Built to be reviewed
HelmHOA holds compliance records, owner information, and the evidence a board relies on. This page collects everything a reviewer, attorney, or security questionnaire needs — and the reasoning behind it.
The posture, in three sentences
Access follows roles, enforced by security rules, not hidden buttons: owners see their own units, field staff their assigned buildings, administrators their scope — and no administrator can edit their own permissions. Administrative actions are audit-logged, destructive operations need a second administrator, and compliance status is computed from evidence rather than hand-edited. Everything is encrypted in transit and at rest on Google Cloud infrastructure.
Security Policy
Infrastructure, authentication, per-association isolation, role-scoped access, audit logging, application security practices, and responsible disclosure.
Read the Security Policy →Privacy Policy
What we collect, how it's used, who can see it, retention and deletion, and your rights — one canonical policy, rendered identically here and inside the app.
Read the Privacy Policy →Subprocessors
The deliberately short list of providers that touch customer data, with the purpose and processing region for each — the page a vendor-review checklist asks for.
See the subprocessor list →AI Disclosure
Where AI is used (sparingly, suggest-and-confirm), where it deliberately is not, and the standing rule: no AI output is a legal determination.
Read the AI Disclosure →Accessibility Statement
WCAG 2.1 AA as the target, what we do to meet it, the gaps we know about, and how to report an issue that blocks you.
Read the Accessibility Statement →Cookie Notice
The short version: this website sets no cookies and runs no third-party trackers — so there's no banner, because there's nothing to consent to.
Read the Cookie Notice →Legal Disclaimer
The full educational-information disclaimer that governs every legal-educational surface on this site and in the platform.
Read the Disclaimer →Terms of Service
Fully drafted and in review with Florida counsel — published only after that review. The terms page carries the current status and what the instrument covers.
Terms of Service status →Data Processing Addendum
Available on request for boards and their attorneys — our handling of customer personal data, subprocessors, retention, and termination, in contract-attachment form.
Request the DPA →Availability
HelmHOA is served from Google's global infrastructure with automatic scaling and redundancy. Field work doesn't depend on a signal: inspections queue locally when a device is offline and sync when connectivity returns.
Data handling, in brief
Your association's data belongs to your association. We don't sell personal information, we don't run advertising, and the platform shares data only with the providers listed publicly, when required by law, or with your community's own management. Retention follows the association's record-keeping decisions, and account deletion is available in-app — including on iOS.
Owner-private data
One class of data sits deliberately outside the role model above. A unit owner’s home manual — the appliance records, model and serial numbers, and the household’s own checklists, notes and vendor contacts — is private to the unit. It is readable by the owners of that unit and by nobody else: not the association’s managers, not its board, not the front desk, not inspectors or maintenance staff, and not a HelmHOA super administrator working in the application. That boundary is enforced in server-side security rules, not by hiding controls in the interface.
It becomes shareable only by owner action, in two forms the owner initiates and controls. The owner can build a trade-scoped PDF and send it to a vendor themselves — a document that leaves the platform, carries no link back into it, and for that reason cannot be recalled. Or the owner can grant their building’s management temporary access, choosing what it covers and how long it runs: the grant expires on its own, can be revoked immediately, never permits deletion, and logs every access and change for the owner to read.
For a reviewer, the short version: the association’s own administrators cannot reach this data through any application surface, and the platform’s answer to “who can see it?” is “the owner, and whoever the owner decided to show it to.”
Security review & questionnaires
Doing vendor due diligence? We'll walk your reviewer through the current posture directly — contact us for security questionnaires, and report suspected vulnerabilities privately to privacy@helmhoa.com (see the responsible-disclosure terms).