Privacy Policy
Privacy Policy
Last updated: September 9, 2026
This Privacy Policy explains how personal data is collected, processed, stored and protected when you use the Zelia website, the Zelia Discord bot, related services, subscriptions, support services and other features provided by Zelia.
We take the protection of personal data seriously and process personal data only where there is a legal basis for doing so.
This Privacy Policy is intended to provide the information required under the General Data Protection Regulation ("GDPR") and applicable German data protection law.
1. Controller
The controller responsible for the processing of personal data in connection with Zelia is:
Yoshua Bieren
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen
Germany
Email: [bierenyoshua@gmail.com](mailto:bierenyoshua@gmail.com)
The controller determines the purposes and means of the processing of personal data carried out directly by Zelia.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed in connection with:
- the Zelia website at zelia.xyz;
- the Zelia Discord bot;
- commands and interactions with Zelia;
- Discord servers using Zelia;
- Zelia's dashboard and configuration systems;
- subscriptions and paid services;
- customer and technical support;
- moderation and security features;
- ticket and ModMail systems;
- integrations provided through Zelia;
- and other services directly operated by Zelia.
Third-party services such as Discord are subject to their own privacy policies where they process personal data independently.
3. What Personal Data We Process
The personal data processed by Zelia depends on which services and features are used.
3.1 Website Data
When you visit our website, our servers or hosting providers may automatically process technical information necessary to deliver and secure the website.
This may include:
- IP address;
- date and time of access;
- requested page or resource;
- HTTP status information;
- browser type and version;
- operating system;
- device information;
- referring website;
- and technical connection information.
This information is primarily processed to provide the website, maintain technical stability, prevent misuse and investigate security incidents.
The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in securely and reliably operating our website.
Where technical processing is strictly necessary to provide a service expressly requested by the user, the applicable requirements of Section 25(2) TDDDG also apply.
4. Data Processed Through the Zelia Discord Bot
When Zelia is added to a Discord server or used through Discord, certain information may be received through Discord's API.
Depending on the permissions granted to Zelia and the features being used, this may include:
Discord account information
- Discord User ID;
- username;
- display name or nickname;
- profile picture or avatar;
- roles;
- server membership information;
- and other basic profile information made available through Discord.
Discord server information
- Discord Server/Guild ID;
- server name;
- channel IDs;
- role IDs;
- configured permissions;
- server settings;
- and Zelia-specific configuration data.
Interaction information
When you interact with Zelia, we may process:
- commands submitted to the bot;
- button and menu interactions;
- command parameters;
- user and server IDs associated with an interaction;
- timestamps;
- requested bot actions;
- and technical information required to execute the command.
This data is generally processed under Article 6(1)(b) GDPR where processing is necessary to provide a requested Zelia service or perform a contract.
Where the processing is necessary for the general operation, security or improvement of Zelia, Article 6(1)(f) GDPR may apply.
5. Message Content
Zelia does not automatically require permanent access to all conversations simply because it is present on a Discord server.
However, certain Zelia features may require the processing of message content.
This may particularly apply to features such as:
- ticket systems;
- ModMail;
- support conversations;
- moderation features;
- reports;
- automated notifications;
- message-based commands;
- logging features configured by a server administrator;
- or other features where message content is necessary for the requested functionality.
In these cases, the content may be processed together with information such as the author's Discord User ID, channel ID, server ID and timestamp.
Message content is processed only to the extent required for the relevant feature.
Server administrators are responsible for configuring Zelia appropriately and for ensuring that their use of optional logging, moderation or similar features complies with applicable law.
6. Tickets, ModMail and Support
If you contact us or use a Zelia ticket, ModMail or support system, we may process information including:
- Discord User ID;
- username;
- email address, where provided;
- message content;
- support request details;
- uploaded attachments;
- timestamps;
- ticket history;
- actions performed by support staff;
- and other information voluntarily provided as part of the request.
We process this information in order to respond to support requests, investigate technical issues, handle contractual matters and provide customer service.
The legal basis is Article 6(1)(b) GDPR where the request relates to a contract or subscription.
For general inquiries, technical troubleshooting, abuse prevention or the defence of legal claims, processing may be based on Article 6(1)(f) GDPR.
7. Moderation, Blacklists and Abuse Prevention
Zelia may provide moderation, security, anti-abuse or blacklist functionality.
Where such features are used, the following information may be processed where necessary:
- Discord User ID;
- Discord Server ID;
- moderation actions;
- timestamps;
- reason for an action;
- reports;
- blacklist entries;
- ticket or support history relevant to abuse;
- and security-related logs.
Such processing may be necessary to protect Zelia, its users and participating Discord communities against spam, fraud, abuse, attacks, exploitation or repeated violations of applicable rules.
The legal basis for processing carried out directly by Zelia for these purposes is generally Article 6(1)(f) GDPR.
Our legitimate interests include:
- protecting our systems;
- preventing fraud and abuse;
- maintaining service integrity;
- enforcing our Terms of Service;
- protecting users;
- and investigating security incidents.
Where a blacklist or moderation feature is operated solely under the control of a Discord server administrator, that administrator may have separate responsibilities under applicable data protection law.
8. Support Rating System
Where Zelia provides a feature allowing users to rate support interactions, we may process:
- the rating submitted;
- the relevant ticket;
- the Discord User ID of the person submitting the rating;
- the support team member associated with the ticket;
- timestamps;
- and optional written feedback.
The purpose of this processing is to evaluate and improve support quality and to associate feedback with the relevant support interaction.
The legal basis is Article 6(1)(f) GDPR based on our legitimate interest in maintaining and improving the quality of our services.
9. Integrations
Zelia may provide integrations with external platforms or services, for example to publish notifications relating to content, streams or other events.
Where a server administrator configures such an integration, Zelia may store information such as:
- channel or account identifiers;
- integration settings;
- Discord Server ID;
- destination channel ID;
- notification settings;
- and publicly available information necessary to provide the integration.
Where an integration requires authentication with a third-party provider, additional information may be processed in accordance with the respective feature.
Third-party providers may independently process personal data under their own terms and privacy policies.
10. Subscriptions and Payments
Where paid Zelia services or subscriptions are purchased, we may process information necessary to administer the subscription.
This may include:
- name, where provided;
- email address;
- customer or account identifier;
- Discord User ID;
- subscription plan;
- subscription status;
- start and end dates;
- payment status;
- transaction reference;
- invoice information;
- billing information where required;
- refunds;
- cancellations;
- and information necessary for tax and accounting purposes.
Actual payment information such as full card numbers may be processed directly by the respective payment service provider rather than by Zelia.
Payment providers may process personal data under their own privacy policies and may act as independent controllers for certain processing activities.
Processing necessary to establish and perform a subscription contract is based on Article 6(1)(b) GDPR.
Processing necessary to comply with accounting, tax or other legal obligations is based on Article 6(1)(c) GDPR.
11. Legal Bases for Processing
Depending on the circumstances, Zelia processes personal data on one or more of the following legal bases:
Article 6(1)(a) GDPR – Consent
Where you have voluntarily consented to a specific form of processing.
Consent may be withdrawn at any time with effect for the future.
Article 6(1)(b) GDPR – Performance of a Contract
Where processing is necessary to:
- provide Zelia;
- execute requested commands;
- manage subscriptions;
- provide purchased services;
- administer your account;
- respond to contractual support requests;
- or take steps prior to entering into a contract.
Article 6(1)(c) GDPR – Legal Obligation
Where processing is necessary to comply with legal obligations, including accounting, taxation or lawful requests from competent authorities.
Article 6(1)(f) GDPR – Legitimate Interests
Where processing is necessary for legitimate interests and those interests are not overridden by the rights and freedoms of the affected person.
Our legitimate interests may include:
- maintaining the security of Zelia;
- preventing fraud and abuse;
- operating our infrastructure;
- investigating technical problems;
- maintaining logs necessary for security;
- improving reliability;
- responding to non-contractual inquiries;
- enforcing our Terms of Service;
- and establishing, exercising or defending legal claims.
12. Cookies and Similar Technologies
Our website may use cookies, local storage or similar technologies where technically necessary to provide requested functionality.
This may include technologies used for:
- login sessions;
- security;
- authentication;
- fraud prevention;
- user preferences;
- session management;
- and essential website functionality.
Where storing information on or accessing information from your device is strictly necessary to provide a service expressly requested by you, consent may not be required under Section 25(2) TDDDG.
Any non-essential cookies or comparable technologies that require consent will only be used after valid consent has been obtained.
Where processing of personal data is based on consent, the legal basis is Article 6(1)(a) GDPR.
You may withdraw your consent at any time through the available cookie or privacy settings.
13. Recipients of Personal Data
Personal data may be disclosed to service providers where this is necessary to operate Zelia.
Recipients may include:
- hosting and infrastructure providers;
- database providers;
- payment service providers;
- email service providers;
- security and anti-abuse providers;
- technical service providers;
- Discord;
- and professional advisers or public authorities where legally required.
Service providers acting on our behalf are required to process personal data only in accordance with applicable data protection requirements and contractual instructions where Article 28 GDPR applies.
We only disclose personal data where there is an appropriate legal basis for doing so.
14. Discord
Zelia operates as an application on the Discord platform.
Discord itself processes personal data independently when you create or use a Discord account and when you interact with the Discord platform.
Zelia may receive information from Discord through the Discord API depending on:
- the features being used;
- the permissions granted to Zelia;
- your interactions with Zelia;
- and the server in which Zelia is installed.
Discord's own processing of personal data is governed by Discord's Privacy Policy.
For users in the European Economic Area, Discord currently identifies Discord Netherlands BV as the controller for personal data processed through Discord's services.
Zelia and Discord are separate services and Zelia is not responsible for processing independently carried out by Discord.
15. International Data Transfers
Some service providers used in connection with Zelia or Discord may process personal data outside Germany or the European Economic Area.
Where personal data is transferred to a country outside the EEA, the transfer will only take place where the requirements of Chapter V GDPR are met.
Depending on the provider and destination country, this may include:
- an adequacy decision of the European Commission under Article 45 GDPR;
- participation in an applicable recognised data protection framework;
- Standard Contractual Clauses under Article 46 GDPR;
- or another legally permitted transfer mechanism.
Where required, additional safeguards will be implemented to ensure an appropriate level of data protection.
16. Data Retention
We do not retain personal data indefinitely.
Personal data is stored only for as long as necessary for the purpose for which it was collected or for as long as a legal obligation requires continued retention.
The following criteria generally apply:
Bot configuration data
Configuration information is generally retained for as long as the relevant Discord server uses Zelia or until the configuration is deleted.
Support and ticket data
Support communications may be retained until the request has been fully resolved and for an additional period where necessary to deal with follow-up requests, complaints or legal claims.
Security and abuse data
Security-related logs, blacklist entries and abuse records may be retained for as long as reasonably necessary to protect Zelia and its users, investigate incidents and prevent repeated abuse.
Retention will be reviewed where appropriate.
Website logs
Technical server logs are retained only for as long as reasonably necessary for security, troubleshooting and abuse prevention, unless continued retention is required in connection with a security incident or legal claim.
Subscription and account information
Subscription information is normally retained for the duration of the contractual relationship and subsequently deleted or restricted unless continued retention is required by law.
Accounting and invoice information
Information forming part of legally required accounting or tax records may need to be retained for the applicable statutory retention period.
Under current German law, certain accounting documents and invoices may be subject to an eight-year retention period.
Once the applicable retention period expires and there is no other legal basis for retaining the information, the data will be deleted or anonymised.
Backup copies may remain temporarily until they are overwritten as part of the normal backup cycle.
17. Removal of Zelia From a Discord Server
Removing Zelia from a Discord server stops the bot from actively providing services to that server.
This does not necessarily result in the immediate deletion of all previously stored data.
Information may continue to be retained where:
- it is necessary to process an outstanding request;
- it forms part of legally required accounting records;
- it is necessary for fraud or abuse prevention;
- it relates to an unresolved security incident;
- it is required to establish, exercise or defend legal claims;
- or another legal obligation requires retention.
Where no continued legal basis exists, the relevant personal data will be deleted in accordance with our retention procedures.
18. Data Security
We implement appropriate technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unlawful processing;
- accidental loss;
- alteration;
- destruction;
- and unauthorised disclosure.
Measures may include access restrictions, authentication mechanisms, encrypted communications, server security measures, backups, logging and permission controls where appropriate.
Despite these measures, no internet-based service can guarantee absolute security.
19. Your Rights Under the GDPR
Where the GDPR applies, you have the following rights subject to the respective legal requirements.
Right of Access – Article 15 GDPR
You have the right to request confirmation as to whether we process personal data concerning you and, where applicable, to obtain access to that data and related information.
Right to Rectification – Article 16 GDPR
You may request correction of inaccurate personal data or completion of incomplete information.
Right to Erasure – Article 17 GDPR
You may request deletion of your personal data where the legal requirements for erasure are met.
The right to erasure does not apply where continued processing is required by law or another legal exception applies.
Right to Restriction of Processing – Article 18 GDPR
You may request that processing of your personal data be restricted under the conditions provided by law.
Right to Data Portability – Article 20 GDPR
Where applicable, you have the right to receive personal data you provided to us in a structured, commonly used and machine-readable format and to transmit that data to another controller.
Right to Object – Article 21 GDPR
Where personal data is processed on the basis of Article 6(1)(f) GDPR, you have the right to object to such processing on grounds relating to your particular situation.
We will then stop processing the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or where processing is necessary for the establishment, exercise or defence of legal claims.
Withdrawal of Consent
Where processing is based on your consent, you may withdraw your consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
20. Exercising Your Rights
Privacy-related requests may be submitted to:
[bierenyoshua@gmail.com](mailto:bierenyoshua@gmail.com)
To protect users against unauthorised disclosure or deletion of their information, we may need to verify your identity before fulfilling certain requests.
Where a request relates to Discord information, providing your Discord User ID may help us identify the relevant data.
We will respond to valid requests within the periods required by applicable data protection law.
21. Right to Lodge a Complaint
You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data violates the GDPR.
You may in particular contact a supervisory authority in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement.
This right exists independently of any other administrative or judicial remedy.
22. Automated Decision-Making
Zelia does not use solely automated decision-making that produces legal effects concerning users or similarly significantly affects them within the meaning of Article 22 GDPR unless expressly disclosed for a specific feature.
Automated bot actions, commands, spam detection or moderation tools do not necessarily constitute automated decision-making within the meaning of Article 22 GDPR.
Where server administrators configure automated moderation features, they remain responsible for reviewing their configuration and use where appropriate.
23. Special Categories of Personal Data
Zelia is not designed for the intentional collection of special categories of personal data within the meaning of Article 9 GDPR, such as health information, religious beliefs, political opinions or biometric data used for identification.
Users should avoid submitting sensitive personal information through tickets, ModMail or other Zelia features unless it is genuinely necessary.
If such information is provided without being required for the relevant service, it may be deleted where appropriate.
24. Personal Data of Minors
Zelia is provided through Discord and may only be used in accordance with Discord's applicable age requirements and applicable law.
We do not intentionally request unnecessary personal information from children.
Server administrators using Zelia are responsible for ensuring that their server and use of Zelia comply with applicable rules relating to minors.
Where we become aware that personal information has been processed unlawfully in relation to a minor, appropriate steps will be taken in accordance with applicable law.
25. Legal Requests and Authorities
Personal data may be disclosed to courts, law enforcement agencies, supervisory authorities or other competent authorities where we are legally required to do so.
Such disclosures will only be made where there is a valid legal basis or legally binding obligation.
We may also process information where necessary to establish, exercise or defend legal claims.
26. Changes to this Privacy Policy
We may update this Privacy Policy where necessary, for example due to:
- changes to Zelia;
- new or modified features;
- changes to our service providers;
- changes to data processing practices;
- or changes in applicable law.
The current version will always be published on our website.
Where legally required, users will be informed separately about material changes.
The date shown at the beginning of this Privacy Policy indicates when it was last updated.
27. Contact
If you have any questions about this Privacy Policy or the processing of personal data by Zelia, please contact:
Yoshua Bieren
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen
Germany
Email: [bierenyoshua@gmail.com](mailto:bierenyoshua@gmail.com)
Zelia – Privacy Policy
Last updated: September 9, 2026