Officer ScribeLegal centre
TermsPrivacySubprocessorsData ProcessingData Deletion
Return home
Data Processing Addendum

Controller and processor terms

This Addendum describes how Officer Scribe processes meeting and guild content on the instructions of the guild or organisation that installs the Service.

Effective
3 August 2026
Last updated
3 August 2026
Operator
Adam Collins, trading as Officer Scribe
Contact
ambcollins123@gmail.com

1. Parties and application

This Data Processing Addendum (DPA) forms part of the Officer Scribe Terms of Service. It applies where the guild, community, business or organisation using Officer Scribe (Controller) is a controller of personal data and Adam Collins, trading as Officer Scribe (Processor) processes that data on its behalf.

A person accepting the Terms for the Controller confirms that they have authority to bind it. If the Controller itself acts as a processor for another controller, Officer Scribe acts as its subprocessor and the references to Controller instructions include the lawful instructions of that other controller.

2. Definitions and priority

Terms such as controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meanings given by applicable data protection law, including the UK GDPR and Data Protection Act 2018 where applicable. If this DPA conflicts with the Terms on the processing of personal data, this DPA takes priority.

3. Documented instructions

The Controller instructs Officer Scribe to process personal data only as necessary to provide, secure, support and delete the Service in accordance with the Terms, this DPA, the Controller's dashboard settings and authorised commands. This includes recording and transcribing meetings, generating minutes, managing schedules and actions, sending notifications and providing authorised access to stored records.

Officer Scribe will process personal data only on those documented instructions unless required by applicable law. Where legally permitted, Officer Scribe will inform the Controller before carrying out legally required processing. Officer Scribe will inform the Controller where, in its reasonable opinion, an instruction infringes applicable data protection law and may suspend the affected processing while the issue is resolved.

4. Controller obligations

The Controller is responsible for:

  • ensuring there is a lawful basis and, where required, an additional condition for all data supplied to Officer Scribe;
  • providing clear privacy information and recording notices to data subjects;
  • ensuring every user and meeting participant is at least 18;
  • configuring roles, channels, retention periods and access appropriately;
  • responding to recording objections and excluding anyone who does not wish to participate;
  • ensuring its instructions, content and use of AI output are lawful, fair and proportionate;
  • notifying Officer Scribe promptly of rights requests, security incidents or unlawful content relevant to the Service; and
  • maintaining any records, assessments or consultations required of it by law.

5. Officer Scribe obligations

Officer Scribe will:

  • ensure that people authorised to process Controller data are bound by confidentiality obligations;
  • implement appropriate technical and organisational measures proportionate to the Service and risks;
  • assist the Controller, taking account of the nature of processing and information available, with data-subject requests, security, breach assessment and required impact assessments;
  • notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data;
  • maintain records reasonably required to demonstrate compliance with this DPA;
  • delete or return Controller data at the end of the Service as described below, unless law requires retention; and
  • not sell Controller data or use it for advertising.

6. Security measures

Officer Scribe's measures currently include, as appropriate:

  • TLS-protected network connections and provider-supported encryption at rest;
  • Discord OAuth authentication, signed HTTP-only session cookies and restricted bot API secrets;
  • guild-scoped database queries, Discord permission checks and configurable authorised roles;
  • separation of production secrets from source code and limited administrative access;
  • recording notices, host confirmation, automatic maximum meeting duration and transcript-retention controls;
  • automatic deletion of expired transcripts and scheduled deletion of disconnected guild workspaces;
  • audit records, operational logging and incident investigation; and
  • reasonable dependency, platform and credential maintenance.

The Controller acknowledges that security is shared: Discord account protection, correct role configuration, lawful meeting practice and the sensitivity of submitted content remain under the Controller's control.

7. Subprocessors

The Controller gives general written authorisation for Officer Scribe to use the providers on the current Subprocessor List. Officer Scribe will require subprocessors to protect personal data through written terms appropriate to the services they provide and remains responsible for its obligations under this DPA to the extent required by law.

Officer Scribe will update the list before material new processing begins where reasonably practical. The Controller may object on reasonable data-protection grounds within ten days of publication by emailing ambcollins123@gmail.com. The parties will work in good faith to resolve the objection. If no reasonable alternative exists, the Controller may stop using the affected feature or terminate the Service.

8. International transfers

The Controller authorises processing in the locations identified on the Subprocessor List. Where a restricted transfer requires safeguards, Officer Scribe will rely on an applicable adequacy decision, the UK International Data Transfer Agreement or Addendum, approved standard contractual clauses, a recognised certification framework or another lawful mechanism made available by the relevant provider.

9. Data-subject requests

Where Officer Scribe receives a request relating primarily to Controller data, it may direct the requester to the Controller and will not respond substantively on the Controller's behalf unless instructed or legally required. Officer Scribe will provide reasonable technical assistance available through existing export, correction and deletion functions. Work beyond ordinary product functionality may be subject to reasonable costs where permitted by law and agreed in advance.

10. Personal data breaches

Officer Scribe will notify the Controller without undue delay after confirming a breach affecting Controller data. The notice will include available information about the nature of the incident, likely consequences, affected data or people, mitigation and a contact point. Information may be provided in stages as the investigation develops. The Controller remains responsible for deciding whether it must notify a supervisory authority or affected people.

11. Return and deletion

During active use, authorised administrators can delete guild data through the dashboard and can export individual meeting records using available product functions. When Officer Scribe is removed from a Discord server, the workspace is normally retained for up to three months to allow reconnection or export, then scheduled for deletion. Earlier deletion may be requested through the deletion process.

Deletion removes active database records and Officer Scribe-controlled working files. Provider backups, security logs and data retained under legal obligations may expire later under isolated retention cycles and will not be restored for ordinary product use after deletion.

12. Information and audits

Officer Scribe will make reasonably available information necessary to demonstrate compliance with this DPA, including this DPA, the Subprocessor List and relevant provider security information. If that is not sufficient and applicable law requires more, the Controller may request an audit no more than once per year, except following a confirmed breach or regulator request. Audits must be proportionate, protect other customers and confidential systems, take place on reasonable notice and avoid unnecessary disruption. The Controller bears its audit costs unless the audit identifies a material breach by Officer Scribe.

13. Duration and liability

This DPA begins when the Controller first uses Officer Scribe to process personal data and continues until that processing ends and the data is deleted. Liability under this DPA is subject to the lawful limitations in the Terms, without limiting rights or liabilities that cannot legally be restricted.

Schedule 1 — Details of processing

Subject matterDiscord guild meeting administration, recording, transcription, minutes, actions, schedules, reminders, access controls and related support.
DurationFor active use and the retention periods selected by the Controller, followed by up to three months after disconnection unless earlier deletion, backup expiry or lawful retention applies.
Nature of processingCollection, recording, organisation, storage, retrieval, consultation, transmission to authorised providers, AI transformation, disclosure to authorised guild users, restriction and deletion.
PurposeTo provide the features requested by the Controller and maintain the security and reliability of those features.
Data subjectsGuild administrators, officers, meeting attendees, action owners, invited members and recruitment applicants whose public profile is deliberately submitted.
Personal dataDiscord identifiers and display information; voice audio; speech and transcripts; meeting metadata; agendas; RSVP responses; minutes; decisions; actions; notes; role and channel configuration; public character and performance data; technical logs.
Sensitive dataNot intentionally required. It may be incidentally spoken during a meeting; the Controller must prevent unnecessary collection and ensure any required legal condition.
FrequencyAs initiated by authorised users and continuously for storage, access control, reminders and retention during the Service term.

Schedule 2 — Contact

Processor: Adam Collins, trading as Officer Scribe
Email: ambcollins123@gmail.com
Correspondence address: available upon legitimate request.

Officer ScribeAdam Collins, trading as Officer Scribe
TermsPrivacySubprocessorsData ProcessingData DeletionGuidesSupport DiscordContact
© 2026 Officer ScribeNot affiliated with Blizzard Entertainment.