Subprocessors
Modora – Discord Bot Platform
PC Servicedesk B.V.
Last updated: 24 February 2026
Modora uses the following subprocessors to operate the Modora Service. This list is incorporated by reference into the Data Processing Agreement (DPA) and is updated when subprocessors are added or changed. You will be notified of material changes in accordance with the DPA.
Overview
| Subprocessor | Purpose | Location | Transfer mechanism (if outside EEA) |
|---|---|---|---|
| Hetzner | Application and bot server hosting (Finland) | Finland (EU/EEA) | N/A (EU) |
| Database | Primary and replica databases (MariaDB); self-hosted on same infrastructure | Finland (EU/EEA), self-hosted | N/A (EU) |
| CDN | Static assets and dashboard delivery; self-hosted (see also Cloudflare) | Finland (EU/EEA), self-hosted | N/A (EU) |
| Cloudflare | CDN, DDoS protection, WAF, proxy/caching for dashboard and traffic | Global (US and other regions) | SCCs, DPF where applicable |
| Sassguard | OCR for image moderation; server administrator (root access for server maintenance) | As per Sassguard | SCCs if outside EEA |
| Stripe | Payment processing, subscription billing, customer payment data | EU (Stripe Ireland) / US (Stripe Inc.) | SCCs (EU-US where applicable) |
| Anthropic (Claude) | AI features (e.g. chatbot, ticket categorization) when enabled | US | SCCs, DPF where applicable |
| Discord | Bot API, OAuth, gateway; data already in Discord's systems | US | SCCs (Discord's DPA/SCCs) |
| Google Analytics | Website and dashboard analytics (usage, traffic) | US | SCCs, DPF where applicable |
| Google Tag Manager | Tag management for analytics and marketing scripts | US | SCCs, DPF where applicable |
| Proton Mail (SMTP) | Transactional emails (e.g. password reset, notifications) via Proton Mail SMTP | Switzerland (adequate) | N/A (adequate) or SCCs |
| Monitoring / logging | Error tracking, performance monitoring where used | EU preferred | SCCs if outside EEA |
Detailed Subprocessor List
1. Hetzner (hosting and infrastructure)
- Entity: Hetzner Online GmbH (Germany) / Hetzner Finland.
- Purpose: Running the Modora dashboard (Laravel), bot application (Node.js), and related services. Servers are located in Finland (EU/EEA).
- Data processed: All application data (Community Data and Platform Data) hosted on the infrastructure.
- Location: Finland (EU/EEA).
- Transfer mechanism: N/A (EU). No international transfer for hosting.
2. Database (self-hosted)
- Purpose: Primary and backup database storage (MariaDB) for guild configs, moderation logs, tickets, anti-scam data, and other Community and Platform Data. Database is self-hosted on the same infrastructure (Hetzner Finland).
- Data processed: Structured data stored by the Modora Service.
- Location: Finland (EU/EEA), self-hosted.
- Transfer mechanism: N/A (EU).
3. Stripe
- Entity: Stripe, Inc. / Stripe Payments Europe, Ltd. (as applicable).
- Purpose: Payment processing, subscription management, invoicing, and fraud prevention for Modora Pro and other paid features.
- Data processed: Billing details, payment method information, transaction data. This is Platform Data for which PC Servicedesk B.V. is Controller; Stripe may also process data on behalf of Modora as processor.
- Location: Ireland (EU) for Stripe Payments Europe; US for Stripe Inc. where applicable.
- Transfer mechanism: Standard Contractual Clauses (SCCs) and, where applicable, Data Privacy Framework (DPF) for US transfers. Stripe's DPA and subprocessor information: https://stripe.com/privacy.
4. Anthropic (Claude)
- Entity: Anthropic PBC (US).
- Purpose: AI-powered features when enabled by the server owner (e.g. ticket categorization, AI chatbot). Content is sent to Anthropic's API for processing.
- Data processed: Message content, prompts, and responses as configured (Community Data). No training on customer data under Anthropic's commercial API terms.
- Location: United States.
- Transfer mechanism: Standard Contractual Clauses (SCCs) and/or Data Privacy Framework where applicable. Only used when the Controller enables AI features.
5. Discord
- Entity: Discord, Inc. (US) / Discord's EU entity where applicable.
- Purpose: Bot API, OAuth authentication, gateway for real-time events. Modora does not determine Discord's processing; server owners and users already have a relationship with Discord.
- Data processed: User IDs, server/channel IDs, message content and metadata, and other data provided via Discord's API in accordance with Discord's Developer Terms and Privacy Policy.
- Location: United States (and other regions as per Discord's infrastructure).
- Transfer mechanism: Discord's own DPA and Standard Contractual Clauses as offered to developers. Controllers should also review Discord's privacy policy: https://discord.com/privacy.
6. Sassguard
- Entity: Sassguard (OCR service provider and server administrator).
- Purpose: (1) OCR – Optical character recognition for image moderation. When the Controller enables OCR image moderation, image content may be sent to Sassguard for text extraction and analysis. (2) Server administration – Sassguard acts as server administrator with root access for server maintenance, updates, and related infrastructure management.
- Data processed: For OCR: images and extracted text as necessary for the OCR/moderation feature (Community Data). For server administration: access to infrastructure and systems where Personal Data may be processed; access is limited to what is necessary for maintenance and is governed by confidentiality and data protection obligations.
- Location: As disclosed by Sassguard (check their terms/privacy policy for current location).
- Transfer mechanism: If outside the EEA, Standard Contractual Clauses (SCCs) or equivalent safeguards are used.
7. Google Analytics and Google Tag Manager
- Entity: Google LLC (US).
- Purpose: Google Analytics and Google Tag Manager are used on the Modora dashboard/website for analytics (traffic, usage, behavior) and for managing tags (e.g. analytics, marketing scripts). This concerns Platform Data and dashboard usage, not Community Data processed on behalf of server owners.
- Data processed: IP address, device/browser information, pages visited, session data, and similar usage data. See our Cookie Policy for cookie details.
- Location: United States (Google's infrastructure may also use global data centers).
- Transfer mechanism: Standard Contractual Clauses (SCCs) and, where applicable, Data Privacy Framework (DPF). Google's advertising and analytics terms and privacy policy apply: https://policies.google.com/privacy.
8. Cloudflare
- Entity: Cloudflare, Inc. (US).
- Purpose: CDN, DDoS protection, web application firewall (WAF), and reverse proxy/caching for the Modora dashboard and related web traffic. Traffic may be routed through Cloudflare before reaching Modora's origin servers.
- Data processed: IP addresses, request headers, URLs, and other traffic data necessary for delivery, security, and caching. This may include Personal Data in HTTP requests (e.g. when users access the dashboard).
- Location: Global (US and other regions; edge locations worldwide). See Cloudflare's Data Localization and Privacy Policy.
- Transfer mechanism: Standard Contractual Clauses (SCCs) and, where applicable, Data Privacy Framework (DPF). Cloudflare's DPA and subprocessor information apply.
9. CDN (self-hosted)
- Purpose: Delivery of static assets and dashboard front-end from Modora's own infrastructure (in addition to or in conjunction with Cloudflare where used).
- Data processed: Served from the same infrastructure (Finland); request data as per normal web server logging.
- Location: Finland (EU/EEA), self-hosted.
- Transfer mechanism: N/A (EU).
10. Proton Mail (SMTP)
- Entity: Proton AG (Switzerland); email sent via Proton Mail SMTP.
- Purpose: Sending transactional emails (e.g. password reset, export ready, security alerts) via Proton Mail's SMTP infrastructure.
- Data processed: Email addresses (recipients) and content of the emails.
- Location: Switzerland (recognized as providing adequate data protection by the EU/EEA).
- Transfer mechanism: N/A (Switzerland is subject to an adequacy decision; no SCCs required for Swiss transfers).
11. Monitoring and error tracking
- Purpose: Application performance monitoring, error tracking, and logging (e.g. Sentry or similar) to ensure service reliability and security.
- Data processed: Logs, error reports, and potentially IP/request metadata; sensitive data is minimized and masked where possible.
- Location: EU preferred; may use US or other regions.
- Transfer mechanism: SCCs where the provider is outside the EEA.
Updates and objections
- Updates: We will update this list when we add or replace subprocessors. Material changes will be communicated in accordance with the DPA (e.g. notice and opportunity to object).
- Objections: If you have a reasonable, data-protection-related objection to a subprocessor, please contact us at legal@modora.gg. We will work in good faith to address your concern (e.g. by not using that subprocessor for your data or by offering alternative arrangements where feasible).
Contact
For questions about subprocessors or the DPA:
legal@modora.gg
PC Servicedesk B.V. (Modora)