Privacy Policy

Last updated: 2026-07-28 (Trustpilot review-invitation disclosure)

Who we are

This site is operated by Heathen Engineering Limited (“Heathen,” “we,” “us”), an Irish registered company (company number 556277, VAT IE3394133CH). For any question about this policy or your data, contact us at support@heathen.group.

What personal data we collect

Account and access data, when you purchase access to our software products:

  • Your name and email address.
  • A login identity with Authentik, our self-hosted identity provider (your email and a password you set there) — this is what you actually log in with. A WordPress account is created automatically alongside it to track your access, but it has no separate password of its own.
  • Subscription/access status (whether you have an active subscription or time-limited access, and its expiry date) — no itemized purchase history is stored on this site (see “Payment data” below for where that actually lives).
  • A reference linking your account to your Creem customer profile, used only so you can manage your own billing/subscription (see “Self-service billing” below).
  • A separate account on our source-code server (Forgejo), created automatically and linked to your Authentik login — there is no separate Forgejo password; you sign in there with the same identity. A personal access token (used for git/package-manager access, not a password) is generated for you automatically and can be regenerated at any time from your account page.

Payment data: we do not process or store your card details or full payment history ourselves. Payments are handled by Creem, who acts as the merchant of record for these transactions — Creem, not Heathen, is the seller for tax and payment-processing purposes. Creem’s own privacy policy governs how they handle your payment details: https://www.creem.io/privacy.

Technical data: standard web server logs (IP address, browser type) and the cookies described below.

Why we collect it, and our legal basis

Performance of a contract

Art. 6(1)(b) GDPR — we can’t provide the service you paid for without this.

  • Creating and managing your account, granting/revoking access to purchased software.
  • Processing your payment (via Creem).
  • Responding to support requests you send us.

Legitimate interests

Art. 6(1)(f) GDPR.

  • Preventing fraud or abuse of our access system.
  • Responding to support requests you send us (dual basis with the above).
  • Inviting you to leave a review of your purchase via Trustpilot, once, after a completed purchase (see “Who we share it with” below).

We do not use your data for marketing without your separate, explicit consent, and we do not sell your personal data to anyone.

Who we share it with

  • Creem (payment processing, merchant of record for these transactions).
  • Infomaniak (Switzerland — covered by an EU adequacy decision), our infrastructure provider, hosting this website, our source-code server, and Authentik (our self-hosted identity/login system) — all on the same infrastructure, no additional third party involved in handling your login credentials.
  • Trustpilot — your email address is shared with Trustpilot after a completed purchase, so they can invite you to leave a review. We don’t send this ourselves as a separate step; it’s a BCC on the purchase confirmation email we already send you. Trustpilot’s own privacy policy governs how they handle it from there: https://corporate.trustpilot.com/legal/for-reviewers/privacy-policy-end-user/jun-2026. Any review invitation you receive from Trustpilot includes their own unsubscribe/opt-out option.
  • We do not share your data with any other third party, and never sell it.

How long we keep it

When your paid access ends (subscription cancelled/expired with no remaining paid time), your live source-code repository access is removed immediately, but your account itself is not deleted. We keep it, along with the date your access ended, specifically so you can still request a courtesy download of whichever version of each product you had access to as of that date — this courtesy is not a purchased entitlement and may be withdrawn without notice, but for as long as it’s offered, it’s the reason this data continues to serve a real purpose for you rather than sitting idle.

You can delete your account yourself at any time, immediately and completely, from your account page — this removes your WordPress account, your Forgejo account, your Authentik login identity, and your courtesy archive-access eligibility together, in one action, and cannot be undone. We do not delete a lapsed account on any fixed timer. We retain it for as long as it continues to serve this purpose for you: until you choose to delete it yourself, or until the underlying archives themselves are no longer available (for example, if this service were ever discontinued).

This does not affect payment/transaction records Creem or our own accounting hold separately, or extend to a specific legal record-keeping obligation — see “Legal record-keeping” below.

Legal record-keeping

Separately from the account data above, transaction-related records may be retained by Creem (as merchant of record) and in our own accounting records, for as long as Irish/EU tax law requires (currently six years from the date of the transaction under Irish statutory requirements). This is a narrower, separate obligation from the account/service data described above, which follows the retention approach described in “How long we keep it” above, not a fixed deletion timer.

Self-service billing

If you have a subscription, you can view or cancel it yourself at any time, via a secure billing-management link we generate through Creem from your account page. We never see or store your card details ourselves — Creem handles this directly, per its own privacy policy linked above.

Cookies

  • Session and authentication cookies, so you can log in and stay logged in to your account.
  • An engine/version preference cookie, on our documentation pages — remembers which game engine (Unity, Unreal, Godot, O3DE) and version you’re viewing documentation for, so the site can automatically show you the right version of the content. A technical display preference, not tracking.
  • Google Analytics, via the Site Kit plugin (confirmed active 2026-07-21) — helps us understand how visitors use this site (pages viewed, general traffic patterns). This one is genuinely an analytics cookie, not just a technical necessity, and is covered by Google’s own privacy policy: https://policies.google.com/privacy.

We do not use Google Ads, Tag Manager, AdSense, or any other Google Site Kit advertising integration — confirmed not connected as of 2026-07-21 (only Analytics, Search Console, and PageSpeed Insights are; the latter two don’t set visitor-facing cookies).

Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Erasure (“right to be forgotten”) — you can do this yourself immediately, at any time, from your account page (see “How long we keep it” above). There is no automatic deletion timer once your access lapses, so exercising this right yourself is the only way it happens at that point.
  • Restrict or object to certain processing.
  • Data portability — receive your data in a portable format.
  • Complain to the Irish Data Protection Commission (dataprotection.ie) if you believe we’ve mishandled your data.

To exercise any of these rights, contact support@heathen.group.

Children’s privacy

Our products and services are intended for businesses and professional developers, not children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy as our systems or legal obligations change. Material changes will be reflected here with an updated “Last updated” date.