Data Retention Policy
Modora – Discord Bot Platform
PC Servicedesk B.V.
Last updated: 24 February 2026
This policy defines how long Modora retains different categories of data. It supports compliance with the GDPR principle of storage limitation (Article 5(1)(e)) and is referenced in the Data Processing Agreement (DPA) and Privacy Policy. Retention applies to both Community Data (processed on behalf of the Discord server owner) and Platform Data (for which PC Servicedesk B.V. is Controller).
1. Summary table
| Data category | Default retention | On server removal | On account termination | Legal exceptions |
|---|---|---|---|---|
| Moderation logs | Configurable; default 90 days | 7 days (free) / 30 days (Pro) – see §4 | N/A (per-guild) | Longer if required by law |
| Tickets | Configurable; default 1 year | 7 days (free) / 30 days (Pro) | N/A (per-guild) | Legal hold / litigation |
| AI prompts / responses | Configurable; default 90 days or off | 7 days (free) / 30 days (Pro) | N/A | As required by law |
| Anti-scam scans | Configurable; default 30–90 days | 7 days (free) / 30 days (Pro) | N/A | As required by law |
| OCR / image moderation | Configurable; default 30–90 days | 7 days (free) / 30 days (Pro) | N/A | As required by law |
| Billing / Stripe data | 7 years (tax/legal) | N/A | Retained per legal obligation | Tax, legal, dispute |
| Account / profile data | Until deletion + 30 days | N/A | Deleted per request or 90 days after termination | Legal obligation |
| Support communications | 2 years | N/A | Deleted with account or 2 years | Legal / dispute |
| Session / technical logs | Up to 30 days | N/A | N/A | Security / incident |
2. Community Data (Processor role)
Community Data is data processed by Modora on behalf of the Discord server owner (Controller). Retention is applied per guild (Discord server). When the Modora bot is removed from a server or the guild is no longer linked to an active account, Community Data for that guild is deleted or anonymized within 7 days (free tier) or 30 days (Pro tier) of the removal or unlink, as set out in section 4.
2.1 Moderation logs
- Default retention: 90 days from the date of the logged event, unless the Controller configures a different period within the limits offered by the product.
- On server removal: All moderation logs for that guild are deleted within 7 days (free tier) or 30 days (Pro tier) of the bot being removed or the guild link being terminated.
- Content: Log entries (e.g. warnings, bans, case notes, automod actions) and related identifiers. Stored only as long as necessary for the Controller's moderation purposes and this policy.
2.2 Tickets
- Default retention: 1 year from ticket closure (or last activity), unless the Controller sets a different retention within product limits.
- On server removal: All tickets and thread content for that guild are deleted within 7 days (free tier) or 30 days (Pro tier) of the bot being removed or the guild link being terminated.
- Content: Ticket subject, messages, attachments metadata, and participant IDs. Attachments may be subject to separate storage/retention (e.g. object storage) in line with this policy.
2.3 AI prompts and responses
- Default retention: 90 days from the interaction, or no storage (ephemeral) where the feature is configured that way. Where the Controller disables AI or deletes guild data, AI-related data for that guild is removed.
- On server removal: Deleted with guild data within 7 days (free tier) or 30 days (Pro tier).
- Content: Prompts and responses sent to/from Anthropic. Retention is minimized and aligned with the Controller's instructions and product settings.
2.4 Anti-scam scans
- Default retention: 30–90 days from the scan (configurable where the product allows). Used for logging and review by the Controller's staff.
- On server removal: All anti-scam scan data for that guild is deleted within 7 days (free tier) or 30 days (Pro tier) of the bot being removed or the guild link being terminated.
- Content: Scan results, links, flags, and related message/user identifiers. No longer than necessary for safety and review.
2.5 OCR and image moderation
- Default retention: 30–90 days from the moderation action (configurable where the product allows). Raw images and extracted text are not retained longer than necessary.
- On server removal: Deleted with guild data within 7 days (free tier) or 30 days (Pro tier).
- Content: Extracted text, hashes or references, and moderation outcomes. Full images are not retained beyond the period needed for the feature and this policy.
2.6 Other guild-linked data
- Stream notifications, FiveM, and other modules: Data specific to a guild (e.g. streamer lists, FiveM server configs) is treated as Community Data. Retention follows the same principle: configurable where offered, and deleted within 7 days (free tier) or 30 days (Pro tier) of server removal or guild unlink.
- Backups: Backups that contain Community Data are purged or overwritten in line with backup retention (e.g. 30 days); restoration is only for disaster recovery and does not extend the effective retention of data beyond this policy.
3. Platform and billing data (Controller role)
PC Servicedesk B.V. is the Controller for account, billing, and support data. Retention is applied when a user account is terminated or when the business relationship ends.
3.1 Billing data (Stripe and related)
- Retention: 7 years from the end of the calendar year in which the transaction or subscription period ends, for tax, accounting, and legal compliance (e.g. Dutch law).
- On account termination: Billing records are not deleted on account closure; they are retained for the 7-year period above.
- Content: Invoices, payment method tokens (as held by Stripe), subscription history, and related identifiers. Stripe's own retention applies to payment data processed by Stripe.
3.2 Account and profile data
- Retention: Until the user requests account deletion or the account is terminated by Modora, plus a 30-day grace period for recovery. After that, account and profile data (e.g. Discord ID, email if collected, preferences) are deleted.
- On account termination: Deletion is completed within 90 days of the effective termination date, except where legal retention applies (e.g. billing, disputes).
- Content: User profile, linked guilds, dashboard preferences, and authentication-related data. No longer than necessary for the contract and this policy.
3.3 Support communications
- Retention: 2 years from the last message in the thread or from account termination, whichever is later, for quality and dispute resolution.
- On account termination: Retained for up to 2 years as above, then deleted unless a legal exception applies.
- Content: Support tickets, emails, and chat logs with Modora support.
3.4 Session and technical logs
- Retention: Up to 30 days for access logs, session data, and security-related logs (e.g. login attempts, IP addresses). Used for security, abuse prevention, and incident response.
- No retention beyond 30 days unless required for an active incident or legal obligation.
4. Deletion upon server removal
When the Modora bot is removed from a Discord server or the guild is permanently unlinked from any Modora account:
- All Community Data for that guild (moderation logs, tickets, AI data, anti-scam data, OCR data, and other guild-specific data) is deleted or anonymized within 7 days (free tier) or 30 days (Pro tier) of the removal or unlink.
- Backups containing that guild's data are purged in line with backup retention and are not used to restore that data except where required by law.
5. Deletion upon account termination
When a user account is terminated (by the user or by Modora):
- Platform Data (account, profile, preferences) is deleted within 90 days of the effective termination, subject to the 30-day grace period where applicable.
- Community Data for guilds that were linked only to that account is handled as in section 4 (server removal). If the guild remains linked to another account, only the link from the terminated account is removed; guild data is retained for the remaining Controller.
- Billing data is retained for 7 years as set out in section 3.1.
- Support data is retained for 2 years as set out in section 3.3.
6. Legal retention exceptions
- Legal obligation: Where Union or Member State law (e.g. tax, anti-money laundering, litigation) requires retention beyond the periods above, data is retained only as long and only to the extent required by that law. Access is restricted and the data is not used for other purposes.
- Legal hold: Where there is a reasonable expectation of litigation or regulatory investigation, Modora may suspend deletion for the relevant data until the hold is lifted, in accordance with applicable law.
- Rights of Data Subjects: Deletion requests from Data Subjects are handled in accordance with the Privacy Policy and the DPA; legal exceptions to deletion (e.g. Article 17(3) GDPR) are applied where applicable.
7. Implementation and review
- Retention is implemented at the application and database layer (e.g. scheduled jobs, lifecycle rules) and is documented in operational runbooks.
- This policy is reviewed periodically and updated to reflect product changes, legal requirements, and regulatory guidance. Material changes will be communicated via the dashboard, email, or the Legal page as appropriate.
Contact: privacy@modora.gg / legal@modora.gg
PC Servicedesk B.V. (Modora)