Skip to content

Data Processing Agreement (DPA)

Last updated: 24 July 2026

This agreement governs the processing of personal data that we carry out on behalf of a server operator. It is concluded between you as the operator of a Discord server ("controller") and us ("processor") as soon as you use Noxa on a server, and applies for the entire duration of that use. No separate signature is required; on request we will provide you with a signed copy.

1. Parties

The controller is the operator of the Discord server on which Noxa is used. The processor is noxa-bot.org – Jan Eder, c/o Online-Impressum #9754, Europaring 90, 53757 Sankt Augustin, reachable at noxa-bot.org@mail.online-impressum.de.

2. Subject matter, duration, nature and purpose of processing

The subject matter is the operation of the Noxa software to manage the Discord server of the controller. Processing serves solely to provide the features enabled by the controller: moderation including automatic moderation and the bot trap, ticket support, verification of new members, ban appeals, polls, giveaways, automations, temporary voice channels, stream notifications and server-level evaluations. Processing is automated and lasts for the period Noxa is used on the server concerned; it ends when the bot is removed.

3. Types of data and categories of data subjects

The following are processed:

  • Categories of data subjects: members of the controller Discord server; dashboard users of the controller including team members they invite; persons affected by a ban who lodge an appeal; streamers entered by the controller.
  • Types of data: Discord user ID, username and display name, avatar; moderation actions including reasons and internal notes; content and attachments of support tickets; content of ban appeals; voting behaviour in polls; entry and winner data from giveaways; triggers and runs of automations; ownership and access data of temporary voice channels; public streaming information; technical log data.
  • Not processed: message content outside tickets and ban appeals, voice or video content, payment data of server members, and special categories under Art. 9 GDPR unless the controller introduces them itself through the design of its polls or free-text entries.

4. Right to issue instructions

We process personal data solely on the documented instructions of the controller. The configuration in the dashboard counts as a documented instruction: which modules are enabled, which rules are set and which periods are chosen is determined by the controller itself. Supplementary instructions are to be sent in text form to noxa-bot.org@mail.online-impressum.de. If we consider an instruction to infringe data protection law, we inform the controller without delay and may suspend execution until they confirm it (Art. 28(3) sentence 3 GDPR).

5. Confidentiality

All persons who may obtain access to personal data of the controller in the course of the assignment are bound to confidentiality and have been instructed in the relevant data protection requirements. Access to production data is limited to those persons necessary for operations.

6. Technical and organisational measures (Art. 32 GDPR)

We implement the measures listed in section 12. They form an integral part of this agreement. We may develop them further as long as the level of protection is not reduced.

7. Sub-processors

The controller grants general authorisation for the use of the sub-processors listed below. We give notice of intended changes at least 30 days in advance; the controller may object within that period and may terminate the agreement if the objection is maintained.

Sub-processorPurposeLocation
Hetzner Online GmbHOperation of servers and databaseGermany
Discord Inc.Platform the bot runs on — technically mandatory, not ours to chooseUSA
Browser vendor push servicesDelivery of optional notifications about ban appealsUSA

8. Assistance to the controller

We assist the controller, so far as reasonable, in responding to requests from data subjects (Art. 12 to 23 GDPR) and in meeting their obligations under Art. 32 to 36 GDPR. If data subjects approach us directly, we refer them to the controller without delay and do not answer them ourselves. The dashboard provides access, export and deletion functions for this purpose.

9. Notification of personal data breaches

If we become aware of a personal data breach affecting data of the controller, we inform them without delay, at the latest within 24 hours of becoming aware, and provide the information they need for their notification under Art. 33 GDPR. Notifying the supervisory authority is the responsibility of the controller.

10. Deletion and return

After use ends we delete the server data according to the periods published in the Privacy Policy, at the latest 30 days after the bot is removed from the server. At the request of the controller, to be made before that period expires, we provide an export beforehand. Statutory retention obligations remain unaffected.

11. Evidence and audits

We make available to the controller all information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits. These take place primarily by way of information in text form and by presenting the documentation of the technical and organisational measures. On-site audits are permitted with reasonable notice, during normal business hours and without disrupting operations.

12. Annex: technical and organisational measures

The following measures are implemented (Art. 32 GDPR):

  • Confidentiality — physical access: operation in a data centre in Germany with documented access control by its operator. System access: sign-in exclusively through Discord OAuth with PKCE, no separate password system, administrative server access only via SSH with a key pair. Data access: server-side permission checks on every single request based on rank and fine-grained permission scopes, tenant separation per server.
  • Encryption — TLS for all connections; field-level AES-256-GCM encryption for ticket and appeal content, moderation reasons and notes, and stored OAuth tokens, each with a separate key per server; session tokens and room passwords stored as hashes only.
  • Integrity — signature verification of all incoming webhooks before any processing; cross-site request forgery protection using the double-submit method; input validation against a central schema; validation of target addresses against an allowlist wherever the server makes outbound calls.
  • Availability and resilience — daily database backup with 30-day rotation and a documented restore procedure; monitoring of services, queues, database and certificates with alerting to the operator; separated services with automatic restart.
  • Traceability — logging of security-relevant and configuration-changing operations per server in the audit log; separate logging of access to internal operational tools including IP address.
  • Data minimisation and robust deletion — automated deletion runs on fixed periods, executed daily; filtering of internal team notes out of transcripts; no storage of message content outside tickets and appeals; no external analytics or tracking services.

13. Liability and final provisions

Liability is governed by Art. 82 GDPR. In all other respects the Terms and Conditions apply. In the event of contradictions between this agreement and the Terms and Conditions, this agreement prevails on questions of data processing. German law applies.