Version: 2.0
Last Updated: July 14, 2026
Travex Inc, doing business as Helimeds ("Helimeds," "we," "us," or "our"), values your privacy and is committed to protecting the confidentiality of your personal data. This Privacy Policy explains how Helimeds collects, uses, discloses, stores, and protects personal data when individuals access or use the Helimeds website, web portal, communications channels, and related services (collectively, the "Services"). This draft is based on the attached Helimeds policy text and rewrites it to correct internal inconsistencies, simplify structure, and better align the disclosures with the data practices described in the source text.
Helimeds supports remote clinical care, patient-provider communications, prescription-related workflows, account management, payment processing, and related support services. The source policy states that the Services may include secure information collection, SMS and MMS communications between patients and providers, and electronic prescribing support.
Some information processed through the Services may constitute health data or protected health information under applicable law. The source policy states that Helimeds intends its privacy practices to comply with HIPAA and applicable state law relating to health data where applicable.
Scope
This Privacy Policy applies to personal data collected through the Services from patient users, provider users, website visitors, customer support contacts, and other individuals who interact with Helimeds in connection with the Services.
For purposes of this Privacy Policy, "personal data" means information that identifies, relates to, describes, can reasonably be associated with, or could reasonably be linked, directly or indirectly, with a particular individual. In some contexts, personal data processed through the Services may also include health data or protected health information.
If Helimeds processes personal data on behalf of an unaffiliated third party and not for its own purposes, the privacy practices of that third party may apply to that processing. The source policy contains a similar controller statement and carveout for third-party processing relationships.
Controller and Contact Information
Travex Inc, doing business as Helimeds, is the entity responsible for the personal data covered by this Privacy Policy.
For privacy questions, account requests, or requests to exercise privacy rights, contact:
Email: hi@helimeds.com
Mailing address: Travex Inc, 11134 Tampere Court, San Diego, California 92131
Phone: 1-254-566-5883
For questions specifically related to healthcare privacy or protected health information, Helimeds may also be contacted at hipaa@helimeds.com. The source policy referenced both a HIPAA contact and general support/privacy email addresses; this rewrite consolidates the primary privacy contact while preserving a dedicated HIPAA contact for healthcare privacy matters.
Please do not send sensitive medical details, payment card data, passwords, or other highly sensitive information through unsecured email.
Categories of Personal Data Collected
Depending on how an individual interacts with the Services, Helimeds may collect the following categories of personal data:
Account and Demographic Information
Name
Birth year or date of birth
Gender
Phone number
Email address
Account credentials or related account administration information
The source policy states that Helimeds collects demographic information such as name, birth year, gender, phone number, and email address in order to create accounts and provide the Services.
Payment and Billing Information
Helimeds may collect billing-related information if payments are made through the Services, including billing name, billing address, and payment-related details necessary to process transactions. The source policy refers to financial and billing information such as billing name and address, credit card number, or bank account information.
Health and Clinical Information
For patient users, Helimeds may collect information regarding health conditions, allergies, symptoms, medical history, treatment-related information, and communications with providers delivered through the Services. The source policy specifically describes collection of health conditions, allergies, medical history, symptoms, and patient-provider communications.
Support and Communications Information
If an individual contacts Helimeds for support, submits a complaint, or otherwise communicates with Helimeds, Helimeds may collect the content of those communications and related technical details. The source policy also states that calls with Helimeds may be recorded or monitored for training, quality assurance, customer service, and reference purposes.
Device, Usage, and Log Information
Helimeds may automatically collect technical data associated with use of the Services, including:
IP address
Proxy server information
Device and application identifiers
Browser type
Operating system and system configuration information
Internet service provider or mobile carrier
Pages viewed, files accessed, searches performed, and timestamps
Approximate location inferred from technical data
The source policy includes substantially these same categories in its device, telephone, and ISP disclosure.
Cookies and Similar Technologies
The source policy states that Helimeds uses cookies, web beacons, pixel tags, clear GIFs, and similar technologies, and also states that Helimeds uses Microsoft Clarity and Microsoft Advertising for behavioral metrics, heatmaps, session replay, site optimization, fraud/security purposes, and advertising.
Because the source policy also said Helimeds uses only essential cookies, but separately disclosed analytics and advertising-related technologies, this rewrite removes that contradiction. Based on the source text, Helimeds should disclose that it may use essential, analytics, and advertising-related technologies where applicable, subject to any legally required consent mechanisms.
How Helimeds Uses Personal Data
Helimeds may use personal data for the following purposes:
To create, maintain, and administer user accounts
To provide the Services and fulfill obligations under applicable terms
To support remote clinical care, patient-provider communications, and prescription-related workflows
To process payments and maintain transaction records
To authenticate users and secure access to the Services
To respond to support requests, complaints, and inquiries
To operate, maintain, troubleshoot, and improve the Services
To analyze usage trends, performance, and user experience
To protect the safety, security, rights, and property of Helimeds, users, and others
To detect, prevent, and investigate fraud, misuse, security incidents, and other harmful activity
To comply with legal obligations, court orders, and enforceable governmental requests
To enforce applicable contracts, terms, and policies
To send service-related notices and updates
To send marketing or promotional communications where permitted by law and consistent with user choices
These uses are drawn from and reorganized from the purpose statements in the source policy.
Where required by applicable law, Helimeds will obtain consent before processing personal data for a purpose that requires consent. Where consent is not required, Helimeds may process personal data as necessary to provide the Services, comply with law, protect vital interests, carry out internal business operations, or pursue other legitimate interests consistent with applicable law.
SMS, MMS, and Communications
The source policy states that the Services may include SMS and MMS communications between patients and providers. Helimeds may therefore use phone numbers and related contact information to send service-related messages, account notices, support communications, care-related communications, and other messages connected to the Services, subject to applicable law and user permissions.
Where Helimeds sends marketing messages by email or SMS, those communications should be managed in accordance with applicable consent and opt-out requirements. This rewrite removes the source policy's contradictory statement that users consent to marketing communications but are not provided an opt-out, because that language creates avoidable legal and operational risk.
Cookies, Analytics, and Advertising Technologies
Helimeds may use cookies and similar technologies to support site functionality, authentication, fraud prevention, analytics, advertising, and service improvement. The source policy expressly references cookies, web beacons, pixel tags, Microsoft Clarity, and Microsoft Advertising.
These technologies may be used to understand how users interact with the website, measure traffic and performance, improve site design and functionality, protect against fraud or abuse, and support advertising activities where permitted. The source policy specifically references behavioral metrics, heatmaps, session replay, popularity measurement, online activity analysis, site optimization, fraud/security, and advertising.
Individuals may be able to control certain cookies through browser settings or consent tools, but disabling some technologies may affect site functionality or account access. The source policy stated that disabling cookies or using do-not-track settings could prevent access to the web portal.
If Helimeds uses non-essential analytics or advertising technologies, Helimeds should provide any notices and obtain any consents required by applicable law before those technologies are activated.
Additional cookie and tracking information
For detailed information about the cookies and similar technologies used on our website (including third-party analytics and advertising tools), please see our dedicated Cookie and Tracking Technologies Policy provided by iubenda, available at https://www.iubenda.com/privacy-policy/52457944. This iubenda-hosted policy is incorporated by reference into this Privacy Policy and may be updated by iubenda as our services and technologies change
Disclosure of Personal Data
Helimeds may disclose personal data in the following circumstances:
Providers and Care-Related Participants
For patient users, Helimeds may share information with the provider user or other authorized care-related participant connected to the patient through the Services where necessary to deliver care, communicate, monitor progress, or otherwise provide the Services. The source policy expressly states that patient information may be shared with the provider user connected through the Services.
Service Providers
Helimeds may share personal data with vendors, contractors, and other service providers that perform services on its behalf, such as hosting, IT support, customer service, analytics, communications, security, and payment processing. The source policy refers to these recipients as business partners and states they are contractually bound to protect personal data and use it only for limited purposes.
Legal Compliance and Protection
Helimeds may disclose personal data when reasonably necessary to comply with law, respond to legal process, cooperate with investigations, protect Helimeds or others, enforce agreements, or pursue available remedies. This is a direct reorganization of the legal and enforcement disclosures in the source policy.
Professional Advisors and Corporate Transactions
Helimeds may disclose personal data to lawyers, auditors, accountants, banks, investors, and other professional advisors where necessary for legitimate business purposes, and in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction. The source policy contains both advisory-services and corporate-transaction disclosures.
Additional Disclosures
If Helimeds intends to disclose personal data in a materially different way than described in this Privacy Policy, Helimeds will provide any notice and choices required by applicable law.
Data Retention
Helimeds retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, and protect Helimeds and its users.
The source policy states that Helimeds may retain personal data for as long as an account remains active and for up to five years after account closure or service termination, depending on the type of personal data, contractual obligations, and applicable law, and that anonymized data may be retained indefinitely.
If Helimeds cannot fully delete information from backups or archival systems for technical reasons, Helimeds may retain the data in a protected form and restrict further use until deletion becomes possible. The source policy includes a similar technical limitation disclosure.
Because health and prescribing-related records may be subject to legal or regulatory retention requirements, actual retention periods may vary by data type, role, jurisdiction, and record category.
International and U.S. Processing Location
The source policy states that personal data collected through the Services is stored on secure servers in the United States and may also be processed by service providers acting on Helimeds' behalf.
Where personal data is transferred to service providers or other recipients, Helimeds will take steps appropriate to the nature of the data and applicable law. The source text states that third parties storing data on Helimeds' behalf are not permitted to transfer personal data outside the United States.
Security
Helimeds states in the source policy that it uses a combination of physical, technical, and administrative safeguards designed to protect personal data, including authentication, encryption, backups, and access controls.
No internet or electronic transmission method is completely secure, and no security program can guarantee absolute security. The source policy makes this point repeatedly and places users on notice that transmission risk cannot be eliminated entirely.
Users are also responsible for maintaining the security of their own devices, login credentials, and local storage environments. The source policy emphasizes that Helimeds cannot control device-level security settings and recommends password protection, encryption, and remote wipe capability where appropriate.
If Helimeds becomes aware of a security incident affecting personal data, Helimeds may provide notice in accordance with applicable law and the contact information available to it. The source policy states that Helimeds may attempt to notify affected individuals by email or phone and that written notice may be required in some jurisdictions.
Individual Rights and Choices
Depending on applicable law and the individual's location, individuals may have rights to:
Access personal data
Correct inaccurate personal data
Delete personal data
Restrict or object to certain processing
Receive a copy of personal data in a portable format where feasible
Withdraw consent where processing is based on consent
Object to certain marketing activities
Lodge a complaint with a supervisory authority or regulator
Request review of certain automated decision-making where applicable
The source policy lists these same general categories of rights.
To exercise a privacy right, submit a request to hi@helimeds.com. Helimeds may need to verify identity before responding, and some rights may be limited by law, technical feasibility, patient safety considerations, recordkeeping obligations, healthcare regulations, contractual requirements, or other permitted exceptions.
Helimeds may update contact details and certain account information upon request. The source policy states that users may contact Helimeds to change email addresses and other contact information, and that provider users may also manage certain account settings through the web portal dashboard.
Marketing Communications
Helimeds may send service-related emails, texts, or other communications necessary to provide the Services, administer accounts, support care delivery, or communicate about operational matters.
Where Helimeds sends marketing communications, individuals may opt out using the unsubscribe method provided in the communication or by contacting hi@helimeds.com, except where a communication is strictly transactional or otherwise exempt from opt-out requirements under applicable law. This revision replaces the source policy's statement that users consent to marketing communications but are not offered an opt-out.
Children's Privacy
The source policy states that Helimeds does not knowingly collect personal data from individuals under the age of 18 and that the Services are not directed to individuals under the age of 13.
To remove the age-related inconsistency, this rewrite states the policy in clearer form: the Services are intended only for individuals who are legally permitted to use them under applicable law, and Helimeds does not knowingly collect personal data from children in violation of applicable law. If Helimeds learns that it collected personal data from a child contrary to applicable law or its policies, Helimeds may deactivate the account and take reasonable steps to delete the information.
If a parent, guardian, or other person believes that a child has provided personal data to Helimeds improperly, they should contact hi@helimeds.com.
California Privacy Disclosures
The source policy states that California residents may request certain information about disclosures of personal data for direct marketing purposes and may submit such requests by email with "California Privacy Rights" in the subject line.
California residents may also have additional rights under California privacy law, depending on Helimeds' processing activities and legal status under those laws. Helimeds should supplement this section with any California-specific notices that are required based on its actual data practices, HIPAA exemptions, and business classification.
Policy Changes
Helimeds may update this Privacy Policy from time to time. When material changes are made, Helimeds may post the updated policy through the website or web portal and may also provide additional notice where required by law. The source policy states that Helimeds may post modified terms and also notify users by email.
The "Last Updated" date at the top of this Privacy Policy indicates when this version was last revised. This rewrite removes the conflicting effective-date language present in the source text and uses a single visible update date instead.
Complaints
Individuals who believe their privacy rights have been violated may contact Helimeds at hi@helimeds.com or, where applicable, may contact the U.S. Department of Health and Human Services or another appropriate regulator. The source policy included both an internal complaints contact and the U.S. Department of Health and Human Services contact reference.
Travex Inc
11134 Tampere Court, San Diego, California, 92131
1-254-566-5883
helimeds.com
hi@helimeds.com
U.S Department of Health and Human Services
200 Independence Avenue, S.W.
Washington, D.C. 20201
1-877-696-6775