1. Definitions
Controller — the operator of the PulseBot#8131 application.
Bot — the PulseBot#8131 account (ID: 1474835666603999354) on Discord.
Website — the website and dashboard available at https://pulsebot.pl.
Discord — the application and service operated by Discord Inc.
User — any person using the Bot or Website.
2. Contact
Privacy requests and data-rights enquiries may be sent to dobrastronastudio@gmail.com. The Discord support server at https://dc.pulsebot.pl is an additional support channel.
3. Data processed by the Website
After login through Discord OAuth2, the Website may process:
- Discord ID, username, display name and avatar URL
- the list of Discord servers, their IDs, names, icons and the User's permissions
- session information, preferred language, CSRF token and required cookie data
- the last dashboard activity time
- an audit log of configuration and dashboard security operations
Session data is removed after logout or session expiry. The server-list cache is short-lived. Other dashboard account data may be removed after the User stops using the Website unless it is still needed for security, billing or legal claims.
4. Data processed by the Bot
The Bot processes data needed for selected modules, including user, server, channel, role and message IDs, nicknames, avatars, membership information and module configuration.
Depending on server settings, this may also include Automoderation warnings and violations, tickets, forms, suggestions, self roles, levels, economy records, giveaways, automatic messages, administration logs and activity aggregates.
The legal basis is performance of the Service or the Controller's legitimate interest in operating, securing and diagnosing the Bot. Data is retained only for as long as required by the relevant feature, server configuration, security needs or applicable law.
5. Support contact
When a User contacts support by email or Discord, the Controller processes Discord account details and the information included in the message. The data is used to handle the request, protect the Service and manage possible claims. It is generally kept for no more than 24 months after the matter is closed unless earlier deletion is possible or law requires a longer period.
6. Premium and payments
For Premium purchases, PulseBot processes the purchaser's Discord ID, server ID and name, Stripe customer, Checkout Session and subscription identifiers, subscription status, trial and billing dates, and the version of accepted legal documents.
Stripe may process email, IP address, billing details and payment-method data under its own privacy policy. PulseBot does not receive or store complete card numbers.
7. Other technical data
The Controller may process server settings, error logs, shard information, latency, event IDs and other technical data required to operate the Service, prevent abuse and diagnose failures.
Technical information is not automatically anonymous. Discord identifiers may be personal data when they can be linked to a particular person.
8. Data recipients
Data may be shared only with parties needed to operate the Service: Discord Inc.; Stripe and its payment providers; SkyPass Solutions Sp. z o.o.; technical service providers; and authorities entitled by law. Each recipient receives only the data needed for its role.
9. Cookies
The Website uses required cookies for login, security, language preferences and session handling. They are stored without separate consent because they are necessary for the Website to work.
Functional or analytics cookies — if introduced — will be stored only after consent where the law requires it.
10. User rights
Each User has the following rights to the extent provided by the GDPR and depending on the legal basis and manner of processing:
- the right of access to personal data (Article 15 GDPR)
- the right to rectification of personal data (Article 16 GDPR)
- the right to request erasure of personal data (Article 17 GDPR)
- the right to request restriction of processing (Article 18 GDPR)
- the right to data portability where the conditions of Article 20 GDPR apply
- the right to object to processing based on the Controller's legitimate interests (Article 21 GDPR)
- the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR)
- the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO)
Requests should be sent to dobrastronastudio@gmail.com. The Controller may request only the information necessary to confirm the User's identity and locate the relevant records.
11. Changes to this Privacy Policy
This Policy may be updated when features, providers, laws or Discord rules change. The current version is published on the Website.
