1.Controller and contact
The controller of personal data is [to be completed: company name], [to be completed: company address], tax ID (NIP): [to be completed: tax ID (NIP)] (“we”). For anything related to data, write to [email protected].
Data protection officer: we have not appointed a data protection officer (we are not required to) — for personal data matters, write to [email protected].
We process data in accordance with Regulation (EU) 2016/679 (GDPR) and Polish law.
2.What data we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | name or nickname, e-mail address, profile picture, Google or Discord account ID, account creation date | from Google or Discord when you sign in with their account |
| Public profile | name or nickname and profile picture shown with moments, comments, following and server pages | from your account and activity |
| Servers | server name and address, settings, plan, world files, player lists (whitelist, bans), console logs — may contain players’ nicknames and IP addresses and chat messages | from you and from the running server |
| Content | server pages, images, videos, captions, comments, likes, followed accounts | from you |
| Payments | amount, pack, payment status, country (for VAT), Stripe identifiers, gem history, text and version of the consumer consent, invoice details if you provide them | from you and from Stripe — we do not receive card details |
| Technical data | IP address, browser type, date and time of requests, security events, rate-limit counters | from your device |
| Integrations | Discord: user ID and name, avatar, Discord servers and channels, encrypted access tokens; AI assistants: application name, consent scope, token hashes | from you, Discord and the application you connect |
| Reports and contact | report content, reporter’s e-mail, a hash of the IP address, correspondence with us | from you |
| SPOT program | computer data and program statistics — details below | from the MineLab Node program |
- Category
- Account data
- Examples
- name or nickname, e-mail address, profile picture, Google or Discord account ID, account creation date
- Where it comes from
- from Google or Discord when you sign in with their account
- Category
- Public profile
- Examples
- name or nickname and profile picture shown with moments, comments, following and server pages
- Where it comes from
- from your account and activity
- Category
- Servers
- Examples
- server name and address, settings, plan, world files, player lists (whitelist, bans), console logs — may contain players’ nicknames and IP addresses and chat messages
- Where it comes from
- from you and from the running server
- Category
- Content
- Examples
- server pages, images, videos, captions, comments, likes, followed accounts
- Where it comes from
- from you
- Category
- Payments
- Examples
- amount, pack, payment status, country (for VAT), Stripe identifiers, gem history, text and version of the consumer consent, invoice details if you provide them
- Where it comes from
- from you and from Stripe — we do not receive card details
- Category
- Technical data
- Examples
- IP address, browser type, date and time of requests, security events, rate-limit counters
- Where it comes from
- from your device
- Category
- Integrations
- Examples
- Discord: user ID and name, avatar, Discord servers and channels, encrypted access tokens; AI assistants: application name, consent scope, token hashes
- Where it comes from
- from you, Discord and the application you connect
- Category
- Reports and contact
- Examples
- report content, reporter’s e-mail, a hash of the IP address, correspondence with us
- Where it comes from
- from you
- Category
- SPOT program
- Examples
- computer data and program statistics — details below
- Where it comes from
- from the MineLab Node program
Providing data is voluntary, but without account data you cannot create an account, and without payment data you cannot buy gems.
3.Purposes and legal bases
| Purpose | Legal basis (GDPR) | How long |
|---|---|---|
| Creating and running your account, signing in | Art. 6(1)(b) — contract | until the account is deleted |
| Server hosting, server pages, MineTok, server list, integrations | Art. 6(1)(b) — contract | until the account or content is deleted; world of an unused server — 14 days from last activity |
| Payments, gems, settlements and accounting | Art. 6(1)(b) and (c) — contract and tax obligations | accounting records — 5 years from the end of the year in which the tax obligation arose |
| Proof of consent to immediate performance, refunds | Art. 6(1)(c) and (f) | until claims are time-barred |
| Service e-mails (e.g. reminders before a world is deleted, payment confirmations) | Art. 6(1)(b) | until the account is deleted |
| Security, protection against abuse and attacks, rate limits, reCAPTCHA checks | Art. 6(1)(f) — legitimate interest (service security) | technical logs — 30 days (browser logs: 7 days) |
| Content moderation, reports and appeals | Art. 6(1)(c) (DSA) and (f) | 12 months from the decision |
| Automated pre-check of a server page before moderation | Art. 6(1)(f) — safety of users, including children | result — until the page is next changed |
| List ordering, MineTok recommendations, service statistics | Art. 6(1)(f) — operating and developing the service | as long as needed for these purposes |
| SPOT program | Art. 6(1)(b) and (f) | see the MineLab Node section |
| Contacting us, complaints | Art. 6(1)(b), (c) and (f) | until the matter is closed and claims are time-barred |
| Ads (if shown) | Art. 6(1)(f); personalised ads — consent (a) | according to Google’s rules |
| Establishing, pursuing and defending claims | Art. 6(1)(f) | until claims are time-barred |
- Purpose
- Creating and running your account, signing in
- Legal basis (GDPR)
- Art. 6(1)(b) — contract
- How long
- until the account is deleted
- Purpose
- Server hosting, server pages, MineTok, server list, integrations
- Legal basis (GDPR)
- Art. 6(1)(b) — contract
- How long
- until the account or content is deleted; world of an unused server — 14 days from last activity
- Purpose
- Payments, gems, settlements and accounting
- Legal basis (GDPR)
- Art. 6(1)(b) and (c) — contract and tax obligations
- How long
- accounting records — 5 years from the end of the year in which the tax obligation arose
- Purpose
- Proof of consent to immediate performance, refunds
- Legal basis (GDPR)
- Art. 6(1)(c) and (f)
- How long
- until claims are time-barred
- Purpose
- Service e-mails (e.g. reminders before a world is deleted, payment confirmations)
- Legal basis (GDPR)
- Art. 6(1)(b)
- How long
- until the account is deleted
- Purpose
- Security, protection against abuse and attacks, rate limits, reCAPTCHA checks
- Legal basis (GDPR)
- Art. 6(1)(f) — legitimate interest (service security)
- How long
- technical logs — 30 days (browser logs: 7 days)
- Purpose
- Content moderation, reports and appeals
- Legal basis (GDPR)
- Art. 6(1)(c) (DSA) and (f)
- How long
- 12 months from the decision
- Purpose
- Automated pre-check of a server page before moderation
- Legal basis (GDPR)
- Art. 6(1)(f) — safety of users, including children
- How long
- result — until the page is next changed
- Purpose
- List ordering, MineTok recommendations, service statistics
- Legal basis (GDPR)
- Art. 6(1)(f) — operating and developing the service
- How long
- as long as needed for these purposes
- Purpose
- SPOT program
- Legal basis (GDPR)
- Art. 6(1)(b) and (f)
- How long
- see the MineLab Node section
- Purpose
- Contacting us, complaints
- Legal basis (GDPR)
- Art. 6(1)(b), (c) and (f)
- How long
- until the matter is closed and claims are time-barred
- Purpose
- Ads (if shown)
- Legal basis (GDPR)
- Art. 6(1)(f); personalised ads — consent (a)
- How long
- according to Google’s rules
- Purpose
- Establishing, pursuing and defending claims
- Legal basis (GDPR)
- Art. 6(1)(f)
- How long
- until claims are time-barred
Where we rely on legitimate interest, you can object (see “Your rights”).
4.Who we share data with
We do not sell data. We share it only with providers who help us run the service (under data processing agreements) or, where necessary, with other controllers:
| Recipient | Purpose | Where |
|---|---|---|
| OVHcloud | application servers, databases and game servers, the SPOT relay server | EU — Poland (Warsaw: application and database) and France (Roubaix: game servers and the SPOT relay server) |
| Cloudflare | delivering the website and protection against attacks, DNS, file storage (world archives, images, videos) | global; US company |
| Stripe | payments, refunds and payment disputes; an independent controller for some data | EU and USA |
| Google sign-in, reCAPTCHA (protecting reports from bots), AdSense ads (if enabled), YouTube player on server pages | USA | |
| Discord | Discord sign-in, server page announcements via the bot | USA |
| OpenAI | automated pre-check of server page text and images before moderation | USA |
| E-mail provider | sending e-mails from the service | OVHcloud (Zimbra service), EU |
| SPOT program participants | free servers may run on their computers (see below) | participant’s place of residence |
| Other users and visitors | see your public profile, server pages and the content you publish | — |
| Applications you connect yourself | an AI assistant or Discord — receive data within the scope of your consent | depends on the provider |
| Public authorities | when required by law (e.g. at the request of a court or prosecutor) | Poland or EU |
| Accounting and legal advisers | bookkeeping and legal services | [to be completed: accounting] |
- Recipient
- OVHcloud
- Purpose
- application servers, databases and game servers, the SPOT relay server
- Where
- EU — Poland (Warsaw: application and database) and France (Roubaix: game servers and the SPOT relay server)
- Recipient
- Cloudflare
- Purpose
- delivering the website and protection against attacks, DNS, file storage (world archives, images, videos)
- Where
- global; US company
- Recipient
- Stripe
- Purpose
- payments, refunds and payment disputes; an independent controller for some data
- Where
- EU and USA
- Recipient
- Purpose
- Google sign-in, reCAPTCHA (protecting reports from bots), AdSense ads (if enabled), YouTube player on server pages
- Where
- USA
- Recipient
- Discord
- Purpose
- Discord sign-in, server page announcements via the bot
- Where
- USA
- Recipient
- OpenAI
- Purpose
- automated pre-check of server page text and images before moderation
- Where
- USA
- Recipient
- E-mail provider
- Purpose
- sending e-mails from the service
- Where
- OVHcloud (Zimbra service), EU
- Recipient
- SPOT program participants
- Purpose
- free servers may run on their computers (see below)
- Where
- participant’s place of residence
- Recipient
- Other users and visitors
- Purpose
- see your public profile, server pages and the content you publish
- Where
- —
- Recipient
- Applications you connect yourself
- Purpose
- an AI assistant or Discord — receive data within the scope of your consent
- Where
- depends on the provider
- Recipient
- Public authorities
- Purpose
- when required by law (e.g. at the request of a court or prosecutor)
- Where
- Poland or EU
- Recipient
- Accounting and legal advisers
- Purpose
- bookkeeping and legal services
- Where
- [to be completed: accounting]
5.Free servers on other players’ computers
- Free servers may run on the computers of SPOT program participants. The server’s files (world, configuration, console logs) are then stored on that computer while the server runs there. During play we regularly make copies of the world and keep them in our file storage, so the server can be moved if the computer goes offline.
- The server runs in an isolated container. Players connect through our relay server, so the participant’s computer does not see their IP addresses.
- SPOT participants are forbidden to open, copy or disclose the files and data of servers running on their computers. Violations lead to exclusion from the program.
- However, a participant has physical access to their computer, so we cannot technically rule out every abuse. That is why paid servers run only on our own machines — and you should not keep anything you want to keep secret on a free server.
- Opting out of placing a free server on participants’ computers: free servers run only in the SPOT pool, which may include participants’ computers — if you do not want that, choose a paid plan (LAB), which runs only on our own servers.
6.Transfers outside the EEA
Some providers (Cloudflare, Stripe, Google, Discord, OpenAI) also process data in the USA or other countries outside the European Economic Area. Transfers are based on a European Commission adequacy decision (the EU-US Data Privacy Framework — for companies that have joined it) or on standard contractual clauses approved by the Commission. You can get a copy of the safeguards by writing to [email protected].
7.How long we keep data
- Account data and content — until the account or content is deleted. After an account is deleted, data may remain in backups for up to 14 days.
- World of an unused server — 14 days from last activity; we send reminders beforehand.
- Payment and accounting records — 5 years from the end of the year in which the tax obligation arose.
- Data needed to defend against claims — until the limitation periods expire.
- Technical and security logs — 30 days (browser logs: 7 days).
- Reports and moderation decisions — 12 months from the decision.
- Sign-in tokens, one-time codes and keys — until they expire; the code for connecting MineLab Node to your account expires after 15 minutes.
8.Your rights
- access to your data and a copy of it;
- rectification of inaccurate data;
- erasure of data (the “right to be forgotten”);
- restriction of processing;
- portability of data we process on the basis of a contract or consent, in a machine-readable format;
- objection to processing based on legitimate interest;
- withdrawal of consent at any time — without affecting the lawfulness of processing before withdrawal;
- not being subject to decisions based solely on automated processing that have legal or similarly significant effects on you.
To exercise your rights, write to [email protected] — ideally from the address linked to your account so we can confirm it is you. We will reply without undue delay and within one month at the latest; in complex cases this may be extended by two further months — we will let you know if so.
9.Children and parents
- The service is for people aged at least 13. People under 18 use the service with their parent’s permission.
- We process children’s data to the same limited extent as adults’ data. We do not profile children for marketing purposes and do not show them personalised ads.
- A parent can exercise a child’s rights on their behalf, e.g. request access to data, its correction or deletion of the account. Write to [email protected]; we may ask you to confirm that you are the parent.
- If we learn that someone under 13 has an account, we will delete it together with its data.
For kids: do not put your full name, address, school or phone number in comments, captions, server names or videos. Everyone can see what you publish.
11.Data from the MineLab Node program
If you take part in the SPOT program, the MineLab Node program sends us:
- when connecting to your account — the computer name, system type (Linux or Windows with WSL) and program version;
- when registering the computer — number of cores and CPU model, amount of RAM, free disk space, the result of a short performance test, the WireGuard tunnel public key and the amount of memory you share;
- every minute — whether sharing is on, CPU load, memory usage, free disk space and the status of the tunnel and the Wings service;
- the IP address the program connects from — seen by our API and relay server; it is necessary to set up the tunnel.
Based on this we record: the tunnel address and assigned ports, the computer’s activity times, minutes of other players’ servers running on your computer and the gems earned. When a computer is connected we also record the version of the SPOT Program Terms you accepted, the time of acceptance and the statement about parental permission.
The program does not read your private files, browsing history or other programs. It runs in a separate environment (a system service and Docker containers; on Windows, a separate WSL distribution). The program token, tunnel keys and configuration are stored on the computer with restricted permissions.
Purposes: running the program and tunnel, assigning servers, calculating gems, detecting abuse and security (Art. 6(1)(b) and (f) GDPR). We keep the data while the computer takes part in the program; gems earned remain in your account history. After a computer is disconnected: we delete this data after 30 days.
12.Profiling and automated decisions
- We order servers in the list and moments on MineTok automatically based on activity (details in the terms). This has no legal or similarly significant effect on you.
- Rate limits and bot protection work automatically to protect the service. If you think you were blocked unfairly, write to us — a human will review it.
- In the SPOT program the reward may depend on an automatically calculated quality score of the computer (e.g. stability). You can dispute the calculation — a human will review it.
- The automated check of server pages only makes suggestions to the moderator — a human decides.
13.Data security
Our measures include encrypted connections (HTTPS), encryption of integration tokens in the database, storing tokens and codes only as hashes, hashing IP addresses in reports, access control and isolating servers in containers. If a data breach is likely to result in a high risk to you, we will let you know.
14.Complaints to the supervisory authority
If you believe we process your data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl) or with the supervisory authority in the EU country where you live or work. We encourage you to write to us first — we will try to help.
15.Changes to this policy
We update this policy when our services, providers or the law change. We will tell you about significant changes in the service or by e-mail. The current version and the date it applies from are always shown at the top of this page.