Privacy Policy
Last updated: 2026-08-12 · Applies to joinourserver.com and all subdomains
api.joinourserver.com.
Contents
- Controller
- Data on mere visit (server logs)
- Cookies and local storage
- Discord login (OAuth)
- Checkout, payment processing & invoices
- Discord bot (role assignment)
- Email notifications
- API usage & webhook logs
- Recipients / processors
- Transfers to third countries
- Retention periods
- Your rights as a data subject
- Data Protection Officer
- Updates to this policy
1. Controller
Controller within the meaning of the GDPR and other national data protection laws is:
Email: info@ak-netbar.de · Full legal notice: /impressum
2. Data on mere visit (server logs)
When you call up our website, the web server automatically records the following data in so-called server logs:
- IP address of the requesting device (truncated/anonymised after 7 days)
- Date and time of the request
- URL called up and HTTP method
- HTTP status code of the response
- Referrer (previously visited page)
- User agent (browser and operating system information)
Purpose: Provision of the website, maintenance of IT security (detection and defence against attacks), error diagnosis.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in the secure operation of the online service).
Retention: a maximum of 7 days; afterwards automated deletion or anonymisation. In the event of a specific security incident, affected entries may be retained longer for the purpose of preserving evidence.
4. Discord login (OAuth)
Login to our platform takes place exclusively via Discord OAuth. We do not operate our own password management. When you click the „Login with Discord" button, you are redirected to Discord, where you consent to the transmission of the following data:
- Your Discord ID (numeric, permanent)
- Your Discord username including discriminator/tag
- Your Discord avatar (image URL)
- Your email address stored at Discord
- Optional (only if expressly granted) the right to add you to a Partner's
Discord server (
guilds.joinscope)
Purpose: Identification and authentication; assignment to Partner communities; display of your avatar/name in the Partner dashboard.
Legal basis: Art. 6 (1) lit. b GDPR (contract initiation /performance). Provider is Discord Inc., 444 De Haro St. Suite 200, San Francisco, CA 94107, USA. Privacy policy: discord.com/privacy.
The transfer to the USA is based on the Standard Contractual Clauses pursuant to Art. 46 (2) lit. c GDPR and on the EU-US Data Privacy Framework, insofar as the recipient is certified.
5. Checkout, payment processing & invoices
When you, as a Member, purchase a paid plan from a Partner, we process the following additional data:
- Invoice data: first name, last name (or company name), postal address (street, postcode, city, country), optionally VAT ID for businesses.
- Payment data: processed exclusively by the payment service provider Mollie. From Mollie we receive only the status (paid / refunded / failed), the payment method (e.g. „creditcard", „paypal"), the Mollie payment ID and optionally the last 4 digits of the credit card for recognition. We do not receive full credit card details or IBANs.
- Invoice PDF: automatically generated for each successful payment and retrievable in the member portal.
- Optional: VAT ID validation via the EU VIES interface for reverse-charge transactions.
Purpose: Contract performance, invoicing, fulfilment of statutory retention obligations (§ 147 AO, § 257 HGB).
Legal basis: Art. 6 (1) lit. b GDPR (contract performance) and Art. 6 (1) lit. c GDPR (legal obligation — tax law retention).
Please note: the contracting party for the paid plan is the respective Partner, not JoinOurServer. JoinOurServer operates the infrastructure and processes the payment via Mollie on behalf of the Partner. For details see Terms Part C.
6. Discord bot (role assignment)
After a successful payment, our Discord bot assigns you the role configured by the Partner on their Discord server. In doing so, only your Discord ID, the server ID and the role ID are exchanged between our server and the Discord API.
Purpose: Automated provision of the paid access.
Legal basis: Art. 6 (1) lit. b GDPR (contract performance with the Partner).
If your subscription ends (cancellation, expired access, failed payment), the role is also automatically removed after the grace period expires. Optionally, the Partner may have configured an additional removal from the server (Discord „kick") on expiry.
7. Email notifications
We send transactional emails to the email address stored at Discord, where this is necessary for contract performance: payment confirmations, reminders before trial end, notices of failed charges, cancellation confirmations.
Dispatch: Emails are sent via an SMTP service provider with servers located within the European Union (processor with contract under Art. 28 GDPR).
Legal basis: Art. 6 (1) lit. b GDPR (contract performance).
We do not send promotional emails. If individual Partners send you mailings beyond this, the privacy policy of the respective Partner applies.
8. API usage & webhook logs
For Partners we provide a REST API at api.joinourserver.com.
Each API call is stored in an audit table:
- API key used (truncated)
- Endpoint called, HTTP method, status code
- IP address of the caller
- User agent
- Timestamp
Likewise, we log incoming webhooks from Mollie and outgoing webhooks to the URL configured by the Partner.
Purpose: Abuse detection, troubleshooting, rate limiting.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in security and diagnosis).
Retention: 90 days, then automatic deletion.
9. Recipients / processors
We use the following third parties who process personal data on our behalf or as independent controllers:
| Provider | Purpose | Location / privacy |
|---|---|---|
| Mollie B.V. | Payment processing, management of recurring subscriptions, invoice dispatch (Mollie Sales Invoices, optional) | Netherlands (EU) · Privacy policy |
| Discord Inc. | OAuth login, Discord bot for role management | USA · DPF / Standard Contractual Clauses · Privacy policy |
| Web hosting provider | Provision of server infrastructure | European Union · Processing under Art. 28 GDPR |
| SMTP delivery service | Dispatch of transactional emails | European Union · Processing under Art. 28 GDPR |
| jsDelivr | Delivery of web fonts and CSS frameworks (Bootstrap, Bootstrap-Icons) via a content delivery network | International CDN · Your IP is transmitted to the CDN provider when loading. Legal basis: Art. 6 (1) lit. f GDPR (secure and performant delivery). |
| Lexware Office (optional, Partner-side) | Accounting export at the option of the respective Partner | Germany · Enabled per Partner; not every community uses this integration |
Each Partner is in turn a controller for the data of their members and may employ their own processors. The respective Partner informs you separately about their data processing.
10. Transfers to third countries
Insofar as we transfer data to third countries (in particular the USA, in connection with the Discord integration), this is based on:
- the Standard Contractual Clauses of the EU Commission (Art. 46 (2) lit. c GDPR) and/or
- a certification of the recipient under the EU-US Data Privacy Framework (adequacy decision of 10 July 2023).
We point out that, despite these measures, the level of protection in the USA does not necessarily correspond to that in the EU; in particular, authorities may access data without the data subject being informed or having effective legal protection.
11. Retention periods
| Data category | Retention period |
|---|---|
| Server logs | max. 7 days |
| API and webhook logs | 90 days |
| Discord account data (username, avatar) | as long as the account exists; immediate anonymisation in our systems upon deletion |
| Active subscriptions / memberships | for the duration of the subscription |
| Invoice and payment data | 10 years from the end of the calendar year in which the invoice was issued (§ 147 (3) AO) |
| Inactive / deleted accounts | personal fields are anonymised, the invoice reference is retained for commercial and tax law archival |
12. Your rights as a data subject
You have the following rights against us at any time:
- Access (Art. 15 GDPR) — you may demand confirmation as to whether and which personal data we process about you. We provide information on informal request to the email address listed below.
- Rectification (Art. 16 GDPR) — you may demand the correction of inaccurate or the completion of incomplete data.
- Erasure (Art. 17 GDPR, „right to be forgotten") — active members can delete their account themselves at any time via the member portal under „Delete account". Invoice data subject to statutory retention obligations is anonymised, but not physically deleted.
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) — you may request the data concerning you in a structured, commonly used, machine-readable format.
- Objection (Art. 21 GDPR) — you may object at any time, on grounds relating to your particular situation, to processing based on a legitimate interest.
- Withdrawal of consent (Art. 7 (3) GDPR) — with effect for the future.
An informal email to info@ak-netbar.de is sufficient to exercise your rights.
Right to lodge a complaint with a supervisory authority
You also have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The competent authority is that of the federal state where you habitually reside or where the controller is based.
13. Data Protection Officer
Due to the size of the company, we are not obliged to appoint a data protection officer under § 38 (1) BDSG. Please direct data protection enquiries directly to info@ak-netbar.de.
14. Updates to this policy
We reserve the right to adapt this Privacy Policy so that it always complies with current legal requirements or to reflect changes to our services, e.g. when introducing new features. The new privacy policy then applies to your next visit.
The current version is always available at joinourserver.com/datenschutz.