GDPR Commitment
How AEGIS protects EU citizens' personal data and complies with the General Data Protection Regulation.
1. Our Role: Controller vs. Processor
Under the GDPR framework, roles are distinctly defined:
Data Controller
For billing information, account creation on our dashboard, and direct communications, AEGIS acts as the Data Controller.
Data Processor
When AEGIS operates within your Discord server scanning messages, events, and user activities to detect anomalies, AEGIS acts as the Data Processor. You (the Server Owner) are the Data Controller.
2. What Discord Data Do We Store in Our Database?
To provide our AI-driven security features, we process Discord events in real-time. However, we practice strict Data Minimization. Our database specifically stores:
- Message Content We DO NOT store the contents of standard text messages persistently in our database. Messages are held in ephemeral RAM for < 50ms to be scored by our AI models and are then immediately flushed.
- Persistent Metadata We store minimal metadata (Discord User IDs, timestamps, action frequencies) in our database to build behavioral baselines. This data is pseudonymized and stored securely via SQLite/PostgreSQL.
- Server Snapshots & Logs Administrative actions (e.g., who deleted a channel) and server structural snapshots (Channel IDs, Role configurations) are logged securely in our database to power the Auto-Recovery and Dashboard features.
3. Your Rights Under GDPR
If you are an EU resident, you possess the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request that we correct any inaccurate data.
Request that we delete your data. Note: If you are a Discord user requesting erasure of logs generated on a server using AEGIS, we facilitate this via our automated /gdpr forget command.
Ask us to pause processing your data.
Request your data in a JSON format.
4. Data Residency & Sub-processors
AEGIS utilizes an Anycast network. However, for communities specifically configured as "EU-Only" in our Enterprise plan, all persistent data (logs, backups, AI baselines) is strictly stored in our Frankfurt (AWS eu-central-1) data centers.
We use the following critical sub-processors:
5. Technical Security Measures
- Encryption at Rest All databases are encrypted using AES-256.
- Encryption in Transit All communications between Discord, our Edge nodes, and our Core Engine occur over TLS 1.3.
- Access Controls No human employee has access to raw server logs or behavioral baselines without explicit authorization and multi-factor authentication (MFA).
Data Protection Officer
To exercise your GDPR rights or ask questions about our privacy practices, please contact our Data Protection Officer directly.
Contact DPO