Privacy Policy
Last updated: 2026-07-25
This Privacy Policy explains how Minexnodes (“Minexnodes”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data when you use our website, create an account, purchase services, contact support, or otherwise interact with us.
This Privacy Policy also explains how Minexnodes handles personal data processed in connection with the hosting services we provide, including game hosting, VPS services, control panels, backups, and related infrastructure.
If you use Minexnodes’ services to host or process personal data relating to your own end users, players, customers, or community members, you may also act as a data controller in your own right. In those cases, Section 12 of this Privacy Policy explains the controller–processor relationship between you and Minexnodes.
- Who We Are
Minexnodes (“Minexnodes”) is the provider of the services described in our Terms of Service.
For the purposes of applicable data protection law, including the EU General Data Protection Regulation (“GDPR”), Minexnodes is the data controller for personal data relating to account creation, billing, customer communications, website operation, support, abuse handling, and the general administration of our services.
Minexnodes is established in Sweden and is primarily subject to Swedish data protection law and supervision by the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, “IMY”), without prejudice to the rights of individuals in other EEA jurisdictions.
- Scope of This Policy
This Privacy Policy applies to personal data processed by Minexnodes in connection with:
a) account registration and account management;
b) ordering, provisioning, renewing, suspending, or terminating services;
c) billing, payments, fraud prevention, and accounting;
d) support requests, abuse reports, and legal communications;
e) website access, client area access, panel access, and infrastructure security; and
f) customer data processed by Minexnodes as a processor where Section 12 applies.
This Privacy Policy does not govern the privacy practices of third-party services, websites, games, mods, plugins, payment providers, or software vendors that you may use together with Minexnodes services, except to the extent Minexnodes directly controls the relevant processing.
- Categories of Personal Data We Process
We may process the following categories of personal data about Clients and authorized users:
3.1 Identification and account data
This may include your name, username, account ID, email address, billing address, country, company name, VAT number, and other information you provide when registering an account or placing an order.
3.2 Contact and communication data
This includes email addresses used for login, service notices, billing, support, abuse handling, and legal communications, as well as the contents of support tickets, emails, and related correspondence.
3.3 Billing and transaction data
This may include payment method metadata, transaction IDs, payment status, invoice history, anti-fraud indicators, and non-sensitive payment references.
We do not store full card numbers or similar sensitive payment instrument details where those are processed directly by third-party payment providers.
3.4 Technical, usage, and log data
This may include IP addresses, login timestamps, panel access logs, support-related diagnostic information, service deployment metadata, infrastructure alerts, system event logs, firewall events, traffic indicators, and service performance or security logs under our control.
For VPS and hosting services, technical metadata may also include service state, assigned resources, internal service identifiers, and security-relevant events necessary to operate or protect the infrastructure.
3.5 Abuse and security data
This includes data used to detect, prevent, investigate, and respond to fraud, DDoS attacks, account compromise, AUP violations, and other abusive or unlawful activity.
3.6 Special categories of personal data
We do not intentionally request special categories of personal data, such as data revealing health, religion, political opinions, trade union membership, biometric data, or similar sensitive information.
If you choose to process such data through our services, you are responsible for ensuring that you have a valid legal basis and that all legal requirements are met. Section 12 applies where we process such data on your behalf as part of the hosting service.
- Purposes and Legal Bases
We process personal data only where we have a valid legal basis under applicable law.
4.1 Contract performance
We process personal data where necessary to perform our contract with you, including to:
a) create and manage your account;
b) provision, operate, maintain, suspend, migrate, renew, and terminate services;
c) provide customer support and incident handling;
d) process orders, invoices, renewals, and payments; and
e) communicate important service-related information.
The legal basis for this processing is Article 6(1)(b) GDPR.
4.2 Legal obligations
We process personal data where necessary to comply with legal obligations, including to:
a) maintain accounting, bookkeeping, tax, and invoice records;
b) comply with anti-fraud, anti-abuse, law-enforcement, and regulatory obligations;
c) respond to legally valid requests from courts or competent authorities; and
d) comply with data protection obligations, including breach response and data subject rights handling.
The legal basis for this processing is Article 6(1)(c) GDPR.
4.3 Legitimate interests
We process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. These interests include:
a) securing, monitoring, and maintaining our systems, infrastructure, and services;
b) preventing fraud, abuse, DDoS attacks, unauthorized access, and misuse of the platform;
c) diagnosing technical issues, ensuring stability, and improving service quality;
d) enforcing our Terms of Service, AUP, and related policies; and
e) establishing, exercising, or defending legal claims.
The legal basis for this processing is Article 6(1)(f) GDPR.
4.4 Consent
Where required, we process personal data based on your consent, including for optional marketing communications or other non-essential processing that requires prior permission.
The legal basis for this processing is Article 6(1)(a) GDPR.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Storage Location and Retention
5.1 Storage location
Minexnodes aims to store and process personal data within the European Union and European Economic Area (EU/EEA), including core infrastructure, primary databases, and operational backups, subject to the use of service providers described in Section 8.
5.2 Account data retention
We retain account and profile data for as long as your account remains active and for as long as necessary to manage the contractual relationship.
If your account is closed, we will generally delete, anonymise, or pseudonymise account-level personal data within a reasonable period, typically around fourteen (14) days, unless longer retention is required or permitted by law or is necessary for disputes, fraud prevention, abuse handling, security, or legal claims.
5.3 Billing and accounting retention
Billing, invoice, transaction, and accounting records may be retained for the period required under applicable law, including Swedish bookkeeping and tax rules, which may require retention for at least seven (7) years after the end of the relevant financial year.
5.4 Backups and logs
Operational backups, snapshots, and system logs may retain historical copies of data for limited periods necessary for service continuity, security, disaster recovery, incident investigation, and operational resilience.
Backup sets may be retained for approximately four (4) weeks or another reasonable operational period, after which they are overwritten, rotated, or deleted in the ordinary course of operations.
5.5 Retention after suspension or termination
Where a service is suspended, expires, or is terminated, related service data may be deleted in accordance with our Terms of Service and operational retention schedules. You remain responsible for maintaining your own independent backups.
- Your Rights
Subject to applicable law, you may have the following rights in relation to your personal data:
a) the right of access;
b) the right to rectification;
c) the right to erasure;
d) the right to restriction of processing;
e) the right to data portability;
f) the right to object to certain processing based on legitimate interests;
g) the right to withdraw consent where processing is based on consent; and
h) the right to lodge a complaint with a competent supervisory authority.
If you are in the EEA, you may lodge a complaint with IMY in Sweden or with the supervisory authority in your country of residence, work, or the place of the alleged infringement.
We may request reasonable information to verify your identity before acting on a rights request.
- Security Measures and Breach Handling
7.1 Security measures
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
These measures may include, where appropriate:
a) encryption in transit;
b) access controls and least-privilege access management;
c) logging and monitoring of security-relevant events;
d) firewalls, filtering, and abuse-prevention systems;
e) infrastructure hardening, updates, and patching; and
f) internal procedures designed to limit access to personal data to those who need it for support, security, legal, or operational reasons.
No internet-connected service can be guaranteed to be completely secure, and you are also responsible for securing systems, software, credentials, and data under your own control.
7.2 Personal data breaches
Where required by applicable law, Minexnodes will investigate personal data breaches and take appropriate mitigation steps.
If a breach is notifiable under GDPR, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Where legally required, and where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay.
- Recipients, Service Providers, and International Transfers
8.1 Recipients and service providers
We may share personal data with selected third-party providers where necessary to operate our services, including:
a) payment processors and anti-fraud providers;
b) datacenter, server, or infrastructure providers;
c) DNS, routing, security, DDoS mitigation, and networking providers;
d) email delivery, monitoring, and support tooling providers; and
e) legal, tax, accounting, or compliance advisors where necessary.
8.2 Sub-processors
Where Minexnodes processes customer personal data on behalf of a Client, these third parties may also act as sub-processors.
A current list of key sub-processor categories, and where appropriate named providers, may be published on our website or made available upon request.
8.3 International transfers
Minexnodes aims to keep processing within the EU/EEA. However, some providers may process or access personal data outside the EU/EEA.
Where personal data is transferred outside the EU/EEA, we will seek to ensure that such transfer takes place only where lawful, including on the basis of:
a) an adequacy decision of the European Commission; or
b) appropriate safeguards such as Standard Contractual Clauses or equivalent lawful mechanisms.
8.4 No sale of personal data
We do not sell personal data and do not disclose personal data to third-party advertisers for their own advertising purposes.
- Cookies and Similar Technologies
We use cookies and similar technologies only to the extent reasonably necessary for website and service functionality, security, authentication, abuse prevention, and session management.
We do not use non-essential marketing or advertising cookies without prior consent where such consent is required by law.
If we later introduce non-essential analytics, marketing, or similar tracking technologies, we will provide additional notice and any required consent mechanism before doing so.
- Marketing Communications
We may send service-related and transactional communications without separate marketing consent where such messages are necessary for account management, security, billing, maintenance, legal notices, or service delivery.
We will send promotional or marketing communications by email only where permitted by law and, where required, only with your prior consent.
You can opt out of marketing communications at any time by using the unsubscribe function or by contacting us.
- Legal Requests and Access to Data
11.1 Disclosure to authorities
We may disclose personal data to courts, law-enforcement authorities, regulators, or other competent bodies only where we have a valid legal basis to do so.
11.2 Notice to affected persons
Where legally permitted, we may use reasonable efforts to notify the affected Client before disclosing data, unless such notice would be unlawful or prohibited.
11.3 Internal access
We will access customer data only to the extent reasonably necessary for purposes such as:
a) complying with legal obligations;
b) responding to abuse, fraud, or security incidents;
c) carrying out support or restoration tasks requested by the Client; or
d) protecting the integrity, security, or continuity of the services.
- Customer Content and Controller–Processor Relationship
12.1 When you are the controller
If you use Minexnodes services to host or process personal data relating to your own players, customers, users, staff, or community members, you generally act as the data controller for that processing.
This may include, for example, usernames, IP addresses, player logs, chat logs, support data, customer records, or application data stored on your hosted services.
12.2 When Minexnodes is the processor
To the extent Minexnodes processes such personal data on your behalf in providing the hosting services, Minexnodes acts as your data processor.
Unless a separate written data processing agreement applies, this Section 12 forms the data processing terms between you and Minexnodes for the purposes of Article 28 GDPR, insofar as Minexnodes acts as processor for personal data under your control.
12.3 Subject matter, duration, nature, and purpose
The subject matter of the processing is the provision of hosting infrastructure and related technical services.
The duration of the processing is the period during which Minexnodes provides the relevant services and any limited post-termination retention period required for operational, legal, or security reasons.
The nature of the processing may include storage, hosting, transmission, organisation, access on support request, backup, deletion, and other operations strictly necessary to provide the services.
The purpose of the processing is to provide, maintain, secure, support, and, where applicable, restore the hosting services ordered by the Client.
12.4 Types of personal data and categories of data subjects
The personal data processed may include any personal data that the Client chooses to host or process using the services.
The categories of data subjects may include the Client’s end users, players, customers, website visitors, employees, contractors, or community members.
12.5 Minexnodes’ processor commitments
Where Minexnodes acts as processor, Minexnodes will:
a) process personal data only on documented instructions from the Client, including as reflected in the Client’s use of the services and configurations, unless otherwise required by law;
b) ensure that persons authorized to process personal data are subject to appropriate confidentiality obligations;
c) implement appropriate technical and organisational measures to protect the personal data;
d) assist the Client, where reasonable and proportionate, with data subject requests, security incidents, and compliance obligations relating to processing under Minexnodes’ control;
e) delete or return personal data at the end of the provision of services, unless retention is required by law or reasonably necessary for security, anti-fraud, abuse handling, dispute management, or legal claims; and
f) make available information reasonably necessary to demonstrate compliance with this Section 12, subject to reasonable confidentiality, security, and proportionality limits.
12.6 Sub-processors
The Client authorizes Minexnodes to engage sub-processors where reasonably necessary to provide the services.
Minexnodes will use commercially reasonable efforts to engage providers that publish or offer data protection terms appropriate to the nature of the services they provide.
Where required by law, Minexnodes will remain responsible for the performance of its sub-processors to the extent provided under applicable data protection law.
12.7 Client responsibilities
Where you act as controller, you are responsible for:
a) ensuring that you have a valid legal basis for your processing;
b) providing any required privacy notices to your end users;
c) handling data subject rights requests directed to you as controller;
d) determining retention periods, access policies, and lawful processing purposes for your own hosted data; and
e) ensuring that any use of the services complies with applicable data protection law.
If you process special categories of personal data or other sensitive data using the services, you are responsible for ensuring that this is lawful, necessary, and appropriately protected.
- Children and Minors
Our services are contractual hosting services and are not primarily directed to children.
We do not knowingly allow independent account registration by children who lack legal capacity to enter into the contract under applicable law.
Where a minor uses the services under the responsibility of a parent, guardian, or other authorised representative, that person remains responsible for the account, the use of the services, and compliance with applicable law.
If we become aware that personal data has been collected from a child in a manner that does not comply with applicable law, we may delete the data, restrict the account, or request verification or parental authorization as appropriate.
- Contact Details
For privacy-related questions, requests, or concerns, you may contact Minexnodes using the contact details published on our website or client area.
Where designated, the following addresses may be used:
support[@]minexnodes.com — general support and privacy requests
abuse[@]minexnodes.com — abuse, misuse, and security-related matters
legal[@]minexnodes.com — legal notices and formal privacy-related correspondence
We may request sufficient information to verify your identity and the scope of your request before responding.
- Changes to This Privacy Policy
Minexnodes may update this Privacy Policy from time to time to reflect changes in law, regulation, technology, service design, operational practice, or risk profile.
Where required by law, we will provide reasonable notice of material changes before they take effect.
The latest version of this Privacy Policy will be published on our website and will indicate the date of the most recent update.