Discord Bot Privacy Policy
Last updated: 16 June 2026· Governing law: England & Wales
How the Vardoxen Discord bot processes data, under the UK GDPR and the Data Protection Act 2018. Data is hosted in the EU/EEA.
1. Controller
Vardoxen (operated from the United Kingdom) is the controller for the personal data processed by the Vardoxen Discord bot. For privacy enquiries or to exercise your rights: legal@vardoxen.tv.
2. What the bot processes
- Discord identifiers (user, server, channel, message, and role IDs).
- Message content and logs, and moderation records (cases and infractions, notes, reports, and appeals), for moderation, logging, and community safety.
- Automation data such as sticky notes, sound bytes, role tenure, and birthdays you choose to set.
- Giveaway entries and winners.
- Introductions you submit, posted via a webhook in the server.
- Cached state for social and live-stream alerts (TikTok, YouTube, Twitch).
- Supporter and Patreon-link data read from the shared website database, used only to display the Wall of Support and keep the supporter (Vanguards) role in sync.
- Configuration and audit data created by server administrators.
3. Why, and lawful basis
The bot processes this data to provide moderation, logging, automation, role management, giveaways, and community features. Our lawful basis is legitimate interests (operating a safe, well-run community for the server that installs the bot), and consent where you voluntarily provide information such as a birthday or an introduction. Where we process data to comply with a legal obligation, such as removing illegal content or responding to a lawful request, that is our basis instead.
4. Recipients, hosting, and transfers
Data is processed through Discord and stored in EU/EEA infrastructure (Railway, acting as our processor). Live-alert features query public endpoints of the relevant platforms (TikTok, YouTube, Twitch). We do not sell data and do not use it for advertising. Any transfer outside the UK or EEA is protected by an appropriate safeguard, such as an adequacy decision or standard contractual clauses with the UK Addendum. We may disclose data where required by law or to protect the safety of the community.
5. Security
We apply appropriate technical and organisational measures, including least-privilege access, encryption of sensitive secrets at rest, access controls, and audit logging, to protect the data the bot processes.
6. Retention
We keep data only as long as necessary for moderation and community features, then delete or anonymise it. Our general periods are:
- Moderation cases, infractions, reports, and appeals: up to 24 months after the case is closed, so repeat behaviour and appeals can be handled fairly.
- Message logs: kept for a limited rolling window for safety and audit, typically up to 90 days, unless attached to an open case.
- Birthdays, introductions, and other data you set: kept until you remove it or leave the server.
- Giveaway entries and winners: kept for the duration of the giveaway and up to 6 months afterwards.
- Alert cache and configuration: kept while the relevant feature is in use.
You can remove data you set, such as a birthday or introduction, at any time.
7. Your rights
You have rights of access, rectification, erasure, restriction, portability, and objection under the UK GDPR, and the right to withdraw consent where processing relies on it. These may be limited where we must keep moderation and audit records. To exercise a right, contact legal@vardoxen.tv or ask your server administrators about data the bot holds. You can also complain to the Information Commissioner's Office at ico.org.uk.
8. Children
The bot is intended for users aged 13 and over, in line with Discord's minimum age, and is not directed at children under 13.
9. Changes
We may update this policy; the “Last updated” date above shows the latest version.