Privacy Notice
This notice explains what personal data Falix collects, why we collect it, who can access it, and the rights and choices available to you.
Jump to a section
1. Who we are #
Falix is operated by SIA Baltijas Pakalpojumi, a company registered in Latvia. For your account and this website, we are the data controller and your point of contact for privacy matters.
Falix is operated by SIA Baltijas Pakalpojumi, registration number 40203476615, VAT LV40203476615, Matīsa iela 61–21, Rīga, LV-1009, Latvia. Managing director: Lilija Blūme.
For your account, billing, this website and the client panel, we are the data controller — the company responsible for deciding how your personal data is processed. For data stored inside a customer's game server, such as their players' activity, the roles are different and are explained in section 3.
Privacy questions and requests should be sent to [email protected]. Legal notices should be sent to [email protected].
Who this notice covers
- Account holders — this notice applies to you in full, on every plan.
- Visitors to falixnodes.net without an account — see sections 2 (website visitors) and 5.
- Players on servers hosted with us — see section 3.
- Business customers, resellers and API partners — see section 10 in addition to the rest of this notice.
This notice is published in English and Latvian. In the event of a discrepancy between the two versions, the English version prevails.
2. What we collect #
We collect your email address and password at registration (a username is optional); your IP address at registration and login; device information for your session overview; billing details if you purchase a plan; the content of your support and AI-assistant conversations; and the content you store on your servers. We do not ask for your legal name or date of birth to create an account.
Account registration
Creating an account requires an email address and a password; without these the account cannot be created. A username is optional at registration — we encourage choosing one, but it is not reserved at sign-up and can be set or changed later in your profile. Passwords are stored in securely hashed form and cannot be read by us. If you register through Discord or Google instead, we receive your email address and your Discord or Google account identifier, along with your Discord username and avatar.
At registration we also record your IP address (stored encrypted), the country derived from it, and a timestamp. The country determines which server locations are available on the free plan; the IP address supports the detection of duplicate accounts created to circumvent limits or bans.
Logins and sessions
Each login records a timestamp and your IP address (encrypted). Your session overview under Profile → Sessions lists the device type, browser, platform and country of each active session, and allows you to terminate any of them. Significant actions in the panel — starting a server, changing a setting, inviting a sub-user — are recorded in an activity log together with your IP address and browser details, providing an audit trail for both you and us.
If you enable two-factor authentication or passkeys, we store the data required to verify them: the 2FA secret, a hashed backup code, and the public key and device name of each passkey.
Payments
Payments are processed by Stripe, PayPal or Revolut, covering cards and local payment methods. Your full card or payment account details are submitted to the payment provider and never reach our systems. We store the payment method used, the provider's customer reference, the transaction amount, and your billing country and postal code, which are required for VAT calculation. For business purchases we additionally store the company name and VAT number in encrypted form, and validate the VAT number against the European Commission's VIES service. Invoices contain the name and address entered on them.
For gift card purchases, we collect the recipient's email address and your message in order to deliver the gift card.
Support and feedback
Support tickets store the text you write, attached files, linked servers, and any ratings you submit. Ticket messages are machine-translated so that staff can respond in your language; both the original and the translation are retained. The feedback widget transmits the page you were on, your browser and screen size, and the most recent lines of your browser's console output, which are frequently necessary to reproduce reported problems. Shared server logs are published under a link with an expiry date that you select.
The AI assistant
Conversations with the AI assistant are stored, including the context it gathers from your server. Please note: when you use the assistant on a server, it can read that server's files, configuration and logs as context, including content you did not paste into the conversation. The assistant's tool activity is logged together with your IP address for abuse prevention. Retention is described in section 8. The AI providers involved are listed in section 6. The assistant supports you in managing your server; it does not make decisions about your account.
Server content
Everything you store on your server resides on our infrastructure: world files, plugins, configuration, databases and backups. Console output and log files are stored as well, and they routinely contain your players' usernames, IP addresses and chat messages. A version history of file edits is retained so that changes can be reverted. Server resource metrics (CPU, memory, network) are recorded to operate the platform and to display usage graphs.
Connected services
The following integrations are optional, and each stores only what it requires: Google Drive backups (your Drive account email and an access token, encrypted), Git deployments via GitHub, GitLab, Codeberg or Bitbucket (an access token, encrypted), Discord webhooks (the webhook URL you provide), and server imports from another host (the FTP address and credentials you provide, used for the transfer).
Website visitors
Our own visitor statistics operate without cookies: the IP address and browser signature are converted into an anonymous token under a key that changes daily, and the token cannot be traced back to you. Forms on the website, such as starting a server or reporting a listing, are protected by Cloudflare Turnstile, which analyses the browser session to filter out automated traffic. If you subscribe to status updates, your email address is stored encrypted and requires confirmation through a verification link before any notification is sent.
3. Players on hosted servers #
If you play on a server hosted with us without holding a Falix account, the server owner is responsible for your data; we store and process it on their behalf. Please contact the server owner first, and contact us if that is not possible.
Servers hosted on Falix process data about the people who play on them: Minecraft usernames and UUIDs, IP addresses, chat messages contained in logs, whitelists and ban lists. For this data, the server owner is the controller and Falix acts as the processor: we store and process it so that the server can operate, and the owner determines its use. If you have questions about this data or would like it deleted, please contact the owner of the server you played on. If you cannot reach them or receive no response, contact [email protected] and we will assist.
Processing Falix performs in its own right
A limited amount of player data is processed by Falix for its own purposes, namely operating and protecting the platform. As a player, the following applies to you, based on data received from the server you connected to:
- Lobby sessions: when you join a server through our shared lobby, we record your Minecraft UUID and username together with join and leave times.
- Username resolution: Minecraft usernames are resolved to UUIDs through Mojang's public API, and the results are cached so that player lists display correctly.
- Network protection: connection metadata — source IP addresses, countries and network operators — is analysed to detect and mitigate attacks. Server owners can view aggregated summaries on their firewall page. Detailed connection records are retained only briefly.
- Abuse detection: player name patterns are analysed to identify bot networks and fake-player exploits.
This section is published so that players can find this information: in most cases we have no means of contacting you directly, because we receive only the data the game transmits to the server, which does not include contact details.
Information for server owners
Under data protection law, you are responsible for your players' data, particularly if your server is open to the public. We recommend informing your players about what you log and why, and deleting data you no longer need. A data processing agreement covering our processing on your behalf is available on request.
4. Why we use your data #
We process personal data for six purposes: providing the service, securing it, billing and accounting, communicating with you, advertising on the free plan (with your consent), and meeting legal obligations. Each purpose has a defined legal basis.
| Purpose | Data involved | Legal basis (GDPR) |
|---|---|---|
| Providing the service — account management, server operation, file storage, the client panel, customer support | Account data, server content, session data, tickets | Performance of a contract (Art. 6(1)(b)) |
| Security and abuse prevention — rate limiting, detection of duplicate accounts, VPN and bot detection, regional availability rules for the free plan, attack investigation, enforcement of suspensions | IP addresses, activity logs, device information, connection metadata | Legitimate interest (Art. 6(1)(f)): protecting our infrastructure and our users against abuse, fraud and attacks. A copy of the balancing assessment is available on request. |
| Billing and accounting — payments, invoices, VAT, refunds | Billing details, payment references, tax data | Performance of a contract; legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Communication — verification emails, password resets, receipts, crash notifications, ticket replies | Email address, notification content | Performance of a contract. Marketing email is handled separately and is sent only with consent (Art. 6(1)(a)); every message contains an unsubscribe link. |
| Advertising on the free plan — the revenue that funds free hosting | See section 5 | Consent (Art. 6(1)(a)), given or refused in the consent banner and withdrawable at any time |
| AI features — the assistant, log analysis, ticket translation | Your messages and the server context you invoke | Performance of a contract for built-in features; separate explicit consent for models that involve extended data sharing, requested before first use |
| Legal obligations and debt recovery | The data required by the specific obligation or claim | Legal obligation; legitimate interest in recovering outstanding amounts |
Automated enforcement
Certain protective measures run automatically: free servers receive periodic AFK checks, bot-like behaviour can cause a server to be stopped, and regional rules determine free-plan availability. Clear-cut violations detected by our systems can also lead to the automatic suspension of a server or account. These measures rely on defined rules and thresholds rather than profiling. If an automated measure affects you incorrectly, you can open a support ticket and the case will be reviewed by a member of staff, who can reverse it.
We apply the principle of data minimisation: we collect only what each purpose requires. We do not request your legal name to provide hosting; a name appears only on invoices, where tax law requires one.
7. Where your data is stored #
Account data is stored in the European Union (France), together with this website and our databases. Game servers are located in the United States, Canada, Germany, Brazil, Singapore and Australia, depending on the location you select. Full platform deployments in the United States and Singapore are planned; every transfer outside the EU is covered by a recognised safeguard.
| Region | Data stored | Transfer safeguard |
|---|---|---|
| France (EU) | Website, account database, panel data, encrypted backups | Not required — within the EU |
| Germany (EU) | Game servers in German locations | Not required — within the EU |
| United States | Game servers in US locations; AI routing (OpenRouter); certain processors listed above | EU–US Data Privacy Framework where the recipient is certified; otherwise Standard Contractual Clauses (2021/914) |
| Canada | Game servers in Canadian locations | European Commission adequacy decision |
| Brazil | Game servers in Brazilian locations | European Commission adequacy decision |
| Singapore & Australia | Game servers in those locations | Standard Contractual Clauses (2021/914) |
If you select a location outside the EU for a server, that server's content — including its world files, logs and its players' IP addresses — is stored in that country. We are expanding towards full platform deployments in the United States and Singapore; before account data is stored in those regions, this section and the change log will be updated.
Standard Contractual Clauses are the European Commission's approved contractual mechanism obliging the receiving company to maintain EU-level data protection. A copy of the clauses applicable to any transfer is available from [email protected]. One consideration should be stated plainly: authorities in third countries may have legal powers to compel disclosure from companies operating there. The safeguards described above exist to constrain such access, and encryption at rest limits what any disclosure could reach.
8. Retention periods #
Data is retained for the life of your account and removed when the account is deleted, after a 14-day cancellation window; certain operational logs are then retained only in de-identified form. Invoices are retained as required by tax law. Encrypted backups rotate out within approximately six months.
| Data | Retention period | Reason |
|---|---|---|
| Account, servers, settings, files | Until deleted by you, or with your account | Core content of the hosting service |
| Panel activity log | Life of the account; afterwards retained only in de-identified form | Investigation of account compromise and abuse |
| Login sessions | Life of the account; individual sessions can be terminated at any time | Account security overview |
| File version history | Life of the account | Recovery of unintended changes |
| AI conversations | Until you delete them or your account | Your conversation history stays available to you |
| Public API request logs | Life of the account | Debugging and abuse detection |
| Website visitor tokens | Under 48 hours; aggregate statistics 12 months | Cookieless analytics requires no longer period |
| Firewall connection details | A short rolling window; aggregates retained longer | Attack analysis requires only recent data |
| Shared log links | Until the expiry date you select | Determined by your selection |
| Invoices, payments, tax records | The period prescribed by Latvian accounting and tax law | Legal obligation; early deletion is not permitted |
| Encrypted backups | Recent snapshots rotate over 30 days; monthly archives within approximately 6 months | Disaster recovery |
Account deletion
You can delete your account under Profile → Settings; the request requires your password and, if enabled, a two-factor code. The process is as follows:
- Days 0–14: the account is deactivated and scheduled for deletion. Logging in during this period cancels the request. The waiting period protects accounts whose credentials have been compromised, since a deletion requested by an attacker can be reversed.
- Day 14: the account, its servers, worlds, files and databases are permanently deleted from live systems. This is a hard deletion, not a deactivation.
- Thereafter: residual copies within encrypted backups are removed as those backups rotate, within approximately six months.
The following survives deletion, in each case for a defined reason: invoices and payment records (tax law), the record of your deletion request (evidence that it was carried out), suspension and abuse records where they are needed to prevent re-registration by banned users, aggregate statistics that no longer identify you, and operational log entries from which references to your account (such as your username) have been removed. Server identifiers and their lifecycle dates are retained for infrastructure accounting.
9. Your rights #
You are entitled to access, correct, delete, restrict and receive a copy of your personal data. Any of these requests can be initiated with a single email to [email protected]. We respond within one month, free of charge.
- Access: you may request confirmation of what personal data we hold about you and receive a copy. A self-service export is not yet available; email us and we will compile and deliver your data within one month.
- Correction: your email address, username and profile can be corrected directly in the panel; for other data, contact us.
- Deletion: you can delete your account yourself (see section 8) or request deletion of specific data by email. Where we must refuse a request — for example, for invoices subject to statutory retention — we will state precisely what is refused and on what grounds.
- Restriction: you may request that specific processing be suspended while a dispute is resolved.
- Portability: you may receive the data you provided to us in a machine-readable format. Server files can be downloaded from the panel at any time.
- Withdrawal of consent: advertising consent is managed through the cookie settings; marketing email through the unsubscribe link; AI data-sharing consent through the assistant's settings. Withdrawal is as straightforward as giving consent and does not affect processing that occurred beforehand.
Where processing is based on legitimate interest (the security measures described in section 4), you may object on grounds relating to your particular situation by writing to [email protected]. We will cease the processing unless we can demonstrate compelling legitimate grounds that override your interests. An objection to direct marketing is absolute and will be honoured without further assessment.
We respond within one month. Where a request is particularly complex, the law permits an extension; if we need one, we will inform you within the first month and explain why. Exercising your rights is free of charge and has no effect on your service. We verify identity in proportion to the request, normally by requiring that it be sent from your account email address or confirmed within the panel.
If you are dissatisfied with our response, you may lodge a complaint with a supervisory authority. Our lead authority is the Latvian Data State Inspectorate (Datu valsts inspekcija, Elijas iela 17, Rīga, LV-1050, dvi.gov.lv); you may equally complain to the authority of the country in which you live or work. No fee or legal representation is required.
10. Businesses & partners #
For company purchases we store the billing identity required by tax law, in encrypted form. Sub-users see only the permissions you grant. API keys are stored hashed, and API request logs are retained for 30 days. A data processing agreement is available on request.
Purchasing as a company
The company name, VAT number, country and postal code are used on invoices and in VAT calculation; VAT numbers are validated against the EU VIES register. This data is stored encrypted and retained for the period required by accounting law. Invoices display the details entered on them; we recommend using a billing contact rather than a personal address where appropriate.
Teams and sub-users
You can invite collaborators to a server by email; the invitation address is stored encrypted, and invited users receive exactly the permissions you assign. Sub-user actions are recorded in the same activity log as your own, attributed to the acting user. Removing a sub-user revokes their access immediately.
API access and resellers
API keys are stored as hashes: we can verify a key but not recover it, so it should be stored securely on your side. Each API request is logged with its source IP address and endpoint for 30 days. If you resell hosting or build services on our API, you are the controller for your own customers' data, and our processing on your behalf is governed by a data processing agreement.
Data processing agreement (DPA)
If you require an agreement under Art. 28 GDPR — as a business customer, reseller, or a server owner whose players' data we process — contact [email protected]. Our standard DPA incorporates the processor list in section 6, and DPA holders are notified of processor changes before they take effect.
11. Security #
Passwords are hashed, sensitive fields are encrypted at rest, all traffic is encrypted in transit, and backups are encrypted before leaving our infrastructure. Staff access exists for support and abuse investigation and is logged.
Specifically: passwords are stored only in securely hashed form; stored IP addresses, connected-service tokens and invitation emails are encrypted at rest; API keys and two-factor backup codes are stored hashed; all connections are encrypted in transit; and backups are encrypted on our systems before transfer to storage. Two-factor authentication and passkeys are available free of charge, and we recommend enabling them — particularly for accounts whose servers support an active community.
Staff access
Support staff can view your account details and tickets. Access to servers is governed by a grant system: you authorise access from within a support ticket, the authorisation expires automatically, and you can revoke it at any time. Beyond this, a limited number of staff can access account data and servers directly when investigating abuse, resolving a live incident, or complying with a legal order. Such access is a measure of last resort, and staff actions in the panel are logged.
Incident notification
If a breach puts your data at risk, we will notify the supervisory authority within 72 hours as required by law, and inform you directly of what occurred, which data was affected, and what measures we are taking.
12. Users under 18 #
A Falix account requires a minimum age of 13. Between 13 and 16, depending on your country, some data-processing choices require a parent's or guardian's agreement. We do not collect your date of birth, and this notice is written to be understandable without legal knowledge.
Many Falix users are teenagers running their first server, and this notice is written with that audience in mind. If any part of it is unclear, please let us know at [email protected] so that we can improve the wording.
The applicable rules are as follows:
- You must be at least 13 years old to create an account. If we learn that an account belongs to someone under 13, we will close it.
- Within the EU, each country sets an age between 13 and 16 at which a person can consent to data processing on their own; in Latvia it is 13. If you are below the age applicable in your country, choices such as the advertising consent banner legally require the agreement of a parent or guardian. If you are uncertain, ask them — or simply decline: the free plan functions identically either way.
- Parents and guardians with questions about a child's account, or wishing to exercise a child's rights, can contact us at the address above; we will verify the relationship and assist.
Two points should be stated openly. We do not collect dates of birth, so we rely on the age you declare at registration. And on the free plan, advertisements — including personalised advertisements where consent has been given — are delivered to all users in the same manner, which is a further reason declining consent remains a genuine option.
13. Changes to this notice #
A dated change log is maintained on this page. For material changes, such as new processing purposes or new storage locations, we notify you in advance by email or through the panel rather than editing this page silently.
Change log
- 11 August 2026 — This notice was rewritten in full to make our data practices easier to understand and more transparent. It now names every company we work with, sets out exact retention periods in a single table, and adds dedicated sections for players on hosted servers, for users under 18, and for US state privacy rights, together with a storage-region overview of our infrastructure locations and planned expansion and the current list of our AI providers. It supersedes the notice dated 23 February 2026.
14. Contact #
Privacy requests and questions: [email protected]
Legal notices: [email protected]
Postal address: SIA Baltijas Pakalpojumi, Matīsa iela 61–21, Rīga, LV-1009, Latvia
General support matters are handled through a support ticket. Privacy rights requests are accepted only at [email protected] — a request submitted in a support ticket is not a valid submission, and you will be asked to resend it by email.
Addendum 1: EEA & UK #
This notice is written to GDPR standards for all readers; this addendum records the formal points.
- Controller: SIA Baltijas Pakalpojumi (details in section 1). Privacy matters are handled at [email protected].
- Legal bases for each purpose are set out in the table in section 4. Where processing relies on legitimate interest, the specific interest is identified there, and the balancing assessment is available on request.
- Lead supervisory authority: Datu valsts inspekcija, Elijas iela 17, Rīga, LV-1050, Latvia (dvi.gov.lv). You may equally lodge a complaint with the data protection authority of the country in which you live or work, in your own language. Complaints concerning cookies and advertising consent are handled directly by your national authority.
- United Kingdom: the same rights apply under UK GDPR; the competent authority is the Information Commissioner's Office.
- Transfers out of the EEA and UK are covered by the safeguards described in section 7; copies of the applicable clauses are available by email.
Addendum 2: US state privacy rights #
This addendum applies to residents of every US state with a comprehensive privacy law in force, and to corresponding laws as they take effect in the future. It uses the categories defined by those laws; where a state defines a term differently, the definition of your state applies.
Categories collected, sources and purposes
| Statutory category | Examples at Falix | Source | Purpose |
|---|---|---|---|
| Identifiers | Email address, username, IP address, Discord/Google identifiers | You; your device | Service provision; security |
| Commercial information | Plans purchased, payment references, invoices | You; payment providers | Billing; tax compliance |
| Internet or network activity | Panel activity, session and device details, pages visited | Your device | Service provision; security; advertising (free plan, with consent) |
| Geolocation (approximate) | Location derived from IP address, which can be accurate to roughly city level | Your device | Free-plan availability; VAT; security. We do not collect precise geolocation such as GPS coordinates. |
| User content | Server files, logs, support tickets, AI conversations | You; your players | Provision of the hosting service |
| Sensitive personal information | Account login credentials | You | Authentication only. We do not sell sensitive personal information or use it beyond the purposes permitted by law. |
“Sale” and “sharing”
We do not disclose personal data in exchange for payment. US privacy laws, however, define “sale” and “sharing” more broadly: delivering personalised advertising through third-party advertising companies qualifies, because the advertising services received in return count as valuable consideration. Under those definitions: on the free plan, with your consent, we sell and share identifiers and internet activity with the advertising partners named in section 6 for targeted advertising. These are the only categories sold or shared in the preceding 12 months, and only to those partners. Data of premium accounts is not disclosed to advertising partners from the panel.
To opt out of sharing: use the cookie settings, which apply per browser, or enable a Global Privacy Control signal in your browser. When our consent tool detects a legally recognised opt-out preference signal, it is applied as an opt-out of sale and sharing for that browser without further steps. No account is required, and opting out does not reduce the functionality of the free plan.
Consumers under 16: we do not knowingly sell or share the personal information of consumers under 16 years of age. We do not collect dates of birth and therefore act on the information available to us: where we learn that a user is under 16, their data is not sold or shared, and consent to such sharing is never assumed.
Your rights
Depending on your state, you have the right to know and access, correct, delete, and receive a portable copy of your personal information; to opt out of sale, sharing and targeted advertising; to limit the use of sensitive personal information; and to non-discrimination — exercising these rights does not affect the price or quality of the service. Requests may be submitted to [email protected]. We verify requests through your account email address, respond within 45 days, and provide reasons for any denial. An authorised agent may submit a request on your behalf with proof of authorisation. If a request is denied, you may appeal by replying to our response with the word “appeal”; the appeal is reviewed by a different person within 45 days, and our decision includes instructions for contacting your state attorney general if you disagree with the outcome.
Questions regarding this addendum may be directed to [email protected].
Exercise your choices
Most data management is available directly in your panel; anything else can be arranged by email.
SIA Baltijas Pakalpojumi · Matīsa iela 61–21, Rīga, LV-1009, Latvia