Privacy notice
Last updated: 16 August 2026
1. Controller and contact
AFKSystems is the controller for personal data processed by this service. AFKSystems is operated outside Germany. Privacy requests may be submitted through a support ticket in the panel or through the AFKSystems Discord linked on the website. Exercising a data protection right is free of charge; proof of account ownership may be requested to prevent disclosure to an unauthorised person.
2. Data we process
- Account and profile data: email address, username, password only as a cryptographic hash, language and settings.
- Sign-in data: session identifier, time, IP address and shortened browser/device information. Session identifiers are held in an HttpOnly cookie and cannot be read by JavaScript.
- Linked services: when used voluntarily, the account ID, name, email address, avatar and Discord membership status supplied by Discord or Google. AFKSystems never receives the password used with those providers.
- Minecraft operations: account name and UUID, destination server, version, bot settings, commands, macros, connection states and technical logs. Microsoft accounts use Microsoft's device sign-in flow; credentials are not requested in the browser.
- Communications: ticket contents, participants, status, Discord mapping, chat and support messages, and emails sent by the service.
- Billing data: credit movements, plans and add-ons, payment amount, method, reference and status. Payments run through Tebex (Tebex Limited) as merchant of record; card details, billing address and VAT are handled there and are not disclosed to AFKSystems. All that comes back is that a payment succeeded, for how much, and which top-up it belongs to.
- Security and operations: audit events, errors, abuse signals, and server or process metrics.
3. Purposes and legal bases
Data is processed to provide accounts and booked bot services, handle payments and credits, provide support, diagnose faults and protect the service from abuse. Where the GDPR applies, processing is based, depending on the activity, on performance of a contract or pre-contractual steps (Article 6(1)(b)), compliance with a legal obligation, particularly payment records (Article 6(1)(c)), legitimate interests in secure and reliable operation (Article 6(1)(f)), or freely given consent that may be withdrawn at any time (Article 6(1)(a)).
4. Recipients and external services
Data is available only to people and providers that need it for operation, hosting, support or billing. Depending on features chosen voluntarily, data is sent to Discord, Google, Microsoft or Tebex. When a bot connects, the selected Minecraft server necessarily receives information such as Minecraft name, UUID, connection IP address and game actions sent. Email providers process sender, recipient and message contents. Personal data is not sold or disclosed for advertising.
Those providers may process information outside the user's country or outside the EU/EEA. Such transfers are made in accordance with applicable legal requirements and the safeguards offered by the provider. The privacy terms of a selected third-party service also apply.
5. Cookies and local storage
AFKSystems uses no advertising or tracking cookies. An HttpOnly session cookie is necessary for sign-in and a language cookie stores the selected language. Language, colour theme, collapsed navigation and dismissed notices may also be stored locally in the browser. Local values do not leave the browser unless a feature expressly synchronises them with the account.
6. Retention
Account data is generally held while the service is used. Sessions end when they expire, the user signs out or they are revoked. Technical logs and security information are kept only as long as reasonably needed for diagnostics, security and abuse prevention. Ticket and contract data is retained for handling and possible evidence. Payment and accounting records are kept for the periods required by applicable commercial, tax or consumer law. Data is then deleted or anonymised unless an unresolved claim, security incident or legal obligation requires continued retention.
7. Rights
Where applicable law provides, users have rights of access, correction, erasure, restriction, portability and objection. Consent can be withdrawn at any time for the future. A complaint may also be made to the competent data protection authority. Information required by law or needed to perform an active contract may be deleted only after that requirement ends.
8. Security and automated decisions
AFKSystems uses measures including encrypted HTTPS connections, hashed passwords, random revocable sessions, role-based access, input validation, security headers and protected server files. No internet service can promise absolute security. There is no solely automated decision producing legal or similarly significant effects. Automatic plan renewals from an available credit balance and technical security restrictions follow the user's settings or explainable security rules.
9. Changes
This notice is updated when functions, providers or legal requirements change. The current version and its date are published on this page.