Polityka prywatności
Ten dokument opisuje, jakie dane zbiera bot i panel Startly, w jakim celu, na jakiej podstawie prawnej i jak długo je przechowujemy. Napisaliśmy go tak, żeby dało się go przeczytać bez prawnika - bez zdań na pół strony i bez ukrywania rzeczy w przypisach.
1. Kto odpowiada za Twoje dane
Administratorem danych osobowych jest Levora Group. W sprawach dotyczących danych osobowych napiszesz do nas nadata@startlybot.info.
Startly działa jako bot na Discordzie oraz panel webowy dostępny po zalogowaniu kontem Discord. Ta polityka obejmuje oba te elementy i tę stronę internetową.
2. Jakie dane zbieramy
Dane z Twojego konta Discord
Kiedy logujesz się do panelu, Discord przekazuje nam identyfikator konta, nazwę użytkownika, awatar oraz listę serwerów, na których masz uprawnienia administracyjne. Nie prosimy o dostęp do Twojej skrzynki e-mail ani do wiadomości prywatnych i nie mamy do nich wglądu.
Dane serwerów
Dla każdego serwera, na którym działa bot, przechowujemy identyfikator serwera oraz ustawienia, które w nim zapisałeś - konfigurację kanałów, ról, ticketów, poziomów i modułów moderacji. To dane niezbędne do tego, żeby bot w ogóle mógł robić to, do czego go dodałeś.
Dane operacyjne
Zapisujemy logi zdarzeń wykonanych przez bota i zmian dokonanych w panelu - kto i kiedy zmienił konfigurację. Służy to diagnostyce awarii i wyjaśnianiu sytuacji spornych na serwerze.
Dane techniczne
Nasz serwer zapisuje standardowe informacje o połączeniu: adres IP, typ przeglądarki i czas żądania. Są to dane zbierane automatycznie przez infrastrukturę i wykorzystujemy je do zapewnienia bezpieczeństwa oraz wykrywania nadużyć.
Czego nie zbieramy
Nie czytamy i nie przechowujemy treści wiadomości z Twojego serwera poza tym, co jest niezbędne do działania włączonych przez Ciebie funkcji. Nie sprzedajemy danych. Nie budujemy profili reklamowych i nie korzystamy z zewnętrznych sieci śledzących.
3. Po co nam te dane i na jakiej podstawie
Dane z konta Discord i konfigurację serwerów przetwarzamy, żeby wykonać umowę o świadczenie usługi - bez nich panel nie ma czego wyświetlić, a bot nie wie, jak ma się zachować (art. 6 ust. 1 lit. b RODO).
Logi operacyjne i dane techniczne przetwarzamy w naszym prawnie uzasadnionym interesie, czyli po to, żeby utrzymać usługę w działaniu, reagować na awarie i bronić się przed nadużyciami (art. 6 ust. 1 lit. f RODO).
Jeśli kiedykolwiek poprosimy Cię o zgodę na coś wykraczającego poza powyższe, będzie to osobne, wyraźne pytanie, a odmowa nie odbierze Ci dostępu do podstawowych funkcji (art. 6 ust. 1 lit. a RODO).
4. Discord jako źródło danych
Startly działa wewnątrz Discorda i korzysta z jego API. Oznacza to, że część danych trafia do nas od Discorda, a Twoje korzystanie z samego Discorda podlegapolityce prywatności Discorda. Nie mamy wpływu na to, jakie dane zbiera Discord ani jak długo je przechowuje.
Zakres uprawnień, które nadajesz botowi przy dodawaniu go na serwer, widzisz w oknie autoryzacji Discorda i możesz je w każdej chwili ograniczyć lub cofnąć w ustawieniach serwera.
5. Pamięć przeglądarki i pliki cookie
Ta strona nie używa plików cookie do śledzenia ani do reklam. Zapisuje natomiast dwie drobne rzeczy w pamięci lokalnej Twojej przeglądarki (localStorage):
theme- czy wybrałeś motyw ciemny czy jasnylang- czy oglądasz stronę po polsku czy po angielsku
Obie wartości zostają na Twoim urządzeniu i nigdy nie są wysyłane na nasz serwer. Wyczyszczenie danych witryny w przeglądarce usuwa je bezpowrotnie i niczego przy tym nie tracisz poza swoim wyborem motywu.
Panel po zalogowaniu korzysta dodatkowo z pliku cookie sesji, który utrzymuje Cię zalogowanym. Jest on niezbędny do działania panelu i wygasa po wylogowaniu lub po upływie czasu sesji.
6. Jak długo trzymamy dane
Konfigurację serwera przechowujemy tak długo, jak bot pozostaje na tym serwerze. Po usunięciu bota dane konfiguracyjne kasujemy w ciągu30 dni - okres karencji istnieje po to, żeby przypadkowe wyrzucenie bota nie kasowało od razu całej Twojej pracy.
Logi operacyjne i techniczne przechowujemy przez90 dni, po czym są automatycznie usuwane.
Dane konta w panelu usuwamy po rozwiązaniu umowy lub na Twoje żądanie, z zastrzeżeniem okresów wymaganych przepisami - na przykład dane rozliczeniowe musimy przechowywać przez czas wskazany w przepisach podatkowych.
7. Komu przekazujemy dane
Nie sprzedajemy danych i nie udostępniamy ich do celów marketingowych. Korzystamy natomiast z dostawców, bez których usługa nie mogłaby działać:
- SkyPass Solutions Sp. z o.o. - Firma udosępniająca usługi hostingowe
- Discord Inc. - platforma, w ramach której działa bot
- Stripe - obsługa płatności za plany płatne
Dane możemy też przekazać uprawnionym organom, jeśli obowiązek taki wynika z przepisów prawa.
Część dostawców może przetwarzać dane poza Europejskim Obszarem Gospodarczym. W takim wypadku przekazanie odbywa się na podstawie standardowych klauzul umownych zatwierdzonych przez Komisję Europejską.
8. Twoje prawa
W odniesieniu do swoich danych masz prawo do:
- Dostępu - możesz zapytać, jakie dane o Tobie mamy, i dostać ich kopię
- Sprostowania - jeśli coś jest nieaktualne albo błędne, poprawimy to
- Usunięcia - możesz zażądać skasowania danych, o ile nie musimy ich trzymać z mocy przepisów
- Ograniczenia przetwarzania - możesz kazać nam wstrzymać przetwarzanie, zamiast od razu kasować dane
- Przenoszenia - wydamy Ci Twoje dane w formacie nadającym się do odczytu maszynowego
- Sprzeciwu - możesz się sprzeciwić przetwarzaniu opartemu na naszym prawnie uzasadnionym interesie
- Wycofania zgody - w każdej chwili i bez podania powodu, jeśli o zgodę prosiliśmy; nie wpływa to na to, co zdarzyło się wcześniej
Żeby skorzystać z któregokolwiek z tych praw, napisz nalegal@startlybot.info. Odpowiadamy najpóźniej w ciągu miesiąca od otrzymania zgłoszenia.
Przysługuje Ci również prawo wniesienia skargi do Prezesa Urzędu Ochrony Danych Osobowych, jeśli uznasz, że przetwarzamy Twoje dane niezgodnie z prawem.
9. Bezpieczeństwo
Połączenia z panelem są szyfrowane (HTTPS), a dostęp do bazy danych mają wyłącznie osoby, którym jest to niezbędne do utrzymania usługi. Tokeny dostępu do Discorda przechowujemy w formie zaszyfrowanej.
Żaden system nie jest w stu procentach odporny na incydenty. Jeśli dojdzie do naruszenia ochrony danych, które może wiązać się z wysokim ryzykiem dla Twoich praw, poinformujemy Cię o tym i zgłosimy sprawę organowi nadzorczemu w terminie wynikającym z przepisów.
10. Wiek użytkowników
Startly działa na Discordzie, którego regulamin wymaga ukończenia 13 lat, a w niektórych krajach więcej. Nie kierujemy usługi do osób poniżej tego wieku i świadomie nie zbieramy ich danych. Jeśli dowiemy się, że takie dane trafiły do nas przez pomyłkę, usuniemy je.
11. Zmiany w tej polityce
Możemy aktualizować ten dokument - na przykład gdy dojdzie nowa funkcja albo zmieni się dostawca. Datę ostatniej zmiany znajdziesz na górze strony. O istotnych zmianach poinformujemy z wyprzedzeniem na naszym serwerze Discord lub w panelu.
12. Kontakt
Masz pytanie, na które ten dokument nie odpowiada? Napisz nalegal@startlybot.info albo odezwij się na naszym serwerze Discord. Odpisujemy.
Privacy policy
This document explains what data the Startly bot and panel collect, why, on what legal basis and how long we keep it. We wrote it so you can read it without a lawyer - no half-page sentences, nothing hidden in footnotes.
1. Who is responsible for your data
The data controller is Levora Group. For anything concerning personal data, write to us at data@startlybot.info.
Startly is a Discord bot plus a web panel you reach by signing in with your Discord account. This policy covers both of those and this website.
2. What data we collect
From your Discord account
When you sign in to the panel, Discord passes us your account ID, username, avatar and the list of servers where you hold administrative permissions. We do not request access to your email inbox or to your direct messages, and we cannot see them.
Server data
For every server the bot runs on we store the server ID and the settings you saved there - the configuration of channels, roles, tickets, levels and moderation modules. This is the data the bot needs in order to do the thing you added it for.
Operational data
We record logs of actions performed by the bot and of changes made in the panel - who changed the configuration and when. This serves fault diagnosis and settling disputes on your server.
Technical data
Our server records standard connection information: IP address, browser type and request time. This is collected automatically by the infrastructure and we use it to keep the service secure and to detect abuse.
What we do not collect
We do not read or store the content of messages on your server beyond what the features you switched on require. We do not sell data. We do not build advertising profiles and we use no third-party tracking networks.
3. Why we need this data and on what basis
We process Discord account data and server configuration in order to perform our service agreement - without them the panel has nothing to show and the bot does not know how to behave (Art. 6(1)(b) GDPR).
We process operational logs and technical data on the basis of our legitimate interest, namely keeping the service running, responding to failures and defending against abuse (Art. 6(1)(f) GDPR).
If we ever ask for your consent to anything beyond the above, it will be a separate, explicit question, and refusing will not take away access to the core features (Art. 6(1)(a) GDPR).
4. Discord as a source of data
Startly operates inside Discord and uses its API. That means part of the data reaches us from Discord, and your use of Discord itself is governed by Discord's privacy policy. We have no influence over what data Discord collects or how long it keeps it.
The permissions you grant the bot when adding it to a server are shown in Discord's authorisation window, and you can narrow or revoke them at any time in your server settings.
5. Browser storage and cookies
This site uses no cookies for tracking or advertising. It does save two small things in your browser's local storage (localStorage):
theme- whether you picked the dark or light themelang- whether you are reading the site in Polish or English
Both values stay on your device and are never sent to our server. Clearing site data in your browser removes them for good, and you lose nothing but your theme preference.
Once you sign in, the panel additionally uses a session cookie that keeps you logged in. It is essential for the panel to work and expires when you log out or when the session times out.
6. How long we keep data
We keep server configuration for as long as the bot stays on that server. After the bot is removed we delete configuration data within 30 days - the grace period exists so that kicking the bot by accident does not wipe all your work straight away.
Operational and technical logs are kept for 90 days and then deleted automatically.
Panel account data is deleted when the agreement ends or at your request, subject to retention periods required by law - billing records, for example, must be kept for the period set out in tax regulations.
7. Who we share data with
We do not sell data and we do not share it for marketing purposes. We do rely on providers without which the service could not run:
- SkyPass Solutions Sp. z o.o. - hosting provider
- Discord Inc. - the platform the bot operates on
- Stripe - payment processing for paid plans
We may also hand data to authorised public bodies where the law obliges us to do so.
Some providers may process data outside the European Economic Area. Where that happens, the transfer is based on standard contractual clauses approved by the European Commission.
8. Your rights
In relation to your data you have the right to:
- Access - ask what data we hold about you and get a copy of it
- Rectification - if something is out of date or wrong, we will correct it
- Erasure - request deletion, unless the law requires us to keep it
- Restriction - tell us to pause processing instead of deleting the data outright
- Portability - receive your data in a machine-readable format
- Objection - object to processing based on our legitimate interest
- Withdrawing consent - at any time and without giving a reason, where we asked for consent; this does not affect what happened beforehand
To exercise any of these rights, write to legal@startlybot.info. We reply within one month of receiving your request at the latest.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Poland) if you believe we process your data unlawfully.
9. Security
Connections to the panel are encrypted (HTTPS), and database access is limited to the people who need it to keep the service running. Discord access tokens are stored encrypted.
No system is a hundred per cent immune to incidents. If a data breach occurs that may carry a high risk to your rights, we will tell you about it and report the matter to the supervisory authority within the period the law requires.
10. Age of users
Startly runs on Discord, whose terms require users to be at least 13, and older in some countries. We do not aim the service at anyone below that age and we do not knowingly collect their data. If we learn that such data reached us by mistake, we will delete it.
11. Changes to this policy
We may update this document - when a new feature ships, for instance, or when a provider changes. You will find the date of the last change at the top of the page. We announce significant changes in advance on our Discord server or in the panel.
12. Contact
Got a question this document does not answer? Write to legal@startlybot.info or reach out on our Discord server. We do reply.