Archived version
Discord Tickets data processing annex
The Art. 28(3) specifics for hosted Discord Tickets, and why the absence of any retention period makes Art. 5(1)(e) entirely yours.
This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.
What this annex is
The Art. 28(3) specifics for Discord Tickets where we host it. It is part of the data processing agreement, which carries the obligations.
Discord Tickets is not a GHub product and does not run on GPlatform. That changes its licence, not our obligations to you.
Nature and purpose of the processing
Operating a support ticket system for your Discord server: receiving tickets, carrying the conversation, archiving it on close, collecting feedback, and running whatever automations you configure.
Categories of data subjects
- Members of your Discord server who open a ticket — and anybody who writes in one, whether or not they opened it.
- Your staff, who appear as claimants, responders and closers.
- Members on your blocklist.
Categories of personal data
Ticket records: opener, topic, category, claimant, closer and close reason, timestamps, message count, priority, tags, and the answers given to your opening questions.
Conversation content, where archiving is on (it is by default): the content of every message, its author, and whether it was edited or deleted; the username, display name, avatar reference and hoisted role of everyone in the ticket; and a rendered HTML transcript of the whole ticket.
Feedback: rating, comment, and the answers to your feedback form.
Configuration: your blocklist of users and roles.
Special categories
Not sought and not intended. A support ticket is free text written by somebody asking for help, and people disclose health, financial and other sensitive matters in support conversations without being asked to. Archiving is on by default, so that material is retained by default. Consider whether your server should have archiving on at all.
Processing operations
Collection from Discord, encryption, storage, retrieval and display to your staff, transcript rendering, automation, export, and deletion when you ask for it.
Sub-processors
Those named in the general agreement — IONOS SE and Contabo GmbH, both in Germany, plus our own hardware in Germany — and no others. This service uses no error reporting service, no analytics and no AI provider.
Discord is the source of the data rather than a sub-processor: the conversation happens in Discord under Discord's own terms with your members.
Security measures particular to this service
- Message content, usernames, display names, feedback and question answers are encrypted before storage. Disabling encryption in a production environment requires deliberately setting a second variable named
I_KNOW_DISABLE_ENCRYPTION_IS_DANGEROUSand the process prints a warning banner at every start. On instances we host it is enabled. - Archiving can be switched off per server, in which case conversations are not written down at all — the strongest available minimisation and the one worth considering first.
- A guild-level data export exists, and pruning tooling exists.
Retention — read this one
There is no automatic deletion and no retention period. A transcript persists until somebody removes it.
That makes the storage limitation principle in Art. 5(1)(e) entirely yours to satisfy. Decide how long your server should hold support conversations and act on it: switch archiving off, or prune on a schedule you set. We will help you do either, and we will not do it unasked, because deleting a customer's support history without being told to would be the worse error.
On termination
As set out in the general agreement: return or deletion at your choice, 30 days of export availability by default, backups expiring on their own cycle.
Version identifier
discord-tickets-revamped-dpa-2026-09-06
Content hash, SHA-256
7a54620a0786f269e3a2071a41b16f0083926723aa1627c6bfd9806be5beedfe