Data Processing Agreement (DPA)
Modora – Discord Bot Platform
Article 28 GDPR – Processor Terms
Version: 1.0
Last updated: 24 February 2026
Controller: Discord Server Owner (Customer)
Processor: PC Servicedesk B.V. (operating as Modora)
1. Definitions
- "Agreement" means this Data Processing Agreement and its Annexes.
- "Controller" means the Discord server owner or authorized representative who determines the purposes and means of processing Personal Data via the Modora Service (the "Customer").
- "Processor" means PC Servicedesk B.V., a company incorporated under the laws of the Netherlands, operating the Modora Discord bot and dashboard platform.
- "Personal Data" has the meaning given in Article 4(1) GDPR.
- "Processing" has the meaning given in Article 4(2) GDPR.
- "Data Subject" has the meaning given in Article 4(1) GDPR.
- "Community Data" means Personal Data processed by Modora on behalf of the Controller in the context of the Discord server(s) to which the Modora bot is added (e.g. moderation logs, tickets, anti-scam scans, OCR results, AI chatbot interactions where configured by the Controller).
- "Platform Data" means Personal Data for which PC Servicedesk B.V. acts as an independent Controller (e.g. account data, billing data, support communications with Modora).
- "Sub-processor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller.
- "Modora Service" means the Discord bot, web dashboard, and related APIs and features provided by PC Servicedesk B.V. under the brand Modora.
- "Instructions" means the Controller's lawful, documented instructions regarding the Processing of Community Data.
2. Subject Matter and Duration
2.1 This DPA is entered into for the purpose of ensuring that Processing of Community Data by the Processor complies with Article 28 GDPR and that Data Subjects' rights are protected.
2.2 The Processor shall Process Community Data only on behalf of the Controller and in accordance with this DPA, the Modora Terms of Service, and the Controller's Instructions. The Processor shall not Process Community Data for its own purposes except where it acts as an independent Controller in respect of Platform Data (e.g. billing, account management).
2.3 This DPA applies for the duration of the provision of the Modora Service to the Controller, and until all Community Data has been returned or deleted in accordance with this DPA.
3. Nature and Purpose of Processing
Processing is carried out for the following purposes:
- Providing the Modora Discord bot and dashboard to the Controller's Discord server(s).
- Moderation (e.g. logs, warnings, bans, automod).
- Logging (message/audit logs as configured by the Controller).
- Ticket system (creation, replies, and storage of ticket content).
- Anti-scam detection and related logging.
- OCR-based image moderation where enabled.
- AI-powered features (e.g. chatbot, ticket categorization) where enabled by the Controller, including transmission of content to AI Sub-processors in accordance with this DPA and the Sub-processor list.
- Stream notifications and other optional modules as configured.
- FiveM integration and related data where configured.
- Backups, security, and incident response as described in the Security Measures document.
4. Categories of Data Subjects
- Members and users of the Controller's Discord server(s).
- Individuals whose content (messages, attachments, usernames, identifiers) is processed through the Modora Service in the context of the Controller's server(s).
5. Categories of Personal Data
- Discord identifiers (user IDs, server IDs, channel IDs).
- Usernames, display names, and profile information as made available via Discord.
- Message content, attachments (including images where OCR is used), and metadata (timestamps, etc.) as necessary for the agreed features.
- Moderation-related data (warnings, bans, notes, case data).
- Ticket content and related communications.
- Data derived from AI processing (e.g. categorizations, chatbot responses) where AI features are enabled.
- Anti-scam scan results and related logs.
- Technical data (IP addresses, user agents) where collected in the context of the Service (e.g. Join Guard, security).
6. Controller Obligations
6.1 The Controller shall comply with applicable data protection law and shall only give Instructions that are lawful.
6.2 The Controller is responsible for ensuring that it has a valid legal basis (and, where required, consent or another appropriate ground) for the Processing of Community Data via the Modora Service, including any use of AI or OCR features that may involve special categories of data or sensitive content.
6.3 The Controller shall inform the Processor without undue delay of any Instruction that, in the Processor's view, infringes applicable data protection law. The Processor may suspend performance of that Instruction until it is confirmed or amended.
7. Processor Obligations
7.1 The Processor shall Process Community Data only on documented Instructions from the Controller, unless required to do so by Union or Member State law; in such a case the Processor shall inform the Controller of that legal requirement before Processing, unless the law prohibits such information.
7.2 The Processor shall ensure that persons authorized to Process Community Data are bound by confidentiality or an appropriate statutory obligation.
7.3 The Processor shall implement appropriate technical and organizational measures as described in the Security Measures document (and Annex II), including to ensure a level of security appropriate to the risk.
7.4 The Processor shall not engage another processor (Sub-processor) without the prior specific or general written authorization of the Controller. General authorization is given for the Sub-processors listed in Annex III, subject to the Processor's compliance with the Sub-processor obligations in this DPA.
7.5 The Processor shall assist the Controller in ensuring compliance with obligations under Articles 32 to 36 GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of the Processing and the information available to the Processor.
7.6 The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under Chapter III GDPR (e.g. access, rectification, erasure, restriction, portability, objection), in accordance with the Data Subject Rights section below.
7.7 At the end of the provision of services relating to Processing, the Processor shall, at the choice of the Controller, delete or return all Community Data, and delete existing copies unless Union or Member State law requires storage.
7.8 The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits and inspections in accordance with the Audit section below.
8. Confidentiality
The Processor shall keep Community Data and any other confidential information received from or on behalf of the Controller strictly confidential. Access shall be limited to personnel who need such access to perform the Modora Service and who are bound by confidentiality. This obligation survives termination of the DPA.
9. Security Measures
The Processor shall implement technical and organizational measures as set out in the separate document Security Measures and in Annex II – Technical and Organizational Measures. Those measures include, in particular as appropriate:
- Encryption in transit (TLS 1.2 or higher).
- Encryption at rest for databases and sensitive storage.
- Access control and role-based access (RBAC).
- Logging and monitoring.
- Multi-tenant data separation.
- Safeguards for AI and OCR processing.
- Backup and incident response procedures.
10. Sub-processors
10.1 The Controller gives general authorization to the Processor to engage Sub-processors listed in Annex III (and any updates thereto in accordance with this clause). The Processor shall maintain an up-to-date list of Sub-processors and make it available to the Controller (including via the document Subprocessors).
10.2 The Processor shall enter into a contract with each Sub-processor that imposes, in substance, the same data protection obligations as set out in this DPA (in particular Article 28(3) GDPR). The Processor remains fully liable to the Controller for the performance of Sub-processors.
10.3 The Processor shall inform the Controller of any intended changes (additions or replacements) concerning Sub-processors, giving the Controller the opportunity to object. If the Controller objects on reasonable grounds relating to data protection, the Processor shall use reasonable efforts to avoid using that Sub-processor for the Processing of Community Data, or to offer alternative arrangements. If the Processor cannot reasonably do so, the Controller may terminate the relevant part of the Service or the agreement in accordance with the Modora Terms.
10.4 Where a Sub-processor is established outside the European Economic Area (EEA), the Processor shall ensure that appropriate safeguards under Chapter V GDPR are in place (e.g. Standard Contractual Clauses and/or an adequacy decision), as described in the Subprocessors document.
11. International Transfers
11.1 Community Data may be transferred to Sub-processors or affiliates outside the EEA only where one of the following applies: (a) an adequacy decision under Article 45 GDPR; (b) appropriate safeguards under Article 46 GDPR (e.g. Standard Contractual Clauses approved by the European Commission); (c) a derogation under Article 49 GDPR where applicable.
11.2 Details of Sub-processor locations and transfer mechanisms are set out in the Subprocessors document and Annex III.
12. Data Subject Rights
12.1 The Processor shall assist the Controller in fulfilling requests from Data Subjects (access, rectification, erasure, restriction, portability, objection, and withdrawal of consent) within the scope of the Modora Service and to the extent the Processor Processes the relevant Community Data.
12.2 The Processor shall forward to the Controller without undue delay any request from a Data Subject that it receives in connection with Community Data. The Controller is responsible for responding to the Data Subject; the Processor will provide such assistance (e.g. locating data, applying technical measures) as is reasonably possible.
12.3 Data Subject requests relating to Platform Data (where PC Servicedesk B.V. is Controller) are handled by PC Servicedesk B.V. in accordance with the Privacy Policy and applicable law.
13. Data Breach Notification
13.1 The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Community Data, and shall provide such information as the Controller reasonably needs to meet its obligations under Article 33 GDPR (notification to the supervisory authority) and Article 34 GDPR (communication to Data Subjects).
13.2 The notification shall at least describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach. The Processor shall cooperate with the Controller and provide further information as it becomes available.
14. Return and Deletion of Data
14.1 Upon termination of the Modora Service for a Controller (e.g. bot removed from server, account closed, or contract ended), the Processor shall, at the Controller's choice and within a reasonable period specified by the Controller (and in any event within 7 days (free tier) or 30 days (Pro tier) for guild removal/unlink as set out in the Data Retention Policy, unless a shorter period is agreed or required by law), delete or return all Community Data in the Processor's possession or control.
14.2 The Processor may retain copies to the extent required by Union or Member State law; in such a case the Processor shall ensure that Community Data remains protected and is not used for any other purpose.
14.3 Deletion and retention periods for specific data categories are further detailed in the Data Retention Policy.
15. Audit and Inspection Rights
15.1 The Processor shall make available to the Controller, on request, all information necessary to demonstrate compliance with Article 28 GDPR and this DPA.
15.2 The Controller (or an agreed third-party auditor bound by confidentiality) may carry out audits and inspections, at most once per calendar year unless required by a supervisory authority or following a Personal Data breach. Audits shall be conducted on reasonable notice, during business hours, and in a manner that does not unreasonably interfere with the Processor's operations. The Controller shall bear the cost of such audits unless the audit reveals a material breach by the Processor, in which case the Processor may bear the cost as agreed or as required by law.
15.3 The Processor may satisfy audit obligations by providing up-to-date attestations, certifications, or audit reports (e.g. SOC 2, ISO 27001) where they cover the Processing of Community Data, in lieu of an on-site audit where the Controller agrees.
16. Liability
16.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Modora Terms of Service, except that nothing in the Terms shall limit either party's liability for breach of data protection law or for matters that cannot be limited under applicable law.
16.2 The Processor shall be liable for damage caused by Processing only where it has not complied with its obligations under Article 28 GDPR or where it has acted outside or contrary to the Controller's lawful Instructions. The Processor shall not be liable for damage caused by the Controller's Instructions or the Controller's failure to comply with its obligations under this DPA or applicable law.
16.3 Where the Processor has engaged a Sub-processor and the Processor is not responsible for the event giving rise to the damage, the Processor may be exempt from liability in accordance with Article 82(2) GDPR if it proves that it was not in any way responsible for the event.
17. Governing Law and Disputes
17.1 This DPA is governed by the laws of the Netherlands. The courts of the Netherlands shall have non-exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to the Controller's right to bring proceedings in the courts of its place of establishment or before the competent data protection supervisory authority.
17.2 Data Subjects may bring claims against the Controller and the Processor in the Member State of their habitual residence, place of work, or place of the alleged infringement, in accordance with Article 79 GDPR.
18. Order of Precedence
In the event of conflict between this DPA and the Modora Terms of Service, this DPA shall prevail with respect to the Processing of Community Data and the parties' data protection obligations.
Annex I – Processing Description
| Item | Description |
|---|---|
| Subject matter | Processing of Community Data in the context of the Modora Discord bot and dashboard. |
| Duration | For the duration of the Service and until return/deletion in accordance with the DPA. |
| Nature and purpose | As set out in Section 3 of this DPA. |
| Categories of Data Subjects | As set out in Section 4. |
| Categories of Personal Data | As set out in Section 5. |
| Sensitive data / special categories | Where the Controller enables AI or OCR on content that may reveal special categories (e.g. health, biometric), Processing is limited to what is strictly necessary and in accordance with the Controller's Instructions and legal basis. |
| Controller's obligations and rights | As set out in the DPA and the Modora Terms. |
Annex II – Technical and Organizational Measures
The technical and organizational measures implemented by the Processor are described in full in the separate document Security Measures. A summary is incorporated by reference here and includes: encryption in transit and at rest, access control (RBAC), logging and monitoring, multi-tenant separation, backup and recovery, incident response, and safeguards for AI and OCR processing.
Annex III – Sub-processors
The current list of Sub-processors (name, purpose, location, and transfer mechanism where applicable) is set out in the separate document Subprocessors and is incorporated by reference. The Processor will update that list and inform the Controller of changes in accordance with Section 10 of this DPA.
For and on behalf of PC Servicedesk B.V. (Modora)
This DPA is applicable to all Controllers using the Modora Service. By using the Modora Service and adding the bot to a Discord server, the Controller accepts the Modora Terms and this DPA where applicable.