s configuration and use of the Service, except where otherwise required by law.

4. Categories of Data Subjects and Personal Data

4.1 Categories of Data Subjects. (a) The investors, LPs, family offices, and company personnel researched through the Service — typically not Controller’s own employees, customers, or end users. (b) Individuals in Controller’s own connected Gmail account and calendar (e.g., prior correspondents, calendar attendees), to the extent incidentally Processed while sending outreach, detecting replies, or checking availability. 4.2 Categories of Personal Data. Depending on the feature used, Processing may include: full name; job title; firm/fund affiliation; LinkedIn profile data (headline, profile URL, investment history, education); business email address; and, where the Gmail/Calendar connection is used, the content of outreach email sent through that connection, inbox metadata needed to detect a reply on a given thread, and calendar free/busy data. Where the Slack app is used, Processing also includes the content of messages sent to the Helium bot.

5. Sub-processors

5.1 Controller authorizes Gravity GTM to engage the following Sub-processors as of the effective date of this DPA. This table is maintained in lockstep with the equivalent table in Section 4 of the Helium Privacy Policy — the two are kept identical and updated together: 5.2 General authorization. Gravity GTM may engage additional or replacement Sub-processors from time to time. Gravity GTM will provide notice of any new Sub-processor by updating this Section and the corresponding table in the Privacy Policy, and by email to Controller’s registered account contact, in either case at least ten (10) days before the new Sub-processor begins Processing Customer Data. Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Controller’s sole remedy is to terminate the affected portion of the Service. 5.3 Gravity GTM remains responsible for each Sub-processor’s compliance with obligations materially equivalent to those in this DPA.

6. Security Measures

Gravity GTM implements and maintains the following technical and organizational measures:
  • API key protection: Customer API keys are stored only as a one-way SHA-256 hash; the plaintext key is displayed once at issuance and cannot be retrieved thereafter, only rotated or revoked.
  • Credential encryption: Slack bot tokens, workspace API keys, and Gmail OAuth refresh tokens are encrypted at rest using AES-256-GCM, each with a distinct encryption context, as they must be used to make live calls on Controller’s behalf.
  • Encryption in transit: All connections to the Service use TLS.
  • Log minimization: Operational logs contain only metadata (request ID, tenant/account ID, API key ID, endpoint called, credits charged, cache hit/miss status, and timestamps). Logs never contain lookup content, message content, or connected-Gmail content. Logs are retained no longer than 30 days.
  • Access controls limiting internal access to Customer Data to personnel who require it to operate the Service.

7. Assistance with Data Subject Rights

Taking into account the nature of the Processing, Gravity GTM will provide reasonable assistance to Controller in responding to requests from Data Subjects to exercise their rights under Applicable Data Protection Law, insofar as such assistance is within Gravity GTM’s control. Gmail/Calendar disconnection is available immediately and independently through Google’s own account permissions page (myaccount.google.com/permissions), or by request to help@gravitygtm.com for removal on Gravity GTM’s end. Requests regarding other Customer Data must be submitted to Gravity GTM at help@gravitygtm.com and will be handled manually by Gravity GTM personnel within a commercially reasonable time.

8. Personal Data Breach Notification

Gravity GTM will notify Controller without undue delay after becoming aware of a Personal Data breach affecting Customer Data, and will provide such information as it has available to assist Controller in meeting its own notification obligations under Applicable Data Protection Law. This notification obligation does not constitute an acknowledgment of fault or liability by Gravity GTM.

9. Deletion and Return of Data Upon Termination

9.1 Cached lookup data ages out automatically regardless of account status: investor/LP/company research results expire from cache within 24 hours. 9.2 Following termination or closure of Controller’s account, Gravity GTM will delete or anonymize Controller’s account data (including stored API key hashes, fundraising profile data, network import data, and, where applicable, encrypted Slack and Gmail credentials) within a reasonable period, except to the extent retention is required for legal, tax, or accounting purposes, or to resolve disputes. Any connected Google account authorization is revoked on Gravity GTM’s end at termination. 9.3 As Helium does not currently offer a bulk data-export or “return of data” mechanism, Controller should retrieve any research results it wishes to retain prior to closing its account.

10. Audit Rights

Upon reasonable prior written request, and no more than once per twelve-month period (unless required by a supervisory authority or following a confirmed breach), Gravity GTM will provide Controller with reasonable information — such as security documentation or responses to a written questionnaire — sufficient to demonstrate compliance with this DPA. Full on-site or third-party audits are not offered as a standard practice and, if requested, are subject to separate written agreement on scope, timing, confidentiality, and cost.

11. International Data Transfers

Where Processing of Personal Data under this DPA involves a transfer across jurisdictions in a manner restricted by Applicable Data Protection Law, the parties will rely on an appropriate transfer mechanism recognized under that law — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful equivalent — as applicable to the parties’ respective locations at the time of transfer. Nothing in this Section asserts that any specific mechanism is currently executed between the parties; the applicable mechanism, if any, will be documented separately upon request.

12. Liability

Each party’s liability arising out of or related to this DPA, including liability for breach of this DPA by either party or its Sub-processors, is subject to the limitations and exclusions of liability set out in the Helium Terms of Service. Nothing in this DPA expands either party’s liability beyond what is set out in the Terms of Service.

13. Governing Law

This DPA is governed by the laws of Delaware, without regard to conflict-of-laws principles, consistent with the governing law provision of the Terms of Service.

14. Acceptance

This DPA is incorporated into, and forms part of, the Helium Terms of Service. By accepting the Terms of Service — including via clickthrough acceptance during account signup or a subsequent credit purchase — Controller is deemed to have accepted this DPA without further action. Enterprise customers requiring a separately countersigned copy for internal recordkeeping may request one by contacting help@gravitygtm.com.