Ecstacy Anticheat Logo ECSTACY
Home Benchmarks Docs Compatibility Status Support Login
Login See Plans

Data Processing Agreement

Last updated: 12 June 2026. This Data Processing Agreement ("DPA") forms part of the Terms of Service between the server owner who installs and operates Ecstacy Anticheat (the "Customer", acting as Data Controller) and Simone B., operator of Ecstacy Anticheat (the "Processor", "we"). It governs the processing of in-game player personal data that we carry out on the Customer's behalf, and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR). Where this DPA conflicts with the Terms on the subject of player-data processing, this DPA prevails.

1. Roles of the Parties

For data about the Customer's own account, licence and billing, Ecstacy acts as an independent Controller (see our Privacy Policy). For data about the players who connect to a server running Ecstacy, the Customer is the Controller and Ecstacy is the Processor, processing only on the Customer's documented instructions. The act of installing and configuring the Software constitutes those instructions.

2. Subject Matter, Duration, Nature & Purpose

  • Subject matter & purpose: detecting and reporting cheating on the Customer's Minecraft server(s) using behavioural analysis and machine-learning models.
  • Duration: for the term of the Customer's active licence, plus the limited retention periods described in section 6.
  • Nature of processing: collection, structuring, storage, analysis, scoring, display to the Customer's authorised staff, and deletion/aggregation.

3. Categories of Data Subjects & Personal Data

  • Data subjects: players connecting to the Customer's server(s).
  • Personal data: player Minecraft UUID and username (cleartext); behavioural gameplay data (movement, rotation, packet-timing features); resulting detection records and model scores.
  • Limited processing: we never receive player IP addresses in clear text. For the alternative-account fingerprint feature, the Customer's server sends an encrypted, irreversible form of a player's IP address or subnet; the original address cannot be recovered from it and it is used only to recognise repeat networks behind multiple accounts. Raw player IP addresses stay on the Customer's server and never reach Ecstacy. We do process the IP/hardware identifier of the server itself, solely for licence-abuse prevention (that is Customer data, not player data).
  • We do not intentionally process special-category data. The Customer must not configure the Software to send us such data.

4. Processor Obligations

As Processor, we undertake to:

  • process player personal data only on the Customer's documented instructions, including for transfers, unless required otherwise by EU or Member-State law (in which case we will inform the Customer unless that law prohibits it);
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (section 7);
  • respect the conditions for engaging sub-processors (section 5);
  • assist the Customer, by appropriate technical and organisational measures, in responding to data-subject rights requests and in meeting its obligations under Articles 32–36 GDPR;
  • at the Customer's choice, delete or return all player personal data at the end of the service and delete existing copies, unless retention is required by law;
  • make available the information necessary to demonstrate compliance and allow for and contribute to audits (section 8).

5. Sub-Processors

The Customer grants general authorisation for us to engage the sub-processors below, each bound by data- protection terms no less protective than this DPA. We will give reasonable notice of any intended addition or replacement and the Customer may object on reasonable data-protection grounds.

  • Cloudflare, Inc.: CDN, DDoS protection, bot mitigation (traffic in transit).
  • EU-based hosting / infrastructure provider: compute and database hosting within the European Union.

Our payment provider (Stripe) is not a player-data sub-processor. It processes Customer billing data as an independent controller, as described in the Privacy Policy.

6. Retention & Deletion

Raw behavioural records are kept for a limited period and then deleted or aggregated. Detection records flagged for human review are kept while the review is open. On licence termination, or on the Customer's written request, we delete or return the player personal data we hold for that Customer within a reasonable period, subject to any overriding legal-retention obligation.

7. Security Measures

Taking account of the state of the art and the risks, we maintain measures including: encryption of data in transit (TLS) across our service mesh; least-privilege access controls and authenticated, audited admin access; network isolation of internal services; storage of licence keys only as irreversible hashes; segregation of customer and player data; and logging and monitoring to detect and respond to incidents.

8. Audit & Cooperation

On reasonable prior written notice and no more than once per year (unless required by a supervisory authority), we will make available information reasonably necessary to demonstrate compliance with this DPA and cooperate with audits conducted by the Customer or a mandated independent auditor bound by confidentiality, in a manner that does not compromise the security or confidentiality of other customers.

9. Personal Data Breach

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's player data, and provide the information the Customer reasonably needs to meet its own notification obligations under Articles 33–34 GDPR.

10. International Transfers

Player personal data is processed within the European Union. If any processing or sub-processing would involve a transfer outside the EU/EEA, it will be carried out only under an appropriate Article 46 GDPR safeguard (such as the European Commission's Standard Contractual Clauses).

11. Liability & Governing Law

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by Italian law, consistent with the governing-law clause of the Terms.

12. Contact

For any matter relating to this DPA, contact the Processor at support@ecstacy.ac.

This document is provided for transparency and may be updated; material changes will be announced. It is a standard-form agreement and does not constitute legal advice.

Ecstacy ECSTACY

Product

Home Benchmarks Docs Compatibility Status

Legal

Privacy Terms DPA EULAWithdrawal

© 2026 Ecstacy Anticheat. All rights reserved.