ALA LAB.

Privacy Policy

Privacy policy of the Ala Lab website — alalab.work
Effective: · Last updated:

Ala Lab is an independent studio that builds custom Minecraft mods and plugins. On alalab.work you can send us a request for a project. This page explains, point by point, what data we receive, why we need it, where it is kept and when it is deleted.

1. Who we are and how to reach us

The controller of your personal data is the Ala Lab studio, which owns the alalab.work website.

For any question about your data — to see it, correct it or delete it — send a request through the form on the main page and start the text with “Data request”. We reply within 30 days.

2. What data we receive and why

Requests sent through the form

When you send a request, we receive your name (how to address you), a contact for the reply (Telegram, Discord or email), the project type and the description of your idea. We need this to reply, clarify the task and quote a price and timeline. Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR). Please do not put unnecessary personal data in the description — it is not needed to estimate a mod.

Technical data

Every time a page is opened, the server receives the IP address, browser details (user agent), the page address, the time of the request and the address you came from. These are ordinary web server logs: we need them to keep the site running, find errors and protect the form from spam and brute force — the number of requests from one IP is limited. Legal basis: our legitimate interest in running the site securely (Art. 6(1)(f) GDPR).

Visit statistics

We see anonymised Cloudflare Web Analytics statistics: how often pages were opened, where visitors came from, their country and device type. It works without cookies and does not track you on other websites. Legal basis: our legitimate interest in knowing whether the site works (Art. 6(1)(f) GDPR).

We do not use your data for advertising, do not build profiles and do not make automated decisions about you.

3. Third-party services

The site relies on three services. Each receives only what it needs to do its job:

  • Cloudflare, Inc. (USA) — DNS, attack protection, site delivery and web analytics. Every request to the site passes through Cloudflare. Cloudflare policy
  • Hetzner Online GmbH (Germany) — the server the site runs on; the data centre is in Finland (EU). Hetzner policy
  • Telegram — requests from the form are delivered to the studio’s private Telegram chat. Telegram policy

Your data is not shared with or sold to anyone else.

4. How long we keep data

  • Requests — while we discuss and work on the order, then as long as needed for support after release. If no order follows, we delete them within 12 months at the latest. Sooner if you ask.
  • Web server logs — 14 days, then deleted automatically.
  • Data held by Cloudflare — under Cloudflare’s rules (link in “Third-party services”).

5. Transfers outside the EU

The website’s server is in the EU. Cloudflare and Telegram may also process data in other countries, including the USA. Cloudflare does so on grounds provided by the GDPR (such as the EU Standard Contractual Clauses), Telegram under its own privacy policy; see the policies of these services for details.

6. Cookies and browser storage

The site sets one cookie of its own — alalab_lang — and only when you choose a language yourself in the menu or in the language suggestion. It remembers your choice for a year so that next time alalab.work opens straight in that language. It holds only the language code (for example, de): it is not used for tracking and is not passed to anyone. The cookie is set by your own action and serves only this setting, which is why there is no consent banner. You can remove it by clearing the site data in your browser settings. The site stores nothing else in your browser.

One exception is not ours: if Cloudflare’s protection finds a connection suspicious, it may show a short check and, after it, set the technical cookie cf_clearance so it doesn’t ask again. It is only for protecting the site from attacks, isn’t used for tracking, and needs no consent.

7. How we protect data

The site works over HTTPS only. The server accepts requests only through Cloudflare, the form is protected from spam and brute force, only the studio has access to requests, and service keys are stored encrypted on the server. No one can rule out every risk on the internet, but we do everything reasonable to keep your data away from others.

8. Your rights

At any time you can:

  • find out what data we hold about you and get a copy;
  • correct inaccurate data;
  • delete your request and the conversation about it;
  • restrict or object to processing;
  • receive your data in a portable format;
  • lodge a complaint with the data protection authority of your country (for EU residents).

To use any of these rights, send a request through the form on the main page, as described in section 1. We reply within 30 days.

9. Age

The site is open to everyone, but a request means discussing paid work. If you are under 16, please send the request together with a parent or with their consent. If we learn that we received a child’s data without parental consent, we will delete it.

10. Changes to this policy

We update this policy when the way the site works changes. The current version is always on this page, and the date of the last update is shown at the top.