Data Processing Agreement
This Data Processing Agreement defines the core GDPR/KVKK responsibilities that apply where TORVIX processes personal data on the instructions of a Discord server administrator.
1. Parties and roles
The person or organization that manages the Discord server and configures TORVIX features is the 'Controller'; TORVIX is the 'Processor' to the extent it processes server data under that configuration.
TORVIX acts as an independent data controller for its own account security, payment records, fraud prevention, service health, and legal-compliance activities.
2. Subject matter and duration
Processing is carried out to provide ticket, transcript, moderation, automation, analytics, and backup features while the bot remains installed, the dashboard account is used, and configured retention periods continue.
3. Data subjects and categories of data
- Discord server members, ticket participants, server administrators, and moderators.
- Discord user/server/channel/role identifiers, username, avatar, and permission information.
- Ticket messages, form answers, attachment metadata, transcripts, and moderation records.
- Server configuration, automation rules, usage records, and security records.
4. Controller instructions
The controller's dashboard configuration, selected channels, access roles, and retention periods are treated as written instructions. Except where required by law or urgent security needs, TORVIX does not process data outside the purpose of those instructions.
5. Confidentiality and security
TORVIX restricts access to personal data to authorized persons and applies appropriate technical and organizational measures. Security measures are described in the Security Policy.
6. Sub-processors
Discord, hosting/VPS, security/CDN, backup, and email services may be used to provide the service. Payment providers such as PayNow.gg, PayTR, or Shopier generally act as independent controllers for payment data.
TORVIX seeks to ensure that sub-processors process data only for service purposes and are subject to appropriate confidentiality and security duties. Material changes to sub-processors may be announced through a policy update.
7. Data-subject requests
The controller is primarily responsible for answering data-subject requests. To the extent technically possible, TORVIX assists with access, deletion, correction, export, and restriction requests.
8. Breach notification
When TORVIX becomes aware of a verified personal-data breach affecting server data, it informs the controller without undue delay and provides available information about the nature of the incident, likely effects, and measures taken.
9. Deletion, return, and end of service
When the bot is removed or the service ends, data is deleted or anonymized according to configured retention periods, subject to legal obligations, security records, active disputes, and backup cycles.
10. Audit and contact
Reasonable information requests about processing, security, or sub-processors may be sent to destek@torvixbot.xyz. Necessary information will be provided while protecting trade secrets and the security of other users.