Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / DAnalytics / DAnalytics data processing annex

DAnalytics data processing annex

The Art. 28(3) specifics for hosted DAnalytics, and what choosing a looser privacy profile makes yours to justify.

Last updated 1 September 2026 Auf Deutsch lesen →

On this page

  1. What this annex is
  2. Nature and purpose of the processing
  3. Categories of data subjects
  4. Categories of personal data
  5. Processing operations
  6. Sub-processors
  7. Security measures particular to this service
  8. Retention
  9. Assisting your data subjects
  10. On termination

This applies alongside the general terms of service and privacy policy. Where they differ on a point about DAnalytics specifically, this page wins.

What this annex is

The Art. 28(3) specifics for hosted DAnalytics. It is part of the data processing agreement, which carries the obligations.

You are the controller for the Discord servers you point it at. The people in those servers are your data subjects, not ours, and most of them have never heard of us — which makes the privacy notice part of how you meet your Art. 13 and 14 duties rather than a formality.

Nature and purpose of the processing

Receiving events from the Discord servers you have added the bot to, storing them under the privacy profile you have configured, aggregating them, and rendering them as dashboards, alerts and exports for you.

Categories of data subjects

  • Members of the Discord servers you add the bot to. The largest group by far, and the one with no relationship to either of us.
  • Your administrators and moderators, who additionally appear as actors in moderation and configuration events.
  • People who sign in to the web interface to view dashboards.
  • Anyone who receives a shared dashboard link.

Categories of personal data

Determined by the profile you set. On the default standard profile: event metadata — times, server, channel, thread, author identifier, hashed message identifier, message length and word count, mentions, attachment counts and kinds, emoji, reply flag — plus voice joins and leaves, membership changes, moderation actions with hashed reasons, reactions, interactions, tickets, boosts and invites.

Not on standard: message content, attachment filenames, nicknames, presence activity names, poll questions, stage topics, typing events.

On full, all of the above in the clear, including message content. That is your choice to make and yours to justify.

Web accounts: Discord id, name, global name, email address, avatar, locale, sessions, hashed API keys.

Dashboard sharing: share tokens, hashed link passwords, expiry and revocation records.

Operational: export jobs, backfill jobs, alert rules and firings, and encrypted credentials for any other bot API you connect.

Special categories

Not sought and not intended. On full, message content is free text from a live community and may contain anything at all, including Art. 9 material. Choosing full is choosing that risk.

Processing operations

Collection from Discord, hashing or dropping per the effective profile, storage, aggregation, retrieval, display, export, restriction, erasure, and deletion under the retention policy.

Sub-processors

Those named in the general agreement — IONOS SE and Contabo GmbH, both in Germany, plus our own hardware in Germany — and no others.

Discord is the source of the data rather than a sub-processor of ours: the data exists in Discord because your members put it there, under Discord's own terms with them.

Security measures particular to this service

  • Identifiers are hashed with HMAC and a per-guild salt, so hashes do not correlate across servers.
  • The effective privacy mode is the strictest of profile, override and global cap, so a cap set above a guild cannot be loosened from inside it.
  • The instance operator can set global caps that bound every guild at once.
  • Member opt-outs are enforced by the service, per guild or globally, and cannot be overridden by a server administrator.
  • Erasure requests are tracked as records through to completion rather than handled ad hoc.
  • API keys and shared-link passwords are stored as hashes; third-party bot credentials are stored encrypted.
  • The voice speaker timeline is a separate opt-in and is off by default.

Retention

365 days by default, enforced by the service. A guild may set its own, which may be longer, and may disable deletion entirely so that events are kept indefinitely.

Where you extend or disable retention you are extending how long personal data about your members is kept, and the storage limitation principle in Art. 5(1)(e) is yours to satisfy.

Assisting your data subjects

Members can exercise opt-out and erasure through the bot's own /privacy command without either of us being involved. For everything else we assist you as set out in the general agreement.

On termination

As set out in the general agreement: return or deletion at your choice, 30 days of export availability by default, backups expiring on their own cycle. Export formats are CSV, JSON, JSONL and PDF.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany