1Who we are
Aki Laboratories Limited ("we", "us", "our") operates Instances, a platform that lets you provision and manage game hosting infrastructure, at www.instances.aki-labs.com.
We are the data controller for the personal data described in this policy.
- Registered address
- 124-128 City Road, London, England, EC1V 2NX
- Company number
- 14904443
- Contact
- help@aki-labs.com
- ICO registration
- ICO registration number — to be added
If you're in the EEA, the UK, or another region with specific rules, see section 16 for additional disclosures.
2What this policy covers
This policy covers aki-labs.com and its subdomains, including the Instances service at www.instances.aki-labs.com.
It does not cover the data processed inside the game servers you deploy through us. Where you run servers that other people connect to, you decide what happens to that data — see section 7, which you should read carefully.
3Our approach
We collect as little as we can. Concretely:
-
We ask for an email address and a username. That's it.
-
Everything inside our own infrastructure identifies you by a random UUID, not by your name or email.
-
We don't run website analytics, advertising, or tracking cookies.
-
We never sell or share your personal data for advertising, and we don't sell or share it as those terms are defined under US state privacy laws.
-
We don't make automated decisions that produce legal or similarly significant effects about you.
-
We don't collect special category or sensitive data — health, biometrics, political opinions, precise location — and we ask that you don't send it to us.
4What we collect
4.1 Account and identity data
Your email address and username, plus your credentials and any multi-factor authentication settings.
This is held by Zitadel Cloud on our behalf, in their European Union region. Our own systems only ever see the UUID that Zitadel issues for your account.
4.2 Authentication and audit records
Records of sign-ins and account activity, including timestamps, success and failure of authentication attempts, session activity, the IP address and user agent used, and a record of significant actions taken in the service.
We keep these to secure accounts, investigate abuse, and answer questions like "who changed this and when".
4.3 Service and infrastructure data
Everything relating to the hosting resources you create: server and project names, regions, instance sizes, configuration, deployment history, resource state, operational logs and metrics.
This is linked to your account by UUID alone. Your name, email and billing details are not stored here.
Anything you type into a name or configuration field is stored as you entered it, so please don't put personal information in there.
4.4 Billing and payment data
Payments and subscriptions are handled by Stripe. Card details go directly to Stripe — we never receive or store your full card number.
From Stripe we receive your Stripe customer ID, subscription and plan status, payment history, card brand and last four digits, and billing country — to be confirmed. Stripe processes payments on our behalf and also acts as a controller in its own right for fraud prevention and its regulatory obligations. See Stripe's privacy policy at stripe.com/privacy.
4.5 Usage and metering data
We send usage measurements to Metronome, our billing platform, so we can calculate what you owe. This is volume data — compute hours, resource counts, bandwidth, storage — to be confirmed — keyed to your account identifier rather than your name.
4.6 Website and server logs
Our web servers and infrastructure automatically record IP addresses, timestamps, requested URLs, response codes, user agents and referrers.
We do not currently analyse these logs, profile visitors, or run any website analytics. They exist so the service works and so we can investigate outages, abuse and attacks. If that changes, we'll update this policy and, where the law requires it, ask for your consent first.
4.7 Emails and correspondence
Automated messages — sign-in links, billing notices and service alerts — are sent from instances@aki-labs.com using Amazon Simple Email Service.
If you write to us at help@aki-labs.com, that correspondence is handled through Proton Mail, an encrypted email provider based in Switzerland. We keep your message and our reply along with whatever contact details you used.
5Why we use it, and our legal basis
| What we do | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Create and administer your account | Account and identity data | Performance of a contract |
| Authenticate you and keep sessions secure | Identity data, authentication records | Performance of a contract |
| Provide and operate the hosting service | Service and infrastructure data | Performance of a contract |
| Send service and account emails | Email address | Performance of a contract |
| Take payment and manage subscriptions | Billing data, account identifier | Performance of a contract |
| Measure usage for billing | Usage and metering data | Performance of a contract |
| Support and respond to your queries | Correspondence, account data | Performance of a contract; legitimate interests in running a supported service |
| Secure the platform, detect and investigate abuse, prevent fraud | Audit records, server logs, IP addresses, server contents where necessary | Legitimate interests in protecting our service, our users and our infrastructure |
| Keep accounting and tax records | Billing data | Legal obligation |
| Respond to lawful requests, establish or defend legal claims | Any of the above | Legal obligation; legitimate interests in defending our position |
| Send product or marketing emails | Email address | , which you can withdraw at any time |
Where we rely on legitimate interests, we've weighed those interests against your rights. You can object at any time — see section 11.
6Cookies and browser storage
We don't use cookies for analytics, advertising or tracking, and we don't show a consent banner because we have nothing to ask your consent for.
What we do use is browser storage, to keep you signed in. When you log in, our identity provider's client library saves your session in your browser's session storage under keys like these:
| Key | Set by | Purpose | Cleared |
|---|---|---|---|
oidc.user:https://aki-labs-msjfyq.eu1.zitadel.cloud:385481520921540573 | Zitadel client library | Holds your current session and tokens so you stay signed in | When you close the tab, or when you sign out |
oidc.[random identifier] | Zitadel client library | Short-lived values used to complete a login redirect securely | As soon as login completes |
Signing in also sets session cookies on our identity provider's own domain,
aki-labs-msjfyq.eu1.zitadel.cloud.
All of this is strictly necessary to deliver a service you've asked for, which is why
we don't need your permission for it. Clearing your browser storage will sign you
out. If we ever add anything that isn't essential, we'll ask first.
7Data about players on your servers
Read this section if other people connect to servers you run.
A game server processes data about everyone who joins it: IP addresses, in-game names and account IDs, chat and event logs, and whatever else the game software records. That data sits on infrastructure we operate.
Who's responsible
You decide what your server runs, who can join, and what it logs, so you are the controller of that data. We act as your processor for the infrastructure underneath it. Data Processing Terms — to be published and linked here
Where it lives
You choose which of our ten hosting regions your server runs in, and that determines where your server's data — including data about your players — is stored. See section 9.
How it's protected
Your server's storage is encrypted at rest using AWS-managed keys, and traffic between you and our platform is encrypted in transit. That protects your data against theft of physical storage media and against access below the level of our own AWS account.
It does not mean we're unable to read it. Encryption at rest is transparent to authorised access — a member of our team with the right permissions can read your server's contents, and we'd rather tell you that than imply a protection that isn't there.
Our access — please read
We are able to access the contents of your servers, including files, world data, logs and chat records. We only do so where:
- you ask us to, as part of a support request you've raised;
- we're investigating a security incident, or a report of abuse or illegal content;
- we need to protect our infrastructure or other customers from harm; or
- we're legally required to.
Access controls and audit logging for staff access to customer servers — to be verified before this claim is published
Your responsibilities
If people outside your own household connect to your server, data protection law applies to you as well as to us. That means telling players what's collected, having a lawful basis for it, responding to their requests, and keeping the server secure. If children are likely to play on your server, further rules apply to you. We can't take these obligations on for you, and this policy doesn't cover them.
Reporting
If you believe a server hosted with us is mishandling your data, contact us at help@aki-labs.com and we'll investigate.
8Who we share data with
We don't sell your data. We share it with the following service providers, who process it on our instructions:
| Provider | What they handle | Where |
|---|---|---|
| Zitadel Cloud (Zitadel, Switzerland) | Identity, authentication, account records | European Union (Frankfurt, Germany) |
| Amazon Web Services | Platform hosting and infrastructure | United States (us-east-1) |
| Amazon Web Services | Hosting regions for your servers | Ten regions worldwide — you choose |
| Amazon Simple Email Service | Automated and transactional email | region — to be confirmed |
| Stripe | Payments and subscriptions | Ireland / United States |
| Metronome | Usage metering and billing | United States |
| Proton AG | Email correspondence with our team | Switzerland |
We may also disclose data to professional advisers such as lawyers and accountants; to regulators, courts or law enforcement where we're legally required to; and to a buyer or successor if we're involved in a merger, acquisition or sale of assets, in which case we'll tell you beforehand.
9Where your data is stored, and international transfers
We're a UK company, and we operate globally. Different parts of your data sit in different places, so it's worth being precise.
-
Your account and login details
are stored by Zitadel in the European Union.
-
Our platform
— audit logs, infrastructure metadata, usage measurements and web server logs — runs in AWS's us-east-1 region in the United States. If you're in the UK or EEA, this means your data is transferred to the US.
-
Your game servers
run in whichever of our ten regions you select. That choice determines where your server's contents, logs and player data are stored. Selecting a European region for your server does not change where our platform data sits.
-
Correspondence with our team
is handled in Switzerland.
Where we transfer personal data out of the UK or EEA, we rely on:
- Adequacy regulations. Switzerland is recognised by both the UK and the EU as offering equivalent protection, which covers our email correspondence and Zitadel's Swiss corporate operations.
- The EU–US Data Privacy Framework and its UK Extension. Amazon and Stripe are certified under the Framework, which permits transfers to their US operations without additional safeguards.
- Standard Contractual Clauses, together with the UK International Data Transfer Addendum, which our providers' data processing agreements incorporate as a fallback.
You can request a copy of the safeguards we use by emailing help@aki-labs.com.
10How long we keep it
| Data | Retention |
|---|---|
| Account and identity data | For as long as your account is open, then deleted within TBC days of closure |
| Authentication and audit records | TBC |
| Service and infrastructure data | For the life of the resource, then deleted within TBC days, allowing up to TBC days for backups to expire |
| Billing and payment records | Six years from the end of the relevant financial year, to meet UK tax and accounting requirements |
| Usage and metering data | TBC |
| Web and server logs | TBC |
| Correspondence | TBC |
| Records of admin access to customer servers | TBC |
Where we're required to keep billing records, we'll retain them after you close your account and won't use them for anything else.
11Your rights
Wherever you live, you can ask us to:
-
Access
the personal data we hold about you, and get a copy
-
Correct
data that's wrong or incomplete
-
Delete
your data, where we don't have an overriding reason to keep it
-
Restrict
how we use your data while a concern is being resolved
-
Port
the data you gave us to another provider, in a machine-readable format
-
Object
to processing we base on legitimate interests
-
Withdraw consent
at any time, where we rely on it
You won't be treated differently or charged more for exercising any of these.
To make a request, email help@aki-labs.com from the address on your account. If we can't verify it's you, we may ask for more information — we won't use anything you send for verification for any other purpose. We respond within one month, or within 45 days where US state law applies. Complex requests may take longer, and we'll tell you if so.
You can also authorise someone else to make a request for you, in which case we'll need proof of their authority.
12How we protect your data
- Traffic is encrypted in transit using TLS, and data is encrypted at rest using AWS-managed keys
- Multi-factor authentication is available on all accounts via our identity provider
- Accounts are isolated from one another, and our internal systems reference you only by UUID
Access control and logging for production systems and customer servers — to be verified before this claim is published
Backup regime, incident response process, vulnerability management and penetration testing — to be documented here
No system is perfectly secure. If a breach occurs that puts your rights at risk, we'll notify the ICO within 72 hours and tell you directly where we're required to.
13Age requirement
You must be 18 or over to use Instances. We don't knowingly collect data from anyone under 18, and we don't allow under-18s to hold accounts.
If we learn that an account belongs to someone under 18, we'll close it and delete the associated data. If you believe a child has created an account, email help@aki-labs.com.
This requirement applies to account holders. If children play on a server you host, that's between you and them — see section 7 — but you should be aware that hosting a service used by children brings obligations of its own.
14Changes to this policy
We'll update this page when our practices change and revise the date at the top. For significant changes — new categories of data, new purposes, or new third parties — we'll notify you by email or in the product before they take effect.
15Contact us
Email help@aki-labs.com, or write to Aki Laboratories Limited, 124-128 City Road, London, England, EC1V 2NX.
16Regional disclosures
16.1 United Kingdom and European Economic Area
Our legal bases are set out in section 5. You have the rights in section 11, plus the right to lodge a complaint with a supervisory authority.
- UK: the Information Commissioner's Office — ico.org.uk, 0303 123 1113
- EEA: your national data protection authority, listed at edpb.europa.eu
Our representative in the EU under Article 27 GDPR is name and address — representative to be appointed.
We'd appreciate the chance to resolve things directly first — email help@aki-labs.com.
16.2 United States
For residents of California, Virginia, Colorado, Connecticut, Texas, Utah and other states with comparable laws.
Categories of personal information we collect: identifiers (email address, username, account ID, IP address); commercial information (subscription and payment history); and internet or network activity (server and audit logs, usage metrics). Sources, purposes and recipients are described in sections 4, 5 and 8.
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we haven't in the preceding 12 months. We don't use or disclose sensitive personal information for purposes requiring a right to limit.
We do not knowingly collect personal information from anyone under 18, and therefore do not sell or share the information of minors.
Your rights to know, delete, correct, and to non-discrimination are described in section 11. Some states also give you the right to appeal a refused request: if we decline, email help@aki-labs.com with "Appeal" in the subject line and we'll respond within 45 days with our reasons.
16.3 Other regions
-
Canada
We handle personal information in line with PIPEDA. You may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca. Quebec residents have additional rights under Law 25, including in relation to automated decisions — we don't make any.
-
Australia
We handle personal information in line with the Australian Privacy Principles. You may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
-
Brazil
We handle personal data in line with the LGPD. You may contact the Autoridade Nacional de Proteção de Dados at gov.br/anpd.
-
Switzerland
We handle personal data in line with the revised Federal Act on Data Protection. You may contact the Federal Data Protection and Information Commissioner at edoeb.admin.ch.