Last updated: August 2, 2026
EYTAK LIMITED ("Eytak", "we", "us", or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Minecraft server hosting platform and related services.
We collect information you provide directly to us when you create an account, purchase a plan, contact support, or interact with our services.
Personal Information: Name, email address, billing address, payment method details (processed by our payment provider), and phone number (optional).
Usage Data: Server configurations, resource usage metrics, IP addresses, browser type, device information, pages visited, and interaction timestamps.
Server Data: We do not routinely access, read, or monitor the content of your Minecraft servers, world files, or plugin configurations. We do read your server's operational logs when you open a support ticket, so that we can diagnose the problem — see section 3.
We use the information we collect to:
• Provide, maintain, and improve our Minecraft server hosting services
• Process transactions and send related billing information
• Send technical notices, security alerts, and support messages
• Respond to your comments, questions, and customer service requests
• Monitor and analyze usage trends to improve user experience
• Detect, investigate, and prevent fraudulent transactions and abuse
• Comply with legal obligations and enforce our terms of service
Email we send you. Most of our email is part of the service and cannot be switched off while your account is open: receipts and invoices, notice before a free trial converts into a charge, payment problems, security alerts, changes to your terms, and replies to your own support tickets.
There is one exception. If you start signing up for a plan and stop at the payment page, we send one reminder that you did not finish, and never a second. It describes only the plan you had already chosen, carries no offer or discount, and every copy of it contains a one-click unsubscribe link that takes effect immediately. The lawful basis is Regulation 22(3) of the Privacy and Electronic Communications Regulations 2003 — you gave us the address while enquiring about this same service — read with Article 6(1)(f) GDPR. Unsubscribing stops it; so does telling privacy@eytak.com. Product news and offers are separate, are sent only if you ticked the optional box when registering, and can be withdrawn at any time.
We use an AI support agent to read and answer support tickets. Every reply it writes is labelled AI in the panel. You can hand any ticket to a person at once with the Request human review button, or by sending Human review requested as your whole message.
What it processes: the ticket's title, description and full comment history; your servers' names, subdomains, status, software and Minecraft version, installed modpack and mods, and allocated resources; your billing tier, status and credit balance; and recent operational log lines from your own servers.
Your players' data: a Minecraft server log can contain the usernames of people who play on your server. We remove IP addresses from log lines before they are sent to the model, because it does not need them to diagnose a fault. Usernames may remain, because the diagnosis usually depends on them.
Who processes it: Microsoft, through the Azure OpenAI Service, acting as our processor under its data protection terms. The deployment we use is in an Azure region inside the United Kingdom or the EEA.
Training: neither we nor Microsoft use your tickets, logs, server details or account data to train any AI model.
Retention at Microsoft: Azure may hold the text sent to and returned by the model for up to 30 days so that Microsoft can detect misuse of the service, and authorised Microsoft personnel may review it for that purpose only. Whatever the agent writes back into your ticket is stored with the ticket and follows section 6.
What it is not allowed to do: the agent can only see and act on your own workspace. It may restart one of your servers; it cannot stop, delete or reinstall a server, restore a backup, or change anything about your billing. Account termination, refunds, billing disputes and complaints are always decided by a person, so the agent makes no decision that produces a legal or similarly significant effect on you (Art. 22 GDPR).
Legal basis: Article 6(1)(b) — handling the support request you made under your contract with us.
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
• Service Providers (sub-processors): With the vendors below, each bound by a data processing agreement and permitted to use your data only to provide their service to us:
— Polar — merchant of record: checkout, subscriptions, invoices and tax.
— Railway — hosting for our application, databases and cache.
— Hetzner — the physical nodes your game servers run on, in Falkenstein, Germany.
— Bunny.net — storage for your server backups and snapshots.
— Resend — delivery of the email described in section 2, both the service messages and the single unfinished-signup reminder.
— Microsoft Azure — the physical nodes your game servers run on when you choose our Madrid, Spain location, and separately the AI support agent described in section 3.
— Google — sign-in, if you choose "Continue with Google"; and Google Analytics on our public website, only if you accept analytics cookies.
— Modrinth and CurseForge — mod and modpack catalogues. We query them on your behalf from our servers; they do not receive your account details.
• Legal Requirements: When required by law, regulation, legal process, or governmental request.
• Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
• With Your Consent: When you explicitly authorize us to share specific information.
These are the controls we actually operate today:
• In transit: TLS on all traffic between you and our services, and between our services and the providers listed in section 4.
• Credentials: passwords and one-time login codes are stored as Argon2 hashes, never in readable form. API tokens and session tokens are stored hashed, so a copy of the database does not yield a usable token.
• Staff access: internal tools require multi-factor authentication, with a fresh challenge before sensitive operations. Staff permissions are granted per role rather than per person, and the second-factor secrets themselves are encrypted with AES-256-GCM.
• Abuse control: rate limiting on authentication and administrative endpoints.
• Data minimisation in support: IP addresses are stripped from server log lines before the AI support agent ever sees them (section 3).
• At rest: databases, backups and object storage are encrypted at rest by the providers that host them — Railway, Bunny.net, Hetzner and Microsoft Azure.
• Network: DDoS filtering is provided at network level by the infrastructure providers our nodes run on.
We describe only controls that are in place. We do not claim certifications, independent security audits or penetration tests that we have not obtained; if we obtain them, we will list them here.
No method of transmission over the Internet is completely secure. We cannot guarantee absolute security, but we are committed to addressing any incident promptly and to notifying the supervisory authority and affected users where the law requires it.
We retain your personal information for as long as your account is active or as needed to provide our services. After account deletion, and subject to the exceptions below:
• Personal data is permanently deleted within 30 days of your request. Deletion is scheduled 28 days out and carried out then, so the work finishes inside the 30 days rather than starting at the deadline
• Server data and product backups are purged within 14 days
• Encrypted residual copies may persist in system-level backups until overwritten by our backup rotation, for no longer than 30 days
• Billing, payment and tax records are retained for 7 years as required by tax regulations, and are anonymised where they no longer need to identify you
• Consent and security records are retained as our audit trail for the period stated in this notice
• Support tickets, including AI replies and the internal notes recording how the agent reached them, are retained with your account and anonymised when you delete it
• Website analytics, collected only from visitors who accepted it, is held by Google Analytics for no longer than 14 months, which is the longest retention that service allows for event data. The analytics cookies themselves expire on your device after 2 years, or immediately if you withdraw consent
• Product analytics recorded inside the panel, described in section 8, is deleted after 12 months, and sooner than that if you delete your account — it is removed with your workspace rather than anonymised
Depending on your jurisdiction, you may have the following rights:
• Access: Request a copy of the personal data we hold about you
• Correction: Request correction of inaccurate or incomplete data
• Deletion: Request deletion of your personal data ("right to be forgotten")
• Portability: Request a machine-readable export of your data
• Objection: Object to processing of your data for specific purposes
• Restriction: Request restriction of processing under certain conditions
You can export your data and delete your account yourself from the Account page in the panel. For anything else, contact us at privacy@eytak.com. We will respond within the period required by applicable law.
Requesting deletion also stops your subscription renewing, so you are not charged again while the grace period runs. Your servers keep running until the end of the period you have already paid for, and usage until then is billed as normal; after that they stop and a recoverable copy is kept for 168 hours as described in the Backup and Data Lifecycle Schedule. If you cancel the deletion after your paid period has ended, you will need to start a new plan.
We set the cookies needed to sign you in and keep the site working, and — only if you accept them — Google Analytics cookies. Analytics is off until you agree, one click rejects it, and you can withdraw at any time through "Cookie settings" in the footer, which also deletes the cookies already set. The same choice covers the public website and the customer panel, because the record of it is held on the eytak.com domain and both read it. We run no advertising pixel and no cross-site tracking. Our Cookie Policy lists every cookie by name.
Product analytics inside the panel. Separately from the above, when you are signed in we record which steps of a flow you reach — for example, how far through creating a server you got, and the step you were on if you stopped. This is recorded on our own servers against the session you are already signed in on. It sets no cookie and stores nothing on your device, so it is not covered by the cookie choice above; we rely on our legitimate interest in understanding where our own customers get stuck, and you can object at any time by writing to privacy@eytak.com. We record the step, your workspace and the options you chose from our own lists (such as the server software and version). We do not record what you typed: not search terms, not server names, not file contents. The record is attached to the workspace rather than to your individual user account — which is why it is not itemised in the personal-data export, and why it is deleted outright with the workspace instead of being anonymised.
Our services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
Your data may be transferred to and processed in countries other than your own. Where a transfer leaves the United Kingdom or the EEA, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum.
Your game server and its world files run in the location you pick when you create it — Falkenstein, Germany or Madrid, Spain — and the panel shows which one each of your servers is in. Backups are separate from that choice: they are held by Bunny.net in Germany, with copies in Sweden and the United Kingdom, whichever location your server runs in.
The AI support deployment described in section 3 is hosted in an Azure region inside the United Kingdom or the EEA, so ticket and log text sent to it is not transferred out of that area by us.
Website analytics is processed by Google LLC in the United States under the Google Ads Data Processing Terms, which incorporate the Standard Contractual Clauses and the UK Addendum. This transfer only happens for visitors who have accepted analytics cookies; if you reject them, nothing about your visit is sent to Google.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, where appropriate, sending you an email notification. Your continued use of our services after changes constitutes acceptance of the updated policy.
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
• Email: privacy@eytak.com
• Abuse Reports: abuse@eytak.com
• Discord: discord.gg/eytak
• Address: EYTAK LIMITED, 82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE