Loadingβ¦
Last updated:
Lyrebird Hosting is committed to protecting your data rights under the EU General Data Protection Regulation (GDPR). This page explains your rights and how to exercise them.
Lyrebird Hosting operates under Estonian law and complies fully with the EU General Data Protection Regulation (GDPR). Your data rights are important to us.
The General Data Protection Regulation (GDPR) is an EU law on data protection and privacy. It applies to all organisations that process personal data of individuals in the EU, regardless of where the organisation is located.
As a data controller, Lyrebird Hosting determines how and why your personal data is processed. We are registered as Lyrebird Hosting (registry code 12345678) in Estonia, an EU member state, and are fully subject to GDPR requirements.
Under the GDPR, if you are located in the European Economic Area (EEA), you have the following rights:
Right of Access (Art. 15)
You can request a copy of all personal data we hold about you.
β Email us at privacy@lyrebirdhosting.com or use /api/account/export
Right to Rectification (Art. 16)
You can correct inaccurate or incomplete personal data.
β Update in dashboard settings or contact us
Right to Erasure (Art. 17)
You can request deletion of your account and all associated data.
β Use account deletion in dashboard settings or contact us
Right to Data Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON).
β Use /dashboard/settings β Export Data
Right to Object (Art. 21)
Object to certain types of processing of your personal data.
β Contact us at privacy@lyrebirdhosting.com
Right to Restriction (Art. 18)
Request restriction of processing under certain circumstances.
β Contact us at privacy@lyrebirdhosting.com
We process your personal data under the following legal bases:
Contract Performance (Art. 6(1)(b))
Processing your email, payment information, and server data to fulfil your subscription contract.
Legal Obligation (Art. 6(1)(c))
Retaining financial records and invoices to comply with EU financial regulations.
Legitimate Interests (Art. 6(1)(f))
Security monitoring, fraud prevention, and abuse detection to protect our platform and users. Also churn-risk and customer-health scoring, and the retention email it drives β we profile accounts from login recency, server downtime, support tickets and payment failures, hold the resulting scores, and may email you or offer a discount when the score is high. You have an absolute right to object to direct marketing under Art. 21(2): use Settings β Email Preferences, or email us.
Consent (Art. 6(1)(a))
Cookie consent. You can withdraw consent at any time via your browser settings.
We primarily store data within the EU β your game servers, both databases and payment processing are hosted in the EEA. Several providers we rely on operate from the United States, and are named with their locations in Who Processes Your Data below. Where data leaves the EEA, we rely on these safeguards:
Requesting deletion starts a 30-day grace period during which you can cancel. Erasure runs on the first scheduled sweep after the period ends, so it completes within 31 days of your request.
Permanently deleted from all backups
Kept after your account is deleted because accounting and tax law requires it. Your name and email are removed from the account record; the invoices themselves are not.
Start/stop, deploy and configuration events on your servers. Kept for abuse prevention and support.
CPU, memory and disk samples used for the dashboard graphs and capacity planning.
Notifications you have already read. Unread ones stay until you read them.
Stripe event records, kept to reconcile payments and prevent duplicate processing.
Records of email we could not deliver to you, kept while we retry and investigate.
Proof that account and billing email was sent.
Kept indefinitely: a small set of audit records β server transfers that failed, refunds processed, pending game-server deletions, account deletions β is never deleted, because we need to be able to show what happened to a payment or an account long after the fact. These records reference the account ID; after erasure that ID no longer resolves to a person.
These are every third party that processes personal data on our behalf. Each is bound by a data-processing agreement under Article 28.
Application hosting, serverless functions, CDN, request logs
Authentication, primary application database (servers, tickets, billing records)
Secondary application database (accounts, plans, subscriptions, invoices)
Payment processing, billing records, invoices, tax calculation
Game server infrastructure β your worlds, plugins and server files
Transactional email delivery (account, billing and support email)
Error monitoring and, with your consent, session replay
AI assistance for support replies, crash-log analysis, and the copy of retention and onboarding emails. Customer-authored support ticket text is sent to this processor.
You can exercise your GDPR rights through the following methods:
We will respond to all legitimate requests within 30 days. We may need to verify your identity before processing your request.
If you are unsatisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection authority.
As Lyrebird Hosting is based in Estonia, the lead supervisory authority is:
For any GDPR-related requests or questions, please contact us:
Also read our Privacy Policy Β· Cookie Policy