Skip to content

legal

Privacy policy

What GuardingPaw stores, for how long, and how to get it back or removed.

Last updated June 2025

What we collect and why

When you invite GuardingPaw to your server, we cache the guild object, its channels and roles. We may also cache user and member objects from the GUILD_CREATE payload. This runs the service and keeps us from asking Discord the same question twice. The legal basis is the contract you enter into by adding the bot (Art. 6(1)(b) GDPR).

When a ticket is closed, its messages and participant data (username, avatar hash, discriminator) are encrypted and stored in our database. Backups are encrypted as well and stored in a Storage Box hosted by Hetzner Online GmbH.

When you sign in to the dashboard, we read your Discord server memberships to check whether you own or help manage a server, and to list the ones you can configure.

Analytics

We only count visits once you allow it. The legal basis is your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG), and you can withdraw it at any time under Cookies below.

We use Matomo on some pages to see what to improve. Matomo runs on our own servers. Nothing is shared with third parties and nothing is used for advertising.

Log data

Our servers log standard browser data on every visit: IP address, browser and version, the pages you opened, and when. We use it to keep the service running and to find abuse.

Storage and security

Access is limited to the people who operate the service. Ticket transcripts and database backups are encrypted before they are stored on servers hosted by Hetzner Online GmbH. We do not sell your data, and we share it only where this policy says so.

How long we keep it

Server analytics are deleted automatically after 90 days. That period is the same for every server, whether it has Premium or not.

Everything else stays as long as you need it and is yours to remove: cached Discord data disappears when the bot leaves your server, and tickets, transcripts and moderation records are deleted when you delete them or ask us to.

Your rights

Under the GDPR, you have the right to:

  • Access your personal data (Art. 15 GDPR)
  • Request correction of inaccurate data (Art. 16)
  • Request deletion of your data (Art. 17)
  • Request restriction of processing (Art. 18)
  • Receive your data in a portable format (Art. 20)
  • Object to processing of your data (Art. 21)
  • Withdraw consent at any time, without affecting what happened before (Art. 7(3))
  • Complain to a supervisory authority (Art. 77)

The supervisory authority for us is the state commissioner for data protection in North Rhine-Westphalia.

Requests and removal

To get a copy of your data or have it removed, join our Discord support server and open a ticket in #support. We handle requests through Discord so we can confirm who is asking. You hear from us within 30 days.

You can also look at it yourself: sign in and open your data to see every record under your account and download it as a file. Server owners can export everything a server holds under Data export in the dashboard.

Cookies

Signing in sets cookies the site cannot work without: your session and a token that protects forms. Those stay. Counting visits is the only thing you decide about, and you can change your mind here.

You have not decided yet.

The choice is stored in a cookie in this browser, for a year.

Contact

Questions about this policy go to our Discord support server or to info@panda-network.de. Who we are is on the imprint page.