Data Processing Addendum
Last updated Version dpa-2026-07-30
This Data Processing Addendum (“DPA”, document version “dpa-2026-07-30”) forms part of the Terms of Service between You and the Company and governs the processing of personal data contained in Discord servers that You instruct the Service to process on Your behalf.
It is concluded under Article 28(3) of Regulation (EU) 2016/679 (“GDPR”). Where You act as controller for Discord Data and the Company acts as processor, this DPA applies. Where the Company acts as controller in its own right — Your account, billing, telemetry and abuse prevention — the Privacy Policy applies instead and this DPA does not.
This DPA is accepted electronically, which Article 28(9) GDPR permits. No signed copy is required.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural. Terms defined in the Terms of Service and the Privacy Policy have the same meaning here unless stated otherwise.
Definitions
For the purposes of this DPA:
- Company (referred to as either “the Company”, “We”, “Us” or “Our”) refers to Merlin Fuchs, Alte Str. 5, 04229 Leipzig, Germany, acting as processor under this DPA.
- You (referred to as either “You” or “the Controller”) means the individual or legal entity that operates a Server and instructs the Service to process Discord Data from it, acting as controller under this DPA.
- Server means a Discord guild that You have connected to the Service.
- Workspace means the organization within the Service through which You manage Your Servers, Your Subscription and the members of Your team.
- Discord Data means content and metadata from a Server that the Service processes on Your instruction, such as server settings, channels, roles, permissions, members, bans, messages and attachments contained in backups, chatlogs, templates and synchronizations.
- Applicable Data Protection Law means the GDPR, the German Federal Data Protection Act (BDSG) and, where applicable to You, the UK GDPR and the Data Protection Act 2018, together with any other data protection law applicable to the processing.
- Sub-processor means any processor engaged by the Company to carry out part of the processing described in this DPA.
- Data Subject Request means a request by a data subject to exercise their rights under Chapter III GDPR, including access, rectification, erasure, restriction, portability and objection.
- Personal Data Breach has the meaning given in Article 4(12) GDPR.
Scope
This DPA is a framework agreement. It is accepted once for Your Workspace and applies to every Server connected to that Workspace, whether the Server was connected before or after You accepted it.
Connecting a further Server extends this DPA to that Server automatically, on the same terms and without a separate acceptance. The Servers connected to Your Workspace at any given time define the scope of the processing under this DPA. Removing a Server ends the processing for that Server as set out under “Deletion and Return” below, and leaves this DPA in force for the remaining ones.
You are notified of this before You connect a Server, and the Company records, for each Server You connect, the version of this DPA in force at that time.
A new acceptance is required only where the Company issues a new version of this DPA, as set out under “Term, Acceptance and Changes” below, or where the controller of a Server is a different legal person than the one that accepted this DPA.
Roles of the Parties
For Discord Data, You are the controller and the Company is the processor. You determine which Server is processed, which feature is used, when it runs and how long the result is kept. The Company processes Discord Data only to deliver the feature You started.
The Company remains an independent controller for the personal data it determines the purposes of, in particular: Your account and login data, Your Workspace and team membership, billing and tax records, usage data, application logs, and data processed to keep the Service secure and to prevent abuse. That processing is described in the Privacy Policy and is not governed by this DPA.
The Company treats every person who connects a Server to a Workspace as the controller for the Discord Data of that Server, and relies on the warranties You give under “Your Obligations as Controller” below in providing the Service. The Company does not determine, and is not in a position to determine, who operates a Discord server or on whose behalf a Server is run.
Where more than one person qualifies as controller for a Server, each of them is bound by this DPA in respect of the instructions they give, and the Company may act on the instruction of any of them.
If it turns out that You are not the controller of a Server You connected, this DPA continues to bind You as controller in respect of the instructions You gave, and the processing carried out on those instructions is attributable to You.
Subject-matter, Duration, Nature and Purpose
The subject-matter of the processing is the creation, storage, inspection, comparison, export, restoration and deletion of snapshots and copies of Discord servers and their content.
The nature of the processing consists of collection from Discord, structuring, storage, retrieval, transmission back to Discord on restore, transmission to You on export, and erasure. The Company does not use Discord Data for its own purposes, does not sell it, does not use it for advertising, and does not use it to train machine learning models.
The purpose of the processing is to provide the features of the Service that You use, namely backups, chatlogs, templates, synchronizations and the restoration and export of those artifacts.
The duration of the processing is the term of Your use of the Service. Individual Discord Data is processed until You delete the artifact that contains it, until the artifact is superseded by the retention limits of Your plan, until You remove the Server from the Service, or until Your Workspace is closed, whichever happens first, plus the deletion periods set out under “Deletion and Return” below.
Types of Personal Data
Depending on which features You use, the processing covers the following categories of personal data:
- Message content and metadata — the text of messages, embeds, reactions, timestamps, message and channel identifiers, and the Discord user ID, username, display name and avatar of the message author, including for messages that started a thread.
- Attachments — files, images and other media posted in messages, together with their filenames and metadata, and any personal data contained inside those files.
- Member lists — Discord user IDs, usernames, display names, server nicknames, avatars, role assignments, join dates and timeout state of the members of Your Server.
- Ban records — the Discord user ID and username of a banned user together with the free-text reason recorded by the moderator who issued the ban. Reasons written by Your moderators may contain data relating to criminal convictions and offences within the meaning of Article 10 GDPR, or special categories of personal data within the meaning of Article 9 GDPR. The Company neither requires nor evaluates that content; it is stored as written.
- Per-user permission overwrites — channel permissions granted to or denied to an individual member, which identify that member by Discord user ID.
- Server-level identifiers — the Discord user ID of the Server owner, and the user IDs recorded as creators of AutoMod rules, webhooks and similar server objects.
- Operator data — the Discord user ID, username and avatar of the person in Your team who started an operation, recorded in the audit log of Your Workspace.
The last three categories are part of a Server’s configuration. They are therefore contained in every backup, including backups taken without message content, and in templates unless the template generation removes them.
Categories of Data Subjects
- Current members of Your Server.
- Former members of Your Server whose messages, member record or permission overwrites were present when a backup or chatlog was taken.
- Users banned from Your Server, who may never have been members of it.
- Bot accounts and webhook identities present in Your Server, to the extent they relate to an identifiable person.
- Members of Your team who operate the Service on Your behalf.
Processing on Documented Instructions
The Company processes Discord Data only on Your documented instructions, including with regard to transfers to a third country, as required by Article 28(3)(a) GDPR.
Your instructions consist of this DPA, the Terms of Service, and the operations You start through the Service — through the Website, the Discord bot, the API or any automation You configure. Starting a backup, chatlog, template, synchronization, restore, export or deletion is an instruction to carry out that operation on the Server and data You selected. Connecting a Server to the Service is an instruction to process that Server as described here. No separate written instruction is required.
Additional or diverging instructions must be agreed in text form and may be subject to a charge where they require work beyond the features of the Service.
The Company may process Discord Data without Your instruction where Union or Member State law requires it, in which case it will inform You of that requirement before processing, unless the law prohibits that information on important grounds of public interest.
The Company will inform You without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend execution of that instruction until it is confirmed or withdrawn.
Your Obligations as Controller
You are responsible for the lawfulness of the processing You instruct. In particular You warrant that:
- You determine the purposes and the means of the processing of Discord Data from every Server You connect, and You are the controller of that Discord Data.
- You have a valid legal basis under Article 6 GDPR — and, for data falling under Articles 9 or 10, under those Articles — for the collection of the Discord Data and for having the Company process it.
- You have provided the members of Your Server with the information required by Articles 13 and 14 GDPR, including that a third-party service creates copies of the Server and its content.
- You are authorised to act for every Server connected to Your Workspace, whether it was connected before or after You accepted this DPA. Accepting this DPA, and connecting a Server afterwards, are each a representation that You hold that authority for the person or entity that operates the Server and that this DPA binds them. If You do not hold it, You accept this DPA in Your own name and are liable for the resulting processing.
- The person or entity that accepted this DPA for Your Workspace is the controller of every Server connected to it. Where a Server is operated by a different legal person — for example where You manage Servers for third parties — that person must accept this DPA for their own Workspace before the Server is connected, or authorise You to accept it on their behalf.
- Your instructions comply with Applicable Data Protection Law, with Discord’s Terms of Service and Developer Terms, and do not require the Company to act unlawfully.
You are responsible for the content of ban reasons and other free-text fields written by Your moderators, and for deciding whether such content may be stored by a processor at all.
Confidentiality
The Company ensures that persons authorised to process Discord Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, as required by Article 28(3)(b) GDPR. That obligation survives the end of their engagement.
Access to Discord Data is limited to persons who need it to operate the Service, to resolve a fault or to respond to a support request, and only for as long as that need lasts.
Security of Processing
The Company implements appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risk to data subjects. The measures in place include:
- Encryption in transit — all traffic between You and the Service, between the Service and Discord, and between the Service and its Sub-processors is encrypted with current TLS. Traffic between the Company’s own systems runs over an encrypted private network.
- Encryption at rest — the database holding Discord Data is stored on an encrypted volume, and its backups are encrypted with AES-256 before they leave the server. Objects in Our storage provider, and the copies of them We keep, are encrypted individually with AES-256 using a key We supply on each request and which the provider does not retain.
- Access control — administrative access to production systems is restricted to named individuals, requires multi-factor authentication and is granted on a least-privilege basis. Application access to Discord Data is scoped to the Workspace that owns it and is enforced on every request.
- Separation — Discord Data is stored per Workspace and is not commingled between customers. Production data is not used in development or test environments.
- Minimisation of Discord permissions — the bot requests only the Discord permissions and gateway intents needed for the features it provides.
- Availability and resilience — regular backups of the systems holding Discord Data, monitoring of availability and errors, and a documented restore procedure.
- Integrity and traceability — operations started through the Service are recorded in the audit log of the Workspace, identifying who started them and when.
- Deletion — deletion routines that remove Discord Data from primary storage and from object storage when an artifact, Server or Workspace is deleted, and that let residual copies in infrastructure backups expire on their rotation cycle.
The Company reviews these measures periodically and may replace a measure with one that offers an equivalent or higher level of protection. The current version of this section is the agreed description of the measures under Article 28(3)(c) GDPR.
Sub-processors
You give the Company general written authorisation to engage Sub-processors for the processing of Discord Data, as provided for in Article 28(2) GDPR. The Company imposes on each Sub-processor, by contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to You for the performance of that Sub-processor’s obligations.
The Company currently engages the following categories of Sub-processor. The corresponding section of the Privacy Policy lists the same set and is kept in sync with this one:
- Discord — the platform the Service operates on and the source and destination of all Discord Data. Discord’s own terms govern Your and Your members’ use of Discord.
- Hosting and infrastructure providers — operate the servers, databases and object storage on which the Service and Your Discord Data reside.
- Logging and error monitoring providers — receive application logs and diagnostic telemetry, which may incidentally contain identifiers such as Discord user IDs and Server IDs.
- Paddle — payment provider and Merchant of Record. Paddle does not receive Discord Data and acts as an independent controller for the billing data it processes.
The Company will inform You of any intended addition or replacement of a Sub-processor at least 30 days in advance, by email to the address associated with Your Workspace or by updating this page and notifying You in the Service. You may object to the change on reasonable data protection grounds within that period. If You object and the Company cannot provide the Service without the Sub-processor, You may terminate the affected part of the Service and have the corresponding Discord Data deleted, with a pro rata refund of any prepaid fees for the unused period.
Assistance with Data Subject Requests
Taking into account the nature of the processing, the Company assists You by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Your obligation to respond to Data Subject Requests, as required by Article 28(3)(e) GDPR.
The Service itself provides the primary means of assistance: You can inspect, export and delete the artifacts that contain Discord Data at any time, and deleting an artifact deletes the personal data it contains.
If a data subject sends a Data Subject Request concerning Discord Data to the Company, the Company will not respond to it on its own account beyond confirming its role as processor, and will forward the request to You without undue delay, together with the information You need to identify the Servers and artifacts concerned.
Standing erasure instruction
You instruct the Company in advance to give effect to a verified erasure request from a data subject whose personal data is contained in Discord Data processed for You, by deleting that person’s personal data from the affected artifacts or, where deletion of the individual records is not possible with reasonable effort, by deleting the affected artifacts.
Before acting, the Company will notify You of the request. You may object within 14 days by informing the Company that an exception under Article 17(3) GDPR applies and by identifying the ground You rely on. If You do not object within that period, the Company will carry out the erasure on the basis of this standing instruction. If You do object, the Company will not act and the responsibility for responding to the data subject remains with You.
This standing instruction does not apply where the Company is required by law to retain the data, and does not affect the Company’s own obligations for data it controls.
Assistance beyond the features of the Service — for example targeted searches across artifacts — is provided at cost where it requires substantial manual effort, unless the effort is caused by the Company’s failure to comply with this DPA.
Assistance with Articles 32 to 36
The Company assists You, taking into account the nature of the processing and the information available to it, in ensuring compliance with the obligations under Articles 32 to 36 GDPR, as required by Article 28(3)(f) GDPR.
Personal data breaches
The Company notifies You without undue delay after becoming aware of a Personal Data Breach affecting Discord Data processed for You, as required by Article 33(2) GDPR. The notification describes, to the extent known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not available at once, it is provided in phases without further undue delay.
Notification to the supervisory authority under Article 33(1) and to data subjects under Article 34 is Your responsibility as controller. The Company does not make those notifications on Your behalf unless You instruct it to and it is in a position to do so.
Impact assessments and prior consultation
The Company provides You, on request, with the information about the processing it carries out that You reasonably need for a data protection impact assessment under Article 35 GDPR or a prior consultation with a supervisory authority under Article 36 GDPR.
Deletion and Return
At Your choice, the Company deletes or returns all Discord Data processed for You after the end of the provision of the Service, and deletes existing copies, unless Union or Member State law requires storage, as provided in Article 28(3)(g) GDPR.
- Return — You can export Your artifacts through the Service for as long as Your Workspace exists. Exporting before deletion is Your responsibility; the Company does not retain a copy in order to return it later.
- Deletion on Your instruction — deleting an artifact, removing a Server from the Service or closing Your Workspace deletes the corresponding Discord Data from primary storage and object storage without undue delay, and at the latest within 30 days.
- Deletion on termination — if this DPA or Your use of the Service ends for any other reason, the Company deletes the Discord Data processed for You within 30 days of the end, unless You instruct otherwise in that period.
- Infrastructure backups — copies of Discord Data contained in the Company’s own encrypted infrastructure backups are not deleted individually. They are overwritten on the ordinary backup rotation cycle, and remain subject to this DPA until they are.
Audit and Information Rights
The Company makes available to You all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by You or an auditor mandated by You, as required by Article 28(3)(h) GDPR.
- The Company answers reasonable written questions about its processing and security measures, and provides any certifications, reports or Sub-processor documentation it holds.
- Where that information is not sufficient, You may carry out an on-site inspection during normal business hours, after at least 30 days’ written notice, no more than once per calendar year, unless a Personal Data Breach or a supervisory authority gives cause for an additional inspection.
- Inspections must not disrupt the operation of the Service and must respect the confidentiality and the personal data of other customers. The Company may require the auditor to sign a confidentiality undertaking and may refuse an auditor who is a competitor.
- Each party bears its own costs. The Company may charge for time spent supporting an inspection beyond the first working day per year, unless the inspection reveals a breach of this DPA.
International Transfers
Discord Data is stored on infrastructure located in the European Economic Area.
Where the Company or a Sub-processor transfers Discord Data outside the European Economic Area, it does so only if the destination country is covered by an adequacy decision of the European Commission, or on the basis of the European Commission’s Standard Contractual Clauses in the modules appropriate to the transfer, together with any supplementary measures the transfer requires. You mandate the Company to conclude those clauses with its Sub-processors on Your behalf. A copy of the safeguards relied on is available on request.
Discord is a United States company and operates the platform on which Your Server exists. Data flowing to and from Discord in the ordinary operation of Your Server is governed by Your own relationship with Discord and is outside the scope of this DPA.
Term, Acceptance and Changes
This DPA takes effect when You accept it and remains in force for as long as the Company processes Discord Data for You. The obligations on confidentiality, deletion and audit survive its end for as long as the Company holds Discord Data processed for You.
Acceptance is electronic and is recorded by the Company together with the version of the document accepted, the account that accepted it and the time of acceptance. Article 28(9) GDPR treats electronic form as equivalent to written form.
The Company may update this DPA where a change in law, in the Service or in its Sub-processors requires it. Material changes are notified at least 30 days in advance by email or in the Service, and continued use of the Service after a material change requires renewed acceptance of the new version. The version identifier at the top of this page states which text is currently in force.
Liability and Order of Precedence
The liability provisions of the Terms of Service apply to this DPA, without prejudice to the rights of data subjects under Articles 79 and 82 GDPR.
In case of conflict, this DPA prevails over the Terms of Service and the Privacy Policy in respect of the processing of Discord Data, and the Standard Contractual Clauses prevail over this DPA in respect of transfers governed by them. In all other respects the Terms of Service remain unchanged.
This DPA is governed by German law. The place of jurisdiction is Leipzig, Germany, to the extent that a place of jurisdiction can be agreed.
Contact
Questions about this DPA, requests for the safeguards or documentation referred to above, objections to a Sub-processor and notifications under the standing erasure instruction go to contact@xenon.bot.