Data Processing Agreement
Contractual terms for processing personal data on behalf of server operators under Article 28 of the General Data Protection Regulation (GDPR).
Version 1.2 · Last updated: 10 October 2026
1. Requesting and concluding a DPA
If you use Vaeros to process personal data on behalf of your organisation or community, you can contact us at bierenyoshua@gmail.com to request a Data Processing Agreement (DPA). Please include your legal name or organisation name, your contact details and the Discord server IDs concerned.
This page sets out the contractual terms for an individual Data Processing Agreement. Publication of these terms, installation of the bot or submission of a request does not by itself conclude a DPA.
A DPA takes effect only when both parties have accepted these terms together with the completed processing schedule, technical and organisational measures, and applicable sub-processor and location information in writing or electronic form. The accepted documentation must identify the parties, covered servers, enabled functions, processing purposes and duration, data categories, retention and deletion arrangements, and authorised contacts. Both parties must be able to retain the accepted version and evidence of acceptance.
Where an Article 28 agreement is required, these public terms do not replace the completed agreement or authorise processing before the necessary arrangements are in place. The obligations below apply as contractual obligations when incorporated into that agreement; applicable statutory obligations remain unaffected.
2. Parties and respective roles
The service provider and contracting party is:
Yoshua Bieren, trading as VaerosSole proprietor
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen, Germany
Email: bierenyoshua@gmail.com
Website: https://vaeros.eu/
This is a correspondence address and does not identify a server or data-centre location.
The customer identified in the individual agreement is the “Controller” where it determines the purposes and essential means of the covered processing. Yoshua Bieren is the “Processor” to the extent that Vaeros processes personal data on that Controller’s behalf and instructions. Technical ownership of a Discord server does not by itself determine the legal role.
If the customer itself acts as a processor for another controller, the parties must agree the appropriate sub-processing arrangement. Processing carried out for genuinely independent purposes, such as the operator’s own billing or statutory accounting duties, must be assessed separately and is not authorised merely by this DPA.
The terms “personal data”, “processing”, “personal data breach” and other data-protection terms have the meanings given in the GDPR. “Covered Data” means personal data processed on the Controller’s behalf within the scope of the individual agreement.
3. Subject matter and scope of processing
The subject matter is the operation of the agreed Vaeros Discord bot functions and associated dashboard for the Controller’s specified servers. Processing is limited to the enabled functions, agreed purposes and data necessary to provide them.
| Service area | Potential processing and data |
|---|---|
| Server administration and dashboard | Discord user, guild, channel and role identifiers; permissions; server settings; authorised staff actions; and authentication or session information needed for administration. |
| Moderation and server protection | Relevant messages and metadata, reports, evidence, moderation cases, warnings, sanctions, rule matches, timestamps and staff decisions. |
| Tickets and modmail | Participant identifiers, submitted messages, attachments or attachment references, case status, transcripts, ratings and timestamps where used by the enabled functions. |
| Community functions | Participation information, XP, levels, achievements, configured birthday fields, role assignments, votes, suggestions, event entries, giveaway entries and invite-related records. |
| Optional integrations and technical operation | Configured account or channel identifiers, announcement content, scheduling information, and necessary request, error or security metadata. IP addresses are included only where actually received and needed for the covered purpose. |
Processing may include receiving, organising, storing, retrieving, displaying, evaluating against configured rules, transmitting to authorised recipients, correcting, exporting, restricting and deleting data. Data subjects may include server members, moderators, administrators, support participants, report submitters and persons mentioned in submitted content.
Access to a Discord interface does not authorise indiscriminate collection or archiving. Voice participation features do not, under these terms alone, authorise recording or transcribing conversations. Intentional processing of special-category data under Article 9 GDPR or criminal-offence data under Article 10 GDPR requires an appropriate lawful basis, express instructions and suitable additional safeguards.
This DPA does not authorise reuse of Covered Data to build a cross-server global ban database or make independent cross-server moderation decisions. Such processing requires a separate assessment of legal roles, lawful grounds, transparency, recipients and retention. Server-specific execution of an agreed protection function must remain within the Controller’s documented instructions.
4. Controller responsibilities and instructions
The Controller is responsible for the lawfulness of its purposes and instructions, required notices to individuals, appropriate feature and permission settings, and its own obligations under applicable data-protection law. These responsibilities do not remove the Processor’s independent statutory obligations.
The Processor shall process Covered Data only on documented instructions from the Controller, including instructions concerning disclosures and international transfers, unless Union or Member State law requires otherwise. In that case, the Processor shall inform the Controller of the legal requirement before processing, unless that law prohibits notification on important public-interest grounds.
Documented instructions include the accepted agreement, its processing schedule, authorised dashboard settings, commands and written requests within the agreed scope. Material changes to purposes, data categories or processing arrangements must be documented and agreed before implementation.
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data-protection law. The affected instruction shall be suspended while its lawfulness is clarified, with appropriate protection for the affected data.
5. Confidentiality and authorised access
The Processor shall restrict access to Covered Data to persons who need it for authorised tasks. Before receiving access, those persons must be subject to a confidentiality commitment or an appropriate statutory duty and receive instructions relevant to their responsibilities.
Access rights shall be reviewed and withdrawn when no longer needed. Confidentiality obligations continue after a person’s engagement or the service relationship ends.
6. Technical and organisational measures
The Processor shall implement and maintain measures appropriate to the risks under Article 32 GDPR, taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals. These measures must address confidentiality, integrity, availability, resilience, recovery and regular evaluation of their effectiveness.
The currently identified security controls include:
- HTTPS for website connections.
- SMTP-TLS with connection verification for the configured mail transport.
- AES-256-GCM encryption for stored OAuth tokens and payment-access credentials.
- Server-side authorisation checks.
- Protection against cross-site request forgery (CSRF).
Encryption of selected credentials does not mean that all stored data is encrypted. Full encryption of the database, messages, transcripts and attachments has not yet been activated across the service. These terms do not claim end-to-end encryption or complete encryption of all storage and backups. Payment-access credentials are mentioned to explain technical coverage; this does not make independent billing processing part of the DPA.
The individual security schedule must describe the actual controls applicable to the agreed processing, including access management, encryption coverage and key management, backup and recovery arrangements, deletion procedures and effectiveness reviews. Planned improvements must be distinguished from measures already in operation.
The Processor shall reassess safeguards when risks or processing change and shall not reduce the agreed level of protection. Material changes affecting the agreed safeguards must be documented and communicated to the Controller. No security measure guarantees absolute protection; this does not limit the Processor’s legal or contractual security duties.
7. Sub-processors
The Processor shall engage another processor for Covered Data only with the Controller’s prior specific or general written authorisation. The applicable providers and their processing activities must be identified in the documentation accepted with the individual DPA. These public terms do not give blanket authorisation for unidentified providers.
Where general authorisation is agreed, the Processor shall notify the Controller at least 30 calendar days before adding or replacing a sub-processor. The notice shall identify the provider, relevant tasks, data, locations and safeguards. The Controller may object on reasonable data-protection grounds during that period.
The Processor shall not give a proposed sub-processor access to affected Covered Data while a timely objection remains unresolved. The parties shall seek a suitable alternative. If none is reasonably available, either party may terminate the affected service before the proposed provider begins processing. Applicable return and deletion obligations shall apply, and prepaid fees attributable to the unused terminated service period shall be refunded where applicable.
Before a sub-processor receives Covered Data, the Processor shall put in place a binding written or electronic agreement imposing the same relevant data-protection obligations. The Processor remains fully liable to the Controller for the sub-processor’s performance of those obligations and shall provide sufficient information to verify compliance.
8. Hosting, service providers and processing locations
Vaeros uses the following services for the purposes described below. Optional integrations are used only when the corresponding function or radio station is selected.
| Provider or service | Purpose within Vaeros |
|---|---|
| DeinServerHost | Server hosting, domain services, DNS and local backups. |
| Discord | Sign-in, bot operation, messaging and voice-related functions. |
| PayPal | Payment processing. |
| Twitch | Optional stream announcements. |
| I Love Music, Rainwave, SomaFM and 181.FM | Radio playback when a corresponding station is selected. |
| Let’s Encrypt | Certificates for HTTPS and mail connections. |
Email is operated using self-hosted Mailcow. This overview describes service usage; it does not classify every listed service as a sub-processor or replace the provider and transfer documentation agreed with an individual DPA. The relevant legal role depends on the actual processing activity. Independent payment processing, platform operations and certificate services must be assessed accordingly.
The hosting provider is:
Christian Ralph Hennig, trading as DeinServerHostGrubenstr. 21
66265 Heusweiler, Germany
Website: https://deinserverhost.de/
DeinServerHost advertises a hosting location near Frankfurt am Main, Germany. This general provider statement does not establish the location of every system, backup or administrative access used for an individual engagement. The applicable locations and access countries must be specified in the agreed processing documentation.
Covered Data shall be processed only in the agreed locations and in accordance with the Controller’s documented instructions. Any transfer subject to Chapter V GDPR requires an applicable lawful transfer mechanism and, where required, a transfer assessment and supplementary safeguards before it takes place. This DPA is not itself an international-transfer mechanism.
If a public authority requests access to Covered Data, the Processor shall assess the request’s lawfulness, limit disclosure to what is legally required and inform the Controller where legally permitted. It shall not voluntarily disclose Covered Data contrary to the agreement or applicable law.
9. Assistance and individual rights
Taking account of the nature of processing, the Processor shall assist the Controller through appropriate technical and organisational measures, insofar as possible, with requests under Chapter III GDPR, including access, correction, erasure, restriction and portability where applicable.
Requests concerning Covered Data received directly by the Processor shall be forwarded to the Controller without undue delay. The Processor shall not respond substantively without instructions unless legally required.
Taking account of the nature of processing and information available to it, the Processor shall also assist the Controller with its obligations under Articles 32 to 36 GDPR, including security assessments, breach notifications, data-protection impact assessments and prior consultation with supervisory authorities.
10. Personal data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting Covered Data. Notification shall be sent to the incident contact agreed with the Controller. An initial notification shall not be delayed until the investigation is complete.
To the extent available, the notification shall describe the nature of the breach, affected data and data-subject categories, approximate numbers of persons and records, likely consequences, containment or remediation measures, and a contact for further information. Additional information shall be provided in phases without undue further delay.
The Processor shall investigate, contain and remediate the breach, preserve relevant evidence securely and cooperate with the Controller. The Controller determines its notifications to authorities and affected individuals, without prejudice to the Processor’s separate legal obligations.
11. Information and audits
The Processor shall make available all information necessary to demonstrate compliance with Article 28 GDPR and the agreed DPA. It shall allow and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by it.
Ordinary audits shall be coordinated with reasonable notice to minimise unnecessary disruption and protect other customers’ information. Urgent circumstances, a relevant breach or a supervisory authority’s requirements may justify shorter notice. Reports and other assurance information may support verification but shall not exclude a necessary inspection.
Confidentiality arrangements, procedures or fees must not prevent effective exercise of mandatory verification rights. The Processor shall address identified deficiencies according to their risk and cooperate with competent supervisory authorities.
12. Retention, return and deletion
Covered Data shall be retained only for the agreed purposes and for no longer than necessary. The individual processing schedule must specify applicable retention periods and triggers, including arrangements for livechat, support records, attachments, moderation records and backups where those categories are within scope.
A software default or disabled automatic-expiry setting does not authorise indefinite retention. The Processor shall implement the agreed deletion arrangements and verify their operation. A shorter lawful Controller instruction takes precedence over an ordinary maximum period.
At the end of the relevant services, the Processor shall, at the Controller’s choice, return Covered Data and delete remaining copies, or delete the data without return, unless Union or Member State law requires storage. Return shall use an agreed secure method and a commonly used, machine-readable format where applicable. The individual agreement shall specify the operational deadlines, without permitting unnecessary delay.
Residual backup copies shall remain protected, excluded from ordinary use and subject to the agreed finite expiry period. If restoration is necessary for recovery, relevant deletion instructions must be reapplied before restored data returns to ordinary processing. These requirements also apply to relevant sub-processors.
Where law requires longer storage, the Processor shall identify the legal requirement and affected data to the Controller unless prohibited, restrict processing to that requirement and delete the data when the obligation ends. On request, the Processor shall confirm completion of deletion and identify any lawful retention exception or pending backup expiry.
Copies already delivered to the Controller’s own Discord channels, downloads or other systems remain subject to the Controller’s management and the applicable platform arrangements. This does not excuse deletion of copies controlled by the Processor or its sub-processors.
13. Duration, suspension and termination
The individual DPA shall remain in force for as long as the Processor or its sub-processors process Covered Data. Confidentiality, protection, assistance and deletion obligations continue for as long as necessary to give effect to the agreement.
The Processor shall promptly inform the Controller if it cannot comply. The Controller may suspend affected processing until compliance is restored and may terminate affected services for a material breach that cannot be remedied or is not remedied within a reasonable period. Immediate suspension or termination remains available where necessary to protect individuals or comply with law.
The Processor may terminate affected processing if the Controller insists on an unlawful instruction. In each case, the agreed return and deletion obligations apply.
14. Relationship to other terms
The accepted DPA and its processing schedules prevail over conflicting service terms concerning Covered Data. Updates to this webpage do not automatically amend an existing agreement. Amendments require a documented agreement in writing or electronic form, except changes expressly permitted by the accepted agreement subject to its safeguards.
Statutory liability, including Article 82 GDPR, the rights of data subjects and the powers of supervisory authorities remain unaffected. German law applies insofar as compatible with directly applicable Union law and other mandatory protections.
For DPA enquiries, contact bierenyoshua@gmail.com. General information about the service operator and personal-data processing is available in our Legal Notice and Privacy Policy.