GDPR Privacy Notice
This notice explains how Partners Bot collects, uses and protects the personal data of individuals in the European Union and the European Economic Area, and the rights the GDPR grants you.
Last updated: 22 July 2026
Data controller
Partners Bot is the data controller responsible for the personal data described in this notice. Partners Bot provides a Discord partnership-automation service and an accompanying web platform and mobile application.
For any question about this notice or how we handle your data, use the Contact & DPO page.
Personal data we process
Depending on how you use our service, we may process:
- Account & identity — Discord ID, username, avatar, email address, and profile details you provide.
- Server data — guilds you own or administer and their configuration.
- Activity — partnership requests, notifications, support tickets and messages.
- Billing — invoices and payment records (payment card data is handled by our payment processors, not stored by us).
- Technical & security — IP address, device and browser information, sessions, and linked login providers.
Legal bases for processing (Article 6)
We rely on the following legal bases:
- Contract (Art. 6(1)(b)) — to provide the service you sign up for.
- Legitimate interests (Art. 6(1)(f)) — to secure, maintain and improve the service and prevent abuse.
- Legal obligation (Art. 6(1)(c)) — to comply with accounting, tax and other legal duties.
- Consent (Art. 6(1)(a)) — where you have given it, e.g. for optional communications. You may withdraw consent at any time.
Purposes of processing
We process personal data to operate and secure the partnership system, manage your account and servers, process payments, provide support, comply with the law, and improve the service. We do not sell your personal data.
International transfers
Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
Retention
We keep personal data only as long as necessary for the purposes above or as required by law (for example, invoices for statutory accounting periods). When data is no longer needed, it is deleted or anonymised.
Your rights
Under the GDPR you have the right to:
- Access your data and receive a copy (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data — the “right to be forgotten” (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
You can exercise access and portability instantly from the My Data portal. For other requests, contact us via the Contact & DPO page.
Automated decision-making
Some features (such as automatic partner approval and AI recommendations) use automated processing to score and match servers. These do not produce legal or similarly significant effects on you, and human review is available on request.
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, hashed credentials and optional two-factor authentication. No system is perfectly secure, but we work continuously to protect your data.
Complaints
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection supervisory authority in the EU/EEA. We would appreciate the chance to address your concern first — please contact us.
Contact & Data Protection
Questions, requests or complaints about your personal data are handled through our Contact & DPO page.
Ready to exercise your rights?
Access and export your personal data in under a minute.
