Kryst
EN

Data processing agreement

pursuant to Art. 28 GDPR · Version 1.0 · Last updated: September 2026

This English version is provided for convenience only. Only the German version is legally binding.

§ 1 Parties and conclusion

The controller (“client”) is whoever sets up Kryst on a Discord server and confirms this agreement during setup with /setup (server operator).

The processor (“contractor”) is Stefan Rohrbach, DMNT Studio, c/o Online-Impressum 10950, Europaring 90, 53757 Sankt Augustin, Germany, email: dmnt-studio@mail.online-impressum.de.

The agreement is concluded by confirmation during /setup (electronic form under Art. 28(9) GDPR). For this purpose, the contractor stores in the record log the Discord ID of the confirming person, the server ID, the time and the agreement version.

§ 2 Subject matter, nature and purpose

The contractor operates Kryst for the client's Discord server and processes personal data of the server members solely to provide the functions activated by the client (e.g. event management, voice channel menu, welcome messages).

Types of data

Message content is not processed. Should this change (e.g. news module), this agreement will first be amended in a new version and confirmed again.

Data subjects

Members and visitors of the client's Discord server.

Duration

The agreement applies for as long as Kryst is used on the client's server. It ends automatically when the bot is removed from the server or the client terminates it.

§ 3 Instructions

The contractor processes the data only on documented instructions from the client. Instructions are this agreement, the settings the client makes in the bot, and messages to the email address above. If the contractor considers an instruction to be unlawful, it informs the client without delay. Processing outside the instructions takes place only where required by EU or German law; the contractor informs the client beforehand where permitted.

§ 4 Confidentiality

Only the contractor has access to the data. Should the contractor engage other persons in future, it will first commit them to confidentiality in writing.

§ 5 Security of processing

The contractor takes the technical and organisational measures under Art. 32 GDPR described in Annex 1. It may develop them further as long as the level of protection does not decrease.

§ 6 Sub-processors

The client consents to the use of the sub-processors listed in Annex 2. The contractor announces new or replacement sub-processors at least 14 days in advance on this page and in the support channel. The client may object within this period; if no agreement is reached, the client may terminate the agreement with immediate effect. The contractor contractually binds sub-processors to the same data protection obligations.

Discord is not a sub-processor of the contractor. The client operates its server on Discord itself and has its own contractual relationship with Discord for this purpose.

§ 7 Assistance to the client

The contractor assists the client to a reasonable extent

If the contractor receives a request directly from a data subject, it forwards it to the client.

§ 8 Personal data breaches

If the contractor becomes aware of a personal data breach, it informs the client without delay, and no later than within 48 hours, via the channel specified by the client during /setup or by Discord direct message to the person who confirmed the agreement. The notification contains, as far as known, the nature of the breach, the data concerned, likely consequences and the measures taken.

§ 9 Deletion after termination

After the end of the agreement, the contractor deletes all data processed on behalf of the client within 30 days. Backups are overwritten in the regular 14-day cycle. On request, the contractor provides the client with a copy of the server settings before deletion. The record log under § 1 is retained because the contractor uses it to fulfil its own accountability obligations (three years after the end of the agreement).

§ 10 Evidence and audits

On request, the contractor provides the client with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. On-site audits are possible with reasonable notice; given the small scale of the service, they are primarily carried out in writing.

§ 11 Liability and final provisions

Liability is governed by Art. 82 GDPR. German law applies. Should any provision be invalid, the remainder of the agreement remains valid. Changes to this agreement receive a new version number and are confirmed again by the client in the bot.

Annex 1 – Technical and organisational measures

Annex 2 – Sub-processors