BLUEGENJI BOT · PRIVACY

Privacy
Policy

This policy informs you of the data processed by the Discord bot BlueGenji Bot, why it is processed, how long it is kept, who receives it and what your rights are (Articles 13 and 14 GDPR).

Last updated1 October 2026
SECTION 01

Data controller

WHO

The data controller is the association Bluegenji Esport, a French non-profit association under the law of 1901 whose registered office is at 4 impasse des Cyprès, 51210 Janvilliers, France. It has put Keryan Houssin, the website's technical host, in charge of receiving requests about your data; this person is not a data protection officer within the meaning of Article 37 GDPR. The means of contacting them are listed in the Contact section.

The Bot is intended for people aged 15 or over (Terms of Service).

SECTION 02

Data processed and purposes

COLLECTION

Relayed advertisements

ID of the original message and of its author, date, IDs of the relayed copies and of their channels: they are used to relay the advertisement, to pass on its edits or deletion, to apply the cooldown between two advertisements, for the message count of /stats, for the bot's dashboard statistics and, on an exclusion, to find and remove the copies of the excluded user's advertisements. Message content is not stored in the Bot's database: it is copied, with its author's name, into the channels of partner servers, where their members read it. These copies are Discord messages: deleting the original advertisement within 7 days also deletes its copies; after that, they remain until the administrators of the server holding them delete them.

Scrims and recruitment

For the /scrim and /recrute commands: author ID, game, level or role sought, server and date, which feed the activity statistics (/stats command, which only shows each user their own activity, and the bot's dashboard). After 30 days these rows are folded into plain counts per day, server and level (or role), without the author's ID; these counts are kept with no time limit, as a history of the Bot's activity. The level (Débutant, Intermédiaire, Avancé) and the role (Tank, DPS, Heal, Coach, Manager) are chosen from a closed list; a value typed as free text before this rule has been mapped onto the list choice it named exactly, and otherwise replaced with "unspecified", including in the per-day counts.

Relay exclusions

IDs of the excluded user and of the moderator, date, and a reference to the log message holding the reason. The IDs of the excluded user and of the moderator, and the reason, are posted in the staff's private log channel; the reason is also sent by direct message to the Bot's owner. These messages are deleted, in the channel and in the direct messages alike, when the exclusion is lifted (section 03, which details the case of an exclusion issued before this rule). An exclusion applies to the whole network of partner servers: this is community moderation, decided (/ban-user-of-this-server, /ban-user-of-another-server) and lifted (/unban) by the administrators — and the holders of the Bot administration role — of any server with at least 50 members (bot accounts included) where the Bot is installed, as well as, from those same servers, by the Bot's owner and the association's presidency; the association's servers are exempt from this threshold (« Relay moderation » section of the Terms of Service). The /ban-list command therefore shows the full list of network exclusions (usernames, reason, date, ID) to the administrators of any server where the Bot is installed — including a server one creates oneself to invite it — and to the holders of the Bot administration role, so that they know who can no longer post through the Bot and why.

Memberships and scheduled reminders

  • Association memberships (commands restricted to the association's servers): when a member's membership is validated, the Bot sends them the confirmation by direct message, with the membership certificate if one is attached, without keeping it; it then records a reminder for the membership's expiry date — which means keeping, until that reminder, the fact that this member belongs to the association and until when.
  • Scheduled reminders (same commands): ID of the targeted member or role and of the author, message, next sending date and frequency.

Server configuration

IDs of the configured servers, channels and roles, the server's invite, and the ID of the administrator who set the invite or the referee role.

Messages from the BlueGenji website

The website sends the Bot a Discord ID or username and the message to deliver (login code, match reminder, referee alert, report; moderation notice — a report naming you, a team logo masked, removed or deleted —; join request for a team you manage; data-protection notice); the Bot delivers personal messages (code, reminder, moderation notice, join request, data-protection notice) by direct message without storing them. Referee alerts and reports, which name no player (team names and tournament links only), are also posted in the staff's private log channel; referee alerts are also sent by direct message to the members of the referee role of every server that has set one (/set-referee-role), reports to the association's management. This processing falls under the website's privacy policy (in French).

Logs

The public activity feed on the bot's page contains no Discord ID; it repeats the time, the server name and the level or role chosen with /scrim or /recrute. The staff's private log channel and the server logs receive the names of servers that add or remove the Bot, operating errors, which may mention a Discord ID, and the website's activity journal (sign-ups, matches, tournaments), written by the website without any player's username. The Bot no longer writes usernames there on its own (messages older than this rule may quote some): the reason for an exclusion, free text written by the moderator, may quote one, and a failed direct-message delivery may mention the account concerned.

Legal basis

This processing is based on the association's legitimate interest (Article 6(1)(f) GDPR): running the relay between partner servers, moderating it and measuring its activity. Messages from the website rely on the legal basis of their original processing, set out in the website's register.

SECTION 03

Retention periods

RETENTION
  • Tracking of relayed advertisements (IDs, date): 7 days; it is erased at the first relay after that deadline, and at the latest during the night or when the Bot restarts. The copies posted in partner channels remain on Discord (section 02).
  • Scrims and recruitment: 30 days with the author's ID; at the clean-up of the following night (or a restart of the Bot), the author's ID is erased and the rows are folded into counts per day, server and level (or role), kept with no time limit as a history of the Bot's activity.
  • Exclusions: the exclusion record, until it is lifted; the notice and the reason posted in the staff's private log channel, and the reason copied by direct message to the Bot's owner, are deleted when it is lifted. For an exclusion issued before this rule, only the reason posted in the channel is: the rest follows the log channel's period (below).
  • Public activity feed (time, server, level or role of each event): 30 days, deleted at the clean-up of the following night.
  • Server configuration (relayed channels and their rank filters, the invite and the referee role with the ID of whoever set them, the Bot administration role, enabled modules): until the administrators remove it, and at the latest until the Bot leaves the server, which erases it. A departure while the Bot is down, which Discord does not notify, is caught up when it restarts.
  • Memberships and scheduled reminders: until the reminder's last sending (for a membership, its expiry date) or its deletion, and at the latest until the Bot leaves the server where they were recorded, which erases them — including a departure while the Bot is down, caught up when it restarts.
  • Staff private log channel (and the Bot's direct messages to its owner): one year (365 days); older messages from the Bot are deleted by the nightly clean-up, in batches (several nights for a large backlog), except the reason posted in the channel for an exclusion still in force — and, for an exclusion issued from this rule on, its notice and the copy of its reason by direct message —, deleted when it is lifted.
  • Server logs: according to their automatic rotation.
  • Backups: the Bot's database is backed up weekly, encrypted, and each copy is permanently deleted after 30 days at most. A restore is made from these archives, decrypted on the Bot's machine: the database no longer travels through Discord; the copy of the previous database it leaves alongside is deleted at the next successful restore, and at the latest during the night after it turns 30 days old.
SECTION 04

Recipients

WHO HAS ACCESS
  • The association's staff, for moderating and administering the Bot.
  • The Bot's owner (its technical host), who receives exclusion reasons by direct message.
  • The excluded user, to whom the Bot sends the reason for their exclusion by direct message when they post an advertisement (a message naming a service) in a relayed channel.
  • The members of the channel where /scrim or /recrute is used: the command replies publicly there, and Discord shows who used it.
  • Members of partner servers, who read the relayed advertisements.
  • Members of the referee role of every server that has set one, for the website's referee alerts.
  • The administrators of any server where the Bot is installed, and the holders of the Bot administration role each server designates (/set-bot-admin), who can read the list of exclusions (/ban-list command, reply visible only to the person who asked).
  • The technical host, Keryan Houssin, who provides the machine the Bot runs on (a Raspberry Pi in Caen, France): processor.
  • Discord, the platform the Bot runs on.
  • Hetzner Online GmbH (Germany), which stores the backups, encrypted before upload with keys Hetzner does not hold, within the European Union: sub-processor, through the technical host.
  • Microsoft, which hosts the technical host's personal mailbox (Outlook.com), through which any request about your data that you email to them, and their emailed reply, pass without encryption by the association, readable by Microsoft.
  • The technical host's phone operator, if you call them or leave them a text or voicemail about your data.
  • No data is sold, or handed over to any recipient other than those listed here.
SECTION 05

Transfers outside the European Union

TRANSFERS
  • Discord (United States): European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework).
  • Microsoft: possible transfer to the United States, as Microsoft does not guarantee the storage location of a personal account; a request emailed to the technical host, and their emailed reply, reach it without encryption by the association, and so readable by Microsoft — European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework).
  • Since 1 October 2026, backups are sent to Hetzner, in Germany: they are not transferred outside the Union.
SECTION 06

Your rights

GDPR

You have the following rights over your data:

  • Access: find out what data the Bot keeps about you and obtain a copy.
  • Rectification: have inaccurate data corrected.
  • Erasure: have your data deleted; some Bot features may then no longer be available to you.
  • Restriction: have the use of data frozen while a dispute is examined.
  • Objection: object, on grounds relating to your particular situation, to processing based on legitimate interest.

The right to data portability does not apply: this processing is based on legitimate interest, not on consent or a contract. To exercise your rights, use the means listed in the Contact section; you will receive a reply within one month.

If you consider that your rights are not respected, you may lodge a complaint with the CNIL, the French data protection authority.

SECTION 07

Security

PROTECTION
  • The Bot's database lives on the technical host's machine, access to which is restricted to the technical manager (SSH key authentication).
  • Exchanges between the website and the Bot stay on that machine and are protected by a token.
  • Backups are encrypted on that machine before any upload.

No measure makes a system infallible: in the event of a data breach likely to put you at risk, the association is required to notify the CNIL and, if the risk is high, the people concerned (Articles 33 and 34 GDPR).

SECTION 08

Changes to this policy

UPDATES

This policy may change along with the Bot. The version in force is the one published on this page, with its update date; significant changes are announced on the association's Discord server.

SECTION 09

Contact

CONTACT

For any question about your data or to exercise your rights:

  • Person to contact for requests about your data: Keryan Houssin, the website's technical host — email address and phone number in the website's privacy policy (in French). This person is not a data protection officer within the meaning of Article 37 GDPR: the association remains the data controller. This processing (legal basis, data, retention period) is described in the website's privacy policy; its recipients and transfers are also listed in sections 04 and 05 of this policy
  • The “Signaler un problème” form at the bottom of every page of the site (“RGPD” category for your data)
  • The association's email address and phone number: see the legal notice
SECTION 10

Hosting

HOSTING PROVIDER

The bot and the website run on the same machine, a Raspberry Pi in Caen, France, provided and administered by their technical host, Keryan Houssin. The host's full details are set out in the website's legal notice.

See the Hosting section of the legal notice (in French) →