Privacy Policy
Effective from
1. Controller and scope
The controller of the personal data described in this Privacy Policy (this "Policy") is PWN d.o.o. (PWN Ltd) ("we", "us", "our"), whose registered particulars are set out in the Legal Notice. Our contact for data protection matters is [email protected]. We have not designated a data protection officer, as none is required.
This Policy applies to Administrators, Subscribers, Members and visitors to the Website. A "Member" is a person who belongs to a Server in which the Bot is present, whether or not that person uses the Service; "you" is the person whose personal data is concerned. Other capitalised terms, including "Terms", have the meanings given in the Terms of Service. Articles cited are those of Regulation (EU) 2016/679 (the "GDPR") unless otherwise stated.
2. Signing in to the Dashboard
To sign you in, we request from Discord only the identify scope (your identity) and the guilds
scope (the Servers you belong to). We do not request the email scope, so Discord does not disclose
your email address to us.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Discord user ID, username, display name and avatar image URL | Signing you in and identifying you | Contract (Article 6(1)(b)) | In your session cookie, 3 days |
| Discord access token | Retrieving from Discord, on your behalf, your identity and your Servers | Contract (Article 6(1)(b)) | In your session cookie, 3 days. Our systems store only a one-way hash of it, as a cache key |
| Your Servers, with their names, icons and your permissions in them | Showing the Servers in which you can configure the Bot | Contract (Article 6(1)(b)) | Cached in our systems, no longer than 1 hour |
| Your profile as returned by Discord (user ID, username, avatar) | Avoiding a request to Discord on every Dashboard request, and operating during a Discord outage | Legitimate interests (Article 6(1)(f)) | Cached in our systems, no longer than 1 hour |
| A request counter linked to your Discord user ID | Preventing one account from overloading the Service | Legitimate interests (Article 6(1)(f)) | no longer than 1 hour |
This data is required to use the Dashboard, but not the Bot's commands in Discord.
3. Configuring the Bot
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Server ID, the IDs of Enabled Channels, and whether the Server has completed channel setup | Determining where the Bot Publishes | Contract (Article 6(1)(b)) | Until the channel ceases to be an Enabled Channel. A Server's configuration is deleted 30 days after the Bot leaves it |
| Whether the Bot is in a Server, and when it joined or left | Identifying the Servers we serve, and keeping their configuration while the Bot is absent | Contract (Article 6(1)(b)) | As above |
| Filters | Determining which messages the Bot Publishes | Contract (Article 6(1)(b)) | Until deleted by an Administrator, or with their Enabled Channel or the Server's configuration |
| The Bot's permissions in each Announcement Channel | Informing Administrators when the Bot cannot Publish | Contract (Article 6(1)(b)) | 14 days |
Personal data in Filters
Each condition of a Filter is of one of four types:
- Content: words or phrases, stored as entered. We ask Administrators not to include personal data in them.
- Author: Discord user IDs.
- Mention: Discord role IDs and user IDs.
- Webhook: Discord webhook IDs only, never webhook names, URLs or tokens.
The Bot reads each Filter from a copy in our systems that has no expiry and is updated and deleted together with the Filter.
4. Members
Messages in Enabled Channels. When you post a message in an Enabled Channel, the Bot reads its text (including that of embeds and message components), your Discord user ID, the users and roles it mentions and the ID of any webhook that posted it, to determine whether to Publish it under any Filter set for the channel. This takes place in memory, and the data is discarded immediately; message content is not stored, logged or transmitted. The Bot passes only the Server, channel and message IDs to the part of our systems that asks Discord to Publish the message. That part keeps a record of those IDs and of the outcome, so that it can repeat a request that Discord could not process, and deletes it about 24 hours after the last attempt. Our system logs can contain the same IDs, never message content, and are overwritten automatically at a fixed size.
The source of this data is Discord's gateway, under the Message Content intent that Discord has granted to the Bot. The legal basis is legitimate interests (Article 6(1)(f)): Publishing messages as configured by the Server's Administrators, which requires each message to be read.
Identifiers in Filters. An Administrator of a Server you belong to may add your Discord user ID, or a role you hold, to a Filter (section 3). That Administrator is the source; the legal basis is legitimate interests (Article 6(1)(f)): operating the Service as the Administrators configure it. The identifier is kept for as long as the Filter contains it; an Administrator of the Server, or we at your request (section 8), can remove it.
5. Subscriptions
Paddle sells each Subscription as Merchant of Record (section 2 of the Terms). The Subscriber enters their name, email address, billing address, tax number and payment details directly in Paddle Checkout, and Paddle processes them as an independent controller under its privacy notice. They are not transmitted to our systems, except as stated in "Notices to Subscribers".
When an Administrator starts a purchase, we send Paddle the Server ID, that Administrator's Discord user ID, and the version of the Terms accepted with the time of acceptance, so that the Subscription is attributed to the correct Server (contract, Article 6(1)(b)). Of the data concerning a Subscription, we retain only the following:
| Data | Legal basis | Retention |
|---|---|---|
| Paddle customer and subscription IDs; the Subscription's status, plan and billing interval; the dates of its start, current Billing Period and any scheduled change, cancellation or refund | Contract (Article 6(1)(b)); legal obligation (Article 6(1)(c)) to keep accounting and tax records | 11 years from the end of the business year it falls in |
| The Subscriber's Discord user ID, which identifies the Subscriber in the Dashboard | Contract (Article 6(1)(b)) | 24 months after the Subscription ends |
| A record of the Paddle notifications already processed | Legitimate interests (Article 6(1)(f)): processing each notification once | 24 hours |
| The Subscriber's Discord display name, retrieved from Discord and held in memory | Legitimate interests (Article 6(1)(f)): showing Administrators who holds the Subscription | no longer than 1 hour |
Administrators with the Manage Server permission see the Subscriber's display name in the Subscription tab of the Dashboard, or the Subscriber's Discord user ID where the display name cannot be retrieved. Only the Subscriber can open the Paddle Customer Portal from that tab.
Withdrawal
If a Consumer withdraws from a Subscription through the Withdrawal Function (see the Refunds & Withdrawal Policy), we keep:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| The email address entered | Sending the confirmation of receipt required by Article 81.a(6) of the Croatian Consumer Protection Act (Zakon o zaštiti potrošača, the "Consumer Protection Act"), and nothing else | Legal obligation (Article 6(1)(c)) | 24 months after the withdrawal is confirmed, then erased from the record. Any copy of the confirmation in our mailbox is kept as correspondence (section 6) |
| The Consumer's Discord user ID | Linking the withdrawal to the Consumer's account | Legal obligation (Article 6(1)(c)) | 24 months after the withdrawal is confirmed, then erased from the record |
| The withdrawal statement (the Consumer's Discord username, and the Server and plan as displayed), the Paddle subscription ID, the date the Subscription was concluded, the times of submission and of our confirmation, and the refund outcome | Proving our compliance with the related information obligations, the burden of which Article 64 of the Consumer Protection Act places on us | Legal obligation (Article 6(1)(c)) | 11 years from the end of the business year it falls in |
An email address is required to use the Withdrawal Function; a Consumer may instead withdraw by email or post (section 2 of the Refunds & Withdrawal Policy). You may request earlier erasure of the address and the Discord user ID (section 8).
Notices to Subscribers
To send a Subscriber the notices that sections 8 and 9 of the Terms require us to give, we obtain from Paddle the email address it holds for the Subscription. We use it only for those notices and do not store it in our systems. The copy of each notice in our mailbox is kept as correspondence (section 6). The legal basis is legal obligation (Article 6(1)(c)) for a notice to a Consumer of a modification of Premium (Article 19 of Directive (EU) 2019/770, as implemented in national law), and otherwise contract (Article 6(1)(b)).
6. Correspondence
When you write to us by email or post, we process your contact details, your message and our reply to deal with it. The legal basis is legal obligation (Article 6(1)(c)) for a request under section 8 or a complaint under the Consumer Protection Act, contract (Article 6(1)(b)) for a message about your use of the Service, and otherwise legitimate interests (Article 6(1)(f)) in responding. We keep a written complaint and our reply for one year from its receipt (Article 10(7) of the Consumer Protection Act), and other correspondence, including copies of the messages we send, for 24 months after the matter it concerns is concluded.
7. Visiting the Website
We keep no access logs of the Website. Every request to it passes through our network provider, which terminates the encrypted connection and keeps technical records, including your IP address: sampled request data for up to 7 days and security events for up to 24 hours (legitimate interests, Article 6(1)(f): securing and delivering the Website). The Website contains no analytics, advertising or tracking code.
Cookies and local storage
We store only the items below on your device. Each is strictly necessary for signing in or records a choice you have made, so none requires your consent.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
authjs.session-token | Cookie | Keeps you signed in to the Dashboard | 3 days |
authjs.csrf-token and authjs.callback-url | Cookies | Protect the sign-in against cross-site request forgery, and record the page to return you to | Until you close your browser |
authjs.pkce.code_verifier | Cookie | A one-time check that completes the sign-in securely | up to 15 minutes; deleted when the sign-in is completed |
ap:pausedBannerDismissed: followed by a Server ID | Local storage | Records that you dismissed the paused-channels notice for that Server | Until you clear your browser's storage; removed earlier once that Server has no paused channels |
Over HTTPS, the cookie names carry a __Secure- or __Host- prefix.
On the checkout page only, the Website loads Paddle's script to display Paddle Checkout, which runs on Paddle's domain under Paddle's own cookies and privacy notice; we neither set nor control them.
8. Your rights
Under the conditions set out in the GDPR, you have the right to:
- access your personal data and receive a copy of it (Article 15);
- have it rectified if it is inaccurate (Article 16);
- have it erased (Article 17), except records the law requires us to keep (sections 5 and 6);
- restrict its processing (Article 18);
- receive it in a machine-readable format (portability, Article 20), including your channel configuration and Filters.
Right to object
Where we rely on legitimate interests (Article 6(1)(f)), you have the right to object to that processing at any time on grounds relating to your particular situation (Article 21). We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or need it for legal claims. Objections may be sent to [email protected] with "Objection" in the subject line.
Requests to exercise any of these rights may be sent to [email protected]. We will respond within one month of receipt, free of charge.
Data held by Discord and Paddle. Requests concerning your Discord account, messages and Servers are to be made to Discord, as their controller. Requests concerning data entered in Paddle Checkout, including erasure, are to be made to Paddle at preferences.paddle.com or [email protected]; we will assist on request.
Complaints. You may lodge a complaint with the Croatian Personal Data Protection Agency (Agencija za zaštitu osobnih podataka, "AZOP"; contact details in the Legal Notice), or with the supervisory authority where you habitually reside or work or where the alleged infringement took place (Article 77).
9. Recipients
| Recipient | Role | Data received |
|---|---|---|
| Discord | Independent controller | We use its API to retrieve your identity and Servers and to Publish messages. Our operational alerts go through a Discord webhook; one alert type contains a Subscriber's Discord user ID |
| Paddle | Independent controller | The data we send when a purchase starts (section 5); the Subscriber provides all other purchase data to Paddle directly |
| Our database provider | Processor | Stores the configuration in section 3 and the records in section 5 |
| Our hosting provider | Processor | Provides the infrastructure on which the Bot, the Dashboard and our other systems run |
| Our email provider | Processor | Hosts our support mailbox (section 6), and sends the confirmations of receipt of withdrawals and the notices to Subscribers (section 5) |
| Our network provider | Processor | Carries every request to the Website and terminates the encrypted connection; keeps the records described in section 7 |
We will name our processors on request to [email protected]. We do not sell personal data or disclose it to data brokers, advertising networks or other monetisation services.
10. International transfers
Our hosting provider is in Germany. The following transfers leave the European Economic Area:
- Discord. Discord Netherlands BV is the controller for users in the European Economic Area, and Discord, Inc., in the United States, for all other users, including those in the United Kingdom and Switzerland. Discord relies on adequacy decisions where they apply, on the EU–US Data Privacy Framework and its Swiss and United Kingdom counterparts, and on Standard Contractual Clauses.
- Paddle. Paddle.com Market Limited is established in the United Kingdom, which benefits from an adequacy decision of the European Commission. Where the Paddle Buyer Terms identify another Paddle group company outside the European Economic Area as the seller, the transfer relies on the controller-to-controller Standard Contractual Clauses (Module 1, Implementing Decision (EU) 2021/914) in our data sharing addendum with Paddle.
- Our database provider. The database is in the European Union, but the provider's contracting entity, which acts as data importer, is established outside the European Economic Area in a country without an adequacy decision. The transfer relies on the Standard Contractual Clauses (Implementing Decision (EU) 2021/914).
- Our network provider is established in the United States and participates in the EU–US Data Privacy Framework, so the transfer relies on the European Commission's adequacy decision (Implementing Decision (EU) 2023/1795) and, should that participation lapse, on the Standard Contractual Clauses in the provider's data processing agreement.
A copy of the safeguards for any of these transfers is available on request to [email protected].
11. Automated decision-making, profiling and model training
We take no decisions based solely on automated processing that produce legal or similarly significant effects for you (Article 22): a Filter determines only whether a single message is Published. We do not profile you, and we do not use personal data, including message content, to train artificial intelligence or machine-learning models.
12. Security
Our connections to Discord, Paddle and our database provider are encrypted (TLS), and our internal services are not accessible from the internet. We will notify AZOP of a personal data breach within 72 hours of becoming aware of it, and inform the persons affected without undue delay, in the cases that Articles 33 and 34 require. We ask that security vulnerabilities be reported to [email protected] before any public disclosure.
13. Children
The Service is not directed at persons below Discord's minimum age, which is 13 or the higher age that Discord sets for their country (section 4 of the Terms). If you believe we hold personal data of such a person, you may inform us at [email protected], and we will delete it.
14. Changes to this Policy
Any change to this Policy will be posted on this page, with a new effective date, before it takes effect.