HeliumOS Data Processing Addendum
EFFECTIVE SINCE
October 9, 2026
LAST UPDATED
October 9, 2026
This HeliumOS Data Processing Addendum (this “DPA”) is incorporated into the Agreement between Nova Labs, Inc., a Delaware corporation doing business as “Helium” ("Nova Labs"), and Customer, and governs Nova Labs' processing of Customer Personal Data.
1. Definitions and Interpretation
1.1 “Agreement” means the agreement between Nova Labs and Customer under which Customer orders the Services, which is the HeliumOS Terms and Conditions posted at helium.com/legal/heliumos unless Customer and Nova Labs have agreed otherwise in a signed writing. If the Agreement uses different defined terms for the concepts described in this DPA, the corresponding terms of the Agreement apply.
1.2 “Data Protection Laws” means all U.S. federal and state privacy and data protection laws applicable to the processing of Customer Personal Data under the Agreement, including the California Consumer Privacy Act of 2018, as amended, and its implementing regulations (the “CCPA”), and other comprehensive U.S. state privacy laws in effect during the term of this DPA.
1.3 “Data Subject Request” means a request from an individual to exercise any right granted to that individual under Data Protection Laws with respect to Customer Personal Data.
1.4 The terms “business,” “service provider,” “controller,” “processor,” “consumer,” “personal information,” “sell,” “share,” and “deidentified” have the meanings given to them in the applicable Data Protection Laws.
1.5 Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.
2. Roles of the Parties
2.1 Customer. Customer is the business or controller with respect to Customer Personal Data. Where Customer processes Customer Personal Data on behalf of a Venue Owner or carrier, Customer is a service provider or processor to that Venue Owner or carrier.
2.2 Nova Labs. Nova Labs is Customer’s service provider or processor with respect to Customer Personal Data. Where Customer acts as a service provider or processor on behalf of a Venue Owner or carrier, Nova Labs is Customer’s subprocessor.
2.3 Authorization. Customer represents and warrants that: (a) its processing instructions, and its appointment of Nova Labs as service provider, processor, or subprocessor, are authorized by each Venue Owner, carrier, and other controller on whose behalf Customer processes Customer Personal Data, consistent with Section 4.3 of the Agreement; and (b) Customer will relay to those parties any communications from Nova Labs that are directed to them. Nova Labs will deal only with Customer and will not communicate directly with Venue Owners or carriers regarding Customer Personal Data, except as required by Applicable Law.
3. Processing Instructions and Restrictions
3.1 Restrictions. Nova Labs shall:
(a) process Customer Personal Data solely for the specific business purposes set forth in Annex 1 and in accordance with Customer’s documented instructions, which consist of the Agreement, applicable Order Forms, Product Schedules, and Customer’s configuration of the Services;
(b) not sell or share Customer Personal Data;
(c) not retain, use, or disclose Customer Personal Data for any purpose, including any commercial purpose, other than the business purposes specified in Annex 1 or as otherwise permitted by Data Protection Laws;
(d) not retain, use, or disclose Customer Personal Data outside the direct business relationship between Nova Labs and Customer, and not combine Customer Personal Data with personal information received from another source or collected from Nova Labs' own interactions with individuals, except as permitted by Data Protection Laws;
(e) comply with applicable Data Protection Laws and provide the same level of privacy protection as required of businesses under the CCPA;
(f) notify Customer if Nova Labs determines that it can no longer meet its obligations under Data Protection Laws; and
(g) notify Customer if Nova Labs believes an instruction from Customer violates Data Protection Laws.
3.2 Remediation. Customer has the right, upon notice to Nova Labs, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data by Nova Labs.
3.3 Certification. Nova Labs certifies that it understands and will comply with the restrictions set forth in this Section 3.
3.4 On-Chain Records. Nova Labs' recording of On-Chain Records as permitted by Section 10.2 of the Agreement is a business purpose under this DPA. On-Chain Records do not contain Customer Personal Data. Nova Labs shall not record any Customer Personal Data, including any name, telephone number, IMSI, MAC address, or other identifier of an End User or device, in an On-Chain Record.
4. Aggregated and Deidentified Data
4.1 Nova Labs may create Aggregated Data in accordance with Section 10.3 of the Agreement.
4.2 To the extent any Aggregated Data is derived from Customer Personal Data, Nova Labs shall: (a) take reasonable measures to ensure that the Aggregated Data cannot be associated with, or used to identify, any individual or household; (b) publicly commit to maintain and use such data only in deidentified form and not attempt to reidentify it, except to test the effectiveness of its deidentification processes as permitted by Data Protection Laws; and (c) contractually require any recipient of such data to comply with the same obligations set forth in this Section 4.2.
5. Confidentiality of Personnel
5.1 Confidentiality. Nova Labs shall ensure that all personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality, whether by contract or by operation of law, before being granted access to Customer Personal Data.
5.2 Access Limitation. Nova Labs shall limit access to Customer Personal Data to those personnel who require such access to perform Nova Labs' obligations under the Agreement and this DPA.
6. Security
6.1 Nova Labs shall implement and maintain the technical and organizational security measures described in the HeliumOS Information Security Exhibit, which are designed to provide a level of security appropriate to the nature and scope of the processing and the risks to Customer Personal Data.
6.2 Nova Labs shall periodically review and update its security measures to address reasonably anticipated threats, consistent with industry standards and Applicable Law. No change to the security measures shall materially reduce the overall level of protection provided to Customer Personal Data.
6.3 Customer is responsible for the security of Customer Systems and for configuring the Services in accordance with the Documentation.
7. Security Incidents
7.1 Consistent with Section 10.6 of the Agreement, Nova Labs shall notify Customer of a Security Incident without undue delay and no later than seventy-two (72) hours after becoming aware of the Security Incident.
7.2 Nova Labs shall provide Customer with information reasonably available to assist Customer in meeting its notification obligations under Data Protection Laws, and shall supplement that information as it becomes available.
7.3 Nova Labs shall take reasonable steps to contain and remediate the Security Incident.
7.4 Customer is responsible for notifying Venue Owners, End Users, carriers, and regulators as required by Applicable Law or the applicable Venue Agreement. Nova Labs shall not notify any third party about a Security Incident affecting Customer Personal Data without Customer’s prior written approval, unless required by law.
7.5 A notification under this Section 7 does not constitute an admission of fault or liability by Nova Labs.
8. Subprocessors
8.1 General Authorization. Customer grants general authorization for Nova Labs to engage Subprocessors to process Customer Personal Data in connection with the Services. Nova Labs' current Subprocessors are listed in the HeliumOS Subprocessor List.
8.2 Subprocessor Contracts. Nova Labs shall enter into a written contract with each Subprocessor, before the Subprocessor processes Customer Personal Data, imposing data protection obligations no less protective than those set forth in this DPA, including the requirements applicable to service providers under Data Protection Laws. That contract may consist of the Subprocessor's standard online terms and data processing addendum.
8.3 New Subprocessors. Nova Labs shall give Customer at least thirty (30) days’ notice before engaging a new Subprocessor, as set out in Section 10.7 of the Agreement, including Customer's right to object under that Section.
8.4 Responsibility. Nova Labs remains responsible for the acts and omissions of its Subprocessors to the same extent as if Nova Labs performed the processing directly.
8.5 Notices of Changes. Customer may subscribe to notices of changes to the Subprocessor List by sending a request to support@helium.com.
9. Assistance and Data Subject Requests
9.1 Assistance with Data Subject Requests. Taking into account the nature of the processing, Nova Labs shall provide reasonable assistance to enable Customer to respond to Data Subject Requests, primarily through the functionality of the Services.
9.2 Forwarding Requests. If Nova Labs receives a Data Subject Request relating to Customer Personal Data, Nova Labs shall promptly forward it to Customer and shall not respond to the individual except to direct the individual to Customer, unless required by Applicable Law. Customer shall inform Nova Labs of any Data Subject Request that Nova Labs must comply with and provide the information necessary for Nova Labs to do so.
9.3 Assessments. Nova Labs shall provide reasonable information to assist Customer with data protection assessments, cybersecurity audits, or risk assessments that Data Protection Laws require of Customer, to the extent related to the Services.
9.4 Cost. Assistance under this Section 9 that exceeds the standard functionality of the Services is at Customer’s reasonable cost, except where the assistance is required because of Nova Labs' breach of this DPA or the Agreement.
10. Audits
10.1 Audits. Customer may verify that Nova Labs processes Customer Personal Data consistently with Customer’s obligations under Data Protection Laws as follows: (a) on request, no more than once in any twelve (12) month period, Nova Labs shall provide its most recent SOC 2 Type II report or equivalent third-party assessment, if one is available, and respond to a reasonable written security and privacy questionnaire; and (b) if the information provided under clause (a) is insufficient to demonstrate compliance, or following a Security Incident or a request from a regulator, Customer (or an independent auditor bound by confidentiality obligations and not a competitor of Nova Labs) may conduct an audit on at least thirty (30) days’ prior written notice, during normal business hours, no more than once in any twelve (12) month period (except following a Security Incident or regulator request), at Customer’s expense, and in a manner that does not compromise the security of Nova Labs' systems or the data of Nova Labs' other customers.
10.2 Audit results, including any reports or findings, are Nova Labs' Confidential Information under Section 12 of the Agreement.
11. Location and International Transfers
11.1 Nova Labs stores Customer Personal Data at rest in the United States, and Subprocessors may process Customer Personal Data in the locations stated in the Subprocessor List, in each case in accordance with Section 10.10 of the Agreement.
11.2 The Services are not designed to process personal data subject to the General Data Protection Regulation (EU) 2016/679 or other non-U.S. data protection laws. Customer shall not use the Services to process personal data subject to those laws unless the Parties first agree in writing on any additional terms required to lawfully authorize the processing, including, where applicable, standard contractual clauses or other approved transfer mechanisms.
12. Special Categories, Health Information, and Carrier Data
12.1 Customer shall not use the Services to process protected health information as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, biometric data, financial account numbers, or government identification numbers unless the Parties agree in writing on appropriate safeguards or the applicable Product Schedule describes the processing and the safeguards that apply. For protected health information, the Parties shall execute a business associate agreement before any such processing begins.
12.2 Customer Personal Data may include carrier subscriber identifiers (such as IMSIs) and customer proprietary network information disclosed by carriers. Customer shall notify Nova Labs in writing of any carrier-imposed handling requirements applicable to that data, and Nova Labs shall comply with requirements that are reasonable and consistent with the Agreement.
12.3 Customer is responsible for providing all notices and obtaining all consents required under Applicable Law and Section 6.3 of the Agreement with respect to location data processed through the Services, including where Data Protection Laws treat Venue-level or access-point-level location data as precise geolocation or sensitive personal information.
13. Return and Deletion
13.1 Return and Deletion. Return and deletion of Customer Personal Data are governed by Section 10.9 of the Agreement. Customer may export Customer Personal Data through the functionality of the Services during the thirty (30) day post-termination export period. Nova Labs shall delete Customer Personal Data within ninety (90) days after that export period ends, except for (a) data in backups, which is deleted in the ordinary backup cycle; and (b) data that Applicable Law requires Nova Labs to retain.
13.2 On Customer’s written request following a valid deletion request from an individual under Data Protection Laws, Nova Labs shall, to the extent the relevant data is identifiable within the Services, confirm in writing that it no longer retains or uses that individual's Customer Personal Data.
14. Liability, Precedence, and Term
14.1 Liability. Each Party’s liability arising out of or relating to this DPA is subject to Section 15 of the Agreement (Limitation of Liability), including the Enhanced Cap applicable to claims for breach of Section 10 of the Agreement or this DPA.
14.2 Precedence. If this DPA conflicts with the Agreement with respect to the processing of Customer Personal Data, this DPA controls, consistent with the order of precedence in the Agreement.
14.3 Term. This DPA is effective as of the effective date of the Agreement and remains in effect for as long as Nova Labs processes Customer Personal Data under the Agreement, including any post-termination period described in Section 10.9 of the Agreement.
Annex 1: Details of Processing
This Annex 1 forms part of the DPA and describes the processing Nova Labs performs on behalf of Customer.
| Element | Description |
|---|---|
| Subject Matter and Duration | Provision of the Services, including Sandbox Services, for the term of the Agreement and the post-termination period described in Section 10.9 of the Agreement. |
| Categories of Individuals | End Users whose devices connect to or through Customer Systems at Venues; End Users whose devices connect to the Helium Network through the Services; Customer’s subscribers and prospective subscribers; users of Customer applications that incorporate Client Software; Authorized Users of Customer and Venue Owners; Customer and Venue Owner personnel named in support communications. |
| Categories of Personal Information | RADIUS authentication and accounting attributes, including usernames that may include IMSIs or other carrier subscriber identifiers; device identifiers (such as MAC addresses, IMEIs, and EIDs); SIM and eSIM identifiers (such as ICCIDs) and telephone numbers; Venue-level and access-point-level location data; session, usage, data volume, signal-quality, and load data, including for sessions on the Helium Network; subscriber account data (such as name, date of birth, service address, email, telephone number, plan, and account status); port-in and port-out data, including prior carrier account numbers and port-out PINs; billing, invoice, and payment status data; call and text detail records; regulatory compliance records; Passpoint profile and certificate identifiers and Client Software event data; Authorized User account data (name, business email, role, and login logs); content submitted to AI features. |
| Sensitive Personal Information | Venue-level and access-point-level location data, which may constitute precise geolocation under certain Data Protection Laws. For the Carrier Enablement Platform, account credentials such as port-out PINs, as described in the applicable Product Schedule. No other sensitive categories are intended. |
| Business Purposes: WOX | Evaluating authentication requests against Customer-configured policies and KPIs; passing approved requests to Customer-designated AAA servers; dashboards, reporting, and trend analysis; troubleshooting; measuring Daily Active Users. |
| Business Purposes: HeliumAI and AI Features | Generating analytics, insights, dashboards, and responses requested by Authorized Users from Customer Data; making Outputs available to tools Customer connects, including through a Model Context Protocol server, at Customer’s direction. |
| Business Purposes: Wi-Fi Toolkit | Issuing, delivering, managing, and revoking Passpoint profiles and EAP-TLS credentials through Client Software; authenticating End Users against Customer’s designated authorization source; reporting on profile delivery, join rates, and location performance. |
| Business Purposes: Carrier Enablement Platform | Creating and managing subscriber accounts; activating, suspending, swapping, and retiring SIMs and eSIMs; processing port-in and port-out requests; applying account security controls; generating invoices and tracking payment status; maintaining regulatory compliance records; in each case as configured by Customer and described in the applicable Product Schedule. |
| Business Purposes: Helium Network Integration | Authenticating, routing, and measuring End User sessions on the Helium Network; recording On-Chain Records as described in Section 3.4; reporting usage to Customer; in each case as described in the applicable Product Schedule. |
| Business Purposes: All Services | Providing support, maintaining and securing the Services, preventing fraud and abuse, and complying with Applicable Law. |
| Retention | As described in the applicable Product Schedule or, if the Product Schedule is silent, the default period in Section 10.9 of the Agreement. |
| Subprocessors | As listed in the HeliumOS Subprocessor List. |