Effective date: 22 July 2026 Version: 1.0 Controller: GuildWard, 1046 Budapest, Klauzál utca 9.
1. Who we are
GuildWard is operated by GuildWard from 1046 Budapest, Klauzál utca 9., Hungary. GuildWard provides Discord access, verification and related trust operations for community administrators.
2. Scope
This Privacy Policy covers the GuildWard website, control plane, Discord integration and member-verification route. A Customer’s independent Discord activity and Discord’s own processing are outside GuildWard’s control and are governed by Discord’s terms and privacy notices.
3. People covered
This policy applies to website visitors, GuildWard administrators and customers, organization members and reviewers, Discord members who complete verification, and people who contact GuildWard in writing about the service.
4. Controller and processor roles
GuildWard acts as independent controller for customer accounts, authentication, service security, audit and product operations. Where GuildWard processes Discord Member data solely to carry out a Customer’s configured verification, role or protection settings, GuildWard acts as processor and the Customer acts as controller for that Member processing. Independent-controller security processing may continue where necessary to protect the service. GuildWard does not assert joint controllership with Customers for ordinary verification operations.
5. Data categories
GuildWard stores Discord user and guild identifiers; username, display name and avatar URL snapshot; organization and membership role; installation and guild metadata; selected role and channel identifiers; session and verification state; hashed tokens; expiry and attempt counters; delivery and action results; Setup Health, Activity and Audit records; job and idempotency records; rate-limit scope keys; versioned verification policy; deduplicated human-join signals; protection incidents; and privacy-minimized Manual Review cases and decisions. If a Customer enables a self-declared minimum age, GuildWard evaluates the entered birth date transiently and stores only the configured threshold, pass/fail result and check time—not the exact date. If message protection is enabled, Gateway message bodies may be processed transiently for rate and exact normalized-repetition detection; GuildWard stores message, channel and member identifiers, timestamps, counts and a keyed HMAC fingerprint, but not raw message bodies. GuildWard does not currently store arbitrary custom-form answers, billing payment-card data or analytics events.
6. Data sources
Data comes from administrators, Discord OAuth and APIs, Discord Gateway events, member browsers, Cloudflare Turnstile, and GuildWard’s own service operations. Written correspondence sent to GuildWard’s postal address may also be processed for support and legal purposes.
7. Purposes and legal bases
GuildWard processes personal data to provide and administer accounts and contracts, install and configure the Discord bot, run member verification on Customer instruction, reconcile roles, protect the service, apply rate limits, troubleshoot faults and keep accountable operational records. Depending on the processing and the person’s role, GuildWard relies on:
- performance of a contract with the Customer, or steps taken at the Customer’s request before a contract (GDPR Article 6(1)(b));
- GuildWard’s legitimate interests in securing the service, preventing abuse, ensuring reliable operations and maintaining limited audit trails, balanced against the rights of the people concerned (GDPR Article 6(1)(f));
- compliance with legal obligations that apply to GuildWard (GDPR Article 6(1)(c)); and
- where GuildWard acts as processor, the Customer’s documented instructions and the Customer’s own legal basis for Member processing.
8. Contract necessity
Account, organization, installation, configuration and service-operation data are processed because they are needed to provide the requested GuildWard service to the Customer. Contract necessity does not automatically extend to every Member or security purpose.
9. Legitimate interests
Security, abuse prevention, reliable operations and limited audit rely on legitimate interests where applicable. Those interests are limited to what is necessary for a safe Discord verification service, and people may object as described in this policy.
10. Consent where genuinely used
GuildWard does not use marketing or analytics consent and does not treat Turnstile completion as privacy consent. If consent is introduced for a future purpose, it will be specific, informed, freely given, recorded and withdrawable without relabeling another legal basis.
11. Legal obligations
GuildWard may process or retain limited data to comply with applicable Hungarian and European Union law, lawful orders, and regulatory duties. If paid billing is introduced later, tax and accounting retention will be described in an updated notice.
12. Security and abuse prevention
GuildWard processes session hashes, event receipts, idempotency keys, normalized errors and rate-limit scope keys to protect accounts, prevent replay and operate safely. Rate-limit design uses an IP-derived keyed hash rather than storing raw IP addresses in rate-limit buckets.
13. Discord authentication and installation data
Administrator OAuth processing includes Discord user identifier, username, display name and avatar URL, one-time OAuth state, session state and organization membership. Installation processing includes guild identifier, name and icon, requested and granted permissions, status, installer, Gateway timestamps and failure codes.
14. Verification-session and continuation data
GuildWard stores guild and Member identifiers, continuation hash, state, attempt limit and count, expiry, used/processing/exchange times and source event key. Raw continuation values are not stored. A scoped browser-session token is stored only as a hash.
15. Discord member and role-action data
Processing includes Member identifier, bot flag, membership and verification state, join and leave times, configured role identifiers, desired role actions, attempts, state, Discord request reference when returned, error code and timestamps.
16. Member fields and review information
A Customer may require a self-declared minimum age during verification. The exact birth date is not retained, and the result is not identity or provider-backed age assurance. Customers remain responsible for selecting a lawful threshold, providing an appropriate notice and support route, and avoiding unlawful discriminatory or high-risk use.
17. Setup-health, activity and audit data
Setup Health stores check key and status, affected capability, permission, explanation, remediation and check time. Activity stores category, severity, subject where applicable, title, explanation, result and correlation. Audit stores actor, event, action, resource, outcome, reason, metadata and time.
18. IP-derived rate-limit or security data
Rate-limit buckets store a keyed scope identifier for an IP, member, session or user, plus action, window, attempts and blocking time. Raw IP addresses are not stored in those buckets.
19. Billing data
GuildWard does not currently operate checkout or paid subscription billing. No payment-card or invoice identity data is processed for GuildWard plans. If paid billing is introduced, this section will be updated before checkout is offered.
20. Support communications
People may contact GuildWard in writing at 1046 Budapest, Klauzál utca 9. Correspondence content, sender details and related attachments are processed to respond to the request, keep a record of the exchange and meet legal obligations.
21. Cookies and local storage
GuildWard uses strictly necessary application-session, OAuth-state and scoped verification cookies. No preference cookie or GuildWard browser local storage is used. Details appear in the Cookie Policy.
22. Analytics only if implemented
No analytics or marketing technology is used in the current GuildWard web application. If added later, it will remain disabled until any legally required consent and disclosure are in place.
23. AI and automated decision-making
GuildWard does not currently use Smart Shield or other AI systems to make automated access decisions. CAPTCHA success is not an identity or behavior decision about a person. No solely automated decision produces legal or similarly significant effects within the meaning of GDPR Article 22 in the current product.
24. External providers
Discord supplies authentication, guild and member context and role APIs. Cloudflare supplies Turnstile. PostgreSQL stores GuildWard records. Optional S3-compatible object storage may hold guild branding assets when that feature is enabled. Details appear in the Subprocessor List.
25. Subprocessors
The Subprocessor List identifies providers used for production processing. Whether Discord and Cloudflare act as processors, independent controllers or both depends on the specific operation and contract.
26. International transfers
Discord and Cloudflare may process data outside Hungary and the European Economic Area. Where a transfer is not covered by an adequacy decision, GuildWard relies on the providers’ applicable transfer mechanisms, including Standard Contractual Clauses where used by those providers, together with the contractual and technical safeguards described in their documentation. GuildWard stores application records in its deployed PostgreSQL environment and does not sell personal data.
27. Retention
| Data category | Purpose | Legal basis | Retention | Deletion trigger | Exceptions |
|---|---|---|---|---|---|
| OAuth state | Login integrity | Security / contract | Expires after 5 minutes by default (configurable 60–900 seconds) | Consumed or expired | Security incident preservation |
| App session | Authenticated access | Contract / security | Expires after 24 hours by default (configurable 1–720 hours) | Expiry, logout or revocation | Legal or security hold |
| Verification / browser session | Member route | Customer instruction / security | Expires after 10 minutes by default (configurable 2–60 minutes) | Completion, expiry or cancellation | Dispute or security evidence |
| Guild / member projection | Operate configured access | Customer instruction | While the guild remains connected and the membership record is needed | Guild removal, member leave or validated deletion request | Legal or security need |
| Activity, Audit and actions | Accountability / reliability | Contract / legitimate interest / instruction | While the Customer relationship and connected guild remain active, and for up to 24 months afterwards for security and dispute evidence | Customer deletion or end of retention period | Legal claim or security hold |
| Rate-limit buckets | Abuse prevention | Legitimate interest | For the configured rate-limit window, then cleaned up | Window and block expiry | Incident investigation |
| Self-declared age-threshold result | Customer-configured access rule | Customer instruction | Attached to the verification-session lifetime; exact birth date is not stored | Session deletion or customer request | Legal or security hold where lawful |
| Join signals and join-burst incidents | Abuse prevention | Customer instruction / security / legitimate interest | For the configured observation window and retained incident history while the guild remains connected | Window expiry and ordinary incident cleanup | Incident investigation where lawful |
| Message-protection signals and incidents | Abuse prevention | Customer instruction / security / legitimate interest | Active detection uses bounded windows; persisted incident records follow the Activity and Audit retention above | Customer deletion or ordinary cleanup | Incident investigation where lawful |
| Manual Review cases and decisions | Human resolution | Customer instruction / accountability | While the guild remains connected and for up to 24 months after closure of the case | Customer deletion or end of retention period | Legal or security hold where lawful |
| Backups | Resilience | Contract / security | According to the deployment backup rotation schedule, typically overwritten within 30 days | Backup rotation | Legal hold |
| Postal support correspondence | Support and legal response | Legitimate interest / legal obligation | Up to 3 years after the last message in the matter, unless a longer period is required | Closure of the matter | Legal claims |
Deletion may be delayed where Hungarian or EU law requires retention for security, claims, tax or audit purposes.
28. Security controls
Controls include hashed credential-like tokens, HttpOnly and SameSite cookies, Secure production cookies, tenant and guild authorization, durable intents, replay receipts, idempotency, bounded leases, server-only secrets and minimized Discord scopes. These controls reduce risk but do not eliminate it.
29. Data-subject rights
Depending on applicable law and your role, you may have rights to information, access, correction, deletion, restriction, objection, portability and complaint. Send privacy requests in writing to GuildWard, 1046 Budapest, Klauzál utca 9., marked “Privacy request”. GuildWard will verify identity proportionately before acting.
30. Access, correction, deletion and restriction
GuildWard will assess requests and respond without undue delay and in any event within one month, extendable by two further months for complex requests as permitted by GDPR Article 12. Where GuildWard acts as processor, a Member may be directed to the relevant Customer, or GuildWard may assist that Customer. A request may be limited where law permits or requires retention.
31. Objection and portability
You may object to legitimate-interest processing. Where portability applies, GuildWard will provide personal data you provided in a commonly used, machine-readable format to the extent technically feasible for the current product.
32. Withdrawal of consent where applicable
Where a future purpose relies on consent, consent may be withdrawn prospectively without affecting earlier lawful processing. No current marketing or analytics consent is used.
33. Complaints and supervisory authority
You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), currently reachable at https://www.naih.hu/, or with another supervisory authority in the European Economic Area where you live or work.
34. Children and minimum age
GuildWard administrator accounts are intended for persons with full legal capacity to contract under Hungarian law (generally 18 years of age). Discord members must meet Discord’s own eligibility rules and any minimum-age rule configured by the Customer. GuildWard’s optional self-declared age check is not age assurance and does not verify identity documents. GuildWard does not knowingly offer administrator accounts to children.
35. Changes
Material updates will receive a new version and effective date. The current version of this Privacy Policy will be published at /privacy. Continued use of the service after the effective date of an update constitutes notice of the revised policy for Customers and administrators; Members should review the notice linked from their verification route.
36. Contact
Controller: GuildWard Postal address: 1046 Budapest, Klauzál utca 9., Hungary Privacy requests: write to the postal address above and mark the correspondence “Privacy request” No Data Protection Officer has been appointed under GDPR Article 37 because GuildWard’s current processing does not meet the mandatory appointment criteria; privacy requests are handled through the postal contact above.