Data Processing Agreement
Last updated: July 2, 2026
1. Parties
This Data Processing Agreement ('DPA') is entered into between:
- Data Controller: You, as the server owner or organisation that installs TIXY in your Discord server and provides the content to be processed.
- Data Processor: TIXY, operated by an individual business registered in Lithuania under Individuali veikla, certificate No. 1359444.
This DPA forms part of your agreement with TIXY and is incorporated by reference into the Terms of Service.
2. Subject matter and duration
TIXY processes the following personal data on your behalf as a data processor:
- Discord ticket messages and metadata (user IDs, timestamps, channel IDs)
- Knowledge base content you upload (documents, Q&A pairs, indexed web pages)
- Server configuration data (ticket categories, AI settings, staff roles)
Processing begins when you install TIXY and continues until you delete your account or remove TIXY from your server, after which data is deleted within 30 days.
3. Nature and purpose of processing
TIXY processes personal data for the following purposes:
- Generating AI-powered responses to Discord support tickets using your knowledge base
- Storing ticket transcripts and analytics for your dashboard
- Enforcing your configured ticket categories and AI settings
4. Categories of data subjects
The personal data processed under this DPA relates to:
- Discord server members who open tickets or whose messages are processed
- Server staff members with access to ticket data
5. Sub-processors
TIXY engages the following sub-processors to provide the service. All are subject to data protection obligations equivalent to those in this DPA:
- Stripe (USA) — payment processing (billing data only)
- OpenRouter / OpenAI-compatible models (USA) — AI response generation; your data is not used to train third-party models under our agreement
- Railway (USA) — API server hosting
- Neon (USA) — PostgreSQL database hosting
- Cloudflare (USA) — CDN, file storage (R2), and email routing
Where data is transferred outside the EU/EEA, TIXY relies on Standard Contractual Clauses or adequacy decisions in accordance with GDPR Article 46.
6. Security obligations
TIXY implements appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS 1.2+) and at rest
- Access controls and multi-factor authentication for production systems
- Regular security reviews and updates
7. Breach notification
TIXY will notify you without undue delay if we become aware of a personal data breach that poses a risk to the rights and freedoms of data subjects, in accordance with GDPR Article 33.
8. Assistance with data subject rights
Upon your reasonable request, TIXY will assist you in fulfilling your obligations under GDPR Articles 15 to 36 (data subject access, rectification, erasure, restriction, data portability, objection, and related rights) to the extent required by law and technically feasible.
9. Return or deletion of data
Upon termination of your account or removal of TIXY from your server, TIXY will delete all personal data processed on your behalf within 30 days, except where required by applicable law to retain certain records (e.g., billing data under Lithuanian accounting law).
10. Governing law
This DPA is governed by the laws of the Republic of Lithuania. Any dispute arising from this DPA shall be submitted to the exclusive jurisdiction of the competent courts of Lithuania.
11. Contact
For questions about this DPA or data processing, email privacy@tixybot.com.
