Data Processing Agreement
Article 28 of the GDPR — Last updated: 24/07/2026
This agreement applies whenever you enable a feature through which CraftLauncher processes personal data of your players on your behalf: in-launcher community (messaging, rooms, voice calls), crash reports, or player moderation. In this context, you are the data controller and CraftLauncher is the processor. It forms an integral part of the Terms of Service and complements the Privacy Policy.
It does not apply to the data of your own CraftLauncher account (email, billing, launchers), for which CraftLauncher itself is the data controller.
1. Parties
- The data controller: you, the holder of the CraftLauncher account, administrator of the launcher(s) concerned (hereinafter "the Client").
- The processor: scoogend, publisher of CraftLauncher, contact@craftlauncher.app (hereinafter "CraftLauncher").
2. Purpose, nature, aim and duration
| Purpose | Providing infrastructure that lets the Client offer their players an in-launcher community (presence, friends, messaging, rooms, voice calls), crash reports and moderation tools. |
| Nature of operations | Collection, recording, organization, storage, encryption, consultation, transmission (relaying), erasure. |
| Aim | Allowing the Client's players to communicate with each other within the Client's community, and allowing the Client to moderate it and ensure the technical stability of their launcher. |
| Duration | Duration of the Client's subscription, for as long as the relevant feature remains enabled. |
3. Categories of data and data subjects
Data subjects: players using a launcher published by the Client.
Categories of data:
- Game identity: Minecraft username and UUID (verified with Microsoft);
- Communication content: room messages, private messages (encrypted at rest);
- Social graph: friends, requests, blocks, room membership;
- Presence data: online / in-game / server joined;
- Technical data: salted IP address fingerprint (anti-abuse), crash logs, playtime;
- Reports: reason, reported content, author and reporter;
- Proof of consent: timestamp of the notice acknowledgment and age declaration.
No sensitive data within the meaning of article 9 of the GDPR is collected. The voice call audio stream is never recorded.
4. CraftLauncher's obligations
- Documented instructions: only process data on the Client's instructions, expressed through the settings they enable in their dashboard, and through this agreement;
- Confidentiality: only allow access to data to persons bound by a confidentiality obligation, and strictly to the extent necessary;
- Security: implement the measures in article 5 below (art. 32 GDPR);
- Assistance: help the Client respond to requests from their players to exercise their rights. In practice, players exercise their right to erasure directly from the launcher: no action is required from the Client;
- Breach notification: inform the Client without undue delay after becoming aware of a personal data breach concerning them, providing the information needed for their own notification to the CNIL (art. 33.2 GDPR);
- Register: maintain a record of categories of processing activities carried out on behalf of the Client (art. 30.2 GDPR);
- Alert: inform the Client if an instruction appears to constitute a breach of the GDPR.
5. Security measures (art. 32)
- Encryption of communications at rest: room messages and private messages encrypted with AES-256-GCM. The database never contains the plaintext;
- Encryption in transit: TLS for all communications; end-to-end DTLS-SRTP for voice calls;
- IP address minimization: never stored in plaintext, only as a salted, non-reversible SHA-256 fingerprint;
- Protection against IP address exposure between players: voice calls are relayed by default, so no participant can discover another's IP address;
- Strict siloing: all data is isolated per launcher; no community has visibility into another;
- Strong player authentication: verification of Minecraft account ownership with Microsoft before any access;
- Confidentiality of correspondence: neither CraftLauncher, the Client, nor their moderators have access to players' private messages, except for explicitly reported content;
- Rate limiting and anti-abuse across all operations;
- Audit log of administration actions.
6. Sub-processors
The Client authorizes CraftLauncher to use the following sub-processors. CraftLauncher holds them to the same obligations as this agreement and remains fully responsible for their performance.
| Sub-processor | Processing entrusted | Location |
|---|---|---|
| Cloudflare, Inc. | Community hosting (Workers, D1, Durable Objects), file storage (R2), voice call relaying (TURN) | European Union (EU jurisdiction enforced) |
| Clouding.io | Launcher build server | European Union |
| Microsoft / Mojang | Verification of the player's game identity (no identifier transmitted to CraftLauncher) | Standard contractual clauses |
CraftLauncher will inform the Client of any planned change regarding the addition or replacement of a sub-processor, at least 30 days in advance, by email and dashboard notification. The Client has this period to raise objections; if they do, they may cancel their subscription without penalty.
7. Rights of data subjects
It is the Client's responsibility, as data controller, to inform their players and respond to their requests. CraftLauncher provides the tools that make this obligation practically achievable:
- an information notice shown to the player in the launcher before any processing (art. 13);
- an age declaration (15 years) timestamped and kept as proof of diligence;
- a self-service erasure from the launcher (art. 17), with no action needed from the Client;
- a reporting mechanism and moderation and sanction tools.
8. Fate of data at end of contract
When a launcher is deleted, or the subscription ends, all data of the community concerned is deleted: messages, social graph, rooms, reports and members. This deletion is final and leaves no copy. The Client may request an export of this data before deletion, by writing to contact@craftlauncher.app.
9. Audit
CraftLauncher makes available to the Client all information necessary to demonstrate compliance with the obligations of article 28 of the GDPR, and allows audits, including inspections, to be carried out by the Client or an auditor they appoint, subject to reasonable notice and under conditions that do not affect the security of other clients. Any request should be sent to contact@craftlauncher.app.