Privacy Policy
1. Controller and contact
The controller within the meaning of Art. 4 No. 7 GDPR for the processing of personal data through this website, the Discord bot “MXO Discord Bot” including its web dashboard, the sale of “MXO Live Studio” and its waiting list is:
c/o TrueConnective Glück & Stolle GbR
Schwägrichenstr. 14b
04107 Leipzig
Germany
E-mail: kontakt@mxomedia.online
The complete provider details are given in the imprint.
Data protection officer
Data protection officer: No data protection officer has been appointed. The requirements of Art. 37 GDPR and Section 38 BDSG are not met: fewer than 20 people are permanently engaged in automated processing, and no processing is carried out that would require a data protection impact assessment.
2. Scope
This privacy policy covers four separate areas:
- This website. It consists exclusively of static files, sets no cookies, embeds no external content and has no contact form; the only processing is the server log files created when the site is accessed (section 3).
- MXO Discord Bot including its web dashboard: on the Discord servers it has been invited to, the bot processes the data required for the modules activated there (sections 6 to 8).
- MXO Live Studio: an application that runs on the provider's servers in a separate instance for each customer. For the viewer data processed there the provider is a processor, not a controller (section 9).
- Games arcade: part of MXO Live Studio; it runs in the same instance and is covered by section 9. For the waiting list the only data processed are the e-mail addresses voluntarily sent in (section 10).
Not covered is processing for which others are responsible: Discord for the platform itself, the operators of the individual Discord servers for the choice of modules and the content of their server. For the viewer data in MXO Live Studio the streamers are the controllers; the provider processes it on their behalf (section 9.2).
3. Visiting this website
When this website is accessed, the server processes technically necessary access data in log files. This is unavoidable when operating a website. The data recorded includes in particular:
- the IP address of the requesting device,
- the date and time of access,
- the name and address (URL) of the file retrieved,
- the volume of data transferred and whether the request was successful,
- the previously visited page (referrer), if the browser transmits it,
- the browser type and version and the operating system of the device.
Purpose and legal basis: The processing serves the technically error-free delivery of the website, its stability and the defence against attacks. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the secure and uninterrupted operation of the site. This data is not merged with other data sources and is not evaluated for advertising purposes.
Storage period: The log files are deleted automatically after seven days. Individual entries are kept longer only where a specific security incident has to be investigated; the data concerned is then stored until the matter has been resolved.
No cookies, no trackers, no external resources
This website is deliberately built without any third-party ingredients. Specifically:
- No cookies are set.
- No analytics, statistics or tracking services are embedded.
- No external fonts, scripts, images or videos are loaded from other servers. Every file is served from the same server as the website.
- There are no social media buttons, map services or embeds.
- There is no contact form and no sign-up.
Because no information is stored on or read from the terminal equipment beyond what is strictly necessary, no consent banner is required under Section 25 TDDDG (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, German Act on Data Protection in Telecommunications and Digital Services). If embeds, third-party fonts or analytics tools are added later, this section must be revised and consent will as a rule be required.
Language preference in browser storage
The website is available in German and English. If you actively click the
language switch in the header, your choice is stored in the browser's local storage
(localStorage) – the only value stored is de or en.
The next time the entry page is opened, the language you last chose is used. Without such
a click nothing is stored; the entry page then merely evaluates the browser's language
setting without saving it.
This entry contains no identifier that could be used to recognise a device or a person, and it is not transmitted to the server or to any third party. It serves solely the explicitly requested purpose of remembering the chosen language and is therefore exempt from consent under Section 25(2) No. 2 TDDDG. You can delete it at any time via your browser settings (“clear site data”).
Contact by e-mail
If you write an e-mail, your address and your message are processed in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where the enquiry concerns a contract or aims at concluding one, otherwise Art. 6(1)(f) GDPR (interest in answering enquiries). Messages are deleted as soon as they are no longer needed and no statutory retention obligation applies (see section 13). Please note that unencrypted e-mail can be read by others while in transit.
4. Hosting
This website does not run on our own hardware but on a rented server. Provider and location: Hostinger International Ltd, 61 Lordou Vironos Street, 6023 Larnaca, Cyprus; server location Frankfurt am Main, Germany.
The hosting provider processes the access data listed in section 3 on our behalf. This requires a data processing agreement under Art. 28 GDPR: A data processing agreement is in place based on the data processing addendum contained in the provider's terms of service.
The Discord bot, the web dashboard and the customer instances of MXO Live Studio run on the same rented server in Frankfurt am Main, Germany.
This is a privately developed project. Uninterrupted availability is not guaranteed; maintenance, outages or moves to other servers are possible. If the provider changes, this section must be updated.
5. Customer account and access to the applications
A subscription requires an account. Sign-in is via Discord; the provider thereby receives the Discord identifier, the display name and – where stored at Discord and released – the e-mail address. No separate password is issued or stored.
Also processed are the subscription status, the identifiers of the payment transaction at Stripe and the point in time at which consent to immediate performance was given. The basis is Art. 6(1)(b) GDPR (contract) and, for invoicing data, Art. 6(1)(c) GDPR (statutory retention).
Access to an instance is via personal addresses containing a secret component. They are generated when the instance is created and renewed on request. Access to an instance is logged (time, shortened IP address, path requested) and deleted after at most 14 days; the purpose is to detect faults and unauthorised access, the basis is Art. 6(1)(f) GDPR.
None of this is needed for a download, because no program files are offered any more: the applications run on the provider's servers (section 9).
6. MXO Discord Bot – what data is processed
The bot processes only the data required for the modules activated on the Discord server in question. Discord identifiers (IDs) are pseudonymous identifiers; they nevertheless count as personal data under the GDPR because they can be linked to a person.
Source of the data
The data is not entered directly with the provider; it arises from the use of the Discord server: the bot receives it through Discord's interface when people write messages, run commands, click buttons or join a server (information on the source pursuant to Art. 14(2)(f) GDPR). For live notifications, publicly available status information about the configured channels on Twitch, YouTube, Kick and TikTok is added.
Categories of data at a glance
| Category of data | Examples | Used for |
|---|---|---|
| Server and structural data | server ID (guild ID), channel IDs, role IDs | assigning settings, posting messages in the selected channels |
| Configuration | per-server settings, custom command names, server language, message texts | all modules |
| User identifiers | Discord user ID, publicly visible display name, address of the profile picture | levelling, economy, welcome and goodbye cards, tickets, giveaways |
| Activity values | XP totals, levels, position on the leaderboard | level system and role rewards |
| Economy data | server currency balance, times of daily and work commands, purchased shop items | economy module |
| Moderation data | moderation cases with the type of action, reason, acting moderator and time; for auto-mod hits additionally a short excerpt of the triggering message in the mod log | moderation, auto-mod, traceability of actions |
| Ticket data | metadata of open and closed tickets (creator, channel, status, timestamps); complete conversations only if the server has itself enabled the premium “transcripts” feature | ticket system |
| Voluntary details | date of birth, if a person enters it themselves via the birthday command | birthday module |
| Participation and status data | entries in giveaways and polls, verification status, reaction-role assignments, temporary voice channels | giveaways, community module, verification, temporary voice channels |
| Channel data for live notifications | the channel or profile names entered by the server for Twitch, YouTube, Kick and TikTok, plus the status last reported | live notifications; avoiding duplicate announcements |
| Subscription data | premium status and term of a server, identifier of the payment subscription | managing the premium subscription |
| Technical logs | error and operating logs of the application | troubleshooting and operational security |
Message content
Messages are only evaluated to the extent required by the activated features – for example for the word filter, invite-link detection, spam protection or awarding XP. Complete chat histories are not stored. There are exactly two exceptions:
- Ticket transcripts: if a server enables the premium feature, the conversation in a ticket channel is saved as a transcript when the ticket is closed. That decision is made by the operator of the server, not by the provider – see the paragraph on responsibility below.
- Auto-mod hits: if a message triggers a filter, a short excerpt of it is recorded together with the moderation case in the mod log so that moderators can understand the action taken.
Purposes and legal bases
- Art. 6(1)(b) GDPR (contract): providing the bot features requested by the respective server, operating the web dashboard and handling a premium subscription.
- Art. 6(1)(f) GDPR (legitimate interests): operational security, defence against abuse and spam, protection against automated joins (verification), error analysis and enforcement of the terms of use. The legitimate interest lies in the secure, trouble-free operation of the service and in protecting the server communities.
- Art. 6(1)(a) GDPR (consent): for voluntary details, in particular a self-entered date of birth. Consent can be withdrawn at any time with effect for the future, for example by deleting the entry via the corresponding command.
- Art. 6(1)(c) GDPR (legal obligation): compliance with commercial and tax retention obligations for payment transactions.
The role of server operators
Which modules run on a Discord server is decided by its administrators. They therefore determine what data arises in the first place – for example whether ticket transcripts are stored, which words the auto-mod filters, or how long moderation cases remain visible. To that extent the server operator shares responsibility for their server; the provider merely supplies the technical function.
Obligation to provide data and minimum age
Nobody is obliged to provide data. Anyone who does not use the bot is not recorded – apart from data that inevitably arises when a message is written in a channel where a module is active. Without certain details, however, individual features do not work, for example the birthday module without a date of birth.
Access to Discord requires a minimum age; Discord's own terms of service are decisive here. The bot is not designed to process children's data. If it becomes known that data is being processed for a person for whom valid consent under Art. 8 GDPR is missing, that data is deleted.
7. Web dashboard and Discord login (OAuth2)
The bot is configured in a web dashboard. Logging in there works exclusively via Discord's OAuth2 interface – no separate password is created and none is stored.
On login, Discord transmits to the dashboard in particular the Discord user ID, the
username or display name, the address of the profile picture and the list of Discord
servers on which the person logging in holds administrative rights. This information is
needed to check which servers someone is allowed to configure.
identify and guilds
A strictly necessary session cookie is set for the login. It serves solely to keep you signed in during the session and is used neither for analytics nor for advertising. The legal basis for the processing is Art. 6(1)(b) GDPR; storing the cookie on the terminal equipment is exempt from consent under Section 25(2) No. 2 TDDDG because it is strictly necessary for the service you explicitly requested. The session ends when you sign out or after seven days without activity.
Discord is responsible for its own processing. Discord's privacy policy: discord.com/privacy
8. Payment processing
Premium subscription for the Discord bot
The premium subscription (€2.99 per month and server) is processed via the payment service provider Stripe. Payment details such as card numbers are entered and processed exclusively at Stripe; the provider has no access to complete payment details. All that is stored on the provider's side is the identifier of the subscription, the premium status and its term, and the link to the respective Discord server.
The provider is Stripe (for customers in the European Economic Area usually Stripe Payments Europe, Ltd.; the parent company is Stripe, Inc. in the United States). The legal basis is Art. 6(1)(b) GDPR (performance of a contract) and, for the retention of accounting records, Art. 6(1)(c) GDPR. Stripe's privacy policy: stripe.com/de/privacy
Subscription for MXO Live Studio
This subscription is also handled by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Payment details are entered and processed directly at the payment service provider. On the provider's side, the details required for contract handling and bookkeeping arise – name, billing address, start and term of the subscription, the monthly amounts and the payment identifiers. The legal basis is Art. 6(1)(b) GDPR and, for retention, Art. 6(1)(c) GDPR.
Payment service providers regularly have corporate ties to the United States. Whether a transfer is based on standard contractual clauses under Art. 46(2)(c) GDPR, on certification under the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR) or on both must be checked for each provider and stated specifically here: Discord Inc. is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); standard contractual clauses under Art. 46(2)(c) GDPR apply in addition
9. MXO Live Studio
The application runs on the provider's servers. Every customer receives their own instance with their own data; the instances are technically separated and cannot reach one another. They are operated in the browser through personal addresses that work like a password.
9.1 Two roles, cleanly separated
Two different kinds of processing meet in these products. Who is responsible for what depends on whose data is being processed:
| Which data | Who is the controller | Role of the provider |
|---|---|---|
| Customer data: e-mail address, subscription status, payments, access addresses, access logs | The provider | Controller under Art. 4(7) GDPR |
| Viewer data arising from use: display names, chat messages, gifts, scores, queues, statistics | The customer (the streamer) | Processor under Art. 28 GDPR |
9.2 Processing on behalf under Art. 28 GDPR
For viewer data the provider processes solely on the customer's instructions. The data processing agreement is concluded together with the subscription; its content is set out in the Data Processing Agreement and covers in particular:
- Processing only for the purpose of providing the application – no own purposes, no analysis, no disclosure, no training of AI models.
- An obligation of confidentiality for everyone involved in the processing.
- Technical and organisational measures under Art. 32 GDPR – set out in detail in section 14.
- Assistance with access, rectification and erasure: on instruction the provider can release or delete data from the instance.
- Deletion after the contract ends: the data remains available for 30 days so that it can be exported, and is deleted after that – from the backups too, at the latest a further 30 days later.
- Sub-processors only with prior notice and a right to object; the current list is in section 11.
What this means in practice. Requests from viewers (“delete my name from the leaderboard”) still go to the person running the stream – they are the controller. The provider must not release or delete such data on its own initiative, but does help the customer comply with the request.
9.3 What data the application receives
On the customer's behalf the instance connects to TikTok LIVE and Twitch and receives chat messages, gifts, follows, likes, shares, subscriptions, bits and the viewer count in real time. Processing by TikTok and Twitch is governed by their own privacy policies.
9.4 Services contacted in the process
Depending on which features the customer switches on, the instance calls further services. Without the relevant feature, no call takes place:
- Signing service for TikTok (tiktok.eulerstream.com): required in order to establish a connection to a TikTok livestream. The TikTok name of the customer's own channel is transmitted – no viewer data.
- Read-aloud voice: if the read-aloud feature is switched on, the text to be read out is transmitted to the chosen service – depending on the setting to Google (translate.google.com) or to ElevenLabs. That text can contain viewers' display names and chat messages. Anyone who does not want that can switch the feature off or choose the browser voice, which needs no transmission.
- Profile pictures and emotes: overlays load Twitch profile pictures via unavatar.io and Twitch emotes from static-cdn.jtvnw.net. These calls are made by the displaying browser, not by the server; what is transmitted is the username or the emote identifier.
Notes for streamers. As the controller for viewer data you should bear the following in mind:
- Tell your viewers that names, gifts and scores are recorded and shown in overlays or leaderboards – for example in the channel description, in a panel or via a chat command.
- Store and display only as much data as you need for your own purpose, and tidy up leaderboards and statistics regularly.
- Delete individual entries on request – the application offers this directly.
- Keep the access addresses secret: whoever knows them reaches the instance.
- Before switching on the read-aloud feature, consider that chat text is transmitted to a third party (section 9.4).
- Comply with the platforms' terms of use.
10. MXO Live Studio – waiting list
MXO Live Studio is not on sale yet. There is neither a sign-up form nor a database of interested people. Anyone who would like to be notified sends an e-mail to the address given on the product page (kontakt@mxomedia.online).
- Data processed: the sender's address and the content of the e-mail.
- Purpose: a single notification once the software is released. There is no newsletter, no further promotional e-mail and no disclosure of the address to third parties.
- Legal basis: Art. 6(1)(a) GDPR – consent is given by sending the e-mail with the corresponding subject line; in so far as the enquiry aims at a later contract, additionally Art. 6(1)(b) GDPR (pre-contractual measure).
- Erasure: the address is deleted once the notification has been sent – at the latest when the project is abandoned.
- Withdrawal: consent can be withdrawn at any time without any formality, for example with a short e-mail to kontakt@mxomedia.online. The address is then deleted promptly. The lawfulness of processing carried out until then remains unaffected.
Technically, the e-mail is received and stored by the provider's e-mail service (see section 11).
11. Recipients and processors
Personal data is only passed on where this is necessary for operation. Data is never sold and never disclosed for advertising purposes. Nor is it used to train AI models.
| Recipient | Purpose | Basis | Third country |
|---|---|---|---|
| Discord | the platform through which the bot communicates at all; every message and interaction runs through Discord's infrastructure. Also the OAuth2 login of the dashboard. | Art. 6(1)(b) GDPR; Discord processes as its own controller under its own privacy policy. | USA – Discord Inc. is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); standard contractual clauses under Art. 46(2)(c) GDPR apply in addition. |
| Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland | payment processing for both subscriptions | Art. 6(1)(b) and (c) GDPR | Contracting party based in Ireland; for transfers to the US group company Stripe relies on standard contractual clauses under Art. 46(2)(c) GDPR. |
| Hostinger International Ltd, 61 Lordou Vironos Street, 6023 Larnaca, Cyprus; server location Frankfurt am Main, Germany | delivery of this website; operation of the bot, the dashboard and the customer instances of MXO Live Studio – at the same time a sub-processor under section 9.2 | processing on behalf under Art. 28 GDPR | No transfer to a third country: provider based in the EU |
| Hostinger International Ltd (business e-mail) | receiving and sending e-mail, including the waiting list | processing on behalf under Art. 28 GDPR | No transfer to a third country: provider based in the EU. |
| EulerStream (signing service for TikTok LIVE) | Required in order to establish a connection to a TikTok livestream (section 9.4). The TikTok name of the customer's channel is transmitted – no viewer data. | Art. 6(1)(b) GDPR; sub-processor under section 9.2 | USA – based on standard contractual clauses under Art. 46(2)(c) GDPR. |
| Google (translate.google.com) or ElevenLabs | Generating the read-aloud voice, only if the customer switches the read-aloud feature on. The text to be read out is transmitted; it can contain display names and chat messages (section 9.4). | On the customer's instructions; sub-processor under section 9.2 | USA – based on standard contractual clauses under Art. 46(2)(c) GDPR. |
| Twitch, YouTube, Kick, TikTok | retrieving publicly available status information for the live notifications. Only the channel names entered by the server and the technical data of the request are transmitted – no data about server members. | Art. 6(1)(b) and (f) GDPR | USA – only publicly available status information is retrieved; the request contains only the channel name configured by the server. |
The recipients marked as sub-processor are at the same time sub-processors within the meaning of the Data Processing Agreement. Beyond that, data may be disclosed to public authorities where there is a legal obligation to do so.
12. Transfers to third countries
Some of the services used – in particular Discord and the payment service providers – are based in or have corporate ties to the United States. As a result, personal data may be processed outside the European Economic Area.
This is only permissible under the conditions of Art. 44 et seq. GDPR. The relevant bases are in particular an adequacy decision of the European Commission under Art. 45 GDPR (for certified US companies, the EU-US Data Privacy Framework) and standard contractual clauses under Art. 46(2)(c) GDPR, where appropriate supplemented by additional safeguards.
Which basis applies to which recipient is set out recipient by recipient in the table in section 11. Discord Inc. is certified under the EU-US Data Privacy Framework; for Stripe, EulerStream and Google or ElevenLabs the transfer is based on standard contractual clauses under Art. 46(2)(c) GDPR.
To be honest about it: in third countries the level of protection may not correspond to that of the GDPR in every respect – for instance regarding access by public authorities and the legal remedies available against it.
13. Storage periods and erasure
Personal data is deleted as soon as the purpose ceases to apply and no statutory retention obligation stands in the way. In detail:
- Server log files of the website and the downloads: They are deleted automatically after seven days.
- Language preference in browser storage: remains on your own device until you delete it there; the provider has no access to it.
- Configuration data of a Discord server: for as long as the bot is a member of that server. After the bot is removed: The data is deleted automatically and completely after 30 days. If the bot is added again within that period, the data is retained; the period can be set between 0 and 365 days in the dashboard.
- XP totals, economy data and leaderboards: until they are reset by the server administrators, deleted on request, or the bot leaves the server.
- Moderation cases and auto-mod excerpts: for as long as they are needed for the server's moderation history – there is no automatic deletion period. Server administrators can remove individual entries and data subjects can request deletion. They are excluded from self-service deletion because the server is allowed to keep them under Art. 17(3) GDPR.
- Ticket metadata and transcripts: as long as the server needs them; deletion is carried out by the server administration or on request. Whether transcripts are enabled at all is decided by the respective server.
- Voluntarily entered date of birth: until the person concerned removes it again or withdraws consent.
- Dashboard session data: until sign-out, or at the latest seven days after signing in.
- Operating and error logs: They are deleted automatically after seven days.
- Waiting-list e-mails: until the single notification has been sent or consent is withdrawn.
- Other e-mail correspondence: until the enquiry has been dealt with, in so far as no retention obligation applies.
- Payment and invoicing records: in line with commercial and tax retention periods – as a rule six and ten years respectively under Section 257 HGB (Handelsgesetzbuch, German Commercial Code) and Section 147 AO (Abgabenordnung, German Fiscal Code). For the duration of these periods the data is restricted in processing and deleted afterwards.
Data in the instances of MXO Live Studio is processed on the customer's instructions and deleted once the subscription ends: after 30 days from the instance, and at the latest a further 30 days later from the backups as well (section 9.2).
14. Your rights as a data subject
You have the following rights vis-à-vis the controller. Exercising them is generally free of charge and requires no particular form; except for the right to object, no reason has to be given.
- Access (Art. 15 GDPR): you can find out whether and which data relating to you is processed, for what purpose, for how long and to whom it is disclosed – and request a copy of that data.
- Rectification (Art. 16 GDPR): inaccurate data must be corrected and incomplete data completed.
- Erasure (Art. 17 GDPR): data must be deleted if it is no longer needed, if consent has been withdrawn or if the processing was unlawful – unless a statutory retention obligation stands in the way.
- Restriction of processing (Art. 18 GDPR): instead of deleting it, data can be “frozen”, for instance while its accuracy is being checked.
- Data portability (Art. 20 GDPR): data you provided yourself and that is processed on the basis of consent or a contract can be given to you in a commonly used, machine-readable format or transferred to another controller.
- Objection (Art. 21 GDPR): you can object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation. Processing is then stopped unless there are compelling legitimate grounds that override your interests.
- Withdrawal of consent (Art. 7(3) GDPR): consent you have given – for example for your date of birth or the waiting list – can be withdrawn at any time with effect for the future. The lawfulness of processing carried out until then remains unaffected.
- Complaint to a supervisory authority (Art. 77 GDPR): independently of everything else, you can lodge a complaint with a data protection supervisory authority.
Right to object under Art. 21 GDPR. Processing operations based on legitimate interests are explicitly marked as “Art. 6(1)(f) GDPR” in this policy – these include in particular the server log files, abuse prevention and the operating logs. An objection can be made informally, for example by e-mail (see section 15).
Competent supervisory authority: Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden, www.datenschutz.sachsen.de. Regardless of this, you may contact any supervisory authority, in particular the one for your habitual residence or the place of the alleged infringement.
On verifying identity: the bot generally knows people only by their Discord user ID. To be able to handle a request, proof is therefore needed that the person making it controls the Discord account concerned – for example a message from that account in the support server. No identity documents are requested.
15. Contact for access and erasure requests
Please send requests concerning stored data, erasure, objection or the withdrawal of consent to:
So that the data can be located, please state what the request is about:
- for the Discord bot: your own Discord user ID and the server ID or the server name,
- for the premium subscription: the server ID and, if available, the invoice number,
- for the waiting list: the e-mail address you wrote from.
You will receive a reply without undue delay, at the latest within one month of receipt of the request (Art. 12(3) GDPR). If a request is particularly complex, this period may be extended by up to two further months; you will be informed of that within the first month. As this is a privately operated project, a reply within a few hours cannot be promised – but the statutory deadlines are met.
For viewer data in an instance of MXO Live Studio the streamer is the controller, not the provider (section 9.1). Such requests go to that person. As a processor the provider must not answer them itself, but assists the controller without undue delay.
16. No automated decision-making
There is no automated decision-making in individual cases, including profiling, within the meaning of Art. 22(1) and (4) GDPR – that is, no decision taken solely by automated means that produces legal effects or similarly significantly affects a person. No advertising or personality profiles are created, no creditworthiness is assessed and no data is evaluated for marketing purposes.
Two features that do work automatically, for the sake of clarity:
- Levels and XP totals are calculated automatically, but they only result in a number and possibly a role within the Discord server concerned. No assessment of personal characteristics and no decision with legal effect is involved; in our assessment Art. 22 GDPR does not apply.
- Auto-mod reacts automatically to configured triggers, for example by deleting a message or applying a temporary timeout. These reactions take effect solely within the Discord server concerned, are defined by its administrators and can be reversed by the moderators at any time. They have no legal effect on the person concerned.
17. Data security
This website and the web dashboard are delivered over an encrypted connection (TLS/HTTPS); you can recognise this by the padlock symbol in your browser's address bar. Access to the server, to the bot's database and to the dashboard is limited to authorised people; in the dashboard, a server's configuration can only be changed by someone holding administrative rights on that Discord server.
The server can only be accessed with an SSH key; password authentication is disabled. A firewall only permits inbound ports 22, 80 and 443; the tools' admin interfaces are not reachable from the internet. All traffic is TLS-encrypted throughout (HTTPS with automatic certificate renewal). Services run under a dedicated system user without a login shell and with restricted write access. Operating system security updates are installed automatically. The bot database is backed up daily and kept for 14 days; system logs are deleted after seven days.
Nobody can guarantee complete security when data is transmitted over the internet. Uninterrupted availability is not guaranteed either. The measures are adapted in line with technical developments.
18. Changes to this privacy policy
This privacy policy will be adapted whenever the feature set of the products, the services used or the legal situation changes. The version published on this page at any given time applies; the date of the last change is shown below the heading at the top.
In the case of substantial changes affecting existing processing, information will additionally be provided where the people concerned can be reached – for example by a notice in the dashboard or in the support server.