Skip to contentFree server — while stock lasts
mcbalkan.xyz
Back to home

Data Processing Agreement

08/11/2026

This agreement under Art. 28 GDPR is concluded between you as the customer and us, as soon as personal data of other people is processed on your server. It forms part of the Terms and Conditions and requires no separate signature.

Why this agreement exists

If you run a server that other people play on, data about those people arises there: player names, player identifiers, IP addresses, chat logs, connection times. Under data protection law you are the controller for that — you decide that the server exists, who plays on it, and what gets logged.

We merely provide the machine it runs on. That makes us your processor, and the GDPR requires a contract for that. This is it.

It protects you above all: without it, the processing on your server would be formally unlawful, regardless of how carefully either of us works.

1. Subject matter, duration and purpose

The subject matter is the provision and operation of game servers together with the associated management, backup and support services.

The purpose of the processing is solely the delivery of that service. We pursue no purposes of our own with the data on your server.

Duration: the agreement runs for as long as the underlying server contract exists.

2. Type of data and categories of data subjects

Categories of personal data (depending on the game and your server's configuration):

  • player names and player identifiers (UUIDs, gamertags, account IDs)
  • IP addresses and connection times
  • chat, console and event logs
  • saved games and game-related data associated with individual players
  • the contents of permission, whitelist, operator and ban lists
  • anything else you or an extension you have installed stores on the server

Categories of data subjects: the players on your server, and the people you have granted administrative rights to.

3. Processing on instructions

We process the data on your server solely on your documented instructions. The contract itself and the settings you make in the customer portal constitute instructions; further instructions are given in text form to privacy@mcbalkan.xyz.

No processing for our own purposes takes place. In particular, we do not analyse the contents of your server, do not build profiles from them, and do not pass them to third parties.

If we are legally obliged to carry out processing, we inform you beforehand unless the law prohibits that.

If we consider an instruction to be unlawful, we will say so and may suspend carrying it out until you confirm or amend it.

4. Confidentiality

Only the owner has access to the systems; there are no employees. Should that change, everyone with access rights will first be bound to confidentiality in writing and briefed on their obligations. That obligation continues beyond the end of their engagement.

5. Security of processing

We implement the technical and organisational measures under Art. 32 GDPR described in Annex 2 and review them regularly. Measures may be developed further as long as the level of protection does not fall.

6. Sub-processors

You hereby grant general authorisation for the engagement of the sub-processors listed in Annex 3.

For them:

  • We conclude a contract with each of them imposing at least the same obligations that bind us here.
  • We notify you by email at least 30 days in advance of the addition of a new sub-processor or the replacement of an existing one.
  • Within that period you may object on reasonable, data-protection-related grounds. If we cannot resolve the objection, you may terminate the contract extraordinarily and free of charge; unused credit is paid out.

Purely ancillary services — telecommunications, post, maintenance of end-user devices — do not count as sub-processing.

7. Place of processing

Processing takes place in data centres in Germany. Your server's data, including backups, does not leave the European Union.

With the services marked in Annex 3 as based outside the EU, processing in a third country may occur. This is based on the European Commission's Standard Contractual Clauses and, where applicable, on an adequacy decision. The contents of your server are not affected by this.

8. Assistance with data subject rights

If one of your players contacts us directly, we refer them to you and inform you. We do not answer such requests ourselves.

We assist you with appropriate means in fulfilling access, rectification, erasure and restriction requests — in particular through the fact that the customer portal gives you full access to all of your server's files, where you can inspect, change and delete data yourself. If that is not sufficient in an individual case, support will help.

9. Further assistance obligations

We assist you, to the extent the information is not otherwise available to you, with:

  • security of processing (Art. 32)
  • notifying personal data breaches to the supervisory authority (Art. 33) and communicating them to data subjects (Art. 34)
  • a data protection impact assessment (Art. 35) and prior consultation (Art. 36)

Personal data breach: if we become aware of a breach affecting data on your server, we inform you without undue delay after becoming aware, with all information available to us on the nature, scope, likely consequences and measures taken. Notifying the supervisory authority is your obligation as controller.

10. Deletion and return

During the term of the contract you can download all of your server's data at any time yourself — through the file manager and the backup function in the customer portal. No separate request for release is needed.

After the contract ends you have 7 days to back up your data. After that, the server, its data and its backups are deleted.

Where credit runs short, the process described in the Terms and Conditions applies instead: 7 days grace, then suspension, deletion 30 days after suspension.

Statutory retention obligations are unaffected; they concern billing data only, not the contents of your server.

11. Evidence and audits

On request we demonstrate compliance with this agreement — by providing information, by documenting the measures in Annex 2, and through the evidence our own sub-processors make available to us.

You have the right to audit the processing. Audits must be announced with reasonable notice, must not unreasonably disrupt operations, and must not jeopardise the confidentiality of other customers' data. As a rule, information in text form will suffice.

12. Liability

The liability provisions of the Terms and Conditions apply, as does Art. 82 GDPR.

  • Subject matter — Provision and operation of game servers
  • Nature of processing — Storage, execution, transmission in the course of gameplay, backup, deletion
  • Purpose — solely the delivery of the contractual service
  • Categories of data — see section 2
  • Data subjects — players and administrators on the customer's server
  • Duration — term of the server contract plus the periods in section 10
  • Location — data centres in Germany

Physical access control. The data centres are operated by our infrastructure providers and have entry security, video surveillance, uninterruptible power supply and fire protection. Their respective Art. 32 evidence forms part of our contracts with them.

System access control. No password login — sign-in exclusively via magic link or Discord. Two-factor authentication available; TOTP secrets stored encrypted, recovery codes only as hashes. Administrative access is limited to the owner.

Data access control. Every access to a server is checked against the ownership of the signed-in account. Customers see only their own servers. Security-relevant actions are logged with time, acting person, IP address and browser identifier; this applies to support access too.

Separation control. Every customer server runs in its own isolated environment with its own files and its own resource limits.

Transmission control. All connections to the website, to the customer portal and between our systems are encrypted.

Input control. Logging of security-relevant actions, retained for 12 months.

Availability control. Redundant power and network connectivity in the data centre, upstream DDoS filtering, backup function in the customer portal.

Resilience and recovery. Restore from backups through the customer portal; regular security updates to the platform.

Instruction control. Art. 28 contracts with all sub-processors; bound by instructions per section 3.

Review. The measures are reviewed regularly and adapted to the state of the art.

Infrastructure — this is where your server's data lives:

  • Hetzner Online GmbH, Gunzenhausen — Germany — approved for server nodes, not currently in use
  • WIIT AG, Düsseldorf — Germany — server nodes in Düsseldorf (brand „webtropia”) — currently the only location
  • IONOS SE, Montabaur — Germany — Operation of the server management software

Platform — this is where account and billing data lives, not your server's contents:

  • Neon — Database region EU — Database for accounts and billing
  • Vercel Inc. — USA * — Hosting and delivery of the website
  • Brevo (Sendinblue SAS) — France — Sending transactional messages
  • Cloudflare — USA * / EU — Protection of the sign-in form

* Third-country transfer; safeguarded by Standard Contractual Clauses. The contents of your server are not affected.

This list is kept current. Changes are announced under section 6.

Questions about this agreement: privacy@mcbalkan.xyz