Data Processing Agreement
Version 2026-09-10 · effective 2026-09-10
These terms apply when you use Titan Community to process personal data about other people — for example applicants who fill in your forms, or members who open tickets. They form part of our Terms of Service.
1. Parties and roles
You (the organisation that created a Titan Community organization) are the controller. Titan Software z.s., Ametystová 702/46, 153 00 Praha 16, Czech Republic, IČO 29738725, is the processor.
We act as an independent controller, not as your processor, for data we need to run the platform itself: your account, authentication, billing, fraud and abuse prevention, platform security, and our legal obligations. Our Privacy Policy covers that processing.
2. Subject matter, duration, nature and purpose
Subject matter: providing the Titan Community ticketing and forms/applications service.
Duration: for as long as your organization exists, plus the retention periods in section 8.
Nature and purpose: storing, displaying, transmitting to Discord and deleting the content your community submits, so that your staff can run support and review applications.
3. Types of personal data and categories of data subjects
Data subjects: members of your Discord server, applicants to your forms, and your own staff.
Types of data: Discord user identifiers, usernames, display names and avatars; messages sent in ticket channels created by our bot; answers submitted to your forms; reviewer notes and decisions; and a pseudonymised hash of the submitter’s IP address for abuse control.
You choose what else is collected. Because you write your own form questions, you may collect categories of data we cannot anticipate. You are responsible for having a lawful basis for that, for telling data subjects about it, and for not collecting special category data (Article 9) unless you have a valid condition for doing so. Our fields are free text; we do not inspect them.
4. Processing on documented instructions
We process this personal data only to provide the service, as configured by you in the dashboard, and as described in our documentation. Your configuration and your use of the product are your instructions. We will not process it for any other purpose.
If we believe an instruction breaches data protection law, we will tell you and may suspend that processing.
5. Confidentiality
Access to your data is limited to the people who need it to operate or support the service, and they are bound by confidentiality obligations.
6. Security (Article 32)
Measures implemented in the product:
- Encryption in transit (HTTPS) for all access.
- Secrets at rest — Discord authorisation tokens and webhook signing secrets — encrypted with AES-256-GCM.
- Credentials stored only as one-way hashes: session tokens, invitation tokens and transcript share tokens.
- Strict tenant separation: every request resolves your organization and every query is scoped to it.
- Granular, role-based staff permissions inside your organization.
- An audit log of administrative actions, and a platform security event log.
- Input validation, output sanitisation and rate limiting on public endpoints.
For the current, detailed description — including known limitations — see docs/SECURITY.md in the product repository.
7. Sub-processors
You give general authorisation for us to engage the sub-processors listed on our sub-processors page. We impose data protection obligations on each of them equivalent to those in this agreement, and we remain responsible to you for their performance.
We will give you reasonable notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may terminate the affected service.
8. Deletion and return
You can delete individual tickets, submissions and forms at any time, and delete your whole organization from Settings. Deleting an organization removes its content permanently after a 30-day recovery window.
Content is also deleted automatically once it reaches the end of its retention period:
- Ticket messages: deleted once a closed ticket falls outside your plan’s history window (14 days on Free, 180 days on Community, 730 days on Pro).
- Form submissions and answers: 730 days.
- Webhook delivery records: 30 days.
- Administrative audit log: 730 days.
You can export your data before deleting anything using the export tools in the dashboard. On termination we delete your content per the above; we do not keep a copy beyond our backup rotation.
9. Assistance with your obligations
Data subject requests. The dashboard lets you find, edit and delete individual records, which is normally enough to answer a request yourself. If you need more, contact us and we will assist.
Breach notification. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and provide the information you need to meet your own Article 33 obligation.
Impact assessments. On request we will provide the information you reasonably need for a DPIA or a prior consultation, to the extent it concerns our processing.
10. Audit
On reasonable written request, and not more than once a year unless required by a supervisory authority, we will provide the information necessary to demonstrate compliance with this agreement. We may satisfy this by supplying documentation rather than granting on-site access, where that is sufficient.
11. International transfers
Our infrastructure is operated within the EU. Two sub-processors may involve transfers outside the EEA — Discord and Stripe — and are listed with their transfer mechanism on the sub-processors page.
12. Acceptance
These terms take effect when you create an organization or continue using the service after they are published, and they form part of our Terms of Service. Where they conflict with the Terms in respect of personal data processed on your behalf, these terms prevail.