heapforge.com Privacy Policy

Last updated: 4 September 2026

This policy explains what personal data Heapforge Ltd. handles in connection with the heapforge.com website, why we handle it, and what rights you have over it.

The Heapforge Reader and Heapforge Journal apps are covered by separate privacy policies: Reader, Journal.

In short

heapforge.com is a static website. It sets no cookies, runs no analytics, embeds no tracking pixels or advertising, and has no user accounts. There is nothing to consent to, which is why you will not see a cookie banner.

The only personal data that reaches us is what our hosting provider records automatically to serve and protect the site, plus whatever you choose to send us by email or post.

Who we are

Heapforge Ltd. is the data controller for the processing described in this policy.

We process personal data in accordance with the UK GDPR and the Data Protection Act 2018, and, where it applies to our activities, the EU General Data Protection Regulation (Regulation (EU) 2016/679).

What we collect, why, and for how long

Hosting and security logs

heapforge.com is hosted on Cloudflare Pages. To deliver the site and to protect it from abuse, Cloudflare automatically records technical request data on our behalf.

Email correspondence

If you write to us — for example to contact@heapforge.com or privacy@heapforge.com — we receive and keep your message.

Postal mail

If you write to our registered address, we receive whatever you send.

Cookies and similar technologies

We set no cookies and use no local storage, session storage, fingerprinting or similar tracking technologies on heapforge.com. The site loads a web font from Google Fonts; when it does, your browser makes a request to Google’s servers, which will see your IP address and user agent as part of serving that font file. No cookie is set by that request.

Who your data is shared with

We do not sell personal data, and we do not share it for advertising or profiling. Personal data is handled on our behalf by the following processors, each under a written data processing agreement:

We may also disclose personal data where we are required to do so by law, or where it is necessary to establish, exercise or defend legal claims.

International transfers

Our providers may process data outside the UK and the EEA, including in the United States. Where that happens, the transfer is covered by appropriate safeguards under Article 46 — the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses — and, where applicable, by the providers’ certification under the EU–US and UK–US Data Privacy Framework.

Your rights

Under the UK GDPR and the EU GDPR you have the right to:

We carry out no automated decision-making or profiling that produces legal or similarly significant effects.

To exercise any of these rights, email privacy@heapforge.com or write to the registered address above. We will respond within one month. That period can be extended by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why. Exercising these rights is free; we may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive.

We may ask for enough information to satisfy ourselves of your identity before acting on a request.

Complaints

If you think we have handled your personal data improperly, please tell us first so we can put it right.

You also have the right to complain to a supervisory authority:

Children

heapforge.com is a company website intended for a general adult audience. It is not directed at children, and we do not knowingly collect personal data from them.

Changes to this policy

If we change how we handle personal data, we will publish an updated version of this policy at this address and change the “last updated” date at the top. Material changes will be summarised here so that you can see what changed.

← Back to Legal & Privacy