1. What is the GDPR?
The General Data Protection Regulation (GDPR) is a European Union law that gives you control over your personal data. At Roody we are committed to complying with it and protecting your rights.
Our commitment
We respect all of your rights under the GDPR and have put processes in place so you can exercise them easily and effectively.
1.1 Does the GDPR apply to me?
- You reside in the European Union.
- You are an EU citizen even if you live abroad.
- You use Roody while you are in the EU.
Even if you are not covered by the GDPR, we apply the same protection standards to all users.
2. Your rights under the GDPR
Right of access Art. 15
Request a copy of all the personal data we hold about you.
What information will you receive? what data we process, why, who we share it with, how long we keep it, and your rights regarding it.
How to request it: email [email protected] with the subject "GDPR - Access Request".
Right to rectification Art. 16
Request the correction of inaccurate or incomplete personal data.
Examples: incorrect profile information, outdated settings, missing information.
Right to erasure ("right to be forgotten") Art. 17
Request the deletion of your personal data when:
- The data is no longer necessary.
- You withdraw your consent.
- The data has been processed unlawfully.
- You no longer use our services.
What will be deleted: server settings, economy and level data, activity logs, dashboard preferences.
Right to restriction Art. 18
Request that we restrict the processing of your data when:
- You contest the accuracy of the data.
- The processing is unlawful but you do not want erasure.
- You need the data for legal claims.
- You object to the processing.
Right to portability Art. 20
Request your data in a structured, commonly used and machine-readable format (JSON).
Right to object Art. 21
Object to the processing of your personal data in specific situations (direct marketing, legitimate interests, research purposes, profiling).
Response deadline: one month from receiving the request for all of the rights above, extendable by two further months if it is complex (art. 12(3) GDPR).
3. How to exercise your rights
3.1 Simplified process
- Identify your right: review the section above to understand which one to exercise.
- Contact us: by email, Discord or the contact form.
- Verification: we will verify your identity to protect your data.
- Processing: we will respond within the legal deadline of one month.
3.2 Information you should include
Required:
- Your Discord user ID.
- A contact email address.
- A clear description of the right you want to exercise.
- The reason for the request (if applicable).
Optional but helpful:
- The IDs of the servers where you use the bot.
- Approximate dates of the activity.
- Any other relevant information.
3.3 Contact methods
- Email (recommended): [email protected] · subject "GDPR - [type]".
- Discord: discord.roody.es, by opening a support ticket. Email is preferable so that we can verify your identity.
- Web form: /soporte/contacto selecting "Privacy/GDPR" · response 24–72 h.
4. Limitations and exceptions
4.1 When we may deny a request
Legitimate grounds for denial
- Legal obligations: when we must keep data by law.
- Legal defence: if the data is needed to defend claims.
- Third-party rights: if it would affect the rights of other users.
- Security: if it would compromise the security of our systems.
- Unfounded requests: if the request is manifestly unfounded or excessive.
4.2 Data we cannot delete immediately
- Security logs: 6 months (for security reasons).
- Billing records: up to 6 years (art. 30 of the Spanish Commercial Code and tax obligations).
- Fraud investigation: until the case is resolved.
4.3 Fees
Exercising your GDPR rights is free. We may charge a reasonable fee if the request is manifestly unfounded or excessive, if you request multiple copies, or if it requires disproportionate administrative effort.
5. Complaints and remedies
5.1 If you are not satisfied with our response
You have two options:
- Internal escalation: email [email protected] with the subject "GDPR Escalation". Response time 14 days.
- Supervisory authority: in Spain, the Spanish Data Protection Agency, C/ Jorge Juan 6, 28001 Madrid, which accepts complaints online. Each EU country has its own authority.
Your rights matter. We constantly work to improve our processes. If you have suggestions on how we can do better, get in touch.
6. Contact for GDPR matters
Data protection contact
- Email: [email protected]
- Recommended subject: "GDPR - [your request]"
- Languages: Spanish, English
- Hours: Monday to Friday, 9:00 – 18:00 CET
Response times
- Acknowledgement of receipt: as soon as we can.
- Full response: one month from receipt, extendable by two further months if the request is complex, telling you why (art. 12(3) GDPR).
Information to include in your request
- Your Discord user ID.
- A clear description of your request.
- Any other relevant information.
- Your preferred response method.