#GDPR Compliance

1 messages · Page 1 of 1 (latest)

chilly dome
#

Does the NQN bot and website comply with the GDPR?

#

any mention of it is completely absent from the terms of service and privacy policy

loud ivy
#

You can export all your data by dming the bot the !gdpr command

#

But yes, it does

#

@chilly dome was there anything in particular you were interested in?

chilly dome
#

Concerning "On the Discord platform"
* Is any of the information collected shared with third parties?
* For how long is log data stored?

Concerning "The nqn.blue website only"
* Why does the website have no prompt requesting consent from the user to store analytics data? The same prompt should also detail exactly what information is collected, how it is used in a simple human readable format, and the ability to accept or refuse consent for each purpose.
* I see calls to the reddit and twitter APIs being made, why is this the case? Why is there no option to either consent or refuse consent to these third parties?
* Other than analytics data, do you collect anything else, and is anything shared with third parties?
* Do you honor requests from European data subjects for a copy of the data you store? Do you also honor requests for deletion?

loud ivy
#

Concerning "On the Discord platform"

  • Is any of the information collected shared with third parties?
    No
  • For how long is log data stored?
    Between a few hours and 2 months
    Concerning "The nqn.blue website only"
  • Why does the website have no prompt requesting consent from the user to store analytics data? The same prompt should also detail exactly what information is collected, how it is used in a simple human readable format, and the ability to accept or refuse consent for each purpose.
    Good point, looking into it. I got rid of it a while back when I removed ads but forgot you still need it for analytics stuff
  • I see calls to the reddit and twitter APIs being made, why is this the case? Why is there no option to either consent or refuse consent to these third parties?
    Where can you see this? It should not call reddit/twitter.
  • Other than analytics data, do you collect anything else, and is anything shared with third parties?
    Anything that you do that interacts with the bot at all gets stored with the bot's data. Aside from google analytics, there is nothing shared to third parties from the website. Aggregate information on things like bot size is shared to bot lists like top.gg, but that's not relevant.
  • Do you honor requests from European data subjects for a copy of the data you store? Do you also honor requests for deletion?
    Yes. Though I store no identifiable data on the website, so I cannot share/delete it.