Privacy Policy

Last updated: 30.07.2026

1. Introduction

This Privacy Policy explains how Baggel ("we", "us", "our") collects, uses, stores, and protects personal data when you use our services.

Baggel is a community-operated project providing Minecraft servers, a website, Discord-based community services, and related moderation systems.

By using our services, you acknowledge that your personal data may be processed as described in this Privacy Policy.

2. Data Controller

Louis Liposcak

c/o IP-Management #11230

Ludwig-Erhard-Str. 18

20459 Hamburg

Contact Email: mail@baggel.de

For all privacy-related inquiries, data access requests, correction requests, or complaints, please contact us using the email address above or through our Discord support system.

We are not required to have a DPO.

3. Services Covered

This Privacy Policy applies to:

  • The Baggel website
  • Baggel Minecraft servers
  • The Baggel Discord server
  • Baggel moderation systems
  • Project registration systems operated by Baggel

4. Website Data Processing

Website Usage

Our website does not require user accounts and does not provide forms for submitting personal information.

We do not intentionally collect personal data through website forms or account systems.

Cookies and Tracking

The website does not use cookies for analytics, advertising, profiling, or user tracking. Embedded YouTube content uses privacy-enhanced mode and does not set cookies unless a video is actively played.

We do not store persistent identifiers on your device.

Server Logs

The website is hosted in Germany.

Like most web services, technical server logs may be generated automatically by the web server and hosting infrastructure. These logs may include:

  • IP addresses
  • Request timestamps
  • Requested resources
  • Technical connection information
  • Error information

These logs are used solely for technical operation, security, abuse prevention, and troubleshooting and are retained for up to 7 days.

Embedded Third-Party Content

Our website may contain embedded YouTube videos using YouTube's privacy-enhanced mode (youtube-nocookie.com). In this mode, YouTube does not store cookies on your device related to video playback unless you actively play the video. Once you interact with an embedded video, YouTube may process information about that interaction, including IP address and device information, according to its own privacy policy.

We do not control the processing performed by these third parties.

Please refer to the privacy policies of the respective providers for additional information.

Google Privacy Policy

5. Data We Collect

Discord Accounts

For Discord accounts we may store:

  • Discord User ID
  • Account linkage information
  • Account activity status
  • Date first known to us
  • Date the account left the Discord server
  • Operational metadata

Minecraft Accounts

For Minecraft accounts we may store:

  • Minecraft UUID
  • Last known Minecraft username
  • Account linkage information
  • Date first known to us
  • Operational metadata

Profiles

Our moderation platform maintains profiles representing individual community members.

A profile may contain:

  • Associated Discord accounts
  • Associated Minecraft accounts
  • Punishment records
  • Project registrations
  • Team memberships
  • Data access requests
  • Data deletion requests
  • Operational metadata

Account associations may be created manually by authorized moderators based on available evidence, including account links, user-provided information, technical indicators, or moderation investigations. Such associations are used solely for community administration, security, and enforcement purposes.

Technical indicators are used only where necessary for moderation and security purposes and are not used for profiling or automated decision-making.

Moderation Records

To enforce community rules, we may store:

  • Punishment type
  • Punishment scope
  • Punishment reason
  • Associated project
  • Creation date
  • Expiration date
  • Revocation information
  • Administrative audit information

Project Registrations and Teams

When participating in community projects we may store:

  • Project registrations
  • Team memberships
  • Leadership status
  • Join dates
  • Team tags and identifiers

Minecraft Server Logs

Minecraft servers may generate operational logs containing:

  • Minecraft UUIDs
  • Usernames
  • Chat messages
  • Connection information
  • IP addresses
  • Security and moderation events

These logs are used for server administration, abuse prevention, troubleshooting, and moderation. The server logs are retained for up to 7 days. This processing is based on our legitimate interest in maintaining security and availability of our services (Article 6(1)(f) GDPR).

6. How We Obtain Data

Data may be obtained:

  • Directly from you when registering for projects
  • From your Minecraft account when connecting to our servers
  • From your Discord account when joining our Discord server
  • Automatically through operation of our services
  • Through moderation activities
  • Through account-linking and profile-merging procedures performed by authorized moderators

If moderation action is required and no profile exists, a profile may be created automatically to enforce community guidelines.

7. Purposes of Processing

We process personal data for the following purposes:

  • Operating our community services
  • Managing Minecraft servers
  • Managing Discord communities
  • Enforcing community guidelines
  • Detecting abuse and ban evasion
  • Maintaining moderation records
  • Managing project participation
  • Managing teams and team tags
  • Responding to support requests
  • Fulfilling legal obligations
  • Exercising and defending legal claims
  • Maintaining security and integrity of our services

8. Legal Basis for Processing

Where the GDPR applies, processing is generally based on one or more of the following legal bases:

Legitimate Interests (Article 6(1)(f) GDPR)

Including:

  • Community moderation
  • Rule enforcement
  • Abuse prevention
  • Ban enforcement
  • Service security
  • Technical administration

We have considered that such processing is proportionate and does not override the rights and freedoms of affected individuals.

Performance of a Service (Article 6(1)(b) GDPR)

Where processing is necessary to provide requested community services, project registrations, team management features, or Minecraft server functionality.

Legal Obligations (Article 6(1)(c) GDPR)

Where processing is required by applicable law.

9. Data Sharing

Access to personal data is restricted to authorized administrators, moderators, and trusted operators who require access to perform their duties.

We use hosting infrastructure provided by Prepaid Host to store and process data on our behalf, under an appropriate data processing agreement where required. This hosting provider does not have independent access to use your data for its own purposes.

We do not sell personal data.

We do not share personal data with advertisers.

Data may be disclosed where required by law or where necessary to protect the rights, safety, and security of our users, community, or services.

10. Hosting and Data Storage

Our infrastructure is hosted in Germany.

Services are hosted through Prepaid Host .

We use hosting providers located in Germany unless otherwise stated. These providers process data on our behalf under appropriate data processing agreements where required.

All personal data we collect and store is hosted and processed exclusively in Germany. We do not transfer collected personal data outside Germany or the European Economic Area.

We receive limited data from Discord and Mojang/Microsoft via their respective APIs for the purpose of operating our services. This is limited to information those platforms have already collected through their own independent processing. We do not send, share, or transfer the personal data we collect back to Discord, Mojang, or Microsoft beyond what is inherently necessary to interact with their APIs (e.g., identifying a Discord user ID to query their public account status).

Discord's and Microsoft's own processing of your data — including any transfers outside the EEA they may perform — is governed by their respective privacy policies and is outside our control.

11. Discord Services

Our community uses Discord as a communication platform. When you join our Discord server, Discord may process personal data independently according to its own privacy policy. We only process information made available to us through Discord APIs.

Discord Privacy Policy

12. Minecraft Services

When you provide your Minecraft account to us or connect to our Minecraft servers, information associated with your Minecraft account may be processed. Minecraft accounts are operated by Mojang Studios and Microsoft. Their processing of personal data is governed by their own privacy policies.

Microsoft Privacy Statement

13. Data Retention

Moderation Records

Warnings, kicks, and mutes are deleted 36 months after creation.

Bans are deleted 36 months after expiration or revocation.

Project-specific bans are deleted 36 months after expiration, revocation, or the end of the relevant project.

These retention periods are necessary to maintain consistent moderation across recurring community projects. Baggel projects may operate for limited periods and may have extended inactive periods between projects. Retaining moderation history allows authorized moderators to identify repeated rule violations, evaluate patterns of behaviour, enforce previous sanctions consistently, and protect the integrity of future projects. A uniform retention period is used for moderation records to provide a clear and predictable retention policy for community members and to ensure consistent handling of moderation data.

The retention period is limited to the time reasonably necessary for these purposes. Moderation records are not used for advertising, profiling, or purposes unrelated to community safety and administration.

Account Records

Minecraft and Discord account records are deleted 30 days after being unlinked from a profile.

Deletion Requests

Deletion request records may be retained for up to 36 months after completion, based on our legitimate interest in demonstrating regulatory compliance and defending against potential disputes regarding the handling of the request (Article 6(1)(f) GDPR, in conjunction with the accountability obligation under Article 5(2) GDPR and the exception under Article 17(3)(e) GDPR).

Operational Data

Operational profile remnants and related operational records are deleted after 30 days where no longer required.

Minecraft Server Logs

Minecraft server logs, including chat history and IP addresses, are automatically deleted after a maximum retention period of 7 days.

Dormant Profiles

If all Discord accounts associated with a profile have left the community for more than 90 days, the profile has not participated in an active project within the previous 90 days, and no active deletion request exists, the profile may be reviewed for deletion and may be removed unless retention is necessary for moderation, security, or legal reasons.

14. Automated Decision-Making

Punishments, access restrictions, and other enforcement actions are always issued by an authorized human moderator. No punishment or restriction is ever imposed automatically.

The only automated decision-making we perform relates to data deletion eligibility. When a deletion request is submitted, our system automatically evaluates whether full or partial deletion is possible by checking for existing active punishments on record (see Section 15, "Right to Erasure"). This check references only straightforward operational facts — whether a punishment created by a human moderator is currently active — and does not involve profiling, behavioral analysis, or technical indicators such as IP addresses.

If you disagree with the outcome of an automated eligibility check, you may request human review by contacting us via a Discord support ticket or email (see Section 20).

15. Your Rights Under GDPR

Subject to applicable law, you may have the following rights:

  • Right of access (Article 15 GDPR)
  • Right to rectification (Article 16 GDPR)
  • Right to Data Portability (Article 20 GDPR)
  • Right to erasure (Article 17 GDPR)
  • Right to restriction of processing
  • Right to object
  • Right to lodge a complaint with a supervisory authority

Right of Access

To request a copy of your data, open a support ticket in our Discord server . You may alternatively contact us via email.

An administrator will provide an automatically generated data export.

Generated exports are retained for up to 49 hours before deletion.

Right to Rectification

To correct inaccurate information, open a support ticket in our Discord server . You may alternatively contact us via email.

Right to Data Portability

Data exports generated in response to access requests are provided in a structured, machine-readable format (ZIP archive containing structured data files). This satisfies the right to data portability under Article 20 GDPR. No separate portability process is necessary, as the standard export mechanism fulfills this right.

Right to Erasure

To request deletion of your data, use the /datenschutz daten_löschung command provided by our Discord bot.

Automated checks may assist in evaluating deletion requests. Where a request cannot be fulfilled automatically or requires further assessment, it may be reviewed by authorized administrators.

Full Deletion

Where eligible, we permanently remove:

  • Project registrations
  • Team memberships
  • Minecraft accounts
  • Discord accounts
  • Punishment records
  • Profiles
  • Operational profile remnants
  • Operational event history

Partial Deletion

If an active ban or active project-ban exists, complete deletion may not be possible because account identifiers are required to enforce community sanctions and prevent ban evasion.

In such cases we may retain only the minimum information necessary for enforcement.

Partial deletion may remove:

  • Project registrations
  • Team memberships
  • Profile metadata
  • Minecraft account metadata
  • Discord account metadata
  • Inactive punishments
  • Operational profile remnants
  • Irrelevant operational history

Deletion eligibility is automatically re-evaluated and full deletion may occur later when retention is no longer required.

Right to Object

Where we process your data based on legitimate interest (Article 6(1)(f) GDPR) — for example, moderation, security, or ban enforcement — you may object to that processing on grounds relating to your particular situation.

To object, open a support ticket in our Discord server or contact us via email (see Section 20).

Upon receiving an objection, we promptly review the affected record. Where continued enforcement is necessary to protect the rights and safety of other community members — for example, an active ban related to abuse, harassment, or cheating — enforcement may continue during this review, consistent with Article 18(2) GDPR. Where no such risk exists, enforcement is paused pending review by revoking the record, as described under "Right to Restriction of Processing" below.

Following review:

  • If your objection is upheld, the record is revoked (or remains revoked) and is handled according to our standard deletion rules.
  • If we determine we have compelling legitimate grounds that override your interests, we will continue or resume enforcement and inform you of the reasons.

You may lodge a complaint with the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) — the data protection supervisory authority responsible for the private sector in Bavaria, Germany:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

Promenade 18, 91522 Ansbach, Germany

Alternatively, you may lodge a complaint with the supervisory authority in your own EU/EEA member state of residence, place of work, or the place of the alleged infringement.

Right to Restriction of Processing

You may request that we restrict processing of your data — meaning we stop actively using or enforcing a record while continuing to store it — in certain circumstances, including where you dispute the accuracy of a record, where processing is contested, or while an objection under Article 21 GDPR is being assessed.

Where restriction applies, it is implemented through revocation: the disputed punishment is revoked, immediately stopping its enforcement while keeping the record available to moderators for reference during investigation. Because our moderation system does not support reactivating a revoked record, any record found to still be warranted after review is reissued as a new punishment rather than reinstated.

Consistent with Article 18(2) GDPR, we may continue enforcing a record during restriction where necessary to protect the rights and safety of other community members, such as active bans related to abuse, harassment, exploiting, or cheating. In such cases, enforcement continues while we conduct a prompt review, rather than pausing automatically.

To request restriction, open a support ticket in our Discord server or contact us via email (see Section 20).

16. Age Requirements

Baggel services are intended for users aged 13 and above. This policy-choice references the minimum age requirements of Discord, which may be required to participate in our community.

We do not collect, verify, or store age or date-of-birth data. All users are treated identically regardless of age, and no age-based profiling, differentiated processing, or special category handling occurs. Users under the applicable minimum age are not permitted to use Baggel services; responsibility for meeting this requirement rests with the user and, where applicable, their parent or guardian.

17. Security

We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction.

We implement:

  • Access control
  • Authentication requirements
  • Logging
  • Encryption where appropriate

However, no system can be guaranteed to be completely secure.

18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

Material changes may be announced through our website, Discord server, or other community communication channels.

The latest version will always be considered authoritative.

19. Definitions

"Profile" refers to an internal community record used to associate accounts, moderation history, and participation information belonging to the same individual.

"Operational data" refers to technical information required to operate, secure, and maintain our services.

"Operational metadata" refers to a reserved technical field used to pass non-personal information between our internal services (for example, between our Discord bot and Minecraft systems), primarily to support internal coordination and non-essential features (such as cosmetic elements). Operational metadata is not used for moderation, security enforcement, or any purpose critical to account status or service delivery. We do not store personal data within operational metadata. Because its content is defined by ongoing internal development rather than by a fixed purpose, operational metadata is treated as inherently transient: it is the first category of data removed whenever a profile is deleted or a deletion request is processed, regardless of whether other data on the same profile is retained for moderation or legal reasons.

20. Contact

For privacy-related inquiries, please contact:

mail@baggel.de