Data Processors & Partners

At Discordium.org, we only collaborate with trusted and compliant partners who meet the highest standards for data protection, encryption, and transparency.

Every processor listed below follows GDPR, UK-GDPR, and CCPA/CPRA frameworks, and has signed a Data Processing Agreement (DPA) with us.

Hosting & Security

Cloudflare, Inc.

  • Purpose: Hosting, CDN, DNS, WAF, TLS encryption, rate-limiting, and bot protection.
  • Data: IPs, request metadata, headers, and logs.
  • Compliance: GDPR (SCCs), ISO 27001, PCI-DSS.

Cloudflare protects Discordium.org against DDoS attacks and improves site speed and availability.

Identity & Integrations

Discord Inc. (OAuth & API)

  • Purpose: User authentication, bot verification, and Discord integration.
  • Data: Discord ID, username, avatar, guild metadata. No access to private messages.
  • Compliance: GDPR, SCCs.

CFX.re / FiveM API

  • Purpose: Public server data and listings for FiveM communities.
  • Data: Server name, slots, IP, online players (public). No personal data collected.

Mojang / Microsoft (Minecraft Query)

  • Purpose: Displaying public Minecraft server status (MOTD, players, version).
  • Data: Public server information only.

Payments & Billing

Stripe Payments Europe Ltd.

  • Purpose: Secure payment processing for Premium & Ads.
  • Data: Tokenized billing data (no card storage).
  • Compliance: PCI-DSS Level 1, GDPR, SCCs.

Stripe ensures safe transactions while Discordium.org never stores full payment details.

Reviews & Feedback

Trustpilot A/S

  • Purpose: Collecting and displaying verified user reviews.
  • Data: Name, Trustpilot profile, review content (voluntary).
  • Compliance: GDPR & EU-based infrastructure.

Analytics & Performance

Google Analytics (Consent Mode v2)

  • Purpose: Aggregated usage statistics (only after consent).
  • Data: Pseudonymized events, truncated IPs.
  • Compliance: GDPR, SCCs.

Cloudflare Web Analytics

  • Purpose: Privacy-friendly website analytics without cookies.
  • Data: Anonymous performance data only.

E-commerce (Merch)

Shopify Inc.

  • Purpose: Merch store, checkout, and shipping operations.
  • Data: Order info, shipping address, email.
  • Compliance: GDPR & PIPEDA.

Communication & Support

Thunderbird (Email Client)

  • Purpose: Handling support messages securely on local systems.
  • Data: Email content processed locally only.

Acts as an internal tool, not an external processor.

Mailjet / Brevo (Sendinblue)

  • Purpose: Sending transactional emails and notifications.
  • Data: Email address, timestamps, delivery status.
  • Compliance: GDPR, EU based.

APIs & Integrations

Discordium Public API

  • Purpose: Provides public server and bot listing data.
  • Data: public metadata only, no personal info.
  • Compliance: Rate-limited, WAF-protected, optional API keys.

Discord API / FiveM API / Minecraft Query

  • Purpose: Fetching verified public data for listings.
  • Data: Non-personal metadata only.

All APIs only expose public information, never private user data.

Retention & Security

All processors have signed DPAs and comply with SCCs for international transfers. We review partner compliance at least once per year.

  • Logs stored short-term for security monitoring
  • Billing data retained per legal requirements
  • API keys can be revoked anytime
  • All partners maintain encryption in transit and at rest

For how this data is used and which rights you hold over it, see the Privacy Policy.

Last Updated: November 3, 2025