FiveBot
Terms of ServicePrivacy PolicyDPAVoice Recording

Data Processing Agreement (DPA) — FiveBot

Version 1.0 · Effective date: 2026-08-26

This DPA forms part of the Terms of Service between SDN Ventures LLC ("Processor") and the customer organization ("Controller") and governs processing of personal data under Art. 28 GDPR. It applies automatically to every paid and trial account; no signature is required, and a countersigned copy is available on request.

1. Subject matter, duration, nature and purpose

Processing of community-support data on the Controller's documented instructions, for the duration of the account, to provide the Service described in the Terms: ticketing with transcripts, AI-assisted answers, translation, moderation tooling, evidence handling, opt-in ban network participation, AI NPC conversations, and consent-based recording of administrative voice conversations.

2. Categories of data subjects and data

Data subjects: members of the Controller's Discord community (players, staff), applicants, reported persons.

Data categories: Discord identifiers and profile basics; ticket messages and form answers; application content; moderation cases, sanctions and their stated reasons; report evidence (clips/screenshots); transcripts of consent-recorded administrative voice conversations and of NPC conversations; pseudonymized cross-community identifiers (keyed hashes) where the Controller opts into the ban network; game identifiers where a game integration is connected. No special categories are solicited; the Controller must not direct such data into the Service.

3. Instructions

The Controller instructs through configuration (dashboard, bot commands) and data-subject flows (/gdpr export, /gdpr delete). The Processor processes only on these instructions, unless EU/member-state law requires otherwise (in which case the Processor informs the Controller before processing, unless that law prohibits it). The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality and security (Art. 32) — technical and organizational measures

  • Tenant isolation enforced in the database layer (PostgreSQL row-level security on every tenant table; a restricted runtime role that cannot bypass it; isolation verified by automated tests for every data model).
  • Encryption in transit (TLS) everywhere; encryption at rest for secrets and tokens (envelope encryption, keys in a KMS, a dedicated non-serializable type preventing accidental exposure in logs or errors).
  • Cross-community identifiers stored only as keyed hashes (HMAC with a KMS-held key); erasure pseudonyms derived under a separate key domain.
  • Voice audio is not persisted by default — in-flight transcription with memory-only buffers; the optional audio-evidence setting stores under §7's retention bounds.
  • Least-privilege access; audit log of configuration changes; structured logging with no message plaintext to external systems; EU hosting (Hetzner, Germany/Finland).

5. Subprocessors

General authorization is granted for the subprocessors listed in the Privacy Policy §5. The Processor announces additions or replacements at least 14 days in advance (dashboard + email); the Controller may object on reasonable data-protection grounds, in which case the parties seek a solution and, failing one, the Controller may terminate with a pro-rated refund of the unused prepaid period. Subprocessors are bound by equivalent written obligations.

6. International transfers

The Processor is established outside the EEA (SDN Ventures LLC, Wyoming, USA). The application, database and AI infrastructure that hold Controller data are in the EU (Hetzner, Germany/Finland), but the Processor accesses them from the US, so the Controller-to-Processor leg is itself a Chapter V transfer.

  • Controller → Processor: Standard Contractual Clauses (2021/914, module 2, controller to processor), incorporated by reference into this DPA where the Controller is established in the EEA.
  • Processor → Subprocessor: Standard Contractual Clauses (2021/914, module 3, processor to subprocessor), or an adequacy decision (EU–US Data Privacy Framework) where the subprocessor is certified under it.

Supplementary measures are applied where required. No Art. 27 GDPR representative in the EU has been appointed yet; see Privacy Policy §9.

7. Retention and deletion

  • Community data is retained for the life of the account, subject to data-subject erasure and the Controller's own deletion actions.
  • Report evidence: min(decision + Controller-configured window (default 90 days), upload + 180 days) — enforced by an automated sweep.
  • On termination: export remains available for 30 days; thereafter all community data is deleted. Deletion covers derived artifacts: search indexes, AI embeddings, semantic-cache entries, and rendered transcript files.
  • Backups: encrypted, retained for a fixed window of 14 days, then aged out. Backups are immutable; if data is restored from a backup after a deletion, the delete-on-restore procedure re-applies recorded deletions before the restored system serves traffic.

8. Assistance

The Processor assists the Controller with data-subject requests (the in-product /gdpr flows execute them directly), with Articles 32–36 (security, breach notification, DPIAs), and provides the information necessary to demonstrate compliance. For Bodycam, the Processor's built-in consent flow (announcement + explicit consent, no-consent → no recording, audit trail of consents) is a processing safeguard offered to the Controller; the lawfulness of recording in the Controller's jurisdictions remains the Controller's responsibility as controller.

9. Personal-data breach

The Processor notifies the Controller without undue delay, and no later than 48 hours after becoming aware of a personal-data breach affecting the Controller's data, with the information required by Art. 33(3), supplemented as it becomes available.

10. Audits

The Processor makes available documentation demonstrating compliance (architecture, isolation-test reports, subprocessor terms). Audits and inspections are supported once per 12 months on 30 days' notice, remotely by default, at the Controller's cost, without access to other controllers' data.

11. Liability and precedence

Liability follows the Terms. In case of conflict regarding personal data, this DPA prevails over the Terms.

Annex — current subprocessors: see Privacy Policy §5. Annex — TOMs: §4 above.

Data Processing Agreement← Back to FiveBot