Data Processing Agreement

Last updated: 28 September 2026

This agreement governs, under Article 28 GDPR, the processing of personal data that RecheBot carries out on behalf of each Discord server. It is accepted when RecheBot is added to a server and forms part of the Terms of Service.

This is an English translation provided for convenience. The Spanish version is the legally binding one and prevails in case of any discrepancy.

Parties

  • Controller: the administrator or owner of the Discord server who adds or keeps RecheBot, on their own behalf or on behalf of the person or organisation they represent (for example, the streamer or the community). Hereinafter "the Controller".
  • Processor: Luis Reche, natural person, tax ID (NIF) [NIF pendiente], address [Domicilio pendiente], email rechedev@hotmail.com. Hereinafter "the Processor".

Subject matter, nature and purpose

The Processor processes personal data on behalf of the Controller for the sole purpose of providing RecheBot's features in its server: giveaways and their public transparency, entry requirements, winner notifications, levels and leaderboard, vouches, scammer flags, anti-scam guard, scheduled announcements, role panels, middleman helper and server template.

The processing operations are: collection through Discord, recording, storage, consultation, use for the listed features, disclosure to the server's members and staff within Discord, publication of giveaway transparency information, pseudonymisation and erasure.

Duration

The agreement lasts while RecheBot is in the Controller's server and ends when the bot is removed. The confidentiality and return or deletion obligations survive it.

Types of data and data subjects

Data subjects: server members, giveaway participants and winners, and staff members.

Data: Discord user, channel, role and server identifiers; server name; configuration; giveaway data (prize, requirements, dates, seed and its hash); entries and winners (time, draw data, copy of the winner's Steam Trade URL, delivery status); message counters, XP and level; vouches with their comment; scammer flags with their reason; scheduled announcement text; blocked domains. For the anti-scam guard, message content and display names are analysed transiently without being stored.

The processing is not intended for special categories of data (Article 9 GDPR) or criminal data. The Controller must not enter them in free-text fields (reasons, comments or announcements).

Controller instructions

The Controller's documented instructions are this agreement, the Terms of Service, and the configuration and commands the Controller and its staff use in RecheBot. The Processor will process the data only on those instructions, unless EU or Spanish law requires otherwise, in which case it will inform the Controller beforehand unless the law prohibits it.

If the Processor considers that an instruction infringes the GDPR or other data protection law, it will inform the Controller immediately.

Processor obligations

  • Confidentiality: only Luis Reche has access to the data, under a confidentiality commitment. If another person were to collaborate in future, they would be bound by the same commitment.
  • Security (Article 32 GDPR): TLS encryption for web communications; database not exposed to the internet; containers with minimum privileges; restricted access to credentials; random single-use tokens; nightly backups kept for 14 days; rotation of technical logs.
  • Data subject rights: it will help the Controller respond to them. The /privacidad command lets each user see and delete their data, and the Processor will forward to the Controller without delay any request it receives about the server's data.
  • Assistance: it will help the Controller comply with Articles 32 to 36 GDPR (security, breach notification, impact assessments and prior consultation), taking into account the information available to it.
  • Security breaches: it will notify the Controller without undue delay, and within 48 hours at most of becoming aware, of any breach affecting its data, with the information available so the Controller can document it and, where appropriate, report it to the authority and to data subjects. Notice will be given by Discord direct message to the server owner or through the channel the Controller has indicated in writing.
  • Records: it will keep a record of processing activities as processor (Article 30(2) GDPR).
  • Information and audits: it will make available to the Controller the information needed to demonstrate compliance with this agreement, and will allow and contribute to reasonable audits, preferably carried out through questionnaires and documentation, with 30 days' notice and without access to other servers' data.

Sub-processors

The Controller gives general authorisation for the engagement of sub-processors. The current sub-processor is:

Sub-processorServiceData location
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (Germany)Server and database hostingHelsinki, Finland (EU)

The Processor will impose on each sub-processor data protection obligations equivalent to those in this agreement. Any change of sub-processor will be published on this page at least 15 days before it takes place. If the Controller objects, it can say so at rechedev@hotmail.com or remove RecheBot from its server.

Discord and Valve (Steam) are not sub-processors: they are the platforms the Controller and users choose to use, and they process data as independent controllers.

International transfers

The Processor does not transfer the Controller's data outside the European Economic Area. Data flowing through Discord or Steam does so because the Controller has chosen to run its community on those platforms.

Controller obligations

  • Have a legal basis for the processing it enables and configure RecheBot lawfully and proportionately.
  • Inform its server's members, for example by publishing its giveaway rules and linking the Privacy Policy.
  • Use scammer flags, the anti-scam guard and free-text fields truthfully and with the minimum data needed.
  • Handle data subject requests about its server's data.
  • Oversee the processing and inform the Processor of any incident it detects.

End of the agreement

When RecheBot is removed from the server, the server's data is erased within 30 days, which allows the configuration to be recovered if the bot was removed by mistake. Backups containing it expire within the following 14 days.

As an exception, records of entries and winners of giveaways already held are pseudonymised rather than erased where they are needed to keep already published results verifiable. When the bot is removed from a server, all of that server's data, including its giveaways and public transparency pages, is erased after 30 days. If the Controller wants a copy of its data before erasure, it must request it by email before that period ends.

Liability and governing law

Each party is liable in accordance with Article 82 GDPR. This agreement is governed by Spanish law. In case of discrepancy between language versions, the Spanish version prevails.