Data processing terms
When your members sign in on your site, you decide what happens to their data and we carry it out. This page is that agreement — the one Article 28 of the GDPR asks for.
Last updated 1 September 2026. Written in plain English on purpose.
Who is who
You, the site owner, are the controller. You decide which questions to ask your members and what to do with the answers. Communio, run by Greenbo Studios, Denmark, is the processor. We only handle that data to run the service for you.
These terms take effect when you create a site and last as long as you have one. They are part of the terms of service. For your own account — your name, your email, your billing — we are the controller, and the privacy page covers that instead.
What we process for you
| Subject matter | Running a community website and its member features |
| Duration | As long as you have a site with us |
| Purpose | Sign-in, member profiles, applications, playtime, roles on your Discord server |
| Categories of data | Discord id, username, display name, avatar, last seen, Discord roles, profile and character details, application answers, playtime |
| Categories of people | Members and applicants of your community |
We do not ask for special categories of data. If you build an application form that asks for health, religion, political views or anything else in that class, that is your choice and your responsibility — and you need a legal basis for it.
What we promise
- We process member data only on your instructions — using the product is the instruction — unless EU or Danish law requires otherwise, in which case we tell you first if we are allowed to.
- Everyone with access to the data is bound to keep it confidential.
- We keep the security measures described on the privacy page: HTTPS everywhere, hashed passwords, hashed session keys, and access limited to the people who run the service.
- We help you answer your members when they ask for a copy, a correction or a deletion — the dashboard already lets you do most of it yourself.
- We help you with security assessments and with notifying the authority, to the extent it concerns what we hold.
- When you close your site, we delete the member data, unless the law says we must keep something.
- We give you the information you need to show you comply, and we accept an audit — a written set of questions, or an inspection at your cost if that is not enough.
If something goes wrong
If we discover a breach that affects your members, we tell you without undue delay and within 48 hours, with what we know: what happened, who is affected, what we have done. You are the one who reports it to Datatilsynet — it is your data — and we give you what you need to do it.
Who we use
You agree that we use these sub-processors. If we want to add or replace one, we tell account holders by email at least 30 days first, and you can object by closing your site before the change takes effect.
| Who | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage and outgoing email for the whole service. | EU and worldwide edge network |
| Discord Netherlands B.V. / Discord, Inc. | Sign-in with Discord, and role changes on a community's own Discord server. | EU and United States |
Both are bound by terms no weaker than these. Where data leaves the EU it does so on the European Commission's standard contractual clauses.
What you promise
- That you have a legal basis for what you collect, and that you have told your members about it.
- That you do not put data into the product that has nothing to do with running your community.
- That you answer your members within a month when they ask about their data.
- That you only give staff access to people who need it, and take it away when they leave.
Asking us something
Write to privacy@communio.page. If you need this agreement signed on paper for your own records, ask and you get it.