Data Processing Agreement (DPA)
This Data Processing Agreement (the "DPA" or "Agreement") is a legally binding and inseparable annex to the Terms of Service (TOS) and constitutes a component of the total and indivisible legal framework governing the relationship between you (the "Data Controller") and The epic cake (the "Data Processor" or "The Company"). Capitalized terms used but not defined herein shall have the meaning ascribed to them in the Terms of Service (see TOS, Preamble) and the Privacy Policy (see Privacy Policy, Preamble), each of which is incorporated herein by reference in its entirety. In the event of a conflict between this DPA and any other document in The Company's legal framework, the order of precedence shall be: (1) the Terms of Service; (2) this DPA; (3) the Privacy Policy; except where a mandatory and non-derogable provision of the GDPR, UK GDPR, or Swiss FADP requires otherwise.
Universal Scope: This DPA applies to all Data Controllers (typically Discord server administrators or community owners) who use or deploy any Covered Product or Service, as defined in the Privacy Policy Preamble and the TOS Preamble, on behalf of individuals located within the European Economic Area (EEA), the United Kingdom, or Switzerland. "Covered Products and Services" includes, without limitation, all The epic cake products and the entire Cosmos+ Networks product line, including all current and future sub-systems, modules, premium tiers, and feature expansions, regardless of whether such products exist at the time this DPA was last revised. The mere use or deployment of any such Covered Product or Service constitutes the Data Controller's acceptance of this DPA in its entirety.
1. Roles, Scope, and Purposes of Processing
1.1 Roles: When you add our Services (e.g., Cosmos+, Cosmos+ Networks) to your Discord server, you assume the role of Data Controller with respect to the personal data of your server members. The Company acts as Data Processor, processing such data exclusively to deliver and improve the Services on your behalf and in accordance with the purposes enumerated in this DPA.
1.2 Nature and Purpose of Processing: The Company processes personal data to fulfill the following operational and developmental purposes:
- Delivery of bot functionalities, including moderation, community management, economy and leveling systems, analytics dashboards, and web-based verification (anti-raid security).
- Operation, monitoring, and improvement of technical infrastructure.
- Security auditing, anti-abuse enforcement, and fraud prevention.
- Artificial Intelligence and Machine Learning Development: Collected personal data, including behavioral telemetry, interaction logs, and user-generated content, may be processed as part of The Company's continuous AI/ML development activities. This constitutes a core, non-waivable purpose of processing under our legitimate interests and under the terms of the broader Terms of Service agreement.
- Business intelligence, research, and development (R&D).
1.3 Categories of Data Subjects: Members of Discord servers that have added our Services.
1.4 Types of Personal Data Processed: Discord User IDs, usernames, display names, roles, message activity and telemetry, voice activity data, virtual economy records, and — where the verification features are enabled — Internet Protocol (IP) addresses and email addresses. Additionally, any AI interaction data (prompts, responses, feedback) generated by Data Subjects using AI-powered features.
2. Processing Instructions
The Company will process personal data solely in accordance with the documented and implied instructions of the Data Controller. Such instructions are constituted by: (a) the Data Controller's configuration of our Services; (b) the Data Controller's use of our dashboards and APIs; and (c) the Data Controller's acceptance of our Terms of Service, Privacy Policy, and this DPA. If The Company is required by applicable law to process data beyond these instructions, it shall notify the Data Controller accordingly, unless such notification is prohibited by law.
2.1 Legitimate Interest Basis: Certain processing activities — including long-term security data retention, AI model training, and historical analytics — are conducted by The Company under the legitimate interests basis (Article 6(1)(f) GDPR), independent of specific Controller instructions, where the Company has a demonstrable and overriding legitimate interest in conducting such processing for the integrity and development of the Ecosystem.
3. Sub-Processors
By accepting these Terms, you grant The Company general written authorization to engage the sub-processors listed below, as well as any future sub-processors, to assist in delivering the Services. The Company shall ensure that all sub-processors are bound by data protection obligations at least as protective as those set forth in this DPA. The Company will use reasonable efforts to notify the Data Controller of material sub-processor changes that may affect the processing of their server's data.
3.1 Current Authorized Sub-Processors:
- Infrastructure and Hosting: Cloudflare, Inc. (CDN, DDoS protection, network security, Cloudflare AI Workers); VPS and Dedicated Server Providers.
- Web Analytics: Google Analytics (Google LLC).
- Payment Processing: WHOP, Stripe, Inc., PayPal Holdings, Inc.
- Artificial Intelligence Providers: The following entities may process user data as part of our AI/ML operations:
- Self-Hosted: Proprietary models operated on Company-controlled infrastructure.
- Groq, Inc.: High-performance inference API services.
- xAI Corp. (Grok): Large language model API services.
- Anthropic, PBC (Claude): Claude model family API services.
- Google LLC (Google AI / Vertex AI / Gemini): Machine learning API services.
- OpenAI, LLC (GPT): Large language model API services.
- Cloudflare Workers AI: AI inference at the network edge.
- Future AI Providers: The Company reserves the right to onboard additional AI infrastructure providers in the future without individual prior consent, provided such providers are contractually bound to data protection standards consistent with this DPA.
4. Technical and Organizational Security Measures
The Company implements appropriate technical and organizational measures (TOMs) to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, without limitation:
- Encryption of data in transit and at rest for sensitive data categories (verification logs, IP addresses, email addresses).
- Role-based access controls restricting data access to Authorized Personnel of The Company only.
- Strict internal confidentiality obligations and Non-Disclosure Agreements (NDAs) binding all Company personnel who may access personal data.
- Network-level security protections via Cloudflare and proprietary DDoS mitigation systems.
- Regular internal audits of data access and processing activities.
4.1 Access Restriction (Critical): All raw user data, verification logs, IP addresses, and email addresses are classified as Restricted Data and are accessible solely by formally employed or contracted personnel of The epic cake as a corporate entity. This access right is never extended to Discord server administrators, server moderators, community staff, premium key holders, or any other non-Company individual.
5. Data Subject Rights Assistance
The Company will provide reasonable technical assistance to the Data Controller in fulfilling the Data Controller's obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law (including rights of access, rectification, erasure, restriction of processing, and data portability). Data Subjects seeking to exercise their rights must be directed by the Data Controller to our official support channels (support@theepiccake.org or our official Discord support server) so that we may process the request within our global systems.
5.1 Limitations on Erasure: Data that has been used in the training of AI/ML model weights may be technically infeasible to individually extract and delete from trained models. The Company will make commercially reasonable efforts to honor erasure requests but cannot guarantee the removal of data contributions already incorporated into trained model parameters. Aggregated or anonymized data that can no longer identify a specific individual is exempt from erasure obligations.
6. Data Retention and Deletion
6.1 Operational Data: Non-restricted operational and configuration data specific to a server may be archived or anonymized upon termination of the Services (e.g., removal of the bot from the server). Archival and anonymization processes occur on a rolling basis in accordance with The Company's internal data lifecycle management schedule.
6.2 Perpetual Retention Under Legitimate Interest: The Company retains the following categories of data indefinitely under the legitimate interest basis pursuant to Article 6(1)(f) GDPR, as these serve compelling and overriding legitimate interests that cannot be adequately fulfilled through less permanent means:
- Security and anti-abuse data (including verification logs, IP records, and global ban/blacklist data), retained to prevent the evasion of sanctions by previously banned individuals;
- Anonymized or pseudonymized behavioral and telemetry data used for AI model training and infrastructure analytics;
- Data subject to a legal hold obligation, law enforcement preservation request, or active investigation.
The Data Controller acknowledges and accepts these retention practices as a fundamental condition of using the Services.
7. International Data Transfers
The Company is based in the Commonwealth of Puerto Rico, United States of America. Personal data collected from individuals in the EEA, UK, or Switzerland may be transferred to and processed in the United States and in the jurisdictions of the sub-processors listed in Section 3. Such transfers are made on the basis of Standard Contractual Clauses (SCCs) where required, the EU-U.S. Data Privacy Framework (where applicable), or other legally recognized transfer mechanisms under the GDPR.
8. Breach Notification
In the event of a confirmed personal data breach affecting data processed under this DPA, The Company shall notify the affected Data Controller without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, to the extent that such notification is reasonably practicable. Notification shall include: a description of the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
9. Governing Framework and Precedence
This DPA is governed by the same terms as the underlying Terms of Service — the laws of the Commonwealth of Puerto Rico and applicable United States federal law. In the event of a conflict between this DPA and the Terms of Service, the Terms of Service shall govern except where a mandatory and non-derogable GDPR provision requires otherwise. The dispute resolution mechanism, arbitration requirement, class action waiver, and global jurisdiction clause set forth in the Terms of Service apply fully to this DPA.