Exylia

Exylia Analytics

Data Processing Agreement

Last updated October 5, 2026

The terms under which we process your players' data on your behalf, as required by article 28 of the GDPR and by Chilean data protection law. It applies automatically to every workspace owner and forms part of the Terms of Service.

1. Parties and scope

This agreement is between the owner of a workspace in Exylia Analytics (the "Customer", controller) and Cristobal Aranda, domiciled in Chile (the "Processor"). It applies to the personal data the Processor processes on the Customer's behalf through the Service, mainly data about the players of the Customer's servers ("Customer Personal Data"). It is accepted together with the Terms of Service and lasts as long as the Customer has a workspace, plus the time needed to delete its data.

Data about the Customer's own account and its members is processed by the Processor as controller under the Privacy Policy, not under this agreement.

2. Details of the processing

  • Subject matter and purpose: collecting, storing, aggregating and displaying analytics about the Customer's Minecraft servers, and the functions of the Service the Customer uses.
  • Nature: collection through the ExyliaAnalytics plugin and connected integrations, storage, aggregation, consultation, display and deletion.
  • Data subjects: players of the Customer's servers, members of its staff (as issuers of punishments) and buyers in its connected store.
  • Categories of data: as listed in section 3 of the Privacy Policy, according to the modules enabled: Minecraft UUID and username, session times, earlier play dates and total playtime from the server's own records, hostname, client version, brand and language, country and network operator, keyed hash and, optionally, encrypted IP address, activity counters, votes, punishments, ranks, placeholder values, economy, anticheat alerts, custom events and purchases.
  • Special categories: none are expected. The Customer must not configure the Service to send them.
  • Duration: raw events 90 days, encrypted IP addresses 90 days, the rest while the workspace exists or until the Customer erases it.

3. Processor obligations

The Processor will:

  • Process Customer Personal Data only on the Customer's documented instructions, which are these terms and the configuration the Customer makes in the Service, unless the law requires otherwise; in that case it will inform the Customer first, unless the law forbids it. It will tell the Customer if it believes an instruction infringes data protection law.
  • Ensure that anyone authorised to process the data is bound by confidentiality.
  • Apply the security measures of section 5.
  • Not use Customer Personal Data for its own purposes, sell it, or combine it with data of other Customers, except for aggregate figures that identify no person or Customer and are used only to operate and improve the Service.
  • Assist the Customer, taking into account the nature of the processing, in answering data subjects' requests, in security, in breach notification and in any data protection impact assessment or prior consultation.
  • Make available the information needed to demonstrate compliance with this agreement and allow reasonable audits, as described in section 8.

4. Customer obligations

The Customer is responsible for the lawfulness of the collection: it will have a legal basis, inform its players (for example with the notice in section 11), enable only the modules it needs, not send sensitive data, and respond to its players' requests. It guarantees that its instructions comply with the law. Creating an API token is an instruction to disclose the player data within that token's scopes to the third-party tool the Customer gives it to, for which the Customer is responsible.

5. Security measures

  • Encryption in transit (TLS) between the plugin, the network provider and the Processor's servers, and for access to the dashboard.
  • IP addresses stored only as an HMAC-SHA256 hash with a secret unique to each workspace; optionally encrypted with AES-256-GCM with per-workspace derived keys and deleted after 90 days. Integration secrets encrypted with AES-256-GCM.
  • Tokens for servers, sessions and invitations stored only as hashes; sign-in through Discord OAuth with PKCE.
  • Logical separation of each Customer's data by workspace in every table and query, and role-based permissions within each workspace, including a specific permission to view IP addresses.
  • Databases reachable only from the Processor's internal network, database users with minimum privileges (read-only for the dashboard) and query logging disabled.
  • Rate limiting and signature verification of incoming webhooks.
  • Automatic deletion of raw events after 90 days and backups rotated within 30 days.

6. Sub-processors

The Customer gives general authorisation for the Processor to use sub-processors. The current ones are:

  • Cloudflare, Inc. (United States; global network): DNS, TLS termination and network protection for all traffic, including the batches sent by the plugin.
  • Functional Software, Inc. "Sentry" (United States): error reports, which may occasionally include fragments of the request that caused the error.

The Service is hosted on servers operated by the Processor itself in Chile. Services the Customer chooses to connect (such as its Tebex store or an AI provider it configures) act on the Customer's instructions and are not sub-processors of the Processor. Player head images are loaded by the browser of the Customer's staff directly from mc-heads.net.

The Processor will impose on each sub-processor data protection obligations equivalent to these and remains responsible for their compliance. It will announce any new sub-processor in the dashboard or by email at least 30 days in advance; the Customer may object on reasonable grounds and, if no solution is found, delete its workspace.

7. Data subject requests and erasure

The Customer can erase all of a player's data in its workspace from Settings, which completes within 24 hours, and can disable modules or servers to stop collection. If a data subject contacts the Processor directly, the Processor will pass the request on to the Customer without undue delay and will not answer it on its own unless the Customer instructs it to.

8. Breaches and audits

The Processor will notify the Customer without undue delay, and in any case within 48 hours of becoming aware of it, of any personal data breach affecting Customer Personal Data, with the information available at the time: its nature, the categories and approximate number of people and records affected, likely consequences and the measures taken or proposed. It will supplement the information as it becomes available.

On written request, no more than once a year unless there has been a breach or an authority requires it, the Processor will answer reasonable questionnaires about its compliance and provide the relevant documentation. On-site audits, if necessary, will be agreed in advance, at the Customer's expense and subject to confidentiality.

9. End of processing

When the Customer deletes its workspace, the Processor deletes all Customer Personal Data within 24 hours from its active systems and within 30 days from backups, unless the law requires it to be kept. Before deleting, the Customer can consult in the dashboard the data it needs.

10. International transfers and law

The Processor is in Chile, a country without an adequacy decision of the European Commission. For Customer Personal Data subject to the GDPR, the parties incorporate by reference the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914: Module Two (controller to processor), or Module Three (processor to processor) when the Customer is itself a processor. For those clauses: clause 7 (docking) applies; in clause 9 option 2 (general authorisation) applies with the notice period of section 6; the optional wording of clause 11 does not apply; in clauses 17 and 18 the law and courts of Ireland apply; Annex I is completed with sections 1 and 2 of this agreement, Annex II with section 5 and Annex III with section 6. For data subject to UK law, the International Data Transfer Addendum issued by the ICO is incorporated in the same way. In case of conflict, the clauses prevail over this agreement.

In all other respects this agreement is governed by the law and courts set out in the Terms of Service, and the liability limits of those terms apply to it to the extent the law allows.

11. Notice template for your players

Customers can publish this text, adapted to their modules, in their rules, website or Discord:

"This server uses Exylia Analytics to understand how the server is used and to improve and moderate it. When you connect, we record your Minecraft UUID and username, when you play, the address you connected to, your client version and language, the country and network derived from your IP address (your IP is stored only as a hash), and counts of your activity (not the content of your chat or commands). [Also: votes, punishments, ranks, economy, anticheat alerts and store purchases, as applicable.] We are responsible for this data; Exylia Analytics processes it on our behalf. Detailed events are deleted after 90 days. To access or delete your data, contact [server contact]. More information: https://analytics.exylia.net/privacy"