Data Processing Addendum
Last updated Version dpa-2026-09-16
This Data Processing Addendum (“DPA”, document version “dpa-2026-09-16”) forms part of the Terms of Service between You and the Company and governs the processing of personal data contained in Discord servers that You instruct the Service to process on Your behalf.
It is concluded under Article 28(3) of Regulation (EU) 2016/679 (“GDPR”). It applies where You act as controller for Discord Data processed through a Workspace and the Company acts as processor. Where the Company acts as controller in its own right (Your account, billing, usage data, abuse prevention and the public gallery, and operational logs except for the Server identifiers they carry), the Privacy Policy applies instead.
This DPA is concluded in electronic form, which Article 28(9) GDPR permits: it is part of the Terms, and You agree to it when You agree to them.
Definitions
Terms defined in the Terms of Service and the Privacy Policy have the same meaning here, and in case of conflict the definitions here prevail. In addition:
- Company (also “We”, “Us” or “Our”) refers to Merlin Fuchs, Alte Str. 5, 04229 Leipzig, Germany, acting as processor under this DPA.
- You means the individual or legal entity that operates a Server and instructs the Service to process Discord Data from it, acting as controller under this DPA.
- Server means a Discord guild that You have connected to the Service.
- Workspace means the organization within the Service through which You manage Your Servers, Your Subscription and the members of Your team.
- Discord Data means content and metadata from a Server that the Service processes on Your instruction, such as server settings, channels, roles, permissions, members, bans, messages, attachments and audit log entries, contained in backups, chatlogs, templates, synchronizations or any other feature of the Service that works on a Server.
- Sub-processor means any processor engaged by the Company to carry out part of the processing described in this DPA.
Scope
This DPA applies to every Server You connect to a Workspace, from the moment You first instruct the Service to process Discord Data from it. Removing a Server ends the processing for that Server as set out under “Deletion and Return” below.
An earlier version of the Service, which predates Workspaces and is being retired, still serves some Discord servers. This DPA describes the Service as it works now: a Server that has not been connected to a Workspace is outside this DPA until it is connected.
Publishing a template to the public gallery falls outside this DPA. Submitting a listing is Your decision, but whether it appears, how it is checked, where it ranks and how long it stands are the Company’s, which makes the Company the controller of that processing. The Privacy Policy describes it.
Roles of the Parties
For Discord Data, You are the controller and the Company is the processor. You determine which Server is processed, which feature is used, when it runs and how long the result is kept. The Company processes Discord Data only to deliver the feature You started.
The Company treats every person who connects a Server to a Workspace as the controller for the Discord Data of that Server, and relies on the warranties You give under “Your Obligations as Controller” below. The Company cannot determine who operates a Discord server or on whose behalf a Server is run. If You are not the controller of a Server You connected, this DPA still binds You in respect of the instructions You gave, and the processing carried out on them is attributable to You.
Where more than one person qualifies as controller for a Server, each is bound by this DPA in respect of the instructions they give, and the Company may act on the instruction of any of them. A Server can be connected to more than one Workspace, and a synchronization configured in one Workspace can copy content out of a shared Server into a Server only that Workspace holds. The Company acts on the instruction of the Workspace that configured it and cannot tell whether the other controllers of the source Server agreed. Deciding who may connect Your Server, and to which Workspace, is Yours.
Subject-matter, Duration, Nature and Purpose
The subject-matter of the processing is the creation, storage, inspection, comparison, export, restoration and deletion of snapshots and copies of Discord servers and their content, and the other operations on a Server that the features of the Service carry out on Your instruction.
The nature of the processing consists of collection from Discord, structuring, storage, retrieval, transmission back to Discord, transmission to You on export, and erasure. The Company does not use Discord Data for its own purposes, does not sell it, does not use it for advertising, and does not use it to train machine learning models.
The purpose of the processing is to provide the features of the Service that You use, such as backups, chatlogs, templates and synchronizations, together with the restoration, export and deletion of what they create.
The duration of the processing is the term of Your use of the Service. Individual Discord Data is processed until You delete the artifact that contains it, until the artifact is superseded by the retention limits of Your plan, or until Your Workspace is closed, plus the deletion periods set out under “Deletion and Return” below.
Types of Personal Data
Depending on which features You use, the processing covers:
- Message content and metadata: the text of messages, embeds, attachments, timestamps, message and channel identifiers, and the Discord user ID, username, display name and avatar of the message author.
- Attachments: files, images and other media posted in messages, with their filenames and metadata, and any personal data contained inside those files.
- Member lists: Discord user IDs, usernames, display names, server nicknames, avatars, role assignments, join dates and timeout state of the members of Your Server.
- Ban records: the Discord user ID and username of a banned user together with the reason recorded by the moderator who issued the ban.
- Audit log entries of Your Server: the Discord user ID of the moderator who took an action, the user or object it was taken on, the kind of action, and the reason the moderator wrote.
- Per-user permission overwrites: channel permissions granted to or denied to an individual member, identified by Discord user ID.
- Server-level identifiers: the Discord user ID of the Server owner, and the user IDs recorded as creators of AutoMod rules, webhooks and similar server objects.
- Other server objects: personal data contained in any other part of a Server that a feature You use processes, to the extent that feature requires it.
Per-user permission overwrites and server-level identifiers are part of a Server’s configuration and are therefore contained in every backup, including backups taken without message content.
Messages, ban reasons and other free text are stored as written and not evaluated by the Company. Being free text, they may incidentally contain special categories of personal data (Article 9 GDPR) or data relating to criminal offences (Article 10 GDPR); whether such content may be processed at all is Your decision as controller.
Categories of Data Subjects
- Current and former members of Your Server.
- Users banned from Your Server, who may never have been members of it.
- Bot accounts and webhook identities present in Your Server, to the extent they relate to an identifiable person.
Processing on Documented Instructions
The Company processes Discord Data only on Your documented instructions, including with regard to transfers to a third country (Article 28(3)(a) GDPR).
Your instructions consist of this DPA, the Terms of Service, and the operations You start through the Service. Starting an operation, such as a backup, chatlog, template, synchronization, restore, export or deletion, is an instruction to carry out that operation on the Server and data You selected. Connecting a Server is an instruction to process that Server as described here. Additional or diverging instructions must be agreed in writing (email suffices) and may be charged where they require work beyond the features of the Service.
The Company may process Discord Data without Your instruction where Union or Member State law requires it, in which case it informs You of that requirement before processing unless the law prohibits it. The Company informs You without undue delay if, in its opinion, an instruction infringes the GDPR, and may suspend that instruction until it is confirmed or withdrawn.
Your Obligations as Controller
You are responsible for the lawfulness of the processing You instruct. In particular You warrant that:
- You are the controller of the Discord Data from every Server You connect.
- You have a valid legal basis under Article 6 GDPR (and, for data falling under Articles 9 or 10, under those Articles) for the collection of the Discord Data and for having the Company process it.
- You are responsible for informing the members of Your Server as Articles 13 and 14 GDPR require, including that a third-party service creates copies of the Server and its content.
- You are authorized to act for every Server You connect and every operation You start on it. Connecting a Server, and starting an operation on it, are each a representation that You hold that authority and that this DPA binds the person or entity that operates the Server. Where a Server is operated by a different legal person, that person must use the Service through a Workspace of their own or authorize You to act on their behalf.
- Your instructions comply with the GDPR and with Discord’s Terms of Service and Developer Terms, and do not require the Company to act unlawfully.
- You decide which Discord permissions the bot holds in Your Server, and You grant it no more than the features You use require.
Confidentiality
Persons authorized by the Company to process Discord Data are committed to confidentiality (Article 28(3)(b) GDPR). Access to Discord Data is limited to persons who need it to operate the Service, to resolve a fault or to respond to a support request, and only for as long as that need lasts.
Security of Processing
The Company implements appropriate technical and organizational measures under Article 32 GDPR. They cover at least:
- Encryption: Discord Data is encrypted in transit between You, the Service, Discord and the Sub-processors, and at rest in the databases and object storage that hold it, with the keys managed separately from the storage they protect.
- Access control: production systems are reachable only over the Company’s private network, administrative access requires cryptographic credentials, and application access to Discord Data is scoped to the Workspace that owns it and enforced on every request.
- Separation: Discord Data is stored per Workspace and is not commingled between customers. Production data is not used in development or test environments.
- Minimization: the bot subscribes only to the Discord events the features of the Service consume and needs only the permissions the feature You use requires, which are set by You and can be changed by You at any time.
- Availability: regular backups of the systems holding Discord Data and monitoring of availability and errors.
- Traceability: operations started through the Service are recorded in the audit log of the Workspace, identifying who started them and when.
- Deletion: routines that remove Discord Data from primary storage and from object storage when an artifact or a Workspace is deleted, with residual copies in infrastructure backups expiring on their rotation cycle.
The measures as currently implemented are described at /security, which forms part of this DPA (Article 28(3)(c) GDPR). The Company may change a measure without reducing the overall level of protection; changes to that page are notified as set out under “Term and Changes” below.
Sub-processors
You give the Company general written authorization to engage Sub-processors for the processing of Discord Data (Article 28(2) GDPR). The Company imposes on each Sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains liable to You for that Sub-processor’s performance.
The Sub-processors currently engaged, what each does and where it processes, are listed at /subprocessors, which forms part of this DPA.
The Company informs You before a Sub-processor first processes Discord Data for You:
- Where a Sub-processor serves a feature You have not used yet, the notice is given with that feature, and the Sub-processor processes Your Discord Data only once You start using it.
- Where a Sub-processor replaces or joins one that already processes Discord Data for You, the notice is given at least 14 days before the change, unless the change is needed without delay to keep the Service secure or available, in which case the Company informs You as soon as it can afterwards.
You may object to a new Sub-processor on reasonable data protection grounds. If the Company cannot provide the affected feature without it, You may stop using that feature and have the corresponding Discord Data deleted, and where You paid for it, the Company refunds the part of the period You have paid for and not received.
Discord is not a Sub-processor: it is the platform Your Server exists on and determines its own purposes for the data it holds. Providers that receive no Discord Data are not Sub-processors under this DPA; the Privacy Policy lists them.
Assistance with Data Subject Requests
Taking into account the nature of the processing, the Company assists You in fulfilling Your obligation to respond to requests by data subjects exercising their rights under Chapter III GDPR (Article 28(3)(e) GDPR). The Service itself is the primary means: You can inspect, export and delete the artifacts that contain Discord Data at any time, and deleting an artifact deletes the personal data it contains.
If a data subject sends such a request concerning Discord Data to the Company, the Company confirms its role as processor and forwards the request to You without undue delay, together with the information You need to identify the Servers and artifacts concerned.
The Company deletes personal data from Discord Data on Your instruction, given through the Service or in writing, by deleting the affected artifact or, where the Service supports it, the individual record. It does not delete on a data subject’s request alone.
Assistance beyond the features of the Service is provided at cost where it requires substantial manual effort, unless the effort is caused by the Company’s failure to comply with this DPA.
Assistance with Articles 32 to 36
The Company assists You, taking into account the nature of the processing and the information available to it, with Your obligations under Articles 32 to 36 GDPR (Article 28(3)(f) GDPR).
The Company notifies You without undue delay after becoming aware of a personal data breach (Article 4(12) GDPR) affecting Discord Data processed for You, with the information Article 33(3) GDPR calls for as far as it is available, and in phases where it is not. Notification to the supervisory authority and to data subjects is Your responsibility as controller.
On request, the Company provides the information about its processing that You reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority.
Deletion and Return
At Your choice, the Company deletes or returns all Discord Data processed for You after the end of the provision of the Service, and deletes existing copies, unless Union or Member State law requires storage (Article 28(3)(g) GDPR).
- Return: You can export Your artifacts through the Service for as long as Your Workspace exists. Exporting before deletion is Your responsibility; the Company does not retain a copy in order to return it later.
- Deletion on Your instruction: deleting an artifact deletes the Discord Data it contains from primary storage and object storage without undue delay, and at the latest within 30 days.
- Closing Your Workspace: You can close a Workspace in the Service or by instructing the Company at dpa@xenon.bot. Closing it deletes the Discord Data it holds, including the Workspace’s audit log.
- Removing a Server: removing a Server from the Service ends the processing of that Server going forward: the Service stops receiving events from it and stops making new artifacts from it. The artifacts already taken from that Server belong to Your Workspace and are not deleted by the removal. They remain subject to this DPA until You delete them or close the Workspace.
- Deletion on termination: where the Company ends the provision of the Service to You, it deletes the Discord Data processed for You without undue delay after telling You, unless You instruct otherwise in the meantime. Leaving the Service unused is not an instruction to delete anything.
- Mirrored audit log entries: entries of Your Server’s audit log that a synchronization records expire 90 days after they were recorded, independently of any artifact.
- Infrastructure backups: copies of Discord Data in the Company’s own encrypted infrastructure backups are not deleted individually. They are overwritten on the ordinary rotation cycle and remain subject to this DPA until they are.
Audit and Information Rights
The Company makes available to You the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by You or an auditor mandated by You (Article 28(3)(h) GDPR).
- The Company answers reasonable written questions about its processing and security measures, and provides the certifications, reports or Sub-processor documentation it holds. This is the ordinary form of an audit.
- Where written information is not sufficient to meet a requirement of Yours under the GDPR, or a supervisory authority requires it, You may carry out an inspection after at least 30 days’ written notice, no more than once per calendar year, unless a personal data breach or a supervisory authority gives cause for an additional one.
- Inspections must not disrupt the operation of the Service and must respect the confidentiality and the personal data of other customers. The Company may require the auditor to sign a confidentiality undertaking and may refuse an auditor who is a competitor.
- Each party bears its own costs. The Company may charge for time spent supporting an inspection, unless the inspection reveals a breach of this DPA.
International Transfers
Discord Data is stored and processed on infrastructure in the European Economic Area, except where the Sub-processor list at /subprocessors says otherwise for a named Sub-processor.
Transfers outside the European Economic Area rely on an adequacy decision of the European Commission or on its Standard Contractual Clauses. A copy of the safeguards relied on is available on request.
Data flowing to and from Discord in the ordinary operation of Your Server is governed by Your own relationship with Discord and is outside this DPA.
Term and Changes
This DPA applies for as long as the Company processes Discord Data for You. The obligations on confidentiality, deletion and audit survive its end for as long as the Company holds Discord Data processed for You.
The Company may change this DPA, the Sub-processor list and the description of the security measures where a change in the law, in the Service or in its Sub-processors requires it, and where the change is reasonable for You taking the Company’s interest and Yours into account. Changes are announced in the Service and on this website before they take effect, with the date they take effect; the section on Sub-processors above says how far ahead a Sub-processor change is announced. The announcement says that continuing to use the Service after that date means the changed text applies, and You may end Your use of the Service before then instead.
A changed DPA carries a new version identifier. The Sub-processor list and the description of the security measures carry their own change history, and a change to them does not change the version of this DPA. This page serves the version in force, and the version it replaces stays published at an address of its own, listed under History below.
Liability and Order of Precedence
The liability provisions of the Terms of Service apply to this DPA, without prejudice to the rights of data subjects under Articles 79 and 82 GDPR.
In case of conflict, this DPA prevails over the Terms of Service and the Privacy Policy in respect of the processing of Discord Data, and the Standard Contractual Clauses prevail over this DPA in respect of transfers governed by them.
This DPA is governed by German law. The place of jurisdiction is Leipzig, Germany, to the extent that a place of jurisdiction can be agreed.
Contact
Questions about this DPA, requests for the documentation referred to above, objections to a Sub-processor, and deletion instructions go to dpa@xenon.bot.
History
- dpa-2026-09-16, , the version in force. Applies through the Terms of Service from the first processing instead of a separate acceptance, and the Sub-processor list and the security measures move to pages of their own.