Data Processing Agreement
This Data Processing Agreement forms part of the Bureaucramancer Terms of Service where a customer uses Bureaucramancer to process personal information on behalf of a Discord server.
1. Parties and roles
The customer operating the relevant Discord server is the Controller and Bureaucramanceris the Processor for Customer Data processed through enabled guild features. Each party remains independently responsible for any processing for which it determines the purposes and essential means.
2. Subject matter, duration, nature and purpose
The subject matter is the processing required to provide the Bureaucramancer Discord administration service. Processing continues for the period the service is enabled for the guild and for the applicable retention/deletion period afterwards. Operations can include collection from Discord, recording, organisation, indexing, storage, retrieval, search, export, restriction, backup, recovery, transmission to authorised users and deletion.
The purposes are those selected by the Controller through enabled modules and documented server use, including administration, continuity, moderation, safeguarding, audit, investigation, backup and recovery.
3. Data subjects and categories of data
Data subjects can include Discord server members, former members, staff, moderators, administrators and other authorised participants.
Personal data can include Discord identifiers, usernames/display names, avatars, message content and metadata, proxy/Tupper identity links, attachments, channel/thread context, role and permission information, moderation notes/evidence, audit events and records needed to perform configured recovery functions.
Customers must not intentionally use Bureaucramancer to process special-category or criminal-offence data unless they have established the required lawful basis and safeguards.
4. Controller instructions
The Processor processes Customer Data only on documented instructions from the Controller, including instructions expressed through service configuration, enabled modules, dashboard actions and authorised API/Discord commands, unless UK law requires different processing. If the Processor believes an instruction infringes applicable data-protection law, it informs the Controller where legally permitted and can suspend the affected instruction.
5. Confidentiality and access
The Processor restricts Customer Data to personnel and subprocessors who need access to provide, secure or support the service and who are subject to appropriate confidentiality obligations. Customer dashboard access is scoped by Discord guild and administrative permissions.
6. Security measures
The Processor maintains technical and organisational measures appropriate to the service and risk, including encrypted transport, server-side sessions, guild-scoped authorisation, CSRF controls, rate limiting, protected private attachment storage, guarded destructive operations, audit logging, automated dependency/secret/code scanning, retention controls, database backups and recovery procedures.
7. Subprocessors
The Controller gives general authorisation for the Processor to use subprocessors required to provide the service. The Processor remains responsible for imposing data-protection obligations appropriate to the processing. Material changes to subprocessors that handle Customer Data are recorded in the service documentation so customers can assess the change and raise a reasonable data-protection objection.
Core service providers include Discord for the platform/API and production infrastructure providers for hosting, database, private object storage, networking and related operational services.
8. International transfers
Where Customer Data is transferred outside the UK and a transfer safeguard is required, the Processor uses an applicable adequacy decision, approved contractual safeguard, UK addendum/IDTA mechanism or another lawful transfer mechanism available under UK data-protection law.
9. Individual rights and controller assistance
Taking account of the nature of the processing, the Processor provides reasonable technical assistance for access, rectification, erasure, restriction, objection and portability requests. Bureaucramancer includes a verified Discord privacy-request workflow and controller-side discovery/export/erasure tools. The Controller remains responsible for deciding whether a request is valid and whether an exemption or retention requirement applies.
10. Security incidents
The Processor notifies the affected Controller without undue delay after becoming aware of a personal-data breach involving that Controller's Customer Data, to the extent required by applicable law. Available information includes the nature of the incident, affected categories, likely consequences and remediation measures as they become known.
11. DPIAs, regulator enquiries and compliance information
The Processor provides reasonable information needed for the Controller's data-protection impact assessment, regulator consultation or processor due-diligence obligations, taking account of the nature of the service and information available to the Processor.
12. Return and deletion
On termination or removal of the service, Customer Data is deleted according to the configured uninstall grace period and published retention rules unless the Controller requests an eligible earlier deletion or applicable law requires limited information to be retained. Backup copies age out through the normal backup rotation and remain protected from ordinary application use.
13. Audit and records
The Processor maintains records and security information sufficient to demonstrate the controls described in this Agreement and makes reasonable compliance information available to the Controller. Audit requests must protect other customers, confidential security information and system integrity; remote/documentary review is used first where it can satisfy the Controller's requirement.
14. Controller obligations
The Controller confirms it has authority and an appropriate lawful basis for the instructions it gives, provides required transparency to Discord members, configures access and retention proportionately, and does not instruct Bureaucramancer to process data in a manner that violates applicable law.
15. Priority
If this DPA conflicts with the Terms of Service on the processing of Customer Data, this DPA controls for that issue. Mandatory data-protection law takes priority over both documents.