Data processing agreement
Data processing agreement
The agreement that covers how Bastion handles your members' data for you. It applies automatically when you add the bot to your server.
Last updated
What this is, and when it applies
When you add Bastion to a Discord server, the bot handles personal data about that server's members for you. Data protection law says that needs a written agreement. This is it.
It is between you, the person or organisation that owns the server or added Bastion to it (the controller), and Xyliase Technologies LTD, trading as BASTION (the processor, "we").
It applies automatically from the moment Bastion is added to your server. You do not need to sign anything. It is part of the terms of service, and if the two ever disagree about personal data, this agreement wins. If your organisation needs a signed copy, email support@bastionbot.xyz.
It does not cover your own dashboard account, billing or marketing email. For those we are the controller, and the privacy policy applies.
What we process, and why
- Subject matter. Running the Bastion security and moderation bot in your server.
- Duration. For as long as Bastion is in your server, plus the 30 days after it is removed.
- Nature and purpose. Reading server events and messages to detect raids, spam and harmful changes. Acting on them as your settings say. Recording moderation actions. Verifying new members, and, where you switch it on, checking at the web verification page for second accounts and for VPN, proxy and Tor connections. Keeping a report of each raid, with the invite each account used. Where you opt in, adding accounts removed in a raid to the shared raid list and checking new members against it. Where you switch it on, sending an image a new member posts to the AI check for scam images. Collecting reports and appeals. Posting logs in the channels you choose. Showing all of this to your staff in the dashboard.
- Whose data. Your server's members, people who join or try to join, your staff, and people who appeal after being banned.
- What data. Discord IDs, usernames and display names. Account age and avatar, read but not stored. Message content, read in memory but not stored. Moderation cases and their reasons. Staff notes. Roles held by quarantined members. Appeal text. Report reasons. Verification attempts. Verification signals from the web verification page, where you switch them on: keyed hashes of a member's connection, its network and a device cookie's random ID, made with a key that belongs to your server alone, and whether the address was on a public VPN list. Never the IP address itself. Automod strike counts. Raid reports: the IDs and names of the accounts that joined in a raid, when each account was made, the invite it used and who made that invite. Test mode records. Temporary bans. A salted hash of each moderator's staff PIN and of your recovery key, never the PIN or the key. A picture you upload for custom branding, until Discord has it. Records of which staff member did what.
- The shared raid list. It is off unless you switch it on. For the list itself we are the controller, not your processor, because it runs across servers: the privacy policy describes it. It holds an account ID, two dates and marks that name no server, for 30 days after the account was last seen in a raid.
- The AI check for scam images. It is off unless you switch it on, and only exists where this installation has been set up for it. Only the image is sent to Anthropic. No message text, name, ID or server goes with it, and we keep only a fingerprint of the image with the answer, never the image.
- Special category data. Bastion is not built to handle it and does not ask for it. Do not put it in case reasons or staff notes.
We act only on your instructions
We process your members' data only as you instruct. Your instructions are: this agreement, the settings you and your staff choose in the dashboard, and the commands and buttons your staff use in Discord.
We do not use your members' data for our own purposes. We do not sell it, use it for advertising, or use it to train models.
If the law ever requires us to process it in another way, we will tell you first unless the law forbids that. If we think an instruction breaks data protection law, we will tell you.
Confidentiality
Only people who need access to run and support Bastion have it, and each of them is bound by a duty of confidentiality.
Security
We keep appropriate technical and organisational measures in place. Today these include:
- Discord sign-in tokens encrypted at rest with AES-256-GCM.
- Dashboard access checked against Discord on every request, so only people who manage your server can see its data.
- The settings that decide whether your server is protected can be changed only by the owner and the people the owner trusts.
- Sessions held in our database, a strict Content-Security-Policy, and limits on how many requests an account can make.
- Message content never written to our database.
- Automatic deletion on the schedule in the privacy policy.
The security page has more detail.
Sub-processors
You give us general permission to use the sub-processors listed on the sub-processors page.
We have a written contract with each one that gives your members' data at least the protection this agreement does, and we remain responsible to you for what they do.
Notice of changes. Before we add or replace a sub-processor that handles your members' data, we update that page at least 14 days in advance. You can object within those 14 days by emailing support@bastionbot.xyz. If we cannot meet your objection, you can remove Bastion from your server, and we refund the unused part of any Pro subscription for it.
Transfers outside the UK and EEA
Where a sub-processor handles your members' data outside the UK or the EEA, we make sure a legal safeguard is in place for the transfer. Where applicable, that is an adequacy decision, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses.
Helping you with people's rights
If one of your members asks to see, correct or erase their data, you are the one who answers. We help in these ways:
- Your staff can look up a member's cases and notes with the bot's commands and in the dashboard.
- Any signed-in person can download the records linked to their own Discord ID from their account page. Other people's names are left out.
- If a member writes to us about a record in your server, we pass the request to you and do not answer for you, unless the law requires us to.
- If you need something the bot and dashboard cannot do, such as erasing one member's records, email support@bastionbot.xyz with the server ID and the member's Discord ID and we will do it.
We also give you the information you reasonably need for a data protection impact assessment or a consultation with a regulator.
If there is a data breach
If we become aware of a breach affecting your members' data, we will tell you without undue delay, and aim to do so within 48 hours.
We will contact the server owner by email where we have an address for them, and otherwise by a direct message from the bot. We will tell you what happened, what data and roughly how many people are affected, what we have done about it, and who to contact. If we do not have every detail yet, we will send what we have and follow up.
You decide whether your regulator and your members need to be told. We will help you with the facts.
Deletion and return
- To end this agreement, remove Bastion from your server.
- Deletion. 30 days after Bastion is removed, everything it held for your server is erased: settings, cases, notes, backups, appeals, reports, events, verification signals and settings history. The delay is there in case the bot was removed by mistake or by an attacker. Adding Bastion back within that time cancels the deletion.
- Sooner. If you want it erased straight away, email support@bastionbot.xyz with the server ID from the owner's account.
- Return. While Bastion is in your server, your staff can read your cases and events in the dashboard. If you need a copy of your server's records before removing the bot, email us and we will send one.
- One thing a member can erase without you. A person who deletes their own Bastion account, or asks us to, has their verification signals erased from every server, because those describe their device and connection. Nothing else you hold about them is touched.
- What stays. Subscription and payment records are ours as controller and are kept as tax law requires. Posts the bot made in your own Discord channels stay in Discord until you delete them.
Information and audits
We will give you the information you reasonably need to show that this agreement is being followed. Start with this page, the security page and the sub-processors page.
If that is not enough, you may ask us written questions, or arrange an audit, once in any 12 months, or more often if a regulator requires it or after a breach. Give us 30 days' notice. An audit must happen in working hours, must not put other servers' data at risk, and is at your own cost.
Your part
- Have a lawful reason to use Bastion on your members' data, and tell your members that your server uses it.
- Choose settings that are fair. Automatic bans and kicks are your decisions, made with your settings.
- Give members a way to question an action, for example by turning on appeals.
- If you switch on second account detection or the VPN check, tell your members that your server checks for these, and prefer the settings that tell your staff over the ones that kick or ban by themselves. A shared connection is a hint, not proof. Recording why you need the check is your decision as controller, and so is acting on a member's objection.
- Keep private information out of case reasons and staff notes unless it is needed.
- Give dashboard access and trusted status only to people who should have it.
Changes, law and contact
We may update this agreement. We change the date at the top, and we will not reduce the protection it gives without at least 30 days' notice on this page.
This agreement is governed by the law of Scotland, in the same way as the terms of service. Each side's liability under it is subject to the limits in those terms, except where the law does not allow a limit.
- Company: Xyliase Technologies LTD, trading as BASTION, a company registered in Scotland.
- Company number: SC888385
- Registered office: Unit 29 Eliburn Industrial Park, Livingston, Scotland, EH54 6GQ
- ICO registration number: ZC246956
- Privacy contact: support@bastionbot.xyz