This privacy policy explains how we collect, use, and protect your personal information. We are committed to transparency and to protecting your data.
Last updated: December 28, 2025
How we handle your data
This privacy policy explains how we collect, use, and protect your personal information. We are committed to transparency and to protecting your data.
Last updated: December 28, 2025
The entity responsible for processing your personal data is:
Heimlane SAS, a simplified joint stock company registered with the Paris Trade and Companies Register under number 994 567 683
1 rue de Stockholm, 75008 Paris, France
Email: privacy@heimlane.com
We do not have a Data Protection Officer (DPO) as it is not required given the nature and scale of our data processing activities.
Our products and services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can delete it.
We use Matomo Analytics in cookieless mode for website analytics. No tracking cookies are set on your device. Matomo is self-hosted in Europe/France on our own infrastructure , your data never leaves the EU or reaches third parties.
We only process personal data when we have a valid legal basis under GDPR Article 6. The table below shows which legal basis applies to each type of processing:
Newsletter subscription, marketing communications, optional cookies. You can withdraw consent at any time.
Account creation, service delivery, authentication, payment processing, customer support for subscribed services.
Service improvement based on usage patterns, security monitoring, fraud prevention. We balance our interests against your rights.
Tax and accounting records retention, responding to lawful requests from authorities, compliance with applicable regulations.
Each Heimlane product may have specific processing or privacy considerations. Click on the corresponding product below for details.
Heimlane Vault uses end-to-end encryption with AES-256. Your data is encrypted on your device before being sent to our servers. We cannot access your passwords, notes, or stored data , only you hold the decryption key.
You can delete your Vault account and all associated data at any time directly from within the product. Upon deletion, all your encrypted vault data is permanently removed from our servers. Any other data is retained in accordance with our retention period.
Our mobile apps may request certain permissions:
Processing details for Heimlane Prism will be added as this product becomes available.
Processing details for Heimlane Realm will be added as this product becomes available.
Processing details for Heimlane Scout will be added as this product becomes available.
We do not sell your personal data. We may share your information with:
Heimlane strives to store and process all personal data within the European Union and requires its hosting providers to host personal data on EU territory.
However, we cannot guarantee that personal data will never be transferred outside the European Union, particularly for:
When transfers outside the EU are necessary, we ensure appropriate protection through:
We use carefully selected third-party service providers to help operate our services. These sub-processors only access data necessary for their specific function and are contractually bound to protect your data:
We make our best efforts to ensure a level of personal data protection that is sufficient and compliant with applicable regulations.
We implement appropriate technical and organizational measures to protect your personal data:
AES-256 encryption for data at rest, TLS 1.3 for data in transit
Strict access controls, principle of least privilege
EU-based data centers with ISO 27001 certification
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
Under the General Data Protection Regulation, you have the following rights:
Obtain confirmation and a copy of your personal data
Correct inaccurate or incomplete data
Request deletion of your data (right to be forgotten)
Limit how we process your data
Receive your data in a structured, machine-readable format
Object to processing based on legitimate interests
Withdraw your consent at any time
To exercise these rights, contact us at: privacy@heimlane.com
Or by post at: Heimlane SAS, 1 rue de Stockholm, 75008 Paris, France
We will respond to your request within one month of receipt, as required by GDPR. This period may be extended by two additional months for complex requests, in which case we will inform you.
We may ask you to verify your identity before processing your request to protect your data.
If you have concerns about our processing of your personal data, you have the right to lodge a complaint with:
CNIL (Commission Nationale de l'Informatique et des Libertés)
3 Place de Fontenoy
TSA 80715
75334 Paris Cedex 07
France
Phone: +33 1 53 73 22 22
Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies before providing any personal information.
We may update this privacy policy periodically. Changes will be posted on this page with an updated "last updated" date.
For any questions about this privacy policy or our data practices:
privacy@heimlane.comHeimlane SAS, 1 rue de Stockholm, 75008 Paris, France
Read our Terms of Service to understand the conditions for using Heimlane products.
Read our Terms of Service