1. Controller
Maurice Unterhoferc/o POSTFLEX PFX-569-184
Emsdettener Straße 10
48268 Greven
Germany
ballsdeepcommunity@gmail.com
2. Hosting and technical logs
The service is hosted on a dedicated server at DeinServerHost. When it is used, IP address, requested resource, date and time, response status, referrer, browser/device information and security events may be processed to deliver and protect the service. The legal basis is Article 6(1)(f) GDPR. Logs are retained only as long as needed for operations, security, troubleshooting and legal obligations.
3. Discord login and bot operation
Login uses Discord OAuth with the identify and guilds scopes. We process Discord IDs, username and display name, avatar/banner identifiers, guild IDs and names, guild ownership and membership/access assignments. The installed bot additionally processes the roles, channels, members, messages, interactions and IDs required for configured features such as commands, tickets, factions, moderation, feeds and notifications. The legal basis is Article 6(1)(b) GDPR for the requested service and Article 6(1)(f) GDPR for security and access control. Discord separately processes data under its Privacy Policy.
4. Community and DayZ server data
Community owners decide which game servers and features to connect. Depending on that configuration, we process community configuration, Nitrado service identifiers, encrypted Nitrado access tokens, DayZ/ADM logs, player and PlayStation/ingame names, account links, connection times, positions, combat and death events, statistics, leaderboards, economy wallets, factions, zones/radars, moderation records, bans, whitelist and priority-queue entries, Discord delivery records and audit logs. This data is used only to provide, secure and document the selected functions.
The community owner or a platform administrator can use Remove Discord to make the bot leave and factory-reset the integration. Nitrado access tokens, connected gameservers, raw logs, Discord-linked accounts, wallets, factions, moderation records, cached members, roles, channels and delivery configuration are permanently erased, while module settings return to their original defaults. Only anonymous lifetime totals needed for global statistics and leaderboards, derived Elo records, billing records and the customer identity required for a later reinstallation are retained.
A separately hosted community bot may act as a federated data source through the authenticated server-to-server interface. It can submit the same relevant DayZ server events as the public bot so they are processed for public statistics and global rankings. To associate a member's existing private-bot profile with the Survivor Portal, the source may synchronize only the Discord ID, linked PlayStation or Xbox account names and main-account marker already managed by that source. Private roles, channels, tickets, wallets, donations, customer details and custom bot functions are not transferred through this interface.
For data that a customer submits about its members or players, the customer may be the controller and Balls Deep may act as a processor. Community owners are responsible for having a lawful basis, giving required notices and configuring retention appropriately.
5. Nitrado
Where a Nitrado server is connected, the service communicates with Nitrado using the credential supplied by the community owner to read logs and perform requested server actions. Nitrado separately processes data under its Privacy Policy. Credentials are stored encrypted and are not shown again in plain text.
6. PayPal billing
Subscriptions are paid through PayPal. We store the Discord community/customer reference, selected billing interval, PayPal subscription ID and status, paid period, cancellation state, webhook references and a versioned record of checkout confirmations. For proof of consent, the record includes a salted hash of the requesting IP address and a shortened user-agent string. We do not receive or store card or bank credentials. Processing is based on Article 6(1)(b) GDPR and Article 6(1)(c) and (f) GDPR for accounting, fraud prevention and legal claims. PayPal's own processing is explained in its Privacy Statement.
7. Essential session cookie
The dashboard sets the technically necessary cookie bd_alpha_session to keep users signed in, protect OAuth and checkout state, and prevent cross-site request forgery. It is not used for advertising or cross-site profiling. The cookie lasts up to 12 hours and is configured Secure in production, HttpOnly and SameSite=Lax. Its use is necessary under Section 25(2) TDDDG; related processing relies on Article 6(1)(b) and (f) GDPR.
8. Retention
OAuth guild snapshots are refreshed on sign-in. Account, community configuration and operational data are generally kept while the account/community uses the service. Raw and derived game data, moderation, security and audit records are retained as needed for the configured service and protection against abuse. Subscription, consent and transaction records may be retained for statutory accounting periods and legal claims. When data is no longer required, it is deleted or anonymised unless storage is required by law.
9. Recipients and transfers
Data may be disclosed to DeinServerHost, Discord, Nitrado, PayPal and competent authorities where necessary. Some providers may process data outside the EEA. The relevant provider is responsible for an applicable transfer mechanism, such as an adequacy decision or standard contractual clauses.
10. Your rights
Subject to legal requirements, you have rights of access, rectification, erasure, restriction, portability and objection. You may withdraw consent for the future and complain to a competent data protection supervisory authority. Send requests to ballsdeepcommunity@gmail.com. We may need to verify your identity.
11. Changes
We may update this policy when the service or legal requirements change. The current version and date are published here.
