Gaston · Privacy statement
Gaston records, transcribes and summarises the meetings of HELX Security staff. This statement describes the data processed by the Gaston web application and its Chrome extension, in accordance with the General Data Protection Regulation 2016/679 of 27 April 2016 ("GDPR"). Last updated: 27 September 2026.
In short: Gaston is an internal tool restricted to helx.io Google accounts. Meeting audio is transcribed on infrastructure run by HELX and is never sent to an artificial intelligence provider. The data is neither sold nor used for advertising.
The data controller is HELX Security, 19 Cité Aubry, 75020 Paris, France (Paris Trade and Companies Register no. 941 968 208).
1. Users
Gaston and its extension are intended exclusively for HELX Security staff. Sign-in uses a Google account of the helx.io domain; no other account can access the application.
2. Data processed
Account: name, email address and photo of the user's Google account, to authenticate them.
Meeting audio: during a Google Meet meeting, the extension records the audio tracks of the speakers. In manual mode, and only after the user clicks, it records the sound of the chosen tab and the microphone.
Meeting information: title, date, duration and participant names as displayed by Google Meet, to attribute each utterance.
Generated content: transcript, summary, minutes, notes and questions the user asks about their meetings, as well as the job title and company of contacts when the user enters them.
Technical access: a device token linking the extension to the user's account and, if the user configures them, their own Claude or ChatGPT API keys or subscription sign-ins, encrypted at rest and never displayed again.
3. Purposes
This data is used solely to provide the service to the user: recording their meetings, transcribing them, producing a summary and minutes, searching and reviewing them, asking questions about their content and, if they choose, sharing them with colleagues. Legal basis: HELX Security's legitimate interest in equipping its staff.
4. Where the data is processed
In the browser: recordings are kept locally by the extension until the Gaston server confirms their receipt and integrity, then deleted from the device.
On HELX infrastructure: the application, its database, the recordings and the transcription (Whisper) are hosted on servers run by HELX Security. Audio never leaves this infrastructure.
At the AI provider chosen by the user: to produce the summary, minutes and answers, the text of the transcript is sent to the provider the user configured themselves (Anthropic for Claude, OpenAI for ChatGPT), with their own account, or processed by a model hosted by HELX. That processing is then also subject to the terms of that provider.
5. Recipients
A meeting is visible only to its owner and to the helx.io colleagues they explicitly share it with, read-only. HELX Security does not sell this data, does not use it for advertising and does not pass it on to any third party other than the AI provider chosen by the user and as required by law.
6. Retention
Meetings and their recordings are kept until the user deletes them. Deleting a meeting erases its audio, transcript and analyses. An account's data is deleted on request or when the staff member leaves.
7. Security
Traffic is encrypted in transit (HTTPS). Access is restricted to helx.io Google accounts, AI keys and tokens are encrypted at rest, and the integrity of each recording is checked (SHA-256) before it is deleted from the device.
8. Informing participants
A user who records a meeting undertakes to inform the other participants, in accordance with applicable regulations.
9. Your rights
You have the right to access, rectify, erase, object to, restrict the processing of and port your data.
To exercise these rights: through our contact form (www.helx.io/contact) or by post to HELX Security, 19 Cité Aubry, 75020 Paris, France.
If you believe your rights are not respected, you may lodge a complaint with the CNIL (www.cnil.fr).
10. Limited use (Chrome Web Store)
The Gaston extension's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Tell us about your project.
Let us talk through your needs and expectations and build the right service for you.
