Archived version
DAnalytics data processing annex
The Art. 28(3) specifics for hosted DAnalytics, and what choosing a looser privacy profile makes yours to justify.
This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.
What this annex is
The Art. 28(3) specifics for hosted DAnalytics. It is part of the data processing agreement, which carries the obligations.
You are the controller for the Discord servers you point it at. The people in those servers are your data subjects, not ours, and most of them have never heard of us — which makes the privacy notice part of how you meet your Art. 13 and 14 duties rather than a formality.
Nature and purpose of the processing
Receiving events from the Discord servers you have added the bot to, storing them under the privacy profile you have configured, aggregating them, and rendering them as dashboards, alerts and exports for you.
Categories of data subjects
- Members of the Discord servers you add the bot to. The largest group by far, and the one with no relationship to either of us.
- Your administrators and moderators, who additionally appear as actors in moderation and configuration events.
- People who sign in to the web interface to view dashboards.
- Anyone who receives a shared dashboard link.
Categories of personal data
Determined by the profile you set. On the default standard profile: event metadata — times, server, channel, thread, author identifier, hashed message identifier, message length and word count, mentions, attachment counts and kinds, emoji, reply flag — plus voice joins and leaves, membership changes, moderation actions with hashed reasons, reactions, interactions, tickets, boosts and invites.
Not on standard: message content, attachment filenames, nicknames, presence activity names, poll questions, stage topics, typing events.
On full, all of the above in the clear, including message content. That is your choice to make and yours to justify.
Web accounts: Discord id, name, global name, email address, avatar, locale, sessions, hashed API keys.
Dashboard sharing: share tokens, hashed link passwords, expiry and revocation records.
Operational: export jobs, backfill jobs, alert rules and firings, and encrypted credentials for any other bot API you connect.
Special categories
Not sought and not intended. On full, message content is free text from a live community and may contain anything at all, including Art. 9 material. Choosing full is choosing that risk.
Processing operations
Collection from Discord, hashing or dropping per the effective profile, storage, aggregation, retrieval, display, export, restriction, erasure, and deletion under the retention policy.
Sub-processors
Those named in the general agreement — IONOS SE and Contabo GmbH, both in Germany, plus our own hardware in Germany — and no others.
Discord is the source of the data rather than a sub-processor of ours: the data exists in Discord because your members put it there, under Discord's own terms with them.
Security measures particular to this service
- Identifiers are hashed with HMAC and a per-guild salt, so hashes do not correlate across servers.
- The effective privacy mode is the strictest of profile, override and global cap, so a cap set above a guild cannot be loosened from inside it.
- The instance operator can set global caps that bound every guild at once.
- Member opt-outs are enforced by the service, per guild or globally, and cannot be overridden by a server administrator.
- Erasure requests are tracked as records through to completion rather than handled ad hoc.
- API keys and shared-link passwords are stored as hashes; third-party bot credentials are stored encrypted.
- The voice speaker timeline is a separate opt-in and is off by default.
Retention
365 days by default, enforced by the service. A guild may set its own, which may be longer, and may disable deletion entirely so that events are kept indefinitely.
Where you extend or disable retention you are extending how long personal data about your members is kept, and the storage limitation principle in Art. 5(1)(e) is yours to satisfy.
Assisting your data subjects
Members can exercise opt-out and erasure through the bot's own /privacy command without either of us being involved. For everything else we assist you as set out in the general agreement.
On termination
As set out in the general agreement: return or deletion at your choice, 30 days of export availability by default, backups expiring on their own cycle. Export formats are CSV, JSON, JSONL and PDF.
Version identifier
danalytics-dpa-2026-09-06
Content hash, SHA-256
4a6ba806c0f87a74ad4a01fb0e9b47a623328f52b549e22655c398f18e81a04c