Privacy Policy
08/13/2026
In short: we do not sell your data, we do not track you across the web, and we do not collect anything we do not need in order to provision your server and bill it. This page tells you in detail what we process, why, on what legal basis, who else gets to see it, and how long we keep it.
1. Controller
Drazen Bebic, trading as "mcbalkan.xyz"
Heiligenstädter Straße 81–87/3/69, 1190 Vienna, Austria
Data protection enquiries: privacy@mcbalkan.xyz
We are not required to appoint a data protection officer and have not appointed one. Enquiries are answered by the owner personally.
2. What we process, for what purpose, and on what basis
2.1 Visiting the website
When you open our pages, technically necessary connection data is processed: IP address, time, the address requested, status code, volume of data transferred, and information about your browser and operating system.
- Purpose: delivering the website, stability, defending against attacks
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation)
- Retention: our hosting provider's server logs are deleted at short intervals; we do not keep persistent access logs ourselves
2.2 Customer account and sign-in
For an account we process your email address, a display name of your choosing, your language preference, and the time your email address was confirmed.
Sign-in is either via a magic link by email or via Discord. If you sign in with Discord, we receive from Discord your Discord ID, username, profile picture, and email address together with its verification status. The access and refresh tokens issued by Discord are stored in our database so the link remains active.
If you enable two-factor authentication, we store your TOTP secret encrypted and only hashes of your recovery codes. We cannot recover the codes themselves.
- Purpose: account creation, authentication, account security
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for two-factor authentication additionally Art. 6(1)(f)
- Retention: for as long as the account exists, then see section 6
2.3 Protection against automated sign-in attempts
The sign-in form is protected by Cloudflare Turnstile. A verification widget is loaded in your browser, which means Cloudflare receives your IP address. For the verification step we additionally transmit your IP address to Cloudflare from our server. Turnstile operates without user profiles and without advertising tracking.
- Purpose: defending against automated sign-in and mail abuse attempts
- Legal basis: Art. 6(1)(f) GDPR
2.4 Provisioning and managing servers
Once your email address is confirmed, we automatically create an account for you in our server management software. Your email address, a derived username and your display name are transferred there. That software also keeps its own access logs, including IP addresses.
On the server itself, game data arises during operation: world data, configuration files, console and connection logs, and backups.
If you access your server's files over SFTP, you generate the password for it yourself in the customer portal. We show it exactly once and do not store it: it exists in the server management software only as a cryptographic hash and cannot be read back by us. SFTP logins and the file changes made through them are logged by that software together with your IP address.
- Purpose: provisioning, controlling and maintaining your server
- Legal basis: Art. 6(1)(b) GDPR
- Retention: for as long as the server exists, then per the process described in the Terms and Conditions
2.5 Billing
We keep a credit account and a ledger: top-ups, debits, amount, reason, time, and the plans and add-ons booked with their billing periods.
We do not see full payment details. Card or bank account numbers are processed exclusively by the payment service provider and are never stored by us.
- Purpose: billing, accounting, meeting tax obligations
- Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (statutory retention obligations)
- Retention: 7 years under § 132 of the Austrian Federal Fiscal Code (BAO)
2.6 Security log
Security-relevant actions in your account are logged: the action performed, the server affected, the time, the acting email address, and IP address and browser identifier. This covers things like starting and stopping servers, file changes, provisioning, cancellations, credit postings, changes to security settings, and issuing or regenerating an SFTP password.
If an administrator exceptionally accesses your account in the course of a support request, that is logged too.
- Purpose: traceability, abuse detection, securing evidence in the event of a dispute
- Legal basis: Art. 6(1)(f) GDPR
- Retention: 12 months
2.7 Emails we send you
We send sign-in links and operationally necessary messages: confirmations, warnings about low credit, suspension, and impending deletion.
These are transactional messages, not advertising. We do not send a newsletter.
- Purpose: performing the contract, warning against data loss
- Legal basis: Art. 6(1)(b) GDPR
2.8 Profile picture
If your account has no picture, we check Gravatar for a stored profile picture. In doing so we transmit a SHA-256 hash of your email address — not the address itself.
This lookup happens on our server, not in your browser. Gravatar therefore learns neither your IP address nor when you are signed in. The same applies to Discord profile pictures: we fetch those server-side too.
- Purpose: displaying a profile picture
- Legal basis: Art. 6(1)(f) GDPR
2.9 Support
If you write to us by email or through Discord, we process your message and the contact details you write from.
- Legal basis: Art. 6(1)(b) GDPR, otherwise Art. 6(1)(f) GDPR
- Retention: until resolved, then until any warranty or limitation periods expire
3. Recipients and processors
We do not pass data to advertisers and we do not sell data. We use the following service providers, who act for us on our instructions only:
Infrastructure
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen — Germany — approved provider for game server nodes. Not currently in use: no customer data is held there.
- WIIT AG, Joachim-Erwin-Platz 3, 40212 Düsseldorf — Germany — game server nodes in Düsseldorf (brand „webtropia”). All customer servers currently live here: world data, server logs, backups, player IP addresses.
- IONOS SE, Elgendorfer Str. 57, 56410 Montabaur — Germany — Operating our server management software: email address, name, username, access logs
- Neon — Database region EU — Accounts, sessions, credit ledger, contract line items, security log
- Vercel Inc. — USA — Hosting and delivery of the website
All servers currently run in the same German data centre; which site your server lands on depends on available capacity and is not something you can choose. Backups are stored on the same node as the server; no external backup storage is currently used.
Communication and account
- Brevo (Sendinblue SAS) — France — Sending all transactional messages
- Discord — Ireland / USA — Discord sign-in, if you use it
Security, content and presentation
- Cloudflare — USA / EU — Turnstile protection of the sign-in form
- Sanity — Norway — Content management and delivery of website images
- Automattic Inc. — USA — Gravatar profile picture lookup, server-side, using a hash only
Only when you use the relevant feature
If you install content from external sources in the customer portal, or use features that reach out to third-party services, requests are made to the respective providers — in particular Modrinth, CurseForge, GeyserMC, the game provider's authentication services, and Crafatar for player avatars. We make all of these requests from our own server: your browser never connects to these providers and they never learn your IP address.
Other recipients
Tax advisors and public authorities to the extent required by law.
4. Transfers to third countries
The great majority of processing takes place within the EU — in particular all server, panel and database content.
With the providers listed above as based in the USA, processing outside the EU may occur. Those transfers are based on the European Commission's Standard Contractual Clauses and, where the provider is certified, on the EU-US Data Privacy Framework.
5. Cookies
We use strictly necessary cookies only. There are no advertising cookies, no Facebook Pixel, no Google Analytics and no cross-site tracking. That is also why you see no cookie banner here: no consent is required for strictly necessary cookies.
- Session cookie — keeps you signed in — up to 30 days
- CSRF token — protects forms against cross-site submission — session
- Return address — redirect after sign-in — session
- Support access — marks an administrator access in a support case — session
- Cloudflare cookies — bot detection on the sign-in form — up to 30 days
Audience measurement
We use Vercel Analytics and Vercel Speed Insights to see which pages are opened and how fast they load. Both operate without cookies and without cross-site recognition; no profiles are built and no data is passed to advertising networks.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning, fast website)
Fonts
Fonts are served from our own server. Your browser makes no connection to Google.
6. Retention at a glance
- Account and sign-in data — for as long as the account exists
- Sessions — 30 days maximum
- Server data where credit runs short — 7 days grace + 30 days after suspension, then deletion
- Server data after cancellation — 7 days, then deletion
- Security log — 12 months
- Invoices and credit ledger — 7 years (§ 132 BAO)
- Dormant accounts with no server and no credit — 24 months, then deletion
- Support correspondence — until resolved, then until limitation periods expire
Where a statutory retention obligation applies, data is not deleted but restricted: it is kept solely to meet that obligation and is not otherwise used.
7. Data on your server
If you run a public server, data about other people arises there — player names, player identifiers, IP addresses and chat logs in your server files.
For that data you are the controller and we are your processor. We do not look at it and do not analyse it; we only provide the infrastructure it sits on. The Data Processing Agreement governs what applies.
In that case you are responsible for informing your players and for having a legal basis for the processing.
8. Children and young people
We conclude contracts exclusively with adults. A customer account may only be opened and held by a person aged 18 or over.
That younger people also play on a server is of course entirely normal — the operator of that server is responsible for their data, see section 7.
If we learn that an account is held by a minor, we delete it and refund any unused credit.
9. Your rights
You have the right to:
- access the data processed about you (Art. 15)
- rectification of inaccurate data (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability in a commonly used format (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent you have given, with effect for the future (Art. 7(3))
Write to privacy@mcbalkan.xyz. We respond within one month. To protect you, we answer requests only to the email address held on the account.
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.
Complaints
If you believe we are processing your data unlawfully, you can complain to the supervisory authority:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40–42, 1030 Vienna
dsb@dsb.gv.at
You may also complain to the supervisory authority of your own country of residence. We would be glad, though, if you tried us first.
10. Data security
Transmission is encrypted throughout. Only the owner has access to customer data. There is no password for signing in to the website — we use magic links and Discord — TOTP secrets are stored encrypted, and recovery codes only as hashes. The one password that does exist is the SFTP password: you generate it on request, we show it once, and we do not store it.
11. Changes
We update this policy when our processing or the legal position changes. The version published here is the applicable one; the date is at the top. We notify you by email of material changes.