Privacy Policy

Last updated: 24 August 2026

In the following, we would like to explain to you how your data is processed by us. We strictly adhere to the provisions of the General Data Protection Regulation (DSGVO) when collecting, processing and using your data.

Responsible

Responsible in the sense of the DSGVO is:
Niklas Mueller
Johann-Sebastian-Bach-Str. 23
34134 Kassel
Germany
info@diszy.com

Processed data

Ⅰ. Access files and log files

When you access our website, your device automatically transmits certain data to the web server of our hoster Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany, for technical reasons. Contabo GmbH can be contacted by phone at +49 89 3564717 71, by fax at +49 89 216 658 62, and by email at info@contabo.com. The company is represented by its managing directors Stephan Wolfram and Mario Wilhelm, registered at AG München under HRB 180722, VAT ID DE267602842. This is the recipient of your personal data and acts as a processor for us. A data processing agreement pursuant to Art. 28 GDPR is in place with Contabo GmbH. The server is located in Germany.

1. Scope of data processing

The following data is stored separately from all other data that you can transmit to us:

  • - IP address
  • - the address of the previously visited website (referrer request header)
  • - Date and time of the request
  • - Time zone difference to Greenwich Mean Time
  • - Content of the request
  • - HTTP status code
  • - amount of data transferred
  • - Website from which the request comes
  • - Information about browser and operating system

2. Purpose of data processing

This is necessary to display our website, ensure stability and security, and monitor for potential misuse or attacks.

3. Legal basis for processing

The legal basis for the temporary storage of the data and the log files is Article 6 Paragraph 1 Sentence 1 lit. f GDPR (legitimate interest in the secure and stable operation of the website).

4. Duration of storage

Your IP address and other data will be stored by Contabo GmbH for 14 days and then deleted.

5. Possibility of objection and elimination

The collection of the data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. There is therefore no possibility of objection.

ⅠⅠ. Cookies

Here you will find all cookies that are necessary for the operation of our website and its functions (technically necessary cookies). These are usually set in response to an action you have taken. These include initiation of the payment process via Stripe. Stripe may place additional cookies during checkout to enable secure transactions, as outlined in their Privacy Policy. It is possible to deactivate these cookies in the browser. In this case, error-free functioning of our website can no longer be guaranteed.

Technically necessary cookies

Here you will find all cookies that are necessary for the operation of our website and its functions (technically necessary cookies). These are usually set in response to an action you have taken. These include, among others, registration, login or initiation of the payment process. It is possible to deactivate these cookies in the browser. In this case, error-free functioning of our website can no longer be guaranteed.

Cookie nameHostTypPurposeAdministered dataThird-party serviceValidity period
__stripe_sid / __stripe_mid (Examples)stripe.com, checkout.stripe.comPersistent / SessionPayment processing, fraud prevention, checkout session managementPayment session ID, device info, user behavior data (anonymized)StripeVaries (Session to 1 year or more)Varies (e.g., USA, EU)

Technically unnecessary cookies

Currently, we do not use cookies that are not absolutely necessary for the operation of our website and its functions (technically unnecessary cookies). The use of such cookies constitutes data processing that is only permitted with your active consent (Art. 6 para. 1 p. 1 lit. a DSGVO). This also applies to the transfer of your personal data to third parties.

1. Scope of data processing

next-auth.session-token / __Secure-next-auth.session-token
When logging in via an external authentication provider (Discord), a cookie named next-auth.session-token (or __Secure-next-auth.session-token) is set. In this process, a temporary session is stored. This session includes, in particular:
(1) Authentication information for user recognition (e.g., user ID, login name, authentication provider)
(2) Session metadata required for the technical maintenance of the session (e.g., expiration time)
The data is processed solely to maintain the session, identify the user, and provide personalized features. No data is shared with third parties.

__stripe_sid / __stripe_mid (examples)
When accessing the payment page or initiating the payment process (e.g., via Stripe Checkout), the third-party provider Stripe sets cookies such as __stripe_sid and __stripe_mid. These are used to associate payments, detect potentially fraudulent activities, and technically manage the payment process.
The following data may be processed, among others:
(1) Session and transaction identifiers
(2) Device and browser information (e.g., IP address, user agent)
(3) Timestamps and usage data related to the payment process
This data is partially anonymized or pseudonymized by Stripe and may be used to enhance security and fraud prevention.

2. Purpose of data processing

next-auth.session-token
The processing of the session data serves to execute the login, authenticate the user, maintain the active session, and provide personalized features within the application.
__stripe_sid / __stripe_mid (examples)
The processing is carried out for the purpose of secure and smooth payment processing, fraud prevention, and the association and management of checkout sessions.

3. Legal basis for processing

next-auth.session-token
The legal basis for processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure execution of the login, session management, and the provision of core functionalities of our application.
__stripe_sid / __stripe_mid (examples)
The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary for the performance of a contract or pre-contractual measures. Additionally, Art. 6(1)(f) GDPR may apply if there is a legitimate interest in fraud prevention and system security. Stripe processes the data independently in accordance with its privacy policies.

4. Duration of storage

next-auth.session-token
The data stored during the user session is retained for the duration of the active session and automatically deleted upon expiration (typically 30 days or when logging out).
__stripe_sid / __stripe_mid (examples)
The cookies __stripe_sid and __stripe_mid have different lifespans:
__stripe_sid is a session cookie and is deleted after the session ends,
__stripe_mid may be stored for up to one year to recognize returning users and ensure the security of the payment system.
The exact duration depends on Stripe’s security and processing policies.

5. Possibility of objection and elimination

next-auth.session-token
You can delete individual or all cookies via your browser settings. Additionally, you have the option to disable cookies entirely or restrict them to specific domains via your browser settings.
__stripe_sid / __stripe_mid (examples)
You can delete individual or all cookies via your browser settings. Additionally, you have the option to disable cookies entirely or restrict them to specific domains via your browser settings.

ⅠⅠⅠ. Payment processing via Stripe

If you purchase Diszy Credits, we process personal and transaction data to create the checkout, fulfil the contract, document the declarations made during ordering, issue the invoice and handle a possible withdrawal. Stripe processes the payment and provides billing and payment status information to us.

1. Scope of data processing

  • - Pseudonymous Discord account identifier
  • - Name, email address and billing address provided through Stripe
  • - Stripe customer, checkout and transaction identifiers
  • - Ordered credit amount, currency, gross price and tax information
  • - Order and invoice number
  • - Version, cryptographic hash and snapshot of the accepted terms and withdrawal policy
  • - Time of acceptance, request for early performance, IP address and user agent
  • - If a withdrawal is submitted: its content, contract identifier, confirmation channel, receipt time and delivery status
This data is used for:
  • - Transaction verification
  • - Contract performance and customer support
  • - Accounting, tax retention and proof of the order and withdrawal declarations

2. Purpose of data processing

The processing of this data serves documentation purposes, fulfillment of our contractual obligations, and compliance with legal requirements (particularly tax regulations).

3. Legal basis for processing

The legal bases are Art. 6(1)(b) GDPR for pre-contractual measures, payment and contract performance, Art. 6(1)(c) GDPR for statutory accounting and tax retention, and Art. 6(1)(f) GDPR for fraud prevention and the establishment, exercise or defence of legal claims. The use of Stripe for the requested payment is not described as consent-based processing.

4. Duration of storage

An incomplete checkout record is deleted after 30 days unless it is needed to investigate misuse or establish legal claims. Invoices and transaction records that are accounting documents are regularly retained for eight years, calculated from the end of the calendar year in which the document was created (§ 147(3) German Fiscal Code and § 14b German VAT Act). Business correspondence, including withdrawal correspondence, is generally retained for six years. A longer period applies only where another statutory provision or a pending tax or legal proceeding requires it. Stripe's own processing is described in its privacy policy.

5. Possibility of objection and elimination

Data required for contract performance or a statutory retention duty cannot be deleted on objection or together with a website account. After account deletion, directly identifying authentication data is removed where possible while protected invoice, transaction and consent records remain restricted until the applicable retention period expires.

IV. Bot Submission and Public Profile

When you submit a bot to our platform, we collect and process the information you provide.

1. Scope of data processing

We process the following data:
- Bot Name, ID, Description, Headline
- Images (Avatar, Background)
- Links (Invite, Support, Website, Repository)
- Your User ID (as the owner)
This information is publicly displayed on the bot's profile page.

2. Purpose of data processing

The purpose is to present your bot to other users on our platform and to enable the core functionality of the bot list.

3. Legal basis for processing

The legal basis is Art. 6(1)(b) GDPR (performance of a contract) as you request this service by submitting your bot.

4. Duration of storage

Public bot data is stored until you delete the bot or request its removal. Deleting the login account removes authentication data but does not itself delete public bot entries; these must be deleted separately before account deletion or by contacting support.

5. Possibility of objection and elimination

You can edit or delete your bot at any time via the dashboard or by contacting support.

V. Transactional emails with Brevo

1. Scope of data processing

For sending transactional emails (e.g., order confirmations, cancellation policies, bot status updates), we use Brevo (provided by the German subsidiary Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin; headquarters in Paris).
The following data may be processed:
- Email address
- Order details (e.g., items, total amount)
- Bot details (e.g., name, status)
- Username (if provided)
- Technical metadata (e.g., sending time, delivery status, IP address upon opening, if available)

2. Purpose of data processing

Brevo is used to ensure reliable delivery of transactional emails (confirmation, cancellation information, bot approval/rejection notifications).

3. Legal basis for processing

The legal basis is Art. 6 (1) (b) GDPR (contract fulfillment). Sending these emails is necessary for the execution of the purchase contract.

3.1. Data processing agreement

Brevo's data processing agreement is incorporated into the applicable Brevo contractual terms.

4. Duration of storage

Delivery data is retained only for as long as it is needed to document delivery and troubleshoot failures, subject to the retention settings of the configured Brevo account. Copies that form part of accounting records or business correspondence follow the eight- or six-year periods described above.

5. Possibility of objection and elimination

Objection is not possible, as these emails are necessary for contract fulfillment or for legal reasons (Art. 6 (1) (b) GDPR).

Ⅴ. Email Support with Zoho

1. Scope of data processing

For sending and receiving emails, we use the email service Zoho Mail, provided by Zoho Corporation Pvt. Ltd., Estancia IT Park, Chennai, India.
The following data may be processed:
- Sender and recipient email addresses
- Email content (including any personal data)
- Technical metadata (e.g., IP address, timestamp, delivery status)

2. Purpose of data processing

Zoho Mail is used for efficient and secure email communication with customers, prospects, or other contacts.

3. Legal basis for processing

The legal basis is Art. 6 (1) (f) GDPR (legitimate interest), where our legitimate interest lies in the professional handling of email communication. If the email relates to a contract, Art. 6 (1) (b) GDPR (contract fulfillment) also applies.

4. Duration of storage

Emails are stored in accordance with legal retention periods (e.g., 6 years for business correspondence under § 257 of the German Commercial Code).

5. Possibility of objection and elimination

If processing is based on Art. 6 (1) (f) GDPR, users may object at any time (Art. 21 GDPR).

VI. Artificial Intelligence Services

Our services utilize artificial intelligence provided by Google LLC ("Google Gemini") to generate responses and process user inputs, including text and uploaded files.

1. Scope of data processing

When you interact with the bot or use features like "File Search" or "Knowledge Base", the following data is transmitted to Google:

  • - User inputs (prompts, questions)
  • - Uploaded files (documents, images)
  • - Contextual information necessary for generating a response

2. Purpose of data processing

The data is processed to generate AI-driven responses, summarize content, and perform semantic searches within your uploaded documents.

3. Legal basis for processing

The processing is based on Art. 6(1)(b) GDPR (performance of a contract) to provide the requested AI features.

4. Third-Party Data Processing

Google processes this data on their servers. For more information on how Google handles data, please refer to the Google Privacy Policy and Gemini API Terms.

Your rights

You have the right to information, the right to rectification or deletion, the right to restriction of processing and the right to object to the processing of your data. If you have given us consent, you can revoke this at any time with effect for the future. Please address your objection informally to the above address. In addition, you have the right to data portability. You further have the right to complain about the processing to a supervisory authority. You can find a list of the relevant authorities at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.