BeroNetwork
Deutsch

Privacy policy

Effective: 4 August 2026

1. Controllers and processing on behalf of server operators

Responsibility is split. The BeroNetwork operator is the controller for sign-in and the dashboard.

Berat Erekinci
An der Alten Ziegelei 38
48157 Münster
kontakt@beronetwork.de

For server content and use of the Bot on a Discord server, the relevant server operator is the controller. BeroNetwork processes that data as a processor on the server operator's documented instructions. The data processing agreement under Article 28(3) GDPR forms part of the terms of service and applies when the Bot is used.

2. Dashboard sign-in

When you sign in through Discord, we process your Discord user ID, display name, and the list of servers on which your account has administrator rights. These details are kept in a signed session cookie, with no server-side session store. The Discord access token is not stored.

This processing is necessary to provide the dashboard and verify access to server administration. The legal basis is Article 6(1)(b) GDPR where processing is necessary for the user relationship, and otherwise Article 6(1)(f) GDPR. Our legitimate interest is to keep server administration secure and limited to authorised administrators.

Signing in and providing this data are voluntary. Without the information, the dashboard cannot be used; use of the Bot within Discord remains available.

3. Strictly necessary cookies

We use exactly two strictly necessary cookies:

  • the __Host-bn_session session cookie for sign-in and permission checks, which lasts no longer than 24 hours,
  • __Host-bn_csrf, which protects forms from forged requests and lasts for 30 days.

We do not use analytics or advertising cookies. Storing and reading these cookies is strictly necessary under section 25(2) TDDDG.

4. Server logs

The nginx web server logs requests, including the visitor's IP address. Logs are used for troubleshooting and security, rotated daily, and deleted after 14 days. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in operating the service securely and reliably. The IP address is transmitted automatically when the site is accessed; without it, the website cannot be delivered.

5. Data processed by the Bot

The information processed depends on the features enabled and configured by the server operator. In relation to BeroNetwork, processing necessary to provide the service is based on Article 6(1)(b) GDPR where the user relationship is with an individual, and otherwise on Article 6(1)(f) GDPR. The legitimate interest is secure provision of the selected Bot features. For processing on the server, the server operator determines and documents the applicable legal basis, such as Article 6(1)(b) GDPR for requested services, Article 6(1)(f) GDPR for administration and moderation, or Article 6(1)(a) GDPR where consent is required.

DataPurposeRetention
Server ID, server name, Discord ID of the server owner, member count, and IDs and names of channels, roles, and emojis Assigning the server, checking permissions, and providing it in the Bot and dashboard Until the server data is deleted
Module settings, target IDs, text supplied by the server operator, embeds, knowledge articles, notifications, and custom Bot settings Running the configured Bot features Until the server data is deleted
Ticket openers, closers and claimants, internal note authors, members submitting ratings, ticket transcripts containing conversation history, free-form answers submitted through ticket forms, internal notes, and satisfaction responses Handling and documenting support requests on the server Until the server data is deleted
Discord IDs of warned or temporarily muted members and moderators, plus warning reasons Server moderation Until the server data is deleted
Discord IDs of inviters and joining members, invite counters per member, and creators of invite links Attributing and analysing invites and managing invite links Until the server data is deleted
Poll creators and voters; giveaway creators, entrants, and winners; creators and participants in player searches; stored birthdays; booster counts per member and reward status Running the community feature selected by the server operator Until the server data is deleted
Alarm creators and the Discord ID of the person who starts an alarm run Configuring alarms and recording their execution Until the server data is deleted
Messages counted per member per day, together with aggregate channel, hourly, activity, join, and leave statistics Community statistics and the Top Members ranking; the server operator's legal basis is Article 6(1)(f) GDPR and its legitimate interest is analysing community activity Up to 14 days, or up to 365 days for Premium servers; a configured override can only shorten the period
Technical jobs containing the server ID and target IDs required for the Bot action Reliably passing dashboard changes to the Bot Completed and failed jobs are deleted 7 days after creation; pending or running jobs remain stored until processed
Server backups: a snapshot of channels, roles, permission overwrites, emojis, server settings, and the role assignments of members at the time of the backup Restoring the server structure after data loss; the stored role assignments are not evaluated and are not shared with third parties Along with the respective backup, at the latest when it is displaced or deleted under the plan's retention limit

The Discord IDs and required information needed for a selected feature are supplied automatically through Discord or by the server operator. Each feature is optional. If the required data is not provided or the module is disabled, that feature cannot operate. Free-form information is voluntary unless the server operator configures a field as required.

After the Bot is removed, the remaining server data is deleted no earlier than 30 days later, during the next daily run after 4:00 a.m. The grace period protects against accidental removal. If the Bot returns during that period, deletion is cancelled. A server administrator can use the dashboard button to initiate deletion of all stored server data immediately. On the next job run, the Bot discards analytics still held in memory; an additional safeguard prevents data from being written again for a deleted server. The Bot remains on the server and every module returns to its default settings. Continued use may therefore create new data.

6. Hosting

The service is hosted by dataforest GmbH in Frankfurt am Main, Germany. Hosting-related processing takes place exclusively within the EU. dataforest receives only the access required for hosting and technical operation.

7. Recipients and international transfers

Discord is a technically necessary recipient because the Bot operates through the Discord platform and its API. For users in the European Economic Area, Discord Netherlands B.V. is the controller for processing by Discord; outside the EEA, this is generally Discord Inc. in the United States. Every use of the Bot necessarily involves processing by Discord.

Discord also processes data in the United States and other countries outside the EEA. According to Discord, transfers outside the EEA are safeguarded, as applicable, by the European Commission's standard contractual clauses, Modules 1 and 2, or by a European Commission adequacy decision. The safeguards can be requested using the contact details in Discord's privacy policy; the standard contractual clauses are also available from the European Commission's website.

8. Your rights

Subject to the statutory requirements, you may request access, correction, deletion, restriction, and data portability, and you may object to processing. Where processing is based on consent, you may withdraw it at any time for the future. You may also lodge a complaint with a data protection supervisory authority.

In particular, under Article 21 GDPR you may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. This also applies to the profiling involved in member statistics.

Server administrators can delete an entire server's data through the dashboard. Requests concerning one person's data can be sent to the email address in the legal notice. For server content, the relevant server operator is normally the first point of contact.

9. Automated decision-making and profiling

There is no automated decision-making within the meaning of Article 22 GDPR. In particular, BeroNetwork makes no decision based solely on automated processing that produces legal effects or similarly significantly affects a person.

When the analytics module is enabled, the Bot counts messages per Discord user ID and day, totals them for the selected period, sorts the totals in descending order, and displays them in the dashboard as a Top Members ranking. This automated evaluation is profiling within the meaning of Article 4(4) GDPR. The legal basis is Article 6(1)(f) GDPR; the server operator's legitimate interest is community statistics. The right to object under Article 21 GDPR is described in section 8.

10. Children

Discord's minimum age applies. BeroNetwork is not intended for children below that age.

BeroNetwork · Discord Dashboard
Legal notice Privacy Terms