Helix Privacy Policy.

Helix QA Workbench is an AI QA workbench developed and supported by PiAI Solutions. Helix transforms Azure DevOps and Jira work items into editable Playwright tests, executes them against your applications, and helps teams maintain test coverage as requirements evolve.

This page explains how Pi Digital Solutions handles personal and customer data in connection with Helix QA Workbench, distributed via the Microsoft commercial marketplace.

1. Who we are

Pieterse Consulting Digital Solutions Ltd, trading as ‘PiAI Solutions’ (“PiAI”, “we”, “us”, “our”), is the publisher of Helix QA Workbench (“Helix”, the “Product”) on the Microsoft commercial marketplace. This Privacy Policy explains what data we and the Product process, why, and the choices and rights available to you. It applies to the Helix QA Workbench offer, our marketplace listing, and our related websites and support channels. It does not replace the data protection terms in your commercial agreement or Microsoft Marketplace contract, which take precedence where there is any conflict.

  • Publisher/data controller for our websites, marketing and support: Pieterse Consulting Digital Solutions Ltd (PiAI Solutions).
  • Registered office: C/O Rodliffe Accounting Ltd, 1 Canada Sq 37th Floor, Canary Wharf, London, England, E14 5AA
  • Company registration number: 10512094
  • Privacy contact: helixsupport@piaisolutions.com

2. The most important thing to understand: where Helix runs

Helix QA Workbench is deployed as a single-tenant application inside your own Microsoft Azure subscription, on your Azure Kubernetes Service (AKS) cluster, or in the single-tenant virtual-machine deployment model. There is no shared, multi-tenant Helix cloud that pools customers together. Your requirements, generated tests, execution results, screenshots, logs and audit artefacts are stored in Azure resources within your subscription and your chosen Azure region. Because of this architecture, for most data the customer is the data controller and PiAl Solutions acts as a data processor (or has no access at all). The exceptions are the limited outbound flows needed for AI test planning and generation, described in section 4.

3. The data Helix stores in your tenant

When you run Helix, the following categories of data are created and stored within Azure resources in your own subscription. Pi Digital does not routinely access these stores; access during support is only with your authorisation.

*Optional

4. AI test planning and generation – what is transmitted, and your controls

To turn your work items into test plans and Playwright code, Helix uses AI agents. This involves limited, purpose-bound outbound processing that you should be aware of and can control:

  • Helix Licensing API: the Product calls the Pi Digital-hosted Licensing API to validate subscription status.
  • Large language model (LLM) provider: test planning and generation rely on a configurable LLM provider. The content sent for processing is limited to what is needed to generate your tests.
  • Your data-residency control: you can pin the LLM provider to Azure OpenAI/Anthropic so that this processing remains within Azure and your chosen region. Where supported by your plan and configuration, processing can be kept within your Azure boundary.
  • We do not use your requirements, application data, generated tests or execution artefacts to train our own or any third party’s foundation models.
  • Connected systems: Helix integrates with the source and destination systems you configure – Azure DevOps Boards, Jira / Xray, your Git repository, and your CI/CD runners. Data flows to and from these systems under your control and their own terms.

5. Personal data we process directly

Separately from the data inside your tenant, we process a small amount of personal data to operate our business, the marketplace listing and our support service:

  • Account and contact data: names, business email addresses, job titles and company details of the people who evaluate, purchase, deploy or administer Helix.
  • Support data: the contents of support tickets, correspondence and any diagnostic information you choose to share with us (for example, the first eight characters of a licence key, Azure region and error logs).
  • Marketplace transaction data: subscription, plan and billing-related information shared with us by Microsoft to fulfil and support your order.
  • Website and listing usage data: limited technical data (such as device and browser information) when you visit our websites; see section 11 on cookies.

6. Why we process data and our lawful bases (UK GDPR / EU GDPR)

Where we act as a controller for the personal data in section 5, we rely on the following lawful bases:

  • Performance of a contract: to provide, deploy, support and administer Helix for you.
  • Legitimate interests: to operate, secure and improve the Product and our websites, and to communicate with business customers – balanced against your rights and freedoms.
  • Legal obligation: to meet tax, accounting, security and other legal and regulatory requirements.
  • Consent: where required, for example certain marketing communications or non-essential cookies – which you can withdraw at any time.
  • Where Helix processes data inside your tenant on your behalf, you are the controller and determine the lawful basis; we act as your processor under the data protection terms of your agreement.

7. Sub-processors and third parties

We use a limited set of trusted providers to deliver Helix. We do not sell personal data. Our sub-processors include:

  • Microsoft Azure – cloud infrastructure on which Helix is deployed (within your own subscription) and on which our hosted services run.
  • The configured large language model provider (which can be pinned to Azure OpenAI/Anthropic) – for AI test planning and generation.
  • Our support, ticketing, billing and communications tooling -used to operate the service and respond to you.
  • A current list of sub-processors, including names, roles and locations, is available on request and will be maintained.

8. International data transfers

Helix is offered internationally. Data stored inside your tenant remains in the Azure region you select. For the limited personal data we process as a controller, and for the AI processing flows in section 4, data may be processed in countries outside the UK or EEA. Where this happens, we put in place appropriate safeguards, such as the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses , so that your data receives an equivalent level of protection. You can keep AI processing within Azure by pinning the LLM provider to Azure OpenAI/Anthropic in your chosen region.

9. Data retention

Data created by Helix inside your tenant is retained for as long as you keep it; you control its lifecycle, export and deletion within your own Azure subscription, and it is removed when you decommission the deployment or delete the underlying resources. For personal data we process as a controller, we keep it only as long as necessary for the purposes described in this policy, to provide and support the Product, and to meet our legal, tax and accounting obligations, after which it is deleted or anonymised. Specific retention periods are available on request.

10. How we protect data

Security is structural to how Helix is built and deployed:

  • Single-tenant isolation: each customer instance runs in its own Azure subscription with isolated storage and execution context,  there is no shared multi-tenant execution.
  • Encryption in transit: TLS 1.2 or higher for connections, including outbound connections to Azure DevOps, Jira and configured AI provider endpoints.
  • Encryption at rest: Azure-managed keys by default, with customer-managed keys available on the Enterprise and Private plans.
  • Secret management: credentials, tokens and secrets are held in Azure Key Vault within your subscription.
  • Identity and access: Microsoft Entra ID with single sign-on and group-based role mapping on the relevant plans.
  • Auditability: every requirement, test, run, result and defect is linked, versioned and queryable, and can be exported to your SIEM via Azure Log Analytics.

11. Cookies and our websites

Our marketing websites and marketplace listing pages may use strictly necessary cookies to function and, where you consent, limited analytics to understand and improve site usage. You can control non-essential cookies through your browser settings and any cookie banner we present. The Helix Product itself, running inside your tenant, is administered by your organisation and is not a public consumer website.

12. Your rights

Subject to applicable law, and depending on whether we act as controller or processor, you have rights over your personal data, including:

  • Access to the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure (‘right to be forgotten’) in certain circumstances.
  • Restriction of, or objection to, certain processing.
  • Data portability for data you have provided to us.
  • Withdrawal of consent where processing is based on consent.
  • The right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office (ICO) at ico.org.uk. Where Helix processes data on your behalf, please direct requests to your own organisation as the controller, and we will support you as your processor.

13. Children

Helix QA Workbench is a business-to-business product intended for use by organisations and their professional staff. It is not directed at, and we do not knowingly collect personal data from, children.

14. Compliance and certification status

We are transparent about where our compliance programme stands. The following reflects our position as at the effective date of this policy and is provided for information; it is not a warranty of certification:

  • MACC / Azure benefit eligibility: aligned at launch.
  • Microsoft 365 Certification: scoped and targeted for a later phase — not yet certified.
  • SOC 2 Type II: in preparation and targeted for a later phase — not yet certified.
  • ISO 27001: scoped and targeted for a later phase — not yet certified.
  • We will update this section as certifications are achieved. Current attestations and evidence packs are available to qualifying customers on request, and bespoke evidence (e.g. SOC 2, ISO 27001, HIPAA, PCI, FCA, SOX) can be arranged under the Private plan.

15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Product, our practices, or legal requirements. When we make material changes, we will update the effective date above and, where appropriate, notify you. The current version will always be available at the link published on our Microsoft marketplace listing.

16. How to contact us

For any question about this policy or your data, or to exercise your rights, please contact us: