HELIOSPrivacy Notice Legal

Privacy • Public website

Privacy Notice.

Effective date: 23 September 2026Last updated: 23 September 2026

1. Who publishes this notice

Mohamed Awais publishes and operates the HELIOS public website in a pre-incorporation capacity. HELIOS is the name used for the site and is not presented in this notice as an incorporated company.

For privacy questions or requests concerning the public website, email awais@heliosengine.ai.

2. Scope of this notice

This notice applies only to the current pre-launch public website. It describes verified behaviour observed on the homepage and Help page on 22 and 23 September 2026.

It does not describe customer accounts, customer environments, Business Memory, documents, connected services, integrations, AI providers, voice or telephony features, Build, Partner or any other future service as live. It also does not make claims about those services' data practices.

3. Verified homepage telemetry

On a fresh, unauthenticated visit to the homepage at /, the hosting platform was observed adding its own TCCL/Signals monitoring code to the page served to the browser. The code loaded a script through img1.wsimg.com and sent two events to csp.secureserver.net:

  1. Page view: a generated trace identifier, browser user agent, viewport and screen dimensions, host, path, full page location, referrer, page-view count, visitor identifier, session identifier, provider page-level properties and an event timestamp.
  2. Page navigation and performance: the same browsing context, together with navigation type, connection and request timings, response and document timings, page-load and download times, response sizes and a content-load classification.

The events were sent automatically during the observed initial page load. No banner, preference control or other user action preceded the observed cookie writes or event transmissions.

4. Cookies observed on the homepage

The provider-injected code created three first-party cookies during the fresh homepage visit. Each was set for .heliosengine.ai with path /.

  1. _tccl_visitor: a generated visitor identifier used as the visitorId in the observed telemetry event. Its observed duration was 365 days.
  2. _tccl_visit: a generated visit or session identifier used as the sessionId in the observed telemetry event. Its observed duration was 30 minutes.
  3. _scc_session: a value containing the session page count and last-touch timestamp. Its observed duration was 20 minutes.

These durations are browser-observed expiry periods from one clean visit. Later activity may refresh them; that was not tested.

A separate clean visit to /help showed no provider script, cookie, browser-storage write or telemetry request. That finding applies only to the observed Help-page visit and must not be generalised to every route. At the evidence date, /privacy had not yet been published, so its eventual live behaviour had not been verified.

5. Authored site code and hosting-provider code

The inspected HELIOS-authored homepage and Help-page files contained no JavaScript, cookie code, browser-storage code or telemetry requests. The monitoring code described above was added to the live homepage response by the hosting platform.

The currently authorised static-site mechanism has no verified in-scope control that disables this provider injection. The provider monitoring is therefore described here as observed current behaviour. This notice must be reviewed if later testing establishes a different live result.

6. Limits of the available evidence

The site inspection did not establish:

  • how long the provider retains received events or server logs;
  • where the provider processes or stores information;
  • the provider's legal role for this processing;
  • whether the provider links the observed identifiers or events with other account, hosting or device information;
  • any recipient beyond the directly observed script host and event endpoint; or
  • any provider-side deletion or opt-out result.

This notice does not make claims about those matters. It also does not state a lawful basis, consent status, necessity or legitimate-interest assessment for the observed telemetry.

7. Browser choices

You can use your browser settings to block or delete cookies. Blocking or deleting cookies may prevent the observed identifiers from remaining in that browser, but it does not establish that information already received by the hosting provider has been deleted.

8. Privacy questions and requests

Email awais@heliosengine.ai if you have a question about this notice or want to make a request concerning information associated with your visit to the public website. Depending on the law that applies, privacy requests may include access, correction, deletion, restriction, objection or portability.

Please describe the website visit or information concerned clearly enough for the request to be assessed. This address is a direct contact route for Mohamed Awais; it is not presented as a data protection officer or territorial representative address.

9. Changes to this notice

This notice may be revised when verified public-site behaviour changes or new evidence becomes available. The date at the top will be updated when the published notice changes.