Privacy policy
This policy describes personal data processing in connection with the Venon Discord bot, administrative dashboard and API (the “Service”), in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable Polish law. Last updated: August 5, 2026.
1. Data controller and roles
The data controller is the entity operating the Service. Contact us about all personal data matters, including exercising the rights described in section 7, at privacy@venon-sec.xyz. Requests submitted to this address are handled within the period specified in Article 12(3) GDPR.
Roles are allocated as follows: for the data of Users on a particular server, the administrator of that Discord server is the data controller, because they decide which modules to enable and their scope. The Service Provider then acts as a processor, following those instructions. For the Service’s own data, including Dashboard accounts, login sessions and requests addressed directly to the Service Provider, the Service Provider is the controller.
2. Scope and categories of data
The categories below reflect those defined in the Service’s implementation. A complete list with table names and source files is available in the Trust Center.
- Server configuration: module settings, protection thresholds, role and channel assignments, panel content and automation rules.
- Operational data: the state of active features, including timed sanctions, ongoing contests, open applications, temporary channels and minigame states.
- Members’ personal data: levels and activity tracks, time in voice channels, daily statistics, profiles, personal preferences, notes and bookmarks.
- Moderation and audit records: cases, warnings, security incidents, signals, protective actions, blocks, reports and the MSIoU lookup register.
- Dashboard sessions: data required to maintain login after authentication through Discord OAuth2.
- Service status samples: availability and latency measurements without user identifiers.
We do not process private message content beyond what is necessary for features enabled by the Server Administrator, such as moderation logs and ticket transcripts. We do not conduct advertising profiling or sell data.
2a. The cross-server MSIoU network
This is the only feature that may display a person’s data outside the server where it originated, so it is described separately and in detail.
MSIoU allows an administrator to view disciplinary history, including warnings, timeouts, removals and bans, recorded on other servers in the network. Access requires reciprocity: the requesting server must belong to the network and have receiving enabled. Data comes only from servers that publish to the network. A server that does not publish contributes nothing to another server’s dossier, even if it uses the same Bot. Any failure to read the network configuration restricts the scope to the requesting server.
- Objection (opt-out): a User can opt out of the network. Their dossier then stops showing disciplinary history from other servers and is restricted to the server where the lookup was made. Opting out removes them from the network, not from records on a server they actually belong to; those remain the responsibility of that server’s administrator.
- Passport (opt-in): positive history, such as membership duration, activity and absence of sanctions, leaves a server only after the person enables their passport. The legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time, deleting the corresponding entry.
- Server names are never disclosed. Neither the dossier nor the passport shows them. Only aggregate figures are visible.
- Activity covers 30 days. The dossier shows statistics from the last 30 days and contains no message content.
- Every lookup is recorded with the identity of the requester and the source of the query. Anyone using a dossier is also accountable, helping prevent its use for surveillance.
3. Purposes and legal bases
- Providing the Service — Article 6(1)(b) and (f) GDPR: performance of a contract and the legitimate interest in providing the bot’s features.
- Security and prevention of abuse — Article 6(1)(f) GDPR.
- Compliance with legal obligations — Article 6(1)(c) GDPR, for example handling data subject requests.
- Optional features requiring consent — Article 6(1)(a) GDPR; consent may be withdrawn at any time.
4. Sources of data
We obtain data from three sources: (1) Discord’s API, within the permissions granted to the Bot by the Server Administrator; (2) Users’ actions on the server, such as commands, tickets, applications and activity counted towards levels; (3) moderation decisions made in the Dashboard. For network features, records from other MSIoU servers are an additional source, under the conditions described in section 2a.
5. Retention period
Data deletion is triggered by removing the Bot from the server, rather than the age of a record. While the Bot operates on the server, configuration and moderation records are retained for their intended purpose: moderation and appeals against moderation decisions.
- When the Bot is removed: the server is marked as left and a grace period starts. Data remains available so that an accidental removal does not erase months of configuration work.
- 30 days after removal: server configuration, module operational data and members’ personal data are deleted. Discord identifiers are removed when personal data is deleted.
- 90 days after removal: moderation and audit records are deleted, followed by the server record itself. Nothing attributable to that server remains after this stage.
- Separately: raw service status samples are deleted after 7 days.
A scheduled process runs every 6 hours and performs deletion in a transaction: the server is either cleared completely or left untouched. Audit records are retained longer so that sanctioned users have evidence for an appeal. Details and source files are available in the Trust Center.
6. Recipients and processors
The current list of subprocessors is maintained in the Trust Center. As of the last update, it includes:
- Discord Inc. (United States) — the platform on which the Bot operates and from which all identifiers originate.
- VPS hosting provider — the application server and SQLite database used by the Bot and Dashboard.
- FACEIT — only when a User voluntarily links their account. No data is exchanged without an account connection.
We do not sell personal data or share it for marketing purposes.
7. Transfers outside the European Economic Area
Discord Inc. is based in the United States, so data may be transferred outside the EEA. Such transfers use mechanisms permitted by the GDPR, including standard contractual clauses or adequacy decisions. We seek to work with providers offering an appropriate level of protection.
8. Data subject rights
Under the GDPR, you have the right to:
- access your data and obtain a copy (Article 15);
- rectify your data (Article 16);
- have your data erased, the “right to be forgotten” (Article 17);
- restrict processing (Article 18);
- data portability (Article 20);
- object to processing (Article 21);
- withdraw consent at any time without affecting the lawfulness of earlier processing.
8a. How requests are handled
Requests are followed through after submission. The Service keeps a request register tied to the relevant server, so the outcome can be checked.
- Where to submit a request. The quickest route is to contact the administrator of the server where the data originated. They are the controller and have the required Dashboard tool. If they cannot be reached or your request receives no response, contact
privacy@venon-sec.xyz. - Types of request. Access, rectification, erasure and appeals against application decisions. An appeal is created automatically and linked to the relevant application.
- Request progress. A request moves through the statuses received, under review, resolved or rejected. The register records who decided the outcome and when.
- A reason is required. Closing a request requires a written decision. A refusal without reasons cannot be recorded, so the person concerned can challenge it.
- Limits to erasure. Moderation records may be retained where necessary for the establishment, exercise or defence of legal claims under Article 17(3)(e) GDPR. Any such refusal must be explained in the decision.
We respond without undue delay and within one month of receipt at the latest, in accordance with Article 12(3) GDPR. You also have the right to complain to the President of the Polish Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw. We encourage you to contact us first, as most issues can be resolved sooner.
9. Cookies and traffic measurement
The website and Dashboard use only essential technical cookies, such as those maintaining login sessions. We do not use marketing or profiling cookies.
Traffic measurement is prepared but disabled by default — until explicitly enabled, the website sends no events to external services. If enabled, it will operate without cookies or identifying individuals. An event contains the action name, such as clicking the add-bot button, and its location on the page. We do not record Discord identifiers, server names or content. We also honour the browser’s “Do Not Track” setting.
Enabling a tool that stores an identifier in a cookie would require prior consent and an update to this section. If that ever happens, the information and date will appear here.
10. Security
We use appropriate technical and organisational measures, including encrypted transmission, access control and monitoring for anomalies. No system is completely immune to threats; if a personal data breach occurs, we act in accordance with our GDPR obligations.
11. User age
Using Discord requires meeting the minimum age set in that platform’s terms, generally 13 and higher in some countries. The Service is not directed at people below that age.
12. Changes to this policy
This policy may be updated as the Service develops or laws change. Significant changes are announced on the official Discord server, and the last-updated date appears at the top of the document.
13. Contact
For personal data matters: privacy@venon-sec.xyz. Please contact us before complaining to a supervisory authority so that we can investigate the matter.
