HalixSolutions
Book a call

Legal / Privacy

Privacy Policy

Last updated: July 9, 2026

We build custom automation systems, so we take data seriously — it’s the raw material of everything we ship. This policy explains what we collect, why, and what we’ll never do with it. No legalese wall; each section opens in plain words.

Who we are

Halix Solutions (“Halix”, “we”, “us”) builds custom AI-powered back-office systems for marketing agencies. This policy covers three places your data can live:

  • This website (halixsolutions.com) — the marketing site you’re reading now.
  • The Halix platform (app.halixsolutions.com and client subdomains) — where clients sign in and use their systems.
  • Client systems — the custom automations we build and run for each client.

Halix Solutions is based in Ontario, Canada. Some of the providers we build on (listed below) operate in the United States, so data handled through the website and platform may be stored or processed there and be subject to that jurisdiction’s laws.

Questions about any of it: hello@halixsolutions.com.

What this website collects

In plain words: almost nothing. No ad trackers, no analytics cookies, no forms that feed a CRM. If you book a call or email us, we get what you send — that’s it.

The website has no sign-up forms and sets no advertising or analytics cookies. We receive personal information from it in only three ways:

  • Booking a call. Scheduling runs on Cal.com, including the booking widget embedded on this site. When you book, Cal.com collects your name, email address, and anything you type into the booking form, and shares it with us so we can hold the call. The embedded widget may set functional (non-advertising) cookies from Cal.com to make scheduling work. Cal.com’s own privacy policy also applies to that data.
  • Emailing us. If you write to hello@halixsolutions.com, we keep the correspondence.
  • Hosting logs. Our hosting provider (Vercel) keeps technical logs — IP address, browser type, pages requested — for security and to keep the site running. We don’t use these to identify or profile visitors.

Signing in: magic links, no passwords

In plain words: we never see or store a password, because there are none. You give us your email once; signing in is a one-time link we send you.

The Halix platform uses passwordless authentication. To sign in, you enter your email address and we send you a single-use sign-in link (“magic link”). For this to work we store:

  • Your email address, as your account identifier.
  • Short-lived sign-in tokens, which expire quickly and can only be used once.
  • A session cookie after you sign in, so you stay signed in. This is a strictly necessary cookie — it does no tracking.
  • Basic security records (sign-in times, IP address) to detect unauthorized access attempts.

Magic links arrive by email, so anyone with access to your inbox could use them. Keep your inbox secure, and tell us immediately if you think someone accessed your account.

Client systems & custom automations

In plain words: every system we build is different, so there’s no single honest answer to “what data does Halix process?” The honest answer lives inside each client’s own workspace: a Data & Integrations page listing exactly what that system reads, writes, and connects to.

Halix builds each client a custom automation system — lead generation, lead scoring, outbound, reporting, and similar back-office work. What data a system touches depends entirely on what that client asked us to build. One client’s system might process scraped business leads and ad-platform metrics; another’s might read calendars and draft follow-up emails.

Because of that, we work on a simple split of responsibility:

  • The client owns and controls their data. For data flowing through a client’s system, the client decides what is collected and why. Halix processes it only on the client’s instructions, to run the system they commissioned — we act as a service provider (a “processor” in GDPR terms).
  • Every workspace documents itself. Each deployed system includes a Data & Integrations page inside the client’s workspace listing the data sources it reads, what it stores, which third-party services it connects to, and how long data is kept. When we change a system, that page changes with it.
  • We never repurpose client data. We don’t sell it, don’t use one client’s data for another client, and don’t train AI models on it. The AI providers our systems call are used under business API terms that don’t allow them to train on your data either.
  • Engagements come with the paperwork. A data processing agreement forms part of every client engagement. And if a data breach ever affects your data, we’ll tell you promptly — with what we know — so you can meet your own notification duties.

If you’re not a Halix client but believe your information appears in a system we run — for example, your business was contacted by an agency using one of our outbound systems — the agency’s own privacy policy governs that use. You can contact them directly, or write to us at hello@halixsolutions.com and we’ll help route your request to the right place.

Third-party services we rely on

We use a small set of service providers to run the website and platform:

  • Vercel — hosting for this website and the platform.
  • Cal.com — call scheduling.
  • Email delivery — a transactional email service that sends magic links and service emails.
  • AI model providers — the language-model APIs our systems call to score, draft, and summarize. Used under business API terms with no training on your data.

Client systems additionally connect to whatever services that client authorized — for example a CRM, ad platform, calendar, spreadsheet, or messaging tool. Those connections exist only with the client’s permission and are listed on the client’s Data & Integrations page. Each connected service handles data under its own privacy policy.

How long we keep data

  • Booking and email correspondence: kept while we’re talking or working together, deleted on request.
  • Platform accounts: kept while the account is active. Sign-in tokens are single-use and short-lived.
  • Client system data: kept per the client’s instructions. When an engagement ends, the client’s data stays available for export for 30 days; after that we delete it, except where law requires us to keep specific records.

Security

Data moves over encrypted connections (TLS). Access to client systems is scoped per client — each workspace runs on its own credentials, kept isolated from every other workspace. Sign-in links are single-use and short-lived. Internally, only the people building or maintaining a system can access it.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal information we hold about you, and to object to certain processing. Email hello@halixsolutions.com and we’ll respond within 30 days. If the data sits inside a client’s system, we’ll coordinate with that client, since they control it.

Children

Our website and services are for businesses and are not directed to anyone under 16. We don’t knowingly collect data from children.

Changes to this policy

When we change this policy we’ll update the date at the top. For meaningful changes affecting platform users, we’ll also notify clients by email.

Contact for anything on this page: hello@halixsolutions.com · See also our Terms of Service.

HalixSolutions

  • hello@halixsolutions.com
  • Privacy Policy
  • Terms of Service

© 2026 Halix Solutions · The creative stays human.