Legal
Data Processing Agreement (DPA)
1. Parties and roles
Customer (Data Controller): The Discord server owner who determines the purposes and means of processing personal data from their Discord server.
BastionHub (Data Processor): BastionHub processes personal data on behalf of the Customer, strictly following documented instructions and this DPA.
2. Scope and purpose
BastionHub processes Discord security metadata — including user identifiers, threat detection types, audit actions, and exposure monitoring findings — for the purpose of providing automated cybersecurity monitoring, policy enforcement, and compliance reporting for the Customer's Discord server.
BastionHub does not process Discord message bodies, attachments, passwords, seed phrases, or raw webhook tokens. Detection occurs in memory; only metadata is persisted.
3. Subprocessors
BastionHub engages the following subprocessors, each bound by equivalent data protection obligations:
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services | Cloud infrastructure and data storage (US-West-2) |
| Supabase | Managed PostgreSQL on AWS |
| Discord Inc. | Source of Discord data via official API |
| Stripe | Payment processing for subscription billing |
| Have I Been Pwned | Breach intelligence for exposure monitoring |
| Vercel | Web application hosting and edge delivery |
BastionHub will notify the Customer at least 30 days before engaging a new subprocessor. The Customer may object by terminating the subscription.
4. Data location and residency
Customer data is stored on AWS infrastructure in US-West-2 (Oregon, USA). EU data residency is available for Enterprise customers on request and may incur additional costs. Data does not leave the designated region without the Customer's written consent.
5. Security measures
BastionHub implements the following technical and organizational measures:
- Encryption in transit: TLS 1.2+ on all connections
- Encryption at rest: AES-256 managed by AWS via Supabase managed PostgreSQL
- Tenant isolation: Every database query is scoped to the Customer's guild ID
- Access control: Server-side Prisma service role only; no browser-side database access
- Authentication: Discord OAuth2 for Owner/Staff Dashboard; TOTP MFA for internal operator access
- Audit logging: All significant actions are logged with actor, timestamp, and guild
- Secrets management: API keys and secrets are stored in environment variables, never in git or frontend bundles
- Fail-closed architecture: If authorization or verification fails, operations do not execute
6. Data retention and deletion
Retention periods are determined by the Customer's plan tier:
| Plan | Retention |
|---|---|
| Basic | 90 days |
| Pro | Up to 7 years (compliance archive). Live threat metadata is owner-configurable and can be shorter. |
| Enterprise | Contract-defined |
The Customer can delete all BastionHub data for their server at any time from the Owner Dashboard. Litigation hold may pause deletion when legally required. Upon termination, all Customer data is deleted within 30 days unless a longer retention period is required by law.
7. Data subject rights
BastionHub assists the Customer in responding to data subject requests (access, rectification, erasure, portability) under GDPR, CCPA, and applicable laws. The Owner Dashboard provides self-service deletion and export capabilities. Per-user anonymization is available through the Compliance Center.
8. Breach detection and notification
BastionHub operates continuous automated breach detection. Security events (rate limit violations, CSRF failures, tenant isolation violations, privilege escalation attempts) are logged to the audit trail when processed with action type SECURITY_ALERT. The Owner Dashboard exposure monitoring page displays a live green-light indicator showing the connection status to the breach intelligence provider (Have I Been Pwned), refreshed hourly.
BastionHub will notify the Customer of a confirmed personal data breach as soon as practically possible after confirmation, including the nature of the breach, the likely consequences, and the measures taken. BastionHub maintains an incident response plan and will cooperate with the Customer's regulatory notification obligations.
9. Data return and deletion on termination
Upon termination of the subscription, the Customer can export all data via the Compliance Center. After export, BastionHub deletes all Customer data within 30 days. Audit logs of the deletion are preserved for BastionHub's legal protection.
10. Audit rights
The Customer may audit BastionHub's compliance with this DPA once per calendar year with 30 days' written notice. Enterprise customers may request more frequent audits as defined in their contract. BastionHub provides compliance documentation including audit logs, encryption certificates, and access records.
11. International transfers
If Customer data is transferred outside the Customer's region, BastionHub ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism. EU residency is available for Enterprise customers to avoid cross-border transfers.
12. Contact
For DPA execution, audit requests, or data protection questions, contact BastionHub through the Contact page or by requesting a signed copy through the Owner Dashboard.
13. Execution and signature blocks
This DPA is effective as of the date of the last signature below. This DPA may be executed electronically and in counterparts, each of which is deemed an original and all of which together constitute one instrument.
| Customer (Data Controller) | BastionHub (Data Processor) |
|---|---|
Authorized signature: ____________________________ Printed name: ____________________________ Title: ____________________________ Organization: ____________________________ Date: ____________________________ Discord server ID: ____________________________ | Authorized signature: ____________________________ Printed name: ____________________________ Title: ____________________________ Organization: BastionHub Date: ____________________________ |
Appendix 1: Standard Contractual Clauses (SCCs)
For transfers of personal data from the EU/EEA or UK to the United States, the Standard Contractual Clauses as adopted by the European Commission under Implementing Decision (EU) 2021/914 apply. The following modules are activated:
- Module Two: Controller to Processor (applies when the Customer is a data controller transferring data to BastionHub as a data processor)
- Module Three: Processor to Processor (applies when the Customer is itself a processor transferring data to BastionHub as a sub-processor)
The following SCC options are selected:
- Clause 7 (docking clause): Not included
- Clause 9 (use of sub-processors): Option 2 (general written authorization) — BastionHub will notify the Customer of new sub-processors 30 days in advance
- Clause 11 (redress): The Customer will forward the list of sub-processors to data subjects where applicable
- Clause 17 (governing law): The law of Ireland applies
- Clause 18 (choice of forum): Disputes will be resolved before the courts of Ireland
- Clause 21 (local laws and practices): BastionHub has assessed that US local laws do not prevent it from fulfilling its obligations under the SCCs
For UK transfers, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, applies.
Appendix 2: Subprocessors
The current list of subprocessors is maintained on the Compliance page and includes:
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services | Cloud infrastructure and data storage — US-West-2 (Oregon) |
| Supabase | Managed PostgreSQL on AWS — US-West-2 (Oregon) |
| Discord Inc. | Source of Discord data via official API |
| Stripe | Payment processing for subscription billing |
| Have I Been Pwned | Breach intelligence provider for exposure monitoring |
| Vercel | Web application hosting and edge delivery |
BastionHub will update this list and notify the Customer at least 30 days before engaging a new subprocessor. The Customer may object by terminating the subscription within 30 days of the notification.
Appendix 3: Description of processing
Categories of personal data processed: Discord identifiers (user IDs, guild IDs, role IDs, channel IDs), server metadata (names, member counts, configuration), threat detection metadata (type, timestamp, action, severity), audit log entries (actor, action, timestamp, guild), exposure monitoring findings (breach name, date, severity, remediation), billing information (Stripe customer ID, subscription status), and authentication data (encrypted OAuth2 tokens, session cookies, TOTP secrets).
Sensitive data: BastionHub does not process special categories of personal data under GDPR Article 9 (health data, racial origin, political opinions, religious beliefs, sexual orientation, biometric data, or trade union membership).
Purposes of processing: Threat monitoring, policy enforcement, compliance and audit, exposure monitoring, billing and subscription management, security and abuse prevention, and service improvement using aggregate anonymized data only.
Frequency of processing: Continuous (real-time threat detection), periodic (exposure scans on demand), and as needed (compliance exports, audit log queries, billing events).
Nature of processing: Collection, recording, organization, storage, retrieval, consultation, use, disclosure by transmission, and erasure of personal data.
Retention period: As specified in Section 6 of this DPA and the Customer's plan tier (90 days for Basic, up to 7 years for Pro compliance archives, contract-defined for Enterprise).
Recipients: BastionHub personnel with authorized access, and the subprocessors listed in Appendix 2.