Privacy Policy
Last updated: 24 July 2026
1. Controller
Controller within the meaning of the GDPR: Timothy Vida, In den Zeuläckern 20, 60389 Frankfurt am Main, Germany — e-mail: [email protected].
No data protection officer has been appointed; the legal requirements for a mandatory appointment (Art. 37 GDPR, § 38 BDSG) are not met for this one-person project. Please address privacy requests directly to the e-mail above.
2. Hosting (Hetzner, Germany)
This website runs on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; the server location is Germany. When you visit the site, the server processes technically necessary data (IP address, date and time, requested page, user agent, referrer) to deliver the website, keep it stable and fend off attacks (Art. 6 (1) (f) GDPR).
Server logs are deleted automatically after a short period. A data processing agreement (Art. 28 GDPR) is in place with Hetzner.
3. CDN and DNS (Cloudflare)
The domain dzpage.com is delivered through the DNS servers and the content delivery network of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. As an upstream proxy, Cloudflare processes technical connection data (in particular the IP address) to serve the site quickly and to mitigate attacks (Art. 6 (1) (f) GDPR).
Cloudflare is certified under the EU-U.S. Data Privacy Framework; EU standard contractual clauses apply in addition.
4. Cookies and consent
Technically necessary cookies do not require consent (§ 25 (2) TDDDG). We use exactly three of them: the login session cookie, the language cookie and the cookie storing your cookie decision.
All non-essential services — currently only Google AdSense — load only after your explicit consent via the cookie banner (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). You can change or withdraw your decision at any time via “Cookie settings” in the footer.
5. Account and Discord sign-in
For the optional sign-in we use Discord OAuth2 (Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands; parent company Discord Inc., USA). On sign-in we receive your Discord ID, username, display name, avatar and — if approved — your e-mail address.
We store this data to provide your account including sessions and API keys (Art. 6 (1) (b) GDPR) until you delete your account. In the settings you can permanently delete your account yourself at any time and export all stored data as JSON.
6. Payments (Stripe)
Payments (one-time support and the supporter subscription) are processed by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. Stripe processes your name, e-mail address, billing address, VAT ID (if provided) and payment details; full card data never reaches our servers.
The legal basis is the performance of a contract (Art. 6 (1) (b) GDPR); invoice data is retained to fulfil statutory obligations (Art. 6 (1) (c) GDPR, § 147 AO). Transfers to Stripe, Inc. (USA) are safeguarded by the EU-U.S. Data Privacy Framework and standard contractual clauses. Details: stripe.com/privacy.
7. Advertising (Google AdSense) — only with consent
Only if you have consented in the cookie banner do we embed Google AdSense (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google then sets cookies or device identifiers to deliver and, where applicable, personalize ads; data may be transferred to the USA (Google LLC is certified under the EU-U.S. Data Privacy Framework).
The legal basis is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time via “Cookie settings” in the footer. Supporters from €5 permanently see no ads — AdSense is not loaded at all for them. More: policies.google.com/privacy and adssettings.google.com.
8. Discord ranks for supporters
If you have supported with at least €5, we transmit your Discord ID to the Discord API to assign the corresponding ranks on our Discord server (Art. 6 (1) (b) GDPR). This requires that you are a member of our server.
9. API keys and logs
For API usage we store, per key, a cryptographic hash (never the plain text), a display name, the creation date and the time of last use (Art. 6 (1) (b) GDPR). To enforce rate limits we count requests briefly in memory (Art. 6 (1) (f) GDPR); no permanent usage profiles are created.
10. Retention and deletion
We store account data until you delete your account. Deletion also removes sessions, API keys, support records and the Stripe customer; an active subscription ends immediately. Statutory retention periods for invoice data (up to ten years, § 147 AO) remain unaffected.
11. Sign-ins, devices and two-factor protection
For every active sign-in we store, alongside the session identifier, the time it was last used, the browser user agent and the device's IP address. We show you this as a device list in your settings so you can spot sessions that aren't yours and end them individually or all at once; it also protects against account takeovers (Art. 6(1)(b) and (f) GDPR).
The data is deleted with the session — at the latest 180 days after it was last used, when you sign the device out, or when you delete your account.
If you enable two-factor sign-in we store the associated secret key so we can verify your one-time codes (Art. 6(1)(b) GDPR). It is deleted as soon as you disable two-factor sign-in or delete your account.
12. Server list, comments and votes
If you add a server to the server list we process the details you enter (server name, description, platform, map, tags, address and ports, links to Discord, TeamSpeak and a website) plus an optional banner image. These details are publicly visible. Comments are published together with your Discord display name and avatar; votes are linked to your account so the limit of one vote per server and period can be enforced (Art. 6(1)(b) GDPR).
Please do not publish other people's personal data in these fields. You can delete your entries and comments yourself at any time; deleting your account removes them as well.
For listed PC servers we query the public Steam query port at regular intervals to display player count, map name and in-game time (Art. 6(1)(f) GDPR — legitimate interest in an up-to-date server list).
13. Uploaded server files
In the Types Editor and the Spawnable Types Editor the XML files you upload are stored on our server so that you can continue later and share the link. Without an account they are deleted automatically 30 days after the last change; in the Spawnable Types Editor this also applies to signed-in users. In the Types Editor uploads by signed-in users become projects: they are kept together with their saved versions until you delete them, and they are removed together with your account (Art. 6(1)(b) GDPR).
All other tools — including the Mission Updater, Types Updater, the gameplay, weather, globals, event and spawnpoint editors and the validators — process your files entirely inside your browser. Those files never leave your device and never reach our server.
14. Contact and cancellation notices
If you write to us by email or on Discord we process your details solely to handle your request (Art. 6(1)(b) GDPR for contractual matters, otherwise Art. 6(1)(f) GDPR). We delete the messages once they are no longer needed and no statutory retention periods apply.
If you submit a cancellation through the cancellation page we store the details entered there (name, email address, contract, requested end date, time of receipt) in order to process it and to document its receipt (Art. 6(1)(b) and (c) GDPR, § 312k German Civil Code). Cancellation records are kept until the statutory retention and limitation periods expire.
15. Moderation of the Discord server
On the DZPage Discord we run our own moderation bot against spam and automated accounts. It processes message metadata there (channel, time, frequency, contained links and mentions), the account age derivable from the Discord ID, and the measures taken (Art. 6(1)(f) GDPR — legitimate interest in protecting the community).
The processing takes place on the Discord platform; Discord is responsible for the platform itself. Logs of measures are kept only as long as moderation requires.
16. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20 — covered by the JSON export in the settings) and objection (Art. 21), as well as the right to withdraw any consent at any time with effect for the future (Art. 7 (3) GDPR).
You may also lodge a complaint with a data protection supervisory authority; the competent authority is the Hessian Commissioner for Data Protection and Freedom of Information (datenschutz.hessen.de).
Right to object: on grounds relating to your particular situation you may object at any time to processing of your personal data that is based on legitimate interests (Art. 6(1)(f) GDPR). On this website that covers delivering and securing the site, the cookie-free traffic measurement, the live status of the server list and Discord moderation. If you object we will stop processing the data concerned unless we can demonstrate compelling legitimate grounds. An informal email to [email protected] is enough.
Using dzpage.com does not require you to provide any personal data. For an account, the server list or a support payment, the data requested there is required: without it we cannot perform the respective contract. Everything else is voluntary.
No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place.
17. Data security and changes
The entire website is delivered exclusively encrypted via TLS (HTTPS). This privacy policy will be updated whenever services or the legal situation change; the version published here applies.
18. Reach measurement (self-hosted, cookie-free)
We measure page views and tool usage with our own, self-hosted system. No cookies and no third-party services are used, and no advertising profiles are created. For visitors without an account, a pseudonymous identifier is computed from a monthly-rotating secret, the IP address and the browser user-agent; only this irreversible hash is stored — never the IP address itself. For logged-in users, usage is linked to the account to power convenience features such as the "Your tools" section and a personalised tool order.
The data is used solely to display aggregate visitor numbers, to rank tools by popularity and to improve the site (legal basis: Art. 6(1)(f) GDPR — legitimate interest in cookie-free, privacy-preserving reach measurement). Country information is derived from a Cloudflare header without storing the IP address. Raw view events contain no personal data beyond the pseudonymous hash and are not shared with third parties.
19. Forum
In the forum we store the content you post (threads and posts), the time of creation and any later edit, your reactions, watched threads, your read status and notifications addressed to you, each linked to your account. Forum contributions in publicly readable forums are visible to everyone on the internet and can be found by search engines — please do not post anything there that you do not want to be public.
The legal basis is Art. 6(1)(b) GDPR for the operation of the account you asked for, and Art. 6(1)(f) GDPR for the coherence and moderation of the discussions. If you delete your account, the link between your posts and your account is removed (they then show as „deleted account“), while the posts themselves remain readable — otherwise deleting a single account would also destroy the answers other people wrote in the same thread. If you want individual posts removed as well, write to the e-mail address in section 1.
Reports of posts are stored with the reason, the reporting account and the reported post so that they can be processed. Page view counters of threads are aggregated numbers without a link to your account.