1. Introduction
This Privacy Policy describes in detail how we collect, use, store, and protect your personal data when you use our Discord applications. We respect your privacy and are committed to protecting your personal data in accordance with applicable legislation, including the General Data Protection Regulation (GDPR) and other relevant data protection laws that may apply in your jurisdiction. By using our applications, you acknowledge that you have read and understood this policy and consent to the processing of your data as described herein.
2. Data Controller
The data controller responsible for the processing of your personal data in connection with our Discord applications is the operator of these applications. As the data controller, we determine the purposes and means of the processing of your personal data and are accountable for ensuring that such processing complies with applicable law. If you have any questions regarding the processing of your personal data, your rights, or how to exercise them, you can contact us at any time using the contact information provided in the Contact section below. We will respond to your enquiries in a timely manner and, where required by law, within the statutory deadlines.
3. What Data We Collect
When you use our Discord applications, we may collect certain categories of personal data. The exact data collected depends on how you interact with the application and which features you use. We only collect data that is necessary for the purposes described in this policy. Below is a comprehensive overview of the types of data we may process:
- •Discord Account Data: This includes your Discord username, unique Discord user ID, profile avatar, discriminator (where applicable), and other information that is publicly available or that you choose to share through your Discord profile. We use this data to identify you within the application and to provide personalised features.
- •Usage Data: We may collect information about how you use the application, including which commands you invoke, which features you use, the frequency and timing of your interactions, and other behavioural data. This helps us understand how the application is used and to improve its functionality and user experience.
- •Technical Data: For operational and security purposes, we may process technical data such as your IP address, device or browser type, operating system, timestamps of requests, and similar technical identifiers. This data is necessary to ensure the proper functioning, security, and stability of our services.
- •Server Data: When our application is added to a Discord server, we may collect and store the server’s unique ID, server name, and basic configuration or settings relevant to the application’s operation within that server. This allows us to deliver the service correctly in each server context.
4. Purpose of Data Processing
We process your personal data only for clearly defined, legitimate purposes. We do not use your data for purposes incompatible with those set out below unless we have obtained your consent or are required to do so by law. The main purposes for which we process your data are:
- •Providing and improving application functionality: We use your data to deliver the features and services you request, to personalise your experience where applicable, and to develop and improve the application based on how it is used.
- •Security and prevention of abuse: We process data to protect the integrity and security of our services, to detect and prevent fraud, abuse, and other harmful or unauthorised use, and to enforce our terms of service.
- •Communication and support: Where you contact us or we need to communicate with you (for example regarding updates, important notices, or support requests), we use your data to respond and to provide assistance.
- •Analytics to improve user experience: We may use aggregated or anonymised data to analyse usage patterns and to improve the design, performance, and user experience of our applications, without identifying you personally where possible.
- •Fulfilling legal obligations: We may process and retain your data where necessary to comply with applicable laws, regulations, court orders, or requests from competent authorities.
5. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR) and equivalent laws, we are required to have a valid legal basis for each processing activity. We process your personal data on one or more of the following bases, as appropriate: (1) Your consent — where you have given clear consent for specific processing; (2) Contract performance — where processing is necessary to perform our contract with you or to take steps at your request before entering into a contract; (3) Legitimate interests — where we have a legitimate interest in processing (such as improving our services, security, or analytics) that is not overridden by your rights; and (4) Legal obligations — where we must process data to comply with a legal obligation. Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal. Further details can be provided on request.
6. Data Retention Period
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, as described in this policy, or for as long as we are required or permitted to retain it by applicable law (for example for tax, legal, or regulatory reasons). Retention periods may vary depending on the type of data and the purpose of processing. Once the retention period has expired or the purpose has been fulfilled, we will securely delete or anonymise your personal data so that it can no longer be attributed to you, unless we are legally obliged or entitled to retain it for a longer period. If you would like to know the specific retention period applied to a particular category of your data, you may contact us using the details below.
7. Sharing Data with Third Parties
We do not sell, rent, or trade your personal data to third parties for their marketing purposes. We may share your personal data with third parties only in the following circumstances: (1) Service providers: We may use trusted third-party service providers (such as hosting providers, infrastructure providers, or analytics services) who process data on our behalf to enable us to deliver and operate our applications. Such processors act only on our instructions and are contractually bound to protect your data and to use it only for the purposes we specify, in accordance with applicable data protection law (including, where relevant, standard contractual clauses or other transfer mechanisms). (2) Legal requirements: We may disclose your data when required by law, court order, or governmental or regulatory authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others. Where permitted, we will endeavour to inform you of such disclosure. We remain responsible for the processing of your personal data and, where we use processors, we ensure that appropriate safeguards are in place.
8. Your Rights
Under the GDPR and applicable data protection laws, you have a number of rights in relation to your personal data. Subject to certain conditions and exceptions set out in law, you may exercise the following rights:
- •Right of access: You have the right to obtain confirmation as to whether we process your personal data and, where that is the case, to access that data and to receive certain information about the processing (including purposes, categories of data, recipients, retention periods, and your rights).
- •Right to rectification: You have the right to have inaccurate or incomplete personal data corrected or completed without undue delay.
- •Right to erasure (“right to be forgotten”): In certain circumstances, you have the right to request the deletion of your personal data (for example where the data is no longer necessary, where you withdraw consent, or where the data has been unlawfully processed).
- •Right to restriction of processing: In certain situations, you have the right to request that we restrict the processing of your data (for example while we verify the accuracy of data or the legitimacy of our grounds for processing).
- •Right to data portability: Where we process your data by automated means on the basis of consent or contract, you may have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
- •Right to object: You have the right to object to processing based on legitimate interests or for direct marketing. Where we process your data for direct marketing, we will cease such processing upon your objection.
- •Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us using the contact details provided in the Contact section below. We will respond to your request without undue delay and in any event within the time limits set by applicable law (typically one month, which may be extended where necessary). You may also have the right to lodge a complaint with a supervisory authority; see the section “Right to Lodge a Complaint” for more information.
9. Data Security
We implement appropriate technical and organisational measures designed to protect your personal data against unauthorised or unlawful access, accidental loss, destruction, alteration, or disclosure. These measures include, where appropriate: the use of encryption (for example in transit via TLS/HTTPS and, where applicable, at rest); secure and restricted access to systems and data; regular review and updating of our security practices and infrastructure; and the selection of service providers that meet adequate security and compliance standards. Despite our efforts, no method of transmission over the internet or electronic storage is completely secure; we cannot guarantee absolute security but we are committed to handling your data responsibly and in line with applicable law. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required by law, affected individuals without undue delay.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the scope of our services. When we make changes, we will update the “Last updated” date at the top of this document. For changes that we consider to be material or that affect how we use your personal data in a significant way, we will endeavour to inform you by posting a notice through the application, by email (where we have your contact details), or by other appropriate means before the changes take effect, where feasible. We encourage you to review this Privacy Policy periodically so that you are aware of how we protect your information. Your continued use of our applications after the effective date of any changes constitutes your acceptance of the updated policy, except where further consent or other steps are required by law.
12. Contact
If you have any questions about this Privacy Policy, about how we process your personal data, or if you wish to exercise any of your rights described in this policy, please contact us at [email protected]. We will do our best to address your request promptly and in accordance with applicable law.
You may use this contact to request access to your data, request rectification or erasure, restrict processing, request data portability, object to processing, withdraw consent, or raise any other privacy-related concern. When contacting us, please provide sufficient information (such as your Discord identifier or the context of your use) so that we can verify your identity and respond appropriately. We will respond to your request without undue delay and in any event within the time limit required by applicable law (typically within 30 days from the date of receipt of your request, subject to any permitted extension where the request is complex or numerous). If we are unable to fulfil your request in full, we will explain the reasons and inform you of your right to lodge a complaint with a supervisory authority.
13. Right to Lodge a Complaint
If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority (data protection authority) in the country of your habitual residence, place of work, or place of the alleged infringement. In the European Union, each member state has a designated supervisory authority; you can find their contact details on the European Commission’s or your national authority’s website. We encourage you to contact us first using the details in the Contact section so that we can try to resolve your concern; however, you are not required to do so before lodging a complaint with a supervisory authority, and the right to lodge a complaint is without prejudice to any other administrative or judicial remedy you may have.