Legal
Privacy Policy
This policy explains how Vyron processes personal data across its website, account dashboard, support system and connected self-hosted panels.
1. Controller
The controller for the Vyron website and account services is Bernd Springer, operating under the names Vyron and Vyron Technology.
A self-hosted panel operator may be a separate controller for data processed on that operator's infrastructure.
2. Website delivery and server logs
When the website or API is accessed, technical data such as IP address, timestamp, requested URL, response status, referrer, browser information and security signals may be processed to deliver the service, prevent abuse and diagnose errors.
Cloudflare may process connection and security data as a network, delivery and protection provider. The legal bases are Article 6(1)(f) GDPR and, where necessary, Article 6(1)(b) GDPR.
3. Cookies and browser storage
Vyron uses necessary browser storage for login sessions, security state, interface preferences and consent choices. This may use secure cookies, local storage or session storage.
Optional analytics and referral storage is used only after consent. Consent can be changed through Cookie settings in the site footer.
4. Referral and usage analytics
After consent, Vyron may record referral parameters such as ?ref=googleads, ?ref=redditads, ?ref=tiktokads, ?ref=metaads, ?ref=chatGPT, ?ref=producthunt and ?ref=youtube to measure campaign sources.
The legal basis is consent under Article 6(1)(a) GDPR. Aggregated statistics may be retained when they no longer identify a person.
5. Accounts and authentication
Registration and login require data such as username, email address, password hash, account and subscription status, sessions, legal acceptance and security events. Passwords are stored as cryptographic hashes.
The legal bases are Article 6(1)(b), Article 6(1)(c) and Article 6(1)(f) GDPR.
6. Panels, teams and API data
When a panel is linked, Vyron may process panel identifiers, display names, domains or network addresses, ownership, sub-user roles, permissions, API-key metadata and audit records.
Minecraft server files and console content normally remain on the panel owner's infrastructure. Explicitly used features may transmit commands, status data, uploads or diagnostics through the Vyron API.
7. Installation and operational telemetry
Installers and panels may report installation events, created or deleted server records, version information, update status and startup errors. Error reports may contain relevant log excerpts. Do not place secrets or unrelated personal data in server names, paths or logs.
8. Support, feedback and uploaded images
Support tickets and feedback may contain a username, messages, status, timestamps and uploaded images. Tickets are visible only to the submitting user and authorized support or administrative personnel according to access rules.
Do not upload secrets, identity documents or sensitive data unless necessary. Authorized administrators may remove tickets and attachments for support, security or legal reasons.
9. Transactional email
Vyron may send account, security, billing and support notifications. Support notifications can include the latest ticket message. The configured email provider may receive the recipient address, sender data, content and delivery metadata.
10. Payments and donations
PayPal processes payment and subscription data when selected at checkout. Vyron receives transaction identifiers, status, plan, amount and limited billing information. Full card or bank credentials are not stored by Vyron.
The Ko-fi donation widget loads only when opened by the user. PayPal and Ko-fi process data under their own privacy policies.
11. Recipients and international transfers
Data may be disclosed where necessary to providers such as Cloudflare, the configured email provider, PayPal, authorized support staff and public authorities where legally required.
Where providers process data outside the European Economic Area, transfers rely on an adequacy decision, the EU-US Data Privacy Framework, standard contractual clauses or another valid GDPR safeguard where required.
12. Retention
Data is retained only as long as needed for the account relationship, security, support, billing and statutory records. Expired sessions, old support records and operational logs may be deleted or anonymized when no longer required.
Mandatory commercial and tax records are kept for the periods required by German law. Backups may remain for a limited additional period until overwritten.
13. Data-protection rights
Subject to the GDPR, users may request access, correction, deletion, restriction, portability and objection. Consent may be withdrawn for future processing. Users may also complain to a competent supervisory authority.
Requests can be submitted through Support & Feedback. Additional verification may be required to protect the account.
14. Security and policy changes
Vyron uses appropriate technical and organizational safeguards against unauthorized access, loss and alteration. No online service can guarantee absolute security.
This policy may be updated when services, providers or legal requirements change. The current version and effective date are published here.