Legal
Privacy Policy
Version 1.0. Effective September 8, 2026.
This policy explains how Heplon UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany ("Heplon", "we", "us", "our") handles personal data for which it is the controller, such as data about visitors to heplon.com and data about the people who hold or administer a Heplon account, including their name, email, and how they use the platform. Full provider details are in our legal notice.
Whether this policy covers personal data that sits inside the systems you connect to the Heplon platform, such as names appearing in source code or logs, depends on the roles the GDPR assigns for the relevant processing. In business use, you may act as a controller or as a processor for someone else. Those roles depend on who determines the purposes and essential means of the processing, not merely on whether the use is commercial.
Where you act as a controller, we process that data on your instructions as a processor. Where you act as a processor for another controller, we process it as your sub-processor. In both cases that processing is governed by our Data Processing Agreement rather than by this policy. You are responsible for ensuring that the relevant controller authorises the processing and provides the information required by data protection law to the individuals concerned.
Where you use the platform purely for your own personal or household purposes, the GDPR does not treat you as a controller, so there is nothing you process that we could process on your behalf and no data processing agreement applies. We are then the controller of that data, we remain fully bound by the GDPR in respect of it, and this policy covers it. The purposes and legal bases are in section 2.
1. Data we collect
Information you provide
- Account information: Email address, name, and, where applicable, company name and invite code, when you sign up or request early access.
- Authentication data: Credentials and sign-in metadata used to secure access to your account.
- Communications: Messages you send us via email or through the platform.
Information collected automatically
- Usage data: Pages visited, features used, and interaction patterns.
- Device data: Browser type, operating system, and IP address.
Information from the systems you connect
- Platform output and telemetry: What the platform produces when it works on your systems, and the material needed to judge it, such as findings, proposed fixes, the surrounding code and configuration they relate to, and telemetry about how the platform ran. These may contain personal data that happens to appear in your code, configuration, or logs.
2. How we use your data
We use your personal data for the purposes below, each with its legal basis under Art. 6 GDPR:
- To provide and maintain our service and manage your account (performance of a contract, Art. 6(1)(b) GDPR).
- To communicate with you about your account or our services (performance of a contract, Art. 6(1)(b), and our legitimate interest in supporting and informing our users, Art. 6(1)(f) GDPR).
- To improve and secure our service and develop new features (our legitimate interest in improving and securing the service, Art. 6(1)(f) GDPR).
- To check that the platform works as intended, which includes review by a limited number of our authorised staff of samples of what the platform produces and the material needed to judge it, such as findings, proposed fixes, the surrounding code and configuration they relate to, and telemetry (our legitimate interest in verifying that our platform works correctly, Art. 6(1)(f) GDPR). We do not use this data to train or fine-tune any machine learning model, and we retain no copy of it for product development.
- To comply with legal obligations (Art. 6(1)(c) GDPR).
3. Data sharing
We do not sell your personal data. We may share data with:
- Service providers who assist in operating our platform (hosting, analytics, email delivery), bound by data processing agreements.
- Legal authorities when required by law or to protect our rights.
Where a service provider processes personal data outside the EU or EEA, we rely on an adequacy decision or the EU Standard Contractual Clauses, and you can obtain a copy of the safeguards by contacting us.
4. Data retention
We retain personal data covered by this policy for as long as your account is active or as needed to provide our services. Customer Personal Data follows the separate return and deletion rules in our Data Processing Agreement.
Your account can also end for the reasons set out in our terms of service. We may close your free self-serve account, whether or not it has been inactive, on 30 days notice to you in writing. We may suspend or end access with immediate effect where there is a security risk, unlawful use, or a serious breach of those terms, for good cause, or for a material breach that is not remedied within 30 days. Your rights as a consumer are unaffected.
When access ends, you can ask us to export your data before or within 30 days, and we will provide it in a reasonable machine-readable format. We delete Customer Data and personal data that is no longer needed from active systems within 30 days after access ends. If you ask for immediate deletion instead of an export, we begin deletion without waiting for the export period to end. Backup copies are deleted as they expire, within a further 35 days. Access and security logs follow their separate 90-day retention period.
Where EU or Member State law requires us to keep particular records, such as commercial or tax records, we retain only the records required for the applicable period and use them only for that retention purpose.
You may request deletion of your data at any time by contacting us or by using the "Close account" function under Settings and Account in the application. If you are a consumer, you may also withdraw from your contract within 14 days using the separate "Withdraw from contract" function in the same place; see our withdrawal policy.
5. Your rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access, correct, or delete your personal data.
- Object to or restrict processing of your data.
- Data portability: receive your data in a structured, machine-readable format.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority.
Your right to object. Where we process your personal data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), which includes the review of platform output described in section 2, you have the right to object to that processing at any time on grounds relating to your particular situation (Art. 21 GDPR). If you object, we will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. To object, write to hello@heplon.com.
6. Cookies
We use the following types of cookies:
- Essential cookies: Required for the operation of our website. These cannot be disabled.
- Analytics cookies: We use Google Analytics to understand how visitors use our site. These cookies (such as
_gaand_ga_*) collect data about pages visited and interactions. Analytics cookies are only set after you give your consent. See section 7 for what happens before you make a choice. - Embedded video: If you click play on the YouTube video embedded on our site, YouTube may set cookies or use similar local-storage technologies in your browser. No such cookies are set until you click play. See section 8 for details.
You can accept or decline analytics cookies when you first visit the site, and change your preference at any time via the "Cookie settings" link in the footer. If you decline, no analytics cookies are stored on your device and no analytics data that could identify you is collected. Declining does not prevent the initial contact with Google's servers described in section 7.
7. Google Analytics
Google Analytics is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), with its parent Google LLC located in the United States. We operate it in Google's consent mode.
Before you make a choice. The Google Analytics script is loaded from Google's servers (googletagmanager.com) when the page loads, which transmits your IP address, browser information, and the referring URL to Google. Until you accept, the script is set to store nothing on your device and to send only cookieless measurement signals: a record that a page was viewed, without any identifier that would let Google or us recognise you across pages or visits. Google uses those signals to estimate aggregate traffic. We do not receive any information about you individually from them.
After you accept. The cookies named in section 6 are set, and your visit is measured in the ordinary way, including pages visited, interactions, approximate location derived from your IP address, and device and browser information.
Legal basis. Your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG) for the cookies and for the measurement carried out after you accept. Our legitimate interest in understanding aggregate traffic to our website and in operating it (Art. 6(1)(f) GDPR) for loading the script and for the cookieless signals sent before a choice is made. You can object to that processing at any time; see section 5.
Google may transfer data to servers in the United States. Such transfers take place on the basis of the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework and, where applicable, Standard Contractual Clauses. Further information is available in Google's privacy policy at policies.google.com/privacy.
8. Embedded content (YouTube)
Our website embeds a video hosted on YouTube, a service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), with its parent Google LLC located in the United States.
To minimise data sharing, we use YouTube's privacy-enhanced mode (youtube-nocookie.com) and a click-to-play mechanism: no YouTube iframe is loaded and no connection to Google's video servers is established until you actively click the play button. When you click play, your IP address, browser information, and referring URL are transmitted to Google, and YouTube may set cookies or use similar local-storage technologies in your browser. The video preview image is loaded from Google's servers (img.youtube.com) when the page loads, which also transmits your IP address to Google.
Because Google may transfer data to servers in the United States, such transfers take place on the basis of the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework and, where applicable, Standard Contractual Clauses.
Legal basis: our legitimate interest in presenting product information in video form (Art. 6(1)(f) GDPR) for the thumbnail preview, and your consent (Art. 6(1)(a) GDPR) for playback, given by clicking the play button. You can object to the processing or withdraw consent at any time; if you do not click play, no iframe is loaded.
Further information is available in Google's privacy policy at policies.google.com/privacy.
9. Security
We implement industry-standard security measures to protect your data, including encryption in transit and at rest.
10. Changes to this policy
We may update this policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the effective date.
11. Contact
If you have questions about this privacy policy or your data, contact us at hello@heplon.com.