Data Processing Agreement
Last updated: September 14, 2026
1. Scope and Parties
This DPA is between JTF LABS PTY LTD (ABN 93 693 353 347), which operates Ticket Tool ("we", "us", "our"), and the person or entity that adds Ticket Tool to a Discord server, holds a subscription, or operates an organization on Ticket Tool ("Customer", "you").
It applies to the extent that Data Protection Law applies to our processing of Customer Personal Data in providing the Service. It does not change how we handle personal data we process as a controller, which is governed by our Privacy Policy.
2. Definitions
Terms not defined here have the meaning given in our Terms of Service. "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR.
- "Customer Personal Data" means personal data that end users and staff submit through the Service in your Discord servers, which we process on your behalf. It includes ticket messages, attachments, transcripts, form and modal responses, and the Discord identifiers attached to them. Annex I describes it in full.
- "Account Data" means personal data we process as a controller to run our business: dashboard account and login data, billing and subscription records, support correspondence with you, security and fraud logs, and website analytics.
- "Data Protection Law" means all laws that apply to the processing of Customer Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as retained in UK law ("UK GDPR") and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Australian Privacy Act 1988 (Cth), and the California Consumer Privacy Act as amended by the CPRA ("CCPA").
- "SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- "Sub-processor" means a third party we engage to process Customer Personal Data.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data held by us or our Sub-processors.
3. Roles of the Parties
- Customer Personal Data: you are the controller (or a processor acting for your own controller) and we are your processor (or sub-processor). You decide whether to use Ticket Tool in your server, which features to enable, what information your ticket forms collect, who on your team can read tickets, and how long tickets and transcripts are kept.
- Account Data: we are an independent controller. This DPA does not apply to it; our Privacy Policy does.
- CCPA: to the extent Customer Personal Data is personal information under the CCPA, we act as your service provider. We will not sell or share it, retain, use or disclose it outside the direct business relationship with you or for any purpose other than providing the Service, or combine it with personal information we receive from other sources except as the CCPA permits. We will tell you if we can no longer meet these obligations.
Discord is not our Sub-processor. You and your end users use Discord under Discord's own terms, and Discord processes their data as an independent controller. Copies of tickets or transcripts that the Service posts into your Discord channels at your direction are held by Discord and controlled by you once posted.
4. Customer Obligations
You are responsible for:
- having a lawful basis for the processing you instruct, and giving end users any notice Data Protection Law requires, including that their ticket messages are stored by a third-party service;
- not using the Service to collect special category data (such as health, biometric, or government identifier data) or data about children under 13, unless you have assessed that doing so is lawful and appropriate;
- the settings you choose, including retention periods, transcript destinations, staff roles and permissions, and whether AI features or third-party integrations are enabled; and
- keeping your dashboard accounts and Discord administrator accounts secure.
Your configuration of the Service, your use of its features, and this DPA together are your complete documented instructions to us. Any additional instruction needs our written agreement.
5. Our Obligations as Processor
For Customer Personal Data, we will:
- process it only on your documented instructions, unless the law requires otherwise, in which case we will tell you first where the law allows;
- tell you promptly if we believe an instruction infringes Data Protection Law;
- ensure that everyone we authorize to process it is bound by confidentiality obligations and has access only as needed to provide, support, or secure the Service;
- not use it to train, fine-tune, or improve any artificial intelligence model, and send it to an AI Sub-processor only when you have enabled an AI feature;
- not use it for advertising, profiling, or any purpose of our own, other than aggregated, de-identified service metrics that do not identify you or any individual; and
- give you reasonable help, taking into account the nature of the processing and the information available to us, with data protection impact assessments and prior consultations with a supervisory authority.
If you connect your own AI provider key, SMS provider account, or other integration, data sent to that provider is sent at your direction under your agreement with that provider. That provider is not our Sub-processor.
6. Security
We implement and maintain the technical and organizational measures in Annex II, which are designed to protect Customer Personal Data against Personal Data Breaches and to ensure a level of security appropriate to the risk. We may update these measures over time, but we will not reduce the overall level of protection.
7. Sub-processors
You give us general authorization to engage the Sub-processors listed in Annex III, and to engage new ones as set out below.
- We impose data protection obligations on each Sub-processor by written contract that are no less protective than those in this DPA, to the extent they apply to the service it provides.
- We will give at least 30 days' notice before a new Sub-processor starts processing Customer Personal Data, by publishing a new revision of this DPA and emailing the account owner of each paid subscription.
- You may object on reasonable data protection grounds within that period by emailing ppa.loot-tekcit@ycavirp. We will work with you in good faith to resolve it. If we cannot, you may cancel the affected subscription and we will refund any prepaid fees for the period after cancellation.
- We remain responsible to you for our Sub-processors' performance of their data protection obligations.
We may replace a Sub-processor without notice in an emergency that threatens the security or availability of the Service. We will then notify you as soon as reasonably possible, and your right to object still applies.
8. Data Subject Requests
The dashboard lets you view, export, and delete tickets and transcripts, and set retention periods for your server. Taking into account the nature of the processing, we will provide further reasonable assistance to help you respond to requests from data subjects to exercise their rights under Data Protection Law.
End users often cannot identify, or reach, the operator of the server they opened a ticket in. If a data subject sends a request about Customer Personal Data to us directly, we will verify their identity and may act on a verified request for access or erasure of their own data ourselves, telling you where we can identify you. We will not otherwise respond to the request except to direct the data subject to you, unless the law requires us to.
9. Personal Data Breaches
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting your Customer Personal Data. We will send notice to the account owner's email address and, where email is unavailable, through Discord.
The notice will describe, as far as the information is available at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point. We will provide further information as it becomes available and take reasonable steps to contain and remediate the breach.
Our notification is not an acknowledgment of fault or liability.
10. Audits and Information
We will make available the information reasonably necessary to demonstrate our compliance with this DPA and Article 28 of the GDPR. We will do this first by answering a reasonable written security questionnaire, no more than once in any 12-month period.
If that information is not enough to demonstrate compliance, or a supervisory authority requires it, you or an independent auditor bound by confidentiality may audit our compliance. You must give at least 30 days' written notice, and the audit must be conducted during business hours, limited to the systems that process your Customer Personal Data, without access to other customers' data, and at your cost. Audits are limited to once in any 12-month period unless a Personal Data Breach has occurred or a supervisory authority requires otherwise.
11. International Transfers
We process Customer Personal Data in the United States, and our Sub-processors process it in the locations listed in Annex III. We will only transfer Customer Personal Data internationally in compliance with Data Protection Law.
11.1 EEA transfers
Where Customer Personal Data subject to the GDPR is transferred to a country that has no adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) applies where you are a processor. You are the data exporter and we are the data importer.
- Clause 7 (docking clause) does not apply.
- Clause 9(a): Option 2 (general written authorization) applies, with the notice period in Section 7 of this DPA.
- Clause 11(a): the optional language does not apply.
- Clause 13(a): the competent supervisory authority is the one determined by Clause 13(a) and the data exporter's establishment or representative.
- Clauses 17 and 18: the SCCs are governed by the law of Ireland, and disputes are resolved by the courts of Ireland.
- Annexes I and II of the SCCs are completed by Annexes I and II of this DPA. The list of sub-processors is Annex III of this DPA.
11.2 UK transfers
Where Customer Personal Data subject to the UK GDPR is transferred, the UK Addendum is incorporated by reference and completes the SCCs as follows: Table 1 is completed with the parties' details in Section 1 of this DPA; Table 2 selects the modules and clauses in Section 11.1; Table 3 is completed by Annexes I to III; and in Table 4, either party may end the UK Addendum as set out in its Section 19.
11.3 Swiss transfers
Where Customer Personal Data subject to the Swiss Federal Act on Data Protection is transferred, the SCCs apply as described in Section 11.1, with references to the GDPR read as references to that Act, the competent supervisory authority being the Federal Data Protection and Information Commissioner, and "Member State" not interpreted so as to exclude data subjects in Switzerland from suing for their rights in their place of habitual residence.
11.4 Australia
For Customer Personal Data subject to the Australian Privacy Act, we take reasonable steps to ensure that overseas recipients do not breach the Australian Privacy Principles, as required by APP 8.
If there is a conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum prevail.
12. Deletion and Return
You can export and delete tickets and transcripts from the dashboard at any time during your use of the Service. When you stop using the Service, you can export your data or ask us to delete it.
If you remove Ticket Tool from your server, we keep your configuration and Customer Personal Data so you can re-add it later, unless you ask us to delete it. On a written deletion request from the server owner or account owner, we will delete Customer Personal Data for that server from our live systems within 30 days. Deleted data can remain in encrypted backups until they rotate out, within 60 days. We do not restore deleted data from backups except to recover from an incident, and we re-apply outstanding deletions after any restore.
We may keep Customer Personal Data where the law requires us to. If we do, this DPA continues to apply to it and we will process it only for that purpose.
13. Liability
Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in our Terms of Service, or in any other agreement between us that governs your use of the Service. Nothing in this Section limits either party's liability to data subjects under the SCCs, or any liability that cannot be limited under applicable law.
14. Term, Precedence and Changes
This DPA applies for as long as we process Customer Personal Data on your behalf. Sections that by their nature should survive, including Sections 9, 12 and 13, survive its end.
If there is a conflict, the following order applies: the SCCs and UK Addendum where they apply, then this DPA, then our Terms of Service.
We may update this DPA to reflect changes in law, in our Sub-processors, or in the Service. We will give at least 30 days' notice of material changes as described in our Terms of Service. We will not reduce the protection this DPA gives Customer Personal Data, except where the law requires it.
Except for the SCCs, which are governed as set out in Section 11, this DPA is governed by the laws of Victoria, Australia, and the courts of Victoria have exclusive jurisdiction, subject to any mandatory rights you have under Data Protection Law.
Annex I: Description of Processing
| Data exporter | Customer, as identified in Section 1. Activities: operating a Discord server or organization that uses Ticket Tool for support, moderation, applications, or community management. |
|---|---|
| Data importer | JTF LABS PTY LTD (ABN 93 693 353 347), Victoria, Australia. Contact: privacy@ticket-tool.app. Activities: providing the Ticket Tool Discord bot and web dashboard. |
| Categories of data subjects | End users who open, reply in, or are added to tickets or submit forms in Customer's servers; Customer's staff, moderators, and team members; other Discord users mentioned in ticket content. |
| Categories of personal data | Discord user IDs, usernames, display names, and avatars; server role and membership information needed to route and permission tickets; ticket message content, attachments, and transcripts; form, modal, and application responses; ticket metadata (timestamps, categories, status, assignees, ratings and feedback); notes and variables created by Customer's flows; AI-generated summaries and suggested replies when AI features are enabled; phone numbers of staff who opt in to SMS notifications. |
| Sensitive data | None intended. Customer controls what its forms ask for and what end users choose to write, and must not use the Service to collect special category data without an appropriate assessment (Section 4). The measures in Annex II apply to all Customer Personal Data. |
| Frequency of transfer | Continuous, for as long as Customer uses the Service. |
| Nature of processing | Collection, storage, organization, retrieval, display, transmission back to Discord, transcript generation, search and semantic indexing, analytics aggregation, AI inference (when enabled), backup, and deletion. |
| Purpose | Providing, securing, and supporting the Service for Customer under the Terms of Service. |
| Retention | For the duration of the Service, subject to the retention settings Customer configures and Section 12. Backups rotate within 60 days. |
| Sub-processor transfers | As listed in Annex III, for the subject matter, nature, and duration described there. |
Annex II: Security Measures
- Encryption: TLS for all data in transit over public networks; AES-256-GCM encryption of stored secrets such as integration credentials and API keys; encrypted off-site backups.
- Tenant isolation: every request for a ticket, transcript, or configuration record is checked against the server or organization it belongs to before data is returned.
- Access control: dashboard sign-in through Discord OAuth with optional two-factor authentication; role-based permissions inside each server; internal staff access granted by narrow, separately scoped permissions, with the most sensitive (such as unmasked personal data and erasure) restricted to named operators.
- Accountability: audit logging of administrative, billing, and staff actions, including staff access to customer dashboards.
- Application security: CSRF protection and rate limiting on state-changing requests, input validation, restrictive CORS and security headers, content-type sniffing and sandbox protections on user uploads, and secret scanning before code is committed.
- Network: production servers sit behind Cloudflare's DDoS protection; databases and internal services are not exposed to the public internet; administrative access is key-only over a private network.
- Availability and resilience: continuous database write-ahead-log archiving for point-in-time recovery, nightly backups, a second backup copy with a separate provider in a different region, and periodic restore testing.
- Monitoring: uptime, resource, and backup monitoring with alerting; error monitoring with session replay captured only on errors and with text content masked.
- Change management: changes are built and checked in CI and deployed through a health-gated process that rolls back automatically on failure.
- Data minimization: the bot stores message content only from ticket channels, not from the rest of a server; Customer-configurable retention and automatic deletion.
- Incident response: a documented process for assessing, containing, and notifying Personal Data Breaches, and a breach register.
Annex III: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| OVH US LLC | Hosting of production servers and databases | United States (Virginia) |
| Cloudflare, Inc. | CDN, DDoS protection, and TLS termination; encrypted backup and file storage (R2) | United States and global edge network |
| Cloudflare, Inc. | AI inference, only when Customer enables AI features (Workers AI) | United States and global edge network |
| Hetzner Online GmbH | Secondary encrypted backup copy | Germany |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
| Resend, Inc. | Transactional email, such as notifications and data exports | United States |
| Add Rabbit LLC (Purelymail) | Email hosting for our support and privacy inboxes, which hold any personal data included in emails sent to us | United States |
Stripe, Inc. processes billing data as an independent controller and Google LLC processes website analytics. Neither receives Customer Personal Data, so neither is listed here; both are described in our Privacy Policy.