1. Who is responsible?
The controller under the General Data Protection Regulation (GDPR) for this website, the LUCWORK dashboard and the LUCWORK Discord bot is:
Lucas Lindner
Erftalle 1
50129 Bergheim, Deutschland
Email: support@lucwork.de
We have not appointed a data protection officer because we are not legally required to.
2. In short
- We only process data we need to run the website, the dashboard and the bot.
- No tracking, no analytics tools, no advertising. We never sell data.
- Most data are Discord IDs (users, servers, channels, roles). Where we store content, such as support tickets, we say so explicitly below.
- Each server's staff decides in the dashboard which bot features run on their server.
3. Visiting this website
Server log files. When you open a page, our hosting provider [fill in: website_host] automatically processes technical data: IP address, date and time, requested URL, referrer, browser and operating system. This is required to deliver the site and detect attacks (Art. 6(1)(f) GDPR, legitimate interest in secure operation). Log files are deleted after [fill in: log_retention_days] days at the latest. We have a data processing agreement with the provider.
Cloudflare. For DNS and protection against attacks (e.g. DDoS), traffic is routed through Cloudflare, Inc. (USA), which processes technical data such as your IP address and timestamps (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses also apply. More: cloudflare.com/privacypolicy.
Cookies and local storage. We only set what is technically necessary or what you choose yourself (Section 25(2) no. 2 TDDDG). No consent is required for this.
| Name | Purpose | Duration |
|---|---|---|
nebula-theme | Remembers light or dark mode (cookie and local storage) | 1 year |
nebula_blog_lang | Remembers your language on the blog and this page | 1 year |
nebula-cookie-notice-dismissed | Remembers that you closed the cookie notice (local storage) | until you clear it |
Embedded images. The "Team" and "Partners" pages load profile pictures from Discord's CDN (Discord Inc., USA) and a partner logo from levlix.io. Your browser connects to those servers and transmits your IP address (Art. 6(1)(f) GDPR, interest in an appealing presentation).
Blog, team and statistics are fetched by our web server directly from our own dashboard server. No data about you is transmitted.
4. Using the dashboard
Login with Discord. You sign in via Discord (OAuth2 with the scopes identify and guilds). We receive your Discord ID, username, avatar and the list of your servers including your permissions there. We do not receive your email address or password. We use this to check which servers you may manage (Art. 6(1)(b) GDPR, providing the dashboard).
We do not store this login data in a database but in a signed cookie in your browser:
| Cookie | Purpose | Duration |
|---|---|---|
nebula_session | Keeps you logged in (Discord ID and server list) | 30 days or until logout |
| OAuth state | Protects the login flow against forgery | 10 minutes |
| 2FA step | Only for team members using two-factor login | 5 minutes |
nebula-theme | Light or dark mode | 1 year |
Settings. What you configure for a server in the dashboard (channels, roles, texts, modules) is stored for that server. Changes in the admin area are logged with Discord ID, action and time so errors and abuse can be traced (Art. 6(1)(f) GDPR).
Two-factor login (team only). For team members we store the authenticator app's secret key while 2FA is enabled.
Abuse protection. To block excessive requests we briefly process your IP address in memory. We do not write it to a database or file.
Images. Your browser loads avatars and server icons from Discord's CDN. Fonts and libraries are served from our own server.
Reachability. The dashboard is served through Cloudflare (see section 3).
5. Using the Discord bot
The bot only processes data on servers where it is installed and only for features the server's staff has enabled. The legal basis is our and the server operators' legitimate interest in providing the requested features (Art. 6(1)(f) GDPR). For features you actively use yourself (e.g. opening a ticket), the basis is Art. 6(1)(b) GDPR.
- Server settings: IDs of servers, channels, roles and messages, plus custom texts and images server staff upload, e.g. for ticket panels.
- Activity statistics: Per message your Discord ID, server and time, without message content. Also start and duration of voice sessions (no audio) and the number of members per online status.
- Command log: Username, command, server and time when you use a bot command (debugging, statistics).
- Level system: XP and level per user and server.
- Moderation: Warnings, kicks, timeouts and bans with reason, acting moderator and time. Also incidents from Anti-Nuke and Honeypot protection and blocks in the verification system.
- Support tickets: When a ticket is closed we store a transcript: all messages in the ticket with author (Discord ID, name, avatar), content and time, plus file names and Discord links of attachments. Also the optional rating (stars, category, handling staff member). The transcript can be viewed by the person who opened the ticket and authorised staff of that server.
- Giveaways: Discord IDs of participants and winners.
- Automatic translation: If enabled on a server, we send the text of affected messages to DeepL SE (Cologne, Germany) or MyMemory (Translated srl, Rome, Italy) for translation. We do not store these texts.
- Vote rewards: If you vote for the bot on top.gg, we receive your Discord ID and the time in order to give you a role.
- Minecraft bans: Minecraft name or UUID, reason and time, if a server uses this feature.
- Social media feeds: Public data of the configured YouTube or X channels, no data of server members.
- Blocklist: Discord IDs of users or servers we excluded from the bot for abuse, with reason.
- Team profiles: Team members can voluntarily create a public profile (short name, GitHub name, website, bio). This can be withdrawn at any time (Art. 6(1)(a) GDPR).
We do not read or store private messages between users.
6. Automated moderation
Server staff can enable features that act automatically, e.g. word filters that warn or mute, or a honeypot channel that bans spam bots automatically. The server's staff sets these rules. If you are affected, you can contact that server's staff to have a human review and reverse the decision.
7. Recipients and transfers outside the EU
- [fill in: website_host]: hosting of website, dashboard and bot (data processor).
- Cloudflare, Inc. (USA): DNS and attack protection.
- Discord Inc. (USA): the platform the bot runs on. Your use of Discord is governed by its privacy policy.
- DeepL SE (Germany) and Translated srl / MyMemory (Italy): only for automatic translation.
- top.gg: only if you vote there.
For transfers to the USA, these providers rely on the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses. Authorities only receive data where we are legally required to provide it.
8. How long we keep data
| Data | Retention |
|---|---|
| Hosting provider log files | [fill in: log_retention_days] days |
| Dashboard login cookie | 30 days or until logout |
| Activity statistics and command log | 90 days |
| Ticket transcripts | 365 days after the ticket is closed |
| Error and change logs | 365 days |
| All other server data (settings, XP, warnings, etc.) | While the bot is on the server; deleted within 30 days after removal |
| Blocklist | Until the block is lifted |
Statutory retention obligations remain unaffected. On request we delete earlier (see section 9).
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where we rely on legitimate interests, you may object on grounds relating to your particular situation (Art. 21). You can withdraw any consent at any time with effect for the future.
How: email support@lucwork.de or open a ticket on our support server. Please include your Discord ID. To make sure nobody requests someone else's data, we confirm your identity via Discord. We reply within one month.
Data a server's staff created about you (e.g. a warning) also concerns that staff. You can additionally contact them about it.
10. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live. The authority responsible for us is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf.
11. Do you have to provide data?
No. Without the data described above, however, the dashboard and some bot features will not work. If you do not want the bot to process data about you, you can leave servers where it is active or contact us.
12. Children
The bot is intended for users allowed to use Discord under Discord's rules (at least 13 years old, or older where local law requires). We do not knowingly collect data from younger children and delete it if we become aware of it.
13. Security
All connections are encrypted via HTTPS, login cookies are signed, team accounts use two-factor login, and only the few team members who need it for operations have access to the databases.
14. Changes
We update this policy when features or the law change. The version published here applies. Important changes are announced on our support server.