Data Processing Agreement: Blaze Bot
Last updated: 25 September 2026
This Data Processing Agreement ("DPA") is part of the Blaze Terms of Service. It applies automatically to everyone who uses Blaze Bot and does not need to be signed. It sets out the terms required by Article 28 of the EU General Data Protection Regulation (GDPR) for the personal data that Blaze processes on your behalf when you use Blaze Bot. Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA applies.
1. The parties
Who is responsible: Blaze. Contact: [email protected]
- Processor:the party named in the block above ("Blaze", "we").
- Controller:you, the person or organisation that has added Blaze Bot to a Discord server and administers it ("you").
Notices and requests under this DPA go to the address in the block above.
2. Subject matter and duration
Blaze processes personal data in order to provide Blaze Bot to you. The processing lasts for as long as you use Blaze Bot. After that it continues only until the data has been deleted as described in section 6(h).
3. Nature and purpose of the processing
The purpose is to answer support tickets in your Discord server. This means:
- receiving and storing ticket messages;
- generating replies with an AI provider and posting them in the ticket;
- handing tickets to your staff;
- keeping transcripts and statistics for your dashboard;
- if you install the connector on your game server, looking up game data there about the person who opened a ticket.
Feedback: partly covered, partly not. Blaze Bot asks the person who opened a ticket whether they got the help they needed (Privacy Policy, section 2). It asks after about one in four manual closes, and after every automatic close if you use auto-close. Apart from the one case described below, it asks the player — before storing anything — whether their feedback is about your server or about the assistant.
- About your server: covered by this DPA. It is your data. Blaze stores it for your Discord server alone, shows it to your staff in the dashboard, posts it to the Discord channel you chose if you chose one, and does nothing else with it. Blaze processes it on your behalf, on your instructions, deletes it when you tell us to, and deletes it in any case two years after it was given (section 6(h)). A player who answers an auto-close follow-up by saying they still need help is not asked the question — they need help, and the new ticket is opened straight away — and that answer is treated as feedback about your server.
- About the assistant: not covered. Blaze processes it as an independent controller, for its own purpose of improving the product, so it is not processed on your behalf. The record of which players were sent a feedback message after a manual close is kept for the same purpose.
The "Ask players for feedback" setting in Blaze Bot is on by default and covers both situations and both destinations. When it is off:
- no feedback message is sent after a manual close;
- answers to the auto-close question are not stored at all — neither for you nor for Blaze.
The auto-close question itself, and the new ticket it opens when a player says their problem was not solved, are part of the service Blaze provides to you under this DPA.
4. Types of personal data
- Discord user IDs, usernames, global display names and avatars;
- the content of messages in tickets;
- images attached to ticket messages. Blaze stores a link to the image, and on Blaze++ sends the image to the AI provider;
- records of ticket activity: who opened, claimed or closed a ticket, who replied, and when;
- what a player says when Blaze Bot asks them about your server: whether they got the help they needed, any comment they write, and which ticket it was about (section 3);
- if you use the connector:
- game data about the ticket opener from your own game server;
- the link between a Discord account and a game character's identifier;
- notes of which ticket openers Blaze has asked the connector about.
The lookups that come with the connector return the player's character name, job, gang, online status and last-seen time; their vehicles (plate, model, condition and location); and their cash, bank balance and items. Lookups you add or write yourself return whatever they are written to return.
5. Categories of data subjects
- members of your Discord server who open or take part in a ticket;
- your staff;
- if you use the connector: players on your game server whose Discord account the connector links to a game character. While the connector is running, this includes every player who loads into your game server with a Discord account connected to the game, whether or not they open a ticket.
6. Blaze's obligations
Blaze will:
(a) Instructions. Process the personal data only on your documented instructions, including with regard to transfers outside the EU/EEA, unless EU or member-state law requires otherwise. In that case Blaze will tell you first, unless that law forbids it. Your instructions are the Terms of Service, this DPA and the settings you choose in Blaze Bot. If Blaze believes an instruction breaks data protection law, Blaze will tell you.
(b) Confidentiality. Ensure that everyone Blaze authorises to process the personal data has committed to confidentiality or is under a statutory duty of confidentiality.
(c) Security. Apply the technical and organisational measures in Annex 2.
(d) Sub-processors. Use only the sub-processors listed in Annex 1, which you authorise by accepting this DPA.
- Notice. Before a new sub-processor starts processing your data, Blaze will email the billing address on your Blaze Bot subscription at least 30 days in advance. If you have no paid subscription, Blaze has no email address for you. In that case the notice is the change to Annex 1 on this page, which is dated and made at least 30 days in advance.
- Objection. You can object by writing to the address in section 1 before the change takes effect. If Blaze cannot meet your objection, you can terminate your use of Blaze Bot and have your data deleted under (h).
- Contracts. Blaze binds each sub-processor by contract to data protection obligations that meet Article 28, and remains responsible to you for its sub-processors.
(e) Data subject requests.Help you answer requests from people exercising their rights under the GDPR, in particular access and erasure. When you ask, Blaze will find, export or delete the data it holds about a given Discord user in your server. The one exception is Blaze's application logs. Deletion does not reach them; they expire on their own (Privacy Policy, section 6).
(f) Your other obligations. Help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation (GDPR Articles 32 to 36), taking into account the nature of the processing and the information available to Blaze.
(g) Personal data breaches. Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information Blaze has at that time, and more as it becomes available.
(h) End of processing. When you stop using Blaze Bot, delete your data under the retention rules in the Privacy Policy:
- Closed tickets are deleted once your plan's retention period has passed since they were closed.
- The feedback your players gave about your server (section 3) is deleted two years after it was given. The two years are the same on every plan.
- The activity statistics behind your dashboard are deleted two years after they were made.
- A person's entry in the cache of Discord profile names is deleted once no ticket or dashboard permission Blaze still keeps shows it, and they have not opened or written in a ticket for 90 days.
- Connector lookup records and notes are deleted after 30 days, and links between Discord accounts and game characters after 90 days without being seen, whether or not your connector still contacts Blaze.
- When Blaze Bot is removed from your Discord server:
- your server's open tickets are closed and then deleted under the same rule;
- the connector's links for your server are deleted;
- the dashboard permissions you gave staff and roles on your server are deleted.
This happens straight away if Blaze Bot is running, otherwise the next time it starts. One exception: if Blaze Bot appears to have been removed from an unusually large share of servers at the same time, it treats that as a fault on our side and changes nothing on that basis until Blaze has checked it by hand.
- If Blaze Bot stays removed from your Discord server for 12 months, Blaze deletes everything it processes for that server under this DPA, even where a longer period applies above. This does not happen if you add Blaze Bot back first, or while you still pay for a subscription for that server. If an unusually large number of servers falls due on the same day, Blaze checks them by hand before deleting. Payment records and feedback sent to Blaze are not processed under this DPA and follow the Privacy Policy, section 6.
- Each backup is deleted at the next successful daily backup once it is 14 days old.
The connector runs on your own game server, under your control. Removing Blaze Bot from Discord does not stop it. While it keeps running, it keeps sending links between Discord accounts and game characters to Blaze. To stop it, do one of these:
- remove it from your game server;
- beforeyou remove Blaze Bot, download the connector again on the Blaze dashboard's Connectors page (Blaze++), which creates a new key and cuts off the old one. The dashboard only lets you manage servers Blaze Bot is in, so after removal this option is gone;
- ask Blaze to disconnect it.
Knowledge base articles and your settings are kept until you delete them, ask Blaze to, or the 12 months above have passed.
If you ask, Blaze will delete all your data at once instead of waiting for the retention periods. Payment records that Danish bookkeeping law requires Blaze to keep are not part of this; they are deleted when the law's five years have passed. If you want a copy first, ask before deletion and Blaze will provide it in a machine-readable format. Application logs are not part of this; they expire on their own (Privacy Policy, section 6).
(i) Demonstrating compliance. Make available the information you need to show that the obligations in Article 28 GDPR are met. Blaze will also allow and contribute to audits, including inspections, by you or an auditor you mandate. An audit starts with written questions, which Blaze will answer. If the answers are not enough, an audit can follow on reasonable notice.
Annex 1: Sub-processors
| Sub-processor | What it does | Personal data it receives | Where | Safeguard for transfers outside the EU/EEA |
|---|---|---|---|---|
| Anthropic PBC | AI provider that writes Blaze Bot's replies | Ticket content, relevant knowledge-base content, images (Blaze++), connector lookup results | United States | Standard Contractual Clauses, in Anthropic's data processing addendum |
| Stripe | Payments | The Discord IDs of the server and of the person paying, and what that person enters at checkout. No ticket content or game data. | May be processed in the United States | EU–US Data Privacy Framework and Standard Contractual Clauses, in Stripe's data processing agreement |
| Hetzner Online GmbH | Hosting of the server that runs Blaze Bot, its database and its backups | Everything Blaze Bot stores | Falkenstein, Germany | Not needed (EU) |
| Cloudflare, Inc. | Network and security for Blaze's websites and API | All traffic to Blaze's websites and API, including the dashboard and the connector's lookup results. Cloudflare decrypts it in order to forward it. | Worldwide network; may be processed in the United States | EU–US Data Privacy Framework and Standard Contractual Clauses, in Cloudflare's data processing addendum |
Annex 2: Technical and organisational measures
Blaze Bot applies these measures:
- Mirrored disks. Blaze Bot runs on one server with two disks mirrored in RAID1. If one disk fails, no data is lost.
- Daily backups on the server. The database is backed up once a day to the same server. When each backup is made, Blaze checks that the file can be read as a backup archive, and a failed backup alerts Blaze. Each backup is deleted at the next successful daily backup once it is 14 days old. Restoring a full backup into a separate database has been tested.
- Encryption in transit.All traffic to Blaze's websites and API (blaze-bot.net, blaze-hq.net), including the connector's traffic, is encrypted with TLS. This covers the path from the user or game server to Cloudflare, and from Cloudflare to our server (Caddy, with a Let's Encrypt certificate). Plain HTTP is redirected to HTTPS. Blaze's own connections to Discord, Anthropic and Stripe use HTTPS.
- Separation between customers.Customer data is stored per Discord server, and the application's queries for customer data filter on that server's ID. The one exception is the cache of Discord profile names, which is shared between servers. It holds only public Discord profile data (username, global display name and avatar), which is the same on every server, and never a nickname someone uses on a particular server.
- Automatic deletion. Closed tickets are deleted according to your plan, and everything else after the periods in the Privacy Policy, section 6. A process looks for what has expired every day. Connector lookup results are deleted from the database as soon as they have been read. If that fails, an hourly clean-up deletes them once they are more than an hour old; it runs while your connector is connected to Blaze. The 30-day and 90-day deletions of connector records and links run every day either way.
- Database not reachable from the internet. The Blaze Bot database accepts connections only from the server itself.
What Blaze does not offer. The database is not encrypted on disk. There is no backup outside the server. The backups are on the same server as the database, so if the whole server is lost or compromised, the backups are lost with it.