Privacy policy
Last updated: September 2026
This English version is provided for convenience only. Only the German version is legally binding.
This policy applies to the Kryst website and to the Discord bot “Kryst”. It explains which personal data we process, for what purpose and for how long.
1. Controller
Stefan Rohrbach, DMNT Studio
c/o Online-Impressum 10950, Europaring 90, 53757 Sankt Augustin, Germany
Email: dmnt-studio@mail.online-impressum.de
No data protection officer has been appointed because there is no legal obligation to do so.
2. Website
Server log files
When you visit the website, the web server automatically stores:
- IP address of the requesting device
- date and time of access
- page requested, status code and amount of data transferred
- browser identifier (user agent) and, if transmitted, the previously visited page
The purpose is the secure and stable operation of the website, for example to detect attacks and errors. The legal basis is Art. 6(1)(f) GDPR. Log files are deleted after 14 days unless a specific incident needs to be investigated for longer.
Cookies and third-party services
The website does not set cookies, does not use tracking and does not load content from third-party servers (such as fonts or analytics services).
If you switch on the sound on the home page or choose a language via the flag in the top right corner, your browser stores this setting locally (local storage) so that it is kept for your next visit. The setting is not transmitted to us and can be changed or deleted at any time via the switch, the language menu or your browser settings. The legal basis is Section 25(2) No. 2 TDDDG, because storing it is necessary for the function you requested.
Encryption
The connection is encrypted with TLS. The certificate is issued by Let's Encrypt. No visitor data is transmitted to Let's Encrypt in the process.
3. Discord bot “Kryst”
Roles
Whoever uses Kryst on their Discord server (server operator) decides what the bot is used for there. The server operator is the controller within the meaning of the GDPR for the data of that server's members. DMNT Studio processes this data as a processor under Art. 28 GDPR on the basis of a data processing agreement, which is concluded during setup with /setup. Members with questions about their data should therefore first contact the respective server operator.
DMNT Studio is the controller for the data of the server operators themselves (setup, contract, records).
Which data the bot processes
- Server settings: ID of the Discord server, IDs of channels and roles, selected settings and booked modules.
- User IDs: the Discord ID of people who use a bot command or trigger a function, where the function requires it.
- Record log: confirmations during setup (e.g. acceptance of the data processing agreement and its version, confirmation that members have been informed), changes to channels and modules, termination and deletion. The Discord ID of the acting person, the server and the time are stored.
- Error logs: technical details about bot actions. People appear in them only as a Discord ID.
The bot does not read or store message content.
Purposes and legal bases
- Providing the bot and its functions to the server operator: Art. 6(1)(b) GDPR (contract); for member data on behalf of the server operator.
- Record log: Art. 6(1)(c) GDPR (accountability under Art. 5(2) and Art. 28 GDPR) and Art. 6(1)(f) GDPR (evidence towards authorities and in disputes).
- Error logs: Art. 6(1)(f) GDPR (secure, error-free operation).
Storage period
- Server settings: until the bot is removed from the server or the contract ends, then deleted within 30 days.
- Record log: for the duration of the contract and three years thereafter (regular limitation period under Section 195 BGB).
- Error logs: no more than 30 days.
- Backups: 14 days, then overwritten.
Discord
The bot works through the Discord platform. All data therefore also passes through Discord. For users in the European Economic Area this is Discord Netherlands BV, Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands. Discord also processes data in the USA. According to its own statements, Discord participates in the EU-U.S. Data Privacy Framework. Which data Discord itself processes is described in Discord's privacy policy.
4. Hosting
The website, bot and database run on a server of Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany. The data centre is located in the European Union (Lauterbourg, France) and is operated by Contabo France SAS. A data processing agreement under Art. 28 GDPR has been concluded with Contabo.
5. Contact by email or Discord
If you write to us by email or in the support channel, we process your details to answer your request. The legal basis is Art. 6(1)(b) GDPR where a contract is concerned, otherwise Art. 6(1)(f) GDPR. We delete the request once it has been dealt with and no retention obligation applies.
6. Your rights
You have the right to
- access your stored data (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
An informal message to the email address above is sufficient. You can also lodge a complaint with a data protection supervisory authority, for example the one responsible for us: Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, www.baden-wuerttemberg.datenschutz.de.
7. Changes
If new functions are added, such as paid tiers or the news module, we will update this policy beforehand. The version published here applies.