Privacy Policy
Last updated: 19 September 2026
This policy explains how personal data is handled when you visit madladsquad.com (including
the documentation under /docs and the interactive demo at uimgui.madladsquad.com, together “the website”) or
contact us about it. It is written to meet the requirements of the UK General Data Protection Regulation (“UK GDPR”),
the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”) and the EU General
Data Protection Regulation (EU) 2016/679 (“EU GDPR”).
In short
- The website is a static site. It has no accounts, forms, comments, analytics, advertising, tracking pixels or social media widgets.
- We do not set cookies and do not store anything in your browser.
- Fonts, scripts, emoji and images are served from our own domain. Your browser does not contact Google, jsDelivr, cdnjs or any other third party to display a page.
- The only personal data processed when you browse is the technical connection data that any web server needs to deliver a page, handled by our hosting providers.
- If you email us, we use your email to reply to you.
1. Who we are
The data controller for the website is:
Heapforge Ltd., a company registered in England and Wales with company number 17418393
Registered address: 82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
Email for privacy matters: privacy@madladsquad.com
MadLadSquad is the open-source project published through this website. In this policy, “we”, “us” and “our” mean Heapforge Ltd.
We have not appointed a Data Protection Officer because we are not required to. Please send any privacy question or request to privacy@madladsquad.com.
2. What we process, why, and on what legal basis
2.1 Visiting the website
When your browser requests a page, it necessarily sends technical information to the servers that deliver it. This consists of:
- your IP address;
- the date and time of the request;
- the address of the page or file requested, and the HTTP method, status and amount of data transferred;
- the referring page, if your browser sends one;
- your browser’s user-agent string (browser type and version, operating system).
The website is hosted on GitHub Pages (GitHub, Inc.) and delivered through Cloudflare (Cloudflare, Inc.), which provides the domain’s DNS, TLS encryption, caching and protection against attacks. Both receive this data when you visit.
- Purpose: to deliver the pages you request, and to keep the website secure and available, for example by detecting and blocking denial-of-service attacks and other abuse.
- Legal basis: our legitimate interests (Article 6(1)(f) UK GDPR and EU GDPR) in operating a website that works and is secure. We consider this data is the minimum needed to serve a web page, it is not used to identify or profile you, and you would reasonably expect it to be processed when visiting a website, so these interests are not overridden by your rights and freedoms.
- We do not use this data for analytics, marketing or profiling, and we do not combine it with other data.
Cloudflare may also ask your browser to report network errors (such as a failed connection) to Cloudflare using the browser’s Network Error Logging feature. These reports contain technical details of the failed request, including your IP address, and are used only to monitor and fix delivery problems, on the same legitimate interests basis.
2.2 Interactive demo
Some pages (for example /desktop) embed an interactive demo of our software from uimgui.madladsquad.com.
It is our own static site, hosted and delivered in the same way as described in section 2.1, and it processes the same
technical connection data for the same purposes and on the same legal basis. It does not set cookies or collect any
other data.
2.3 Contacting us
If you email us, we process your email address, your name if you give it, the content of your message and any attachments, and the replies we exchange.
- Purpose: to read and answer your message and deal with what you ask.
- Legal basis: our legitimate interests (Article 6(1)(f)) in responding to people who contact us. Where your message relates to a contract with you, or steps you have asked us to take before entering into one, the basis is Article 6(1)(b).
2.4 Privacy requests
If you exercise any of your rights under section 7, we process the information needed to identify you, handle the request and keep a record of how we dealt with it.
- Legal basis: compliance with our legal obligations under data protection law (Article 6(1)(c)), and our legitimate interests in being able to show that we handled your request properly (Article 6(1)(f)).
2.5 What we do not do
We do not sell or rent personal data, share it for advertising, or use it for automated decision-making or profiling that produces legal or similarly significant effects on you (Article 22). We do not collect special category data and the website is not directed at children.
You are not required to provide any personal data to use the website. Connection data is needed for your browser to receive the pages at all. Emailing us is optional, but we cannot reply without your email address.
3. Cookies and similar technologies
The website does not set cookies and does not use localStorage, sessionStorage, IndexedDB, fingerprinting or any
other technology to store or read information on your device. There is no cookie banner because none is needed.
If Cloudflare detects traffic from your connection that looks automated or malicious, it may set a short-lived security
cookie (such as __cf_bm or cf_clearance) to tell legitimate visitors apart from bots. Such cookies are used only to
protect the website, are strictly necessary for that purpose, and are therefore exempt from the consent requirement
under regulation 6(4) of PECR and Article 5(3) of the ePrivacy Directive (2002/58/EC). They are not used to track you.
4. Who receives your data
We share personal data only with:
- GitHub, Inc. (hosting of the website and the demo);
- Cloudflare, Inc. (DNS, content delivery and security);
- our email service provider, which stores and delivers email sent to and from our addresses;
- professional advisers, courts, regulators or law enforcement, where we are legally required to or where it is needed to establish, exercise or defend legal claims.
GitHub and Cloudflare act as our service providers when delivering the website. For some processing, such as their own security monitoring and service improvement, they act as independent controllers and their own privacy statements apply: GitHub General Privacy Statement and Cloudflare Privacy Policy.
5. International transfers
GitHub and Cloudflare are based in the United States and operate servers worldwide, so connection data may be processed outside the UK and the European Economic Area.
- For transfers from the UK, we rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”) for recipients certified under it, and otherwise on the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner.
- For transfers from the EEA, we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework for certified recipients, and otherwise on the Standard Contractual Clauses adopted by the European Commission (Article 46(2)(c) EU GDPR).
- Transfers from the EEA to us in the UK are covered by the European Commission’s adequacy decision for the United Kingdom.
You can ask us for more information about these safeguards using the contact details in section 1.
6. How long we keep data
| Data | How long |
|---|---|
| Connection data and network error reports (section 2.1, 2.2) | We do not keep our own copies. GitHub and Cloudflare keep their logs for the limited periods set out in their privacy statements, for security and operational purposes. |
| Email correspondence (section 2.3) | For as long as needed to deal with your message and any follow-up, after which we delete it unless we need it to comply with a legal obligation or to establish, exercise or defend legal claims. |
| Records of privacy requests (section 2.4) | For as long as needed to show how we handled the request, and no longer than the limitation period for any related claim. |
7. Your rights
Under the UK GDPR and the EU GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Article 15);
- have inaccurate data corrected or incomplete data completed (Article 16);
- have your data erased in certain circumstances (Article 17);
- restrict how we use your data in certain circumstances (Article 18);
- receive data you gave us in a portable, machine-readable format and have it transferred to another organisation, where processing is based on contract or consent and carried out by automated means (Article 20);
- object at any time to processing based on our legitimate interests, on grounds relating to your particular situation (Article 21). We will then stop unless we have compelling legitimate grounds that override your interests, or need the data to establish, exercise or defend legal claims.
We do not rely on consent for any processing, so there is no consent to withdraw.
To exercise any of these rights, email privacy@madladsquad.com. It is free of charge. We will reply without undue delay and within one month of receiving your request. If a request is complex or we receive several from you, we may extend this by up to two further months, and will tell you within the first month if we do. We may ask for information to confirm your identity before acting on a request, and in that case the time limit starts once we have it.
Because we do not keep our own logs of website visits, we usually hold no personal data about people who have only browsed the website. We will still confirm this to you if you ask, and can help you direct a request to GitHub or Cloudflare where appropriate.
8. Complaints
If you are unhappy with how we have handled your personal data, please contact us first at privacy@madladsquad.com so we can try to put it right.
You also have the right to complain to a data protection supervisory authority:
- In the UK: the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk/make-a-complaint.
- In the EU/EEA: the supervisory authority of the country where you live, work or where the alleged infringement took place. A list is published by the European Data Protection Board.
9. Security
All traffic to the website is encrypted with HTTPS/TLS. The website is static, with no database, server-side application or user accounts, which keeps the data that could be exposed to a minimum. Access to our email and hosting accounts is restricted to the people who need it and protected with strong authentication.
10. Links to other websites
The website links to other websites and services, such as GitHub, Discord, Ko-fi and Heapforge. These links are plain links: nothing is loaded from those services until you click one. Once you follow a link, the other website’s own privacy policy applies, and we are not responsible for how it handles your data.
If you take part in our projects on GitHub or Discord (for example by opening an issue, submitting a pull request or posting a message), that content is published on those platforms under their terms and privacy policies. Pull requests and commits become part of the project’s public history.
11. Changes to this policy
We will update this policy when the way we process personal data changes, and change the “Last updated” date above. Every past version is available in the website’s public Git history.
12. Contact
Heapforge Ltd.
82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
privacy@madladsquad.com