Data Processing Addendum (DPA)
Version 1.0 · Last updated: August 2026
This Data Processing Addendum applies between Vantom (“Processor”, operated by eNcrypt, a sole proprietor based in New Zealand) and any customer (“Controller”) who uses Vantom to process personal data of Discord users. It supplements the Terms of Service and forms part of the agreement.
1. Definitions
- Personal Data — any information relating to an identified or identifiable natural person per GDPR Art. 4(1)
- Processing — any operation performed on Personal Data per GDPR Art. 4(2)
- Controller — the customer, who determines the purposes and means of processing
- Processor — Vantom, which processes Personal Data on behalf of the Controller
- Sub-processor — any third party engaged by the Processor to process Personal Data
- GDPR — Regulation (EU) 2016/679
- Standard Contractual Clauses (SCCs) — the EU Commission’s standard contractual clauses for international transfers
2. Scope and Nature of Processing
2.1 Categories of Personal Data Processed
- Discord account identifiers (user ID, username, discriminator, avatar)
- Guild (server) IDs and configuration provided by the Controller
- Moderation records, tickets, form submissions, and support interactions
- Message content processed in real time to enforce the Controller’s moderation and AutoMod rules (not stored beyond moderation records)
- AFK status and highlight/keyword subscriptions
- Economy account balances and transaction history
- Payment information (processed by Stripe; card details are not stored by the Processor)
2.2 Categories of Data Subjects
- Discord users who interact with the Controller’s server(s)
- The Controller’s staff/administrators who use the dashboard
2.3 Purposes of Processing
- Provide and maintain the bot and dashboard service
- Enforce the Controller’s moderation and AutoMod settings
- Process payments through Stripe
- Improve the service based on aggregate analytics
- Secure the service (two-factor authentication, audit logs)
- Comply with legal obligations
2.4 Duration
Processing continues for the duration of the agreement. Personal Data is deleted per Section 7 upon termination.
3. Processor Obligations
3.1 The Processor shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure persons authorized to process are bound by confidentiality
- Implement appropriate technical and organizational measures per GDPR Art. 32
- Not engage Sub-processors without prior written authorization (see Section 4)
- Assist the Controller with data subject rights requests (access, rectification, erasure, portability)
- Assist the Controller with GDPR Art. 32 security and Art. 33 breach notification
- Delete or return all Personal Data at the Controller’s choice upon termination
- Make available information necessary to demonstrate compliance
3.2 The Processor shall notify the Controller without undue delay if:
- An instruction infringes GDPR or applicable data protection law
- A Personal Data breach occurs (within 48 hours of awareness)
4. Sub-processors
4.1 Authorized Sub-processors
The Controller generally authorizes the following Sub-processors:
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Discord Inc. | Authentication, service delivery | USA | SCCs + Discord DPA |
| Stripe Inc. | Payment processing | USA | SCCs + Stripe DPA |
| Sentry | Error monitoring and crash diagnostics | USA | SCCs + Sentry DPA |
| Hosting provider | Infrastructure and storage | New Zealand | Sub-processor DPA on request |
4.2 New Sub-processors
The Processor will notify the Controller of any new Sub-processor at least 30 days before engagement. The Controller may object within 14 days if the objection is reasonable. If the objection is not resolved, the Controller may terminate for cause.
5. International Data Transfers
5.1 Transfers outside the EEA
Where Personal Data is transferred outside the EEA, the Processor ensures:
- An adequacy decision, OR
- Standard Contractual Clauses (2021/914), OR
- Binding Corporate Rules, OR
- Another GDPR Art. 46 mechanism
5.2 Current Transfers
- Discord (USA): SCCs + Discord DPA
- Stripe (USA): SCCs + Stripe DPA
- Sentry (USA): SCCs + Sentry DPA
- Hosting (New Zealand): no transfer
6. Data Subject Rights
The Processor will assist the Controller in fulfilling data subject requests:
- Access: provide a copy of Personal Data in machine-readable format
- Rectification: correct inaccurate data
- Erasure: delete Personal Data (subject to legal retention)
- Portability: export in a structured, commonly used format
- Restriction/Objection: restrict or object to processing
Requests must be made via the Controller; the Processor acts on the Controller’s instructions. End users may also exercise rights directly through their Vantom account page (export / delete).
7. Data Retention and Deletion
| Data Category | Retention Period | Deletion Trigger |
|---|---|---|
| Moderation logs | 2 years (TTL) | Auto-expiry or Controller request |
| Tickets & transcripts | 1 year | Auto-expiry or Controller request |
| Audit logs | 1 year | Auto-expiry or Controller request |
| Economy transactions | 1 year | Auto-expiry or Controller request |
| Analytics snapshots | 90 days | Auto-expiry |
| Guild data | Until bot removal or deletion request | Controller request or bot removed |
| Account data | Until account deletion requested | Controller/user request |
Upon termination, the Processor deletes all Personal Data within 30 days unless a legal hold applies.
8. Security Measures
The Processor implements:
- Encryption in transit (TLS 1.2+)
- Encryption at rest for stored secrets and backups
- Access controls (role-based, least privilege, 2FA for admin accounts)
- Encrypted off-host backups with periodic restore drills
- Error monitoring (Sentry) and health/alerting
- Incident response with 48-hour breach notification
9. Audit Rights
The Controller may audit the Processor’s compliance once per 12 months with 30 days’ notice. Audits are conducted during business hours, at the Controller’s expense, under a non-disclosure agreement. The Processor provides independent security reports (when available) in lieu of an on-site audit.
10. Liability
Each party’s aggregate liability is capped at 12 months’ fees paid under the agreement. Neither party is liable for indirect, consequential, or punitive damages. The Processor indemnifies the Controller for the Processor’s GDPR violations.
11. Term and Termination
This DPA survives agreement termination. Sections 7, 10, 11, and 12 survive.
12. General
- Governing Law: laws of New Zealand
- Dispute Resolution: good-faith negotiation, then the courts of New Zealand (except where applicable law grants you the right to bring a claim in your local courts)
- Entire Agreement: this DPA together with the Terms of Service constitute the entire understanding
- Amendments: written agreement required
Contact
To request a signed copy of this DPA for your organization, contact us via the support page.