Skip to main content
Hellia
Use casesResourcesSecurityAbout
FR/EN
Sign inRequest a demo
  1. Home
  2. Privacy policy

HELLIA PRIVACY POLICY

Version 1.0

Effective date: 10 June 2026

1. INTRODUCTION

This Privacy Policy explains how personal data is processed when you use the Hellia platform (the "Service"), accessible in particular at app.hellia.ai.

The Service is provided by HELL OUT, a single-member limited liability company (EURL) under French law, registered with the RCS of Paris under number 881 415 269, with registered office at 34 rue Sedaine, 75011 Paris, France, trading as "Hellia" and "Hello Escape" ("Hellia", "we", "us").

Privacy contact: laurent@hello-escape.com

This policy supplements the Terms of Use. It is written for the people who use the Service, typically employees of the organisation that subscribed to it, and for visitors of the public demo.

2. THE SHORT VERSION

  • Your voice is not recorded. During a voice simulation, your microphone audio is streamed in real time to the AI provider to hold the conversation; Hellia never records or stores the audio or the transcript.
  • What is stored: your profile (name, e-mail, role, organisation), session results (score, duration, completion), the AI's written feedback on your performance, and the prompts and documents you submit to create content.
  • No biometrics, no emotion analysis: we never identify you by your voice and never analyse tone, sentiment or stress.
  • No AI training on your data: neither Hellia nor its AI providers use your data to train models.
  • Your organisation is in charge: in most cases your organisation (typically your employer) is the data controller and decides why the Service is used; authorised managers in your organisation can see your results. Exercise your privacy rights with your organisation first.
  • No advertising, no tracking: we use no advertising or third-party analytics trackers, and we never sell personal data.
  • Hosted in the EU: data at rest is stored on Microsoft Azure in the European Union (France).

3. WHO IS RESPONSIBLE FOR YOUR DATA

3.1 When you use the Service as a member of an organisation (your account was created or invited by your employer or a training partner), that organisation is the data controller for the personal data processed through your use of the Service. It decides the purposes, for example which trainings you take and how results are used. Hellia processes this data as a processor on the organisation's behalf, under a data processing agreement (GDPR Article 28).

3.2 Hellia acts as a data controller only for limited processing of its own: (a) the public demo (Section 11), which requires no account; (b) business and contractual contacts of customer and partner organisations; (c) correspondence you address to us directly (for example support or privacy enquiries); (d) security, audit and service telemetry to the extent Hellia processes it for its own accountability and the protection of the Service.

4. WHAT DATA IS PROCESSED

4.1 Data stored by the Service:

  • Account and profile: identifiers, e-mail address, display name (first and last name), role, organisation, account status, timestamps. Identity and sign-in are operated through Microsoft Entra External ID.
  • Session results: feature used (Simulation, Trainer, Quiz, Podcast), content name, start and end time, duration, completion status, and an overall score (0 to 100).
  • AI feedback: for evaluated sessions, per-criterion scores (1 to 10) with the AI's written reasoning and improvement notes, and a general comment. This is the AI's commentary on your performance, not a recording or transcript of what you said.
  • Content you create or import: authoring prompts you type, documents and files you import to generate trainings, and the generated content. Imported documents may contain personal data if they were not anonymised before import (see the Terms of Use; you are asked not to include personal or sensitive data).
  • Technical and audit logs: service telemetry, error logs and administrator-action logs.

4.2 Data processed only transiently, never stored by Hellia:

  • Your voice during a live session: streamed from your browser directly to the AI provider to hold the conversation, then discarded. Hellia has no recording of it.
  • The conversation transcript: produced during the session to enable the conversation and the post-session evaluation, then discarded. It is never stored by Hellia.

4.3 What is never done:

  • No speaker identification, voiceprint or other biometric analysis.
  • No emotion, tone, sentiment or stress analysis.
  • No use of your data to train or fine-tune AI models, whether by Hellia or by its AI providers (contractually excluded under paid-tier terms).
  • No advertising profiles, no sale of personal data.

5. VOICE SESSIONS IN DETAIL

5.1 Voice simulations use your microphone only with your browser permission. The audio is converted in your browser and streamed in real time directly to the AI provider (Google Gemini Live by default, or Microsoft Azure voice services depending on configuration) so the AI persona can hear and answer you. There is no Hellia server in the audio path, and no recording.

5.2 Because the audio is processed live, it cannot be filtered before reaching the AI provider. Do not say sensitive personal data aloud during a session.

5.3 If you prefer not to use your voice, you are not required to take part in voice simulations; a written mode for simulations can be made available to your organisation on request.

5.4 After the session, the evaluation is computed from the textual content of the conversation and only the results described in Section 4.1 are kept.

6. PURPOSES AND LEGAL BASES

6.1 As processor for your organisation, Hellia processes the data in Section 4 to: operate your account and access rights; run simulations, trainings, quizzes and podcasts; generate AI evaluations and feedback; display progress dashboards to you and to your organisation's authorised managers; provide support; and keep the Service secure. The legal basis for these processing operations is determined by your organisation as controller (for employee training this is typically its legitimate interest in training its workforce or the performance of its obligations); your organisation is responsible for informing you accordingly.

6.2 As controller, Hellia processes: - demo-visitor data (Section 11) on the basis of its legitimate interest in demonstrating and improving the commercial demo; - business-contact and correspondence data on the basis of its legitimate interest in managing customer relationships and responding to enquiries, or to perform contracts; - security and audit logs on the basis of its legitimate interest in protecting the Service and meeting its accountability obligations.

6.3 Automated decision-making. Hellia does not make any decision producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing (Article 22 GDPR). AI scores and feedback are training aids; any decision your organisation takes on their basis is made under its responsibility and is expected to involve human review.

7. WHO CAN SEE YOUR DATA

7.1 Within your organisation. You see your own results. Authorised managers and administrators of your organisation can see individual results (scores, AI feedback, duration, completion) for members of that organisation, and can share them for legitimate purposes, for example with HR. How those results are used is your organisation's responsibility as controller. No one outside your organisation's authorised roles can see your individual results; access across organisations is blocked by design (Hellia's own platform administrators excepted, for support and operation).

7.2 Service providers (sub-processors). Hellia relies on the following providers, under data-processing agreements: - Microsoft (Azure): hosting (EU, France Central primary), identity (Entra External ID), transactional e-mail, telemetry, and voice services where configured; optional PII-detection service where enabled. - Google (Gemini API): AI models for live conversation, content generation, evaluation and text-to-speech. - Gamma: slide generation, only when the "describe and generate" feature is used. - CloudConvert (Lunaweb GmbH, Germany): file conversion. - A transactional e-mail provider (SendGrid or Postmark) where configured. The maintained sub-processor list is available on request at laurent@hello-escape.com.

7.3 Authorities. We disclose personal data to public authorities only where legally required.

8. WHERE DATA IS PROCESSED, INTERNATIONAL TRANSFERS

8.1 All stored data is hosted on Microsoft Azure in the European Union (France Central as primary region).

8.2 Some processing may take place outside the EU/EEA: - The Google Gemini API runs on Google's global infrastructure (not pinned to an EU region). This transfer is governed by Google's data processing terms and the European Commission's Standard Contractual Clauses. An EU-resident AI path (Azure voice services and EU-region generation endpoints) can be configured for organisations that require it. - Gamma (US) and, where configured, the transactional e-mail provider (US), under Standard Contractual Clauses and/or the EU-US Data Privacy Framework, as applicable. - Microsoft support operations may involve access from outside the EEA under the Microsoft data-processing agreement and its transfer safeguards.

8.3 Details of the transfer mechanism applicable to your organisation's configuration are available via your organisation or on request at laurent@hello-escape.com.

9. HOW LONG DATA IS KEPT

9.1 Voice audio and conversation transcripts: not stored at all (Section 4.2).

9.2 Files uploaded for content generation are processed and the transient ingestion copies are automatically deleted within 24 hours; the retained source documents and generated content remain stored as part of your organisation's content.

9.3 Stored data (profile, content, results, AI feedback) is kept for the duration agreed with your organisation and deleted when your organisation removes the content or account or instructs deletion, and at the latest at the end of the contract between Hellia and your organisation (deletion or return, at the organisation's choice).

9.4 When a user account is removed, Hellia deletes the user's data in full: identity, profile, session results, AI feedback, authored content and associated stored files.

9.5 Technical logs and encrypted backups are retained for limited periods and purged on their normal rotation cycles.

10. SECURITY

Key measures protecting your data include: EU hosting (Azure, France Central); encryption at rest (AES-256) and in transit (TLS 1.2+); secrets management in Azure Key Vault; nominative accounts with multi-factor authentication and least-privilege, just-in-time administrative access; role-gated, organisation-scoped access in the application; administrator- action audit logging; monitoring and alerting. A detailed description of technical and organisational measures is provided to organisations in the data processing agreement.

11. THE PUBLIC DEMO

11.1 The public demo can be used without an account. For the demo, Hellia is the data controller.

11.2 The demo stores a randomly generated visitor identifier in your browser's local storage to count demo usage (sessions started, features tried). This identifier is not linked to your name or e-mail, which the demo does not ask for, and is not used for advertising.

11.3 Demo conversations work like the main Service: voice is streamed to the AI provider for the conversation and is not recorded or stored by Hellia. Do not submit personal or sensitive data in the demo.

12. COOKIES AND BROWSER STORAGE

12.1 The Service uses no advertising cookies and no third-party analytics trackers.

12.2 The Service stores only what is strictly necessary for it to work, plus minimal preferences: - Authentication: session tokens kept in browser storage, and a refresh token set as an HttpOnly cookie by the backend, so you stay signed in securely. - Preferences: interface preferences (for example sidebar state, selected organisation, display filters) kept in a cookie or local storage. - Demo: the anonymous visitor identifier described in Section 11. These do not require consent under the ePrivacy rules as applied by the CNIL, being strictly necessary or minimal preference storage.

13. YOUR RIGHTS

13.1 Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection, in the conditions set by the GDPR.

13.2 For your use of the Service through your organisation, your organisation is the controller: address your request to it in the first instance (typically your HR department, training manager or the administrator who invited you). Hellia assists your organisation in responding, including by providing a copy of your stored data, rectifying profile fields and deleting your data in full.

13.3 For processing where Hellia is controller (Section 3.2), contact us directly at laurent@hello-escape.com. We respond within the time limits set by the GDPR.

13.4 You may lodge a complaint with a supervisory authority, in France the CNIL (Commission Nationale de l'Informatique et des Libertés, www.cnil.fr).

14. MINORS

The Service is intended for professional use by adults. It is not directed at, and may not be used by, persons under 18.

15. CHANGES TO THIS POLICY

We may update this policy, in particular to reflect changes in the Service, in law or in our providers. The current version, with its effective date, is available within the Service. Material changes are notified through the Service or to your organisation with reasonable advance notice.

16. CONTACT

For any privacy question or request: laurent@hello-escape.com

HELL OUT (EURL), trading as Hellia / Hello Escape RCS Paris 881 415 269, VAT FR17881415269 34 rue Sedaine, 75011 Paris, France

Hellia

Conversational training powered by AI.

Product

AI TrainerAI PodcastAI QuizAI SimulationIntegrations

Company

Use casesCustomersAboutContact

Resources

AI-generated trainingConversational AI for trainingAI training avatarAI roleplay

© 2026 Hellia. All rights reserved.

Legal noticePrivacy policyTerms of use