Data processing agreement
pursuant to Art. 28 GDPR · Version 2.4 · Last updated: October 2026
This English version is provided for convenience only. Only the German version is legally binding.
§ 1 Parties and conclusion
The controller (“client”) is whoever sets up Modario on a Discord server and confirms this agreement during setup with /modario setup (server operator).
The processor (“contractor”) is Stefan Rohrbach, DMNT Studio, c/o Online-Impressum 10950, Europaring 90, 53757 Sankt Augustin, Germany, email: dmnt-studio@mail.online-impressum.de.
The agreement is concluded by confirmation during /modario setup (electronic form under Art. 28(9) GDPR). For this purpose, the contractor stores in the record log the Discord ID of the confirming person, the server ID, the time and the agreement version.
§ 2 Subject matter, nature and purpose
The contractor operates Modario for the client's Discord server and processes personal data of the server members solely to provide the functions (modules and plugins) activated by the client, e.g. event management and calendars, group search, welcome messages with ranks, activity levels and classes, moderation, own voice channels, announcements, live notifications for Twitch and news summaries. Which data is processed depends on which modules the client switches on. A module that is not switched on processes no data.
Types of data
- Basic data (all modules): Discord user IDs, display names and roles, where a function requires them; interactions with the bot (commands, button clicks, input in forms); IDs of channels, roles and messages on the server.
- Events: title, description, start and end, location (voice channel), cover image, custom channel status text and the Discord ID of the person creating the event; the number of interested members without names. In addition series (rule, title, description, cover image and Discord ID of the person creating them), the addresses of calendars from which Modario imports dates, and secret subscription addresses through which calendar apps fetch the server's dates (only the time of the last fetch is stored, no IP address and no device information).
- Group search: searches (title, text, date, duration, slots, template, Discord ID of the creator), participants with their chosen slot and their answers to date changes, requests from latecomers and the waiting list, votes of a date poll, recipes for “Again” with the Discord IDs of the previous round, the “Sidebar” setting and the IDs of the voice channels, Discord events and messages created for it.
- Own voice channels: room data (channel, Discord ID of the owner, name, limit, status text, invited and kicked members) and – when the owner clicks it – “My room” (their saved settings per join channel). Modario only processes the owner's game status for the room name; it is not stored.
- Announcements and weekly overview: the content the client creates (texts, images, buttons, schedule, channel, roles, Discord ID of the person creating it), the ID of the last message sent and a counter per role and week of how often Modario pinged it (without member data).
- Live (Twitch): for each member who adds their Twitch channel, the Discord ID, the Twitch name and Twitch user ID, the approval status (waiting, approved, rejected, paused), the time of the entry and the Discord ID of the person who approves or rejects it; while a stream is running, stream ID, start, title, game, the IDs of the live card and channel and the live role given. For the check Modario only sends the Twitch name or Twitch user ID to Twitch; no Discord data goes to Twitch.
- Ranks: an open promotion case (Discord ID, ID of the mod card, next check date) and a demotion note (Discord ID, time). Modario reads the rank itself from the Discord roles; it is not stored.
- Activity: per member one points value for activity and, per chosen main class, one class points value, each with a timestamp and the points per source for the current day; an objection (“Don't track”) with Discord ID and time. Presence in voice rooms of group searches and events and the “Interested” list of Discord events are only evaluated in memory and not stored.
- Classes and class choice: the server's classes and subgroups (name, emoji, description, role); per member the chosen main class, the side interests and the time of the choice.
- Profile: /profile shows existing data together and stores nothing of its own.
- Welcome: members joining and leaving with time, display name and avatar for the welcome message, automatically assigned roles.
- Moderation: case file (member concerned, measure, duration, reason, acting moderator, time), evidence messages (copied text or image link of a message a moderator saves as evidence), appeals, hits of the automatic moderation and entries from the server's audit log about kicks, bans and timeouts. In addition: reports (evidence, reason and Discord ID of the reporting member, false reports), temporarily cached image attachments of reported messages, appeal texts, ticket transcripts (text, attachments only as file names) and the rules of automatic moderation stored by the client (custom words, patterns, link allowances, exceptions for roles and channels).
- Message content: only in modules the client expressly switches on for this, and only for their purpose: moderation (checking for rule violations such as flooding or repetition, evidence in the case file) and news (summary of the channels selected for it).
Without such a module, Modario neither reads nor stores message content.
Storage period during operation
- Events: until 24 hours after they actually end, cancelled events deleted immediately. Unfinished input (drafts including images) is deleted 3 hours after the last input. What remains is a counter per server and month without personal reference. Series, calendar and subscription addresses until the client deletes or replaces them, ended series 24 hours after ending.
- Group search: participants including requests, waiting list and votes 24 hours after the search ends or is cancelled; recipes for “Again” 90 days after their last use, the previous round in them 30 days after the round ended; drafts 3 hours after the last input; settings, templates and searches like the server settings.
- Own voice channels: room data together with the room; “My room” until “Forget” or the person leaves, at most 90 days after its last use.
- Announcements: until the client deletes them; ping counters 8 weeks.
- Live: the entry until the member removes it, a moderator removes it, the member leaves or the bot leaves the server; stream details until the stream ends (the live card stays as a normal message in the channel).
- Ranks: a promotion case until the decision, the member leaving or the guest role being removed; a demotion note until the person is no longer a guest or leaves the server.
- Activity and class choice: until 30 days after the member leaves (whoever returns earlier keeps their status); “No class” deletes the choice immediately. An objection until it is withdrawn or the agreement ends.
- Moderation: a case 12 months after the last case of the member concerned, evidence messages including reporter, reason and ticket transcript 90 days, image attachments of reported messages at most 24 hours or until moderation decides, report cards without a decision 7 days, a ban entry for as long as the ban exists. The client may set these periods shorter, but not longer.
- Message content for news summaries: no longer than 24 hours.
- Server settings: until the end of the agreement (§ 9).
Data subjects
Members and visitors of the client's Discord server.
Duration
The agreement applies for as long as Modario is used on the client's server. It ends automatically when the bot is removed from the server or the client terminates it.
§ 3 Instructions
The contractor processes the data only on documented instructions from the client. Instructions are this agreement, the settings the client makes in the bot, and messages to the email address above. If the contractor considers an instruction to be unlawful, it informs the client without delay. Processing outside the instructions takes place only where required by EU or German law; the contractor informs the client beforehand where permitted.
§ 4 Confidentiality
Only the contractor has access to the data. Should the contractor engage other persons in future, it will first commit them to confidentiality in writing.
§ 5 Security of processing
The contractor takes the technical and organisational measures under Art. 32 GDPR described in Annex 1. It may develop them further as long as the level of protection does not decrease.
§ 6 Sub-processors
The client consents to the use of the sub-processors listed in Annex 2. The contractor announces new or replacement sub-processors at least 14 days in advance on this page and in the support channel. The client may object within this period; if no agreement is reached, the client may terminate the agreement with immediate effect. The contractor contractually binds sub-processors to the same data protection obligations.
Modules with AI functions (e.g. news) may require further sub-processors. They are announced following the procedure in paragraph 1 and used only for servers on which the client switches on the respective module.
Discord is not a sub-processor of the contractor. The client operates its server on Discord itself and has its own contractual relationship with Discord for this purpose.
Twitch (Twitch Interactive, Inc., USA) is not a sub-processor either. For live notifications Modario only queries public channel data there; only the Twitch name or Twitch user ID of members who add their channel themselves is transmitted. As of this version of the agreement, Twitch does not participate in the EU-U.S. Data Privacy Framework. Modario therefore informs members in the entry form about the query in the USA; submitting the form is their consent to this transfer (Art. 49(1)(a) GDPR), removing the entry ends it.
§ 7 Assistance to the client
The contractor assists the client to a reasonable extent
- with requests from data subjects (access, erasure, etc.) by providing or deleting the data stored for a Discord ID within 14 days,
- with the security of processing, notifications of personal data breaches and data protection impact assessments (Art. 32 to 36 GDPR).
If the contractor receives a request directly from a data subject, it forwards it to the client.
§ 8 Personal data breaches
If the contractor becomes aware of a personal data breach, it informs the client without delay, and no later than within 48 hours, via the channel specified by the client during /modario setup or by Discord direct message to the person who confirmed the agreement. The notification contains, as far as known, the nature of the breach, the data concerned, likely consequences and the measures taken.
§ 9 Deletion after termination
After the end of the agreement, the contractor deletes all data processed on behalf of the client within 30 days. Backups are overwritten in the regular 14-day cycle. On request, the contractor provides the client with a copy of the server settings before deletion. The record log under § 1 is retained because the contractor uses it to fulfil its own accountability obligations (three years after the end of the agreement).
§ 10 Evidence and audits
On request, the contractor provides the client with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. On-site audits are possible with reasonable notice; given the small scale of the service, they are primarily carried out in writing.
§ 11 Liability and final provisions
Liability is governed by Art. 82 GDPR. German law applies. Should any provision be invalid, the remainder of the agreement remains valid. Changes to this agreement receive a new version number and are confirmed again by the client in the bot.
Annex 1 – Technical and organisational measures
- Location: a rented server of Contabo GmbH in a data centre in the European Union (Lauterbourg, France). Physical access and power supply are the responsibility of the data centre.
- Server access: only the contractor, via an encrypted SSH connection. Login only with a cryptographic key; password login is disabled.
- Separation: bot, database and website run in separate Docker containers in their own isolated network. The database cannot be reached from outside.
- Credentials: passwords and tokens are stored in configuration files on the server, not in the source code.
- Transmission: website only via HTTPS (TLS). The bot communicates with Discord and Twitch exclusively in encrypted form.
- Data minimisation: message content only in modules the client switches on for this, and only for as long as stated in § 2; activity only as a total per member (and per main class), no individual events; game status is only processed, not stored; people in error logs only as a Discord ID; error logs no longer than 30 days.
- Separation of customers: all data is assigned to the respective server ID; commands only affect the own server.
- Availability: daily database backup, retained for 14 days.
- Changes: new versions run on a test server first.
Annex 2 – Sub-processors
- Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany · hosting of server and database
- Contabo France SAS, 2 rue Taunus, 67630 Lauterbourg, France · operation of the data centre (sub-processor of Contabo GmbH)
Changes in version 2.4 compared to version 2.3
- § 2, purpose: live notifications for Twitch added.
- § 2, type of data: new “Live (Twitch)” – Twitch name and user ID, approval status, running stream.
- § 2, storage period: periods for Live.
- § 6: Twitch is not a sub-processor; only public channel data is queried, Twitch does not participate in the EU-U.S. Data Privacy Framework, members consent in the entry form.
- Annex 1, transmission: Twitch also only encrypted.
Changes in version 2.3 compared to version 2.2
- § 2, type of data: activity now also includes one class points value per chosen main class (participation in group searches); presence in voice rooms and the “Interested” list of Discord events are only evaluated in memory.
- Annex 1, data minimisation: activity only as a total per member and per main class.
Changes in version 2.2 compared to version 2.1
- § 2, purpose: examples extended by calendars, group search, ranks, activity, classes, own voice channels and announcements.
- § 2, types of data: series, calendar and subscription addresses (events), group search, own voice channels, announcements and weekly overview, ranks, activity, classes and class choice and the profile (without data of its own) are now listed.
- § 2, storage period: periods for series and calendars, group search, own voice channels, announcements and ping counters, ranks, activity, class choice and objections.
- Annex 1, data minimisation: activity only as a total per member; game status only processed, not stored.
Changes in version 2.1 compared to version 2.0
- § 2, types of data (moderation): reports with reporter, reason and false reports, cached image attachments of reported messages, appeal texts, ticket transcripts and the rules of automatic moderation stored by the client are named expressly.
- § 2, storage period (moderation): evidence including reporter, reason and ticket transcript 90 days; image attachments of reported messages at most 24 hours or until a decision; report cards without a decision 7 days.
Changes compared to version 1.0
- § 2: types of data per module (events, welcome, moderation, news) instead of one general list.
- § 2: message content is no longer excluded but allowed only in modules the client expressly switches on for this (moderation, news).
- § 2: new list “Storage period during operation”.
- § 6: note on sub-processors for AI functions.
- Annex 1: data minimisation adapted to the modules.