Data Processing Agreement
Annex 1 to the General Terms and Conditions · Version: September 30, 2026 · Boxshop, owner Erwin Boxberger, Wiesenweg 10, 74424 Bühlertann
§ 1 Subject matter and duration
(1) This agreement governs the processing of personal data by Boxshop, owner Erwin Boxberger, Wiesenweg 10, 74424 Bühlertann, Germany (hereinafter “Provider”), on behalf of the Customer pursuant to Art. 28(3) GDPR. It is Annex 1 to the Terms and applies insofar as the Customer uses the Discord bot Asward-Helper on a Discord server for which the Customer is responsible and the bot processes personal data in doing so (hereinafter “Customer Data”).
(2) With regard to the Customer Data, the Customer is the controller within the meaning of Art. 4(7) GDPR and the Provider is the processor. The Customer is responsible for ensuring that the processing on the Customer’s server is lawful and that the data subjects are informed.
(3) The agreement applies for as long as the Provider processes Customer Data – for the duration of use and thereafter until the Customer Data is deleted or returned in accordance with § 9.
§ 2 Nature and purpose of the processing, type of data, data subjects
(1) Purpose: The Provider provides the functions of the bot that the Customer switches on and sets up in the dashboard – such as moderation and auto-moderation, tickets, applications, welcome messages, levels and XP, polls, giveaways, reminders, birthdays, invite tracking, logs of server events, time clock, staff and faction management and notifications about Twitch, YouTube and Instagram.
(2) Nature of the processing: collection via Discord’s interface, storage, evaluation and display in the dashboard, output on the Customer’s server (messages, roles), erasure.
(3) Type of data, depending on the functions switched on:
- Discord IDs, names, profile pictures, roles and time of joining
- messages, insofar as a function evaluates them (auto-moderation, XP, logs)
- tickets and their histories including attachments
- applications and answers to forms
- warnings, mutes, bans and other moderation records
- ban appeals including details and attachments
- birthdays, invitations, votes in polls, participation in giveaways, suggestions and reminders
- time clock records as well as entries in staff, employee, dues, cash register and storage lists
- texts and settings that the Customer and the Customer’s team enter in the dashboard
The processing of special categories of personal data (Art. 9 GDPR) is not intended. If messages, tickets or appeals contain such data, the Provider processes it only within the scope of the respective function.
(4) Categories of data subjects: members and visitors of the Customer’s Discord server, persons who submit a ban appeal via the appeal link, and members of the server team who use the dashboard.
§ 3 Instructions
(1) The Provider processes the Customer Data only on documented instructions from the Customer – including with regard to transfers to a third country – unless required to do so by Union or Member State law; in such a case, the Provider informs the Customer of that legal requirement before processing, unless that law prohibits such information. The instructions result from this agreement, the Terms and the settings that the Customer makes in the dashboard; the Customer gives further instructions in text form, for example by email to info@boxshopde.de. Every setting in the dashboard counts as a documented instruction.
(2) The Provider immediately informs the Customer if, in the Provider’s opinion, an instruction infringes the GDPR or other data protection provisions. The Provider may then suspend its execution until the Customer confirms or changes it.
(3) The Provider does not use the Customer Data for any other purposes.
§ 4 Confidentiality
The Provider ensures that all persons who have access to the Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR).
§ 5 Technical and organisational measures
(1) The Provider takes the measures required under Art. 32 GDPR. Currently these are:
- operation on a server in a data centre in Germany
- encrypted transmission (HTTPS with TLS, HSTS); the bot also communicates with Discord only in encrypted form
- firewall: from outside, only web access (HTTP/HTTPS) and server administration (SSH) can be reached; the database and cache can only be reached on the server itself
- access credentials and keys are kept in a configuration file that only the service can read
- only the Provider and the automatic deployment via a stored key have administrative access to the server
- login to the dashboard only via Discord; the session is kept as a signed token in a cookie that cannot be read by JavaScript (httpOnly) and becomes invalid on logout
- the data of a server can only be viewed and changed in the dashboard by those who are its owner or have the Discord permission “Administrator” or “Manage Server” there (checked with Discord), by those to whom the Customer expressly grants access, and by the Provider for operation and support
- protection against misuse: limiting requests per sender, protection against requests from other websites (CSRF), Content Security Policy
- data minimisation: in the database and in the application’s files, IP addresses are stored only as a shortened hash value; the server logs (accesses and errors) contain IP addresses and are deleted with the regular, automatic rotation
- error reports contain no cookies, no request contents and no values of program variables; email and IP addresses in error messages and log lines as well as access credentials in addresses called are redacted automatically before sending
- daily backup of the database and files on the server in a directory accessible only for administration; backups are deleted after 30 days; monitoring reports missing backups
- changes only go into operation after automatic tests and on a test server; if a deployment fails, the previous state is restored automatically
- operation is monitored continuously: error reports (see § 6) and a check of reachability from outside
(2) The Provider may adapt the measures to the state of the art as long as the level of protection does not decrease.
§ 6 Sub-processors
(1) The Customer grants the Provider general authorisation to engage sub-processors (Art. 28(2) and (4) GDPR). The Provider imposes on them the same data protection obligations as in this agreement and is liable for them as for its own conduct.
(2) Currently engaged:
- a hosting provider with registered office and data centre in Germany – provision of the server on which all Customer Data is stored
- Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA – error reports that may contain Discord IDs and names; storage in the EU region in Frankfurt am Main, transfer to the USA on the basis of the EU-US Data Privacy Framework (Art. 45 GDPR); deletion after 90 days at the latest
- Sendinblue SAS (Brevo), France – sending of emails that the Provider sends in connection with the processing
(3) Discord (Discord Netherlands BV or Discord Inc.) is not a sub-processor of the Provider: the Customer operates their own server on Discord; the bot only uses Discord’s interface for this.
(4) If the Provider intends to add or replace a sub-processor, the Provider informs the Customer at least 14 days in advance – by email to the address stored in the account or on this page. Within this period, the Customer may object for an important reason relating to data protection. If the parties cannot agree, the Customer may terminate the contract and remove the bot.
§ 7 Assistance to the Customer
(1) The Provider assists the Customer with appropriate measures in responding to requests from data subjects under Articles 12 to 23 GDPR. The Customer can view and delete much of the data directly in the dashboard; otherwise the Provider provides information about the Customer Data on request, rectifies it or deletes it. If data subjects contact the Provider directly, the Provider forwards the request to the Customer.
(2) Taking into account the nature of the processing and the information available to the Provider, the Provider assists the Customer in complying with the obligations under Articles 32 to 36 GDPR (security, notification of breaches, data protection impact assessment, prior consultation).
§ 8 Personal data breaches
If the Provider becomes aware of a breach of the protection of Customer Data, the Provider notifies the Customer without undue delay (Art. 33(2) GDPR) by email to the address stored in the account, with the information known to the Provider under Art. 33(3) GDPR, and takes the necessary measures to secure the data and to mitigate adverse consequences.
§ 9 Deletion and return
(1) After the end of the provision of the processing services, the Provider deletes the Customer Data or returns it to the Customer, at the Customer’s choice, unless Union or Member State law requires storage.
(2) If the Customer removes the bot from the Customer’s server, the Customer Data initially remains stored so that the Customer can invite the bot again without setting it up anew. If the Customer does not add the bot again within 6 months of removing it, the Provider deletes the Customer Data automatically once this period has expired. A custom bot that is linked to Asward-Helper in the web dashboard counts like the bot: the period only begins once neither of them is on the server any more. If the bot was already removed before September 30, 2026, the period begins on that day. As long as the server is registered in the server slots of an account with an active paid plan, the Provider does not delete the Customer Data even after the period has expired. The Customer may also demand deletion or return earlier; an email to info@boxshopde.de is sufficient. The Provider then deletes the Customer Data without undue delay or first hands it over in a common, machine-readable format.
(3) Copies in the daily backups are deleted automatically after 30 days.
§ 10 Evidence and audits
The Provider makes available to the Customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor mandated by the Customer who is bound to confidentiality. On-site audits must be announced with reasonable notice and carried out in such a way that operations are not disrupted; as a rule, written information is sufficient at first.
§ 11 Final provisions
(1) Art. 82 GDPR applies to liability; otherwise the Terms apply. In the event of contradictions between the Terms and this agreement, this agreement takes precedence with regard to the protection of personal data.
(2) The agreement is concluded in electronic form (Art. 28(9) GDPR). Should a provision be invalid, the remaining provisions remain valid.