Data Processing Agreement (AVV/DPA)

Pre-review Article 28 terms for Customer-controlled Discord data.


Date updated: 25 September 2026

Parties and application

This Data Processing Agreement (“DPA”) is between the Customer that accepts or signs it (“Controller”) and Martin Haslien, trading as Archivian (“Processor”). It forms part of the agreement governing the Customer's use of Archivian.

This DPA applies only to Customer Personal Data processed by Archivian on behalf of the Customer. It does not govern processing for which Archivian is an independent controller, including its own account, billing, service-security, abuse-prevention, support, and legal-compliance processing.

1. Definitions and precedence

Applicable Data Protection Law includes the GDPR and applicable German data-protection law. Customer Personal Data, personal data, processing, controller, processor, data subject, and personal data breach have the meanings in Applicable Data Protection Law. If this DPA conflicts with the Service Terms on processing Customer Personal Data, this DPA controls.

2. Subject matter, duration, nature, and purpose

Archivian processes Customer Personal Data to provide configurable Discord moderation, logging, security, verification, server-management, reporting, appeals, record-keeping, automation, support, and related functions selected by the Customer. Processing continues for the Service term and any limited period needed to return, delete, secure, or lawfully retain data after termination. Annex 1 contains further processing details.

3. Documented instructions

  1. Archivian will process Customer Personal Data only on documented Customer instructions, including the Service agreement, Customer configuration, authorized API use, and written support requests, unless Union or Member State law requires otherwise.
  2. If law requires processing outside the Customer's instructions, Archivian will inform the Customer before processing unless the law prohibits notice for important public-interest reasons.
  3. Archivian will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law and may pause that instruction while the parties resolve it.
  4. The Customer is responsible for the lawfulness, fairness, transparency, accuracy, and proportionality of its instructions and for providing required notices to Community Members.

4. Confidentiality and access

Archivian will ensure that people authorized to process Customer Personal Data are bound by confidentiality and receive access only as needed for their responsibilities. Access will be withdrawn when no longer required. Where the Processor is a solo operator, the same need-to-know and confidentiality obligations apply to the operator and any future contractor or employee.

5. Security

Taking account of the state of the art, implementation costs, scope and context of processing, and the risks to individuals, Archivian will maintain appropriate technical and organizational measures under Article 32 GDPR. The current factual measures are described in Annex 2 and the maintained Technical and Organizational Measures. Archivian may improve or replace measures without materially reducing the overall level of protection.

6. Subprocessors

  1. The Customer gives general written authorization for the subprocessors identified as such at Subprocessors and Service Providers to process Customer Personal Data.
  2. Archivian will impose data-protection obligations on each subprocessor that are no less protective in substance than the obligations applicable to that subprocessing.
  3. Archivian remains responsible to the Customer for a subprocessor's performance to the extent required by Article 28 GDPR.
  4. Archivian will give at least 7 days advance notice through dashboard banner and our subprocessor list before a new subprocessor begins processing Customer Personal Data, except where an urgent security or legal need makes advance notice impracticable, in which case Archivian will notify the Customer as soon as practicable afterwards.
  5. The Customer may object on reasonable data-protection grounds during the notice period. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate the affected Service without penalty for future periods; the refund treatment for prepaid unused periods follows the refund-handling terms of the Service Terms.

7. International transfers

Archivian will not transfer Customer Personal Data to a third country or international organization unless permitted by Applicable Data Protection Law and supported by an adequacy decision, appropriate safeguards such as the European Commission's Standard Contractual Clauses, or a valid derogation. Where needed, Archivian will assess transfer risks and implement supplementary measures. Archivian maintains current provider regions and transfer mechanisms in the Subprocessor List.

8. Assistance with data-subject rights

Taking account of the nature of processing, Archivian will assist the Customer through available technical functions and reasonable manual measures with requests under GDPR Chapter III. If Archivian receives a request concerning Customer Personal Data, it will not respond on the merits except on the Customer's instructions or where legally required, and will refer or forward the request where practicable. Controllers remain responsible for their decisions on requests and their retention reasons. Where deletion tooling for a data category is not yet complete, Archivian discloses this in the Technical and Organizational Measures.

9. Breach cooperation

  1. Archivian will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
  2. As information becomes available, notice will describe the nature of the breach, affected data and people, likely consequences, measures taken or proposed, and a contact point.
  3. Archivian will reasonably assist the Customer with Articles 33 and 34 assessments and notifications. The Customer remains responsible for notifications it must make as controller.
  4. Notification is not an admission of fault or liability.

10. DPIAs and supervisory authorities

Taking account of the nature of processing and information available to it, Archivian will reasonably assist the Customer with data-protection impact assessments and prior consultations relating to the Service. Assistance beyond standard documentation may be subject to reasonable fees where legally permitted and agreed in advance.

11. Return and Deletion

Upon termination or the Customer's instruction to end processing, Archivian will delete Customer Personal Data in accordance with the categories and scope described in this Section 11, unless law requires retention.

For the purposes of this DPA, Customer Personal Data is categorized as:

  1. Server-Specific Data: Personal data that is uniquely attributable to the Customer's server and processing activities, including messages, files, reports, appeals, moderation records, and other data created or modified specifically within the Customer's server context.
  2. Shared Data: Personal data that may be associated with multiple servers or is required for the operation of Archivian's services across multiple customers, including Discord user profiles, account metadata, and other global identifiers that are not unique to a single server.

Electronic Data Storage

Archivian stores all Customer Personal Data in electronic form using cloud-based infrastructure and third-party data centers. For electronic data storage, deletion is the appropriate and complete method to ensure no data remains with the processor as required by Article 28(3)(g) GDPR.

No Physical Data Return

Archivian does not have physical access to data carriers or on-premise storage. Any data export would provide a copy while the original data remains in Archivian's systems. Therefore, Archivian does not offer data export as an alternative to deletion at termination, as this would not satisfy the requirement that no data remain with the processor.

Data in Backups

Data may remain temporarily in protected infrastructure backups until ordinary rotation. It is isolated from routine use and deleted at the end of that cycle. Routine backups rotate within 7–14 days; disaster-recovery backups are maintained for up to 1 year for technical reasons.

Data Subject Rights

Nothing in this section limits data subject rights under GDPR Chapter III. Discord users may exercise their rights through the request channels described in Archivian's Privacy Policy; requests concerning Customer Personal Data are handled as described in Section 8 of this DPA.

Deletion Scope

Upon termination, Archivian will delete all Server-Specific Data. Shared Data may be retained by Archivian where such retention is necessary for:

Confirmation of Deletion

Upon written request, Archivian will provide the Customer with confirmation that Server-Specific Data has been deleted in accordance with this Section 11, excluding data that may remain in backups as described above.

12. Termination

Termination by Customer

The Customer may at any point remove Archivian from its server. As documented controller instruction agreed to in this DPA, if the Customer has not added Archivian back to their server for 7 consecutive days, this constitutes termination of the processing relationship.

Deletion at Termination

At the point of termination, Archivian will delete all Server-Specific Data in accordance with Section 11. Some data may still remain in backups after termination as described in Section 11.

Customer Control

The Customer may prevent automatic deletion by re-adding Archivian to their server at any time during the 7-day period, or by providing written notice to [email protected] requesting to pause or cancel the deletion process.

13. Information and audits

  1. Archivian will make information reasonably necessary to demonstrate compliance with Article 28 available to the Customer, including this DPA, TOMs, and subprocessor information.
  2. No more than once annually, unless a breach or regulator requires more, the Customer may request a reasonable audit relevant to Customer Personal Data. The audit may be carried out by the Customer or by an independent auditor mandated by the Customer, provided that the auditor is not a competitor of Archivian and is bound by written confidentiality obligations no less protective in substance than those in this DPA.
  3. Audits will be conducted in the first instance by documentation and remote review, including this DPA, the TOMs, subprocessor audit reports and certifications available to Archivian, and written responses to the Customer's questions. On-site inspection may be requested only where the Customer demonstrates that documentation and remote review are insufficient to resolve a specific and substantiated compliance question.
  4. On-site inspection is limited to facilities under Archivian's control at which Customer Personal Data is stored or processed. Archivian operates no data-processing facilities of its own; the processing infrastructure is operated by the subprocessors listed in Annex 3, for which Archivian will make available such audit reports, certifications, and contractual inspection rights as it holds. This clause confers no right of entry to private residential premises.
  5. Any on-site inspection requires at least 45 days advance written notice, or such shorter period as a competent supervisory authority requires or as is reasonable where a personal data breach affecting the Customer's Personal Data has occurred. The inspection must take place during normal business hours on a date agreed between the parties, must not unreasonably disrupt Archivian's operations, and must preserve the confidentiality, security, and personal data of other customers. Inspection confers no access to unrelated Customer data, credentials, secrets, or source code beyond what is strictly necessary to resolve the substantiated question.
  6. The Customer bears its audit costs; Archivian may charge reasonable costs for unusually burdensome assistance unless the audit identifies a material breach by Archivian.
  7. Nothing in this section limits the investigative, corrective, or other powers of a competent supervisory authority under Applicable Data Protection Law.

14. Customer obligations

The Customer will:

15. Liability and termination

Liability is governed by the Service Terms and mandatory Article 82 GDPR rules. This DPA ends when Archivian no longer processes Customer Personal Data for the Customer, except for provisions that must survive to protect retained data or enforce accrued rights.

Annex 1 — Processing details

Subject matterProvision of Archivian's configured Discord moderation, logging, safety, verification, server-management, automation, support, and record functions.
DurationService term plus feature-specific retention and the post-termination period to be completed above.
Nature of processingCollection, receipt, recording, organization, structuring, storage, retrieval, consultation, use, comparison, automated evaluation, transmission to Discord or authorized users, restriction, export, and deletion.
PurposesCustomer-configured moderation, evidence and audit history, reports and appeals, automated actions, verification, pattern recognition, staff collaboration, server configuration, backups/rollback, and support.
Data subjectsCommunity Members, server owners and administrators, moderators/staff, reporting users, reported users, appellants, invited staff, and other Discord users referenced in Customer Content.
Identity dataDiscord user ID, username/display name, avatar/profile attributes, server membership, roles, permissions, and staff assignment.
Content dataMessages and history, embeds, attachments/files, reports, appeals and chat, moderation notes, case entries, reasons, and Customer-provided free text.
Event and metadataServer/channel/message/role IDs, timestamps, edits/deletions, interaction and audit events, configured rules, strikes, violations, verification and anti-abuse signals, and actions.
Special categoriesNot intentionally required, but may occur in user-generated messages, attachments, reports, appeals, or moderation records. Customer must minimize and provide a valid Article 9 condition where applicable.
FrequencyContinuous or event-driven while relevant features are enabled.

Annex 2 — Technical and organizational measures

Annex 3 — Subprocessors

The current list is maintained at /legal/subprocessors.

Contact

Data-processing notices and instructions: [email protected].