Privacy Policy
This policy explains how CordIQ ("we", "us") handles personal data. It covers two separate things: this website, and the Discord bots we build for clients.
1. Who we are
CordIQ is the name two independent developers work under, building custom Discord bots. We act jointly as the data controller for everything described in this policy.
- Contact: contact@cordiq.xyz
Email is the fastest way to reach us and the right channel for anything in this policy. It reaches both of us, and either of us can answer a request about your data.
2. This website
The site itself sets no tracking cookies and runs no advertising trackers.
What we collect
- Enquiry details you type into the contact form - name, email, Discord handle, project type, budget range and your brief.
- Third-party requests. Code libraries are served from a third-party content delivery network, which receives your IP address as a technical necessity of delivering those files to your browser. Fonts are served from this site itself and involve no third party.
Why
To answer your enquiry and, if you become a client, to deliver the work. The lawful basis is legitimate interest for replying to you, and performance of a contract once we are working together.
How long
Enquiries that do not lead to work are deleted within 12 months. Client records - quotes, invoices and the correspondence that supports them - are kept for as long as accounting and tax rules require us to keep them, currently up to 10 years. Anything not needed for that purpose is deleted sooner.
3. Bots we build for clients
This is the part most bot privacy policies get wrong. Under the GDPR, receiving a Discord event containing a user ID is already processing personal data - even if nothing is written to a database.
When we build a bot for a client, roles usually break down like this:
- The client (the server owner) is the data controller. They decide what the bot does and why.
- CordIQ does not host or operate delivered bots. Once a project is handed over, the bot runs on the client's own infrastructure and we have no ongoing access to end-user data. We are therefore not a data processor for live bot data.
- During development we may see limited test data in the client's staging environment. We do not export or retain it, and it is deleted from our machines at handover.
Data a bot may process
- Discord user IDs, usernames and display names
- Server (guild) IDs, channel IDs and role assignments
- Message content, but only where a feature genuinely requires it
- Command usage and timestamps, for diagnostics
- Feature-specific records - economy balances, tickets, warnings and similar
Our defaults
- Data minimisation. We store the least a feature can work with, and prefer IDs over content.
- No message-content retention unless a feature requires it and the client's own policy discloses it.
- No selling or sharing of end-user data with third parties, ever.
- Documented retention windows per data type, agreed with the client in writing.
Each bot we deliver ships with its own privacy policy covering exactly what that bot does. Discord's Developer Policy requires one for every application, and bot verification is refused without it.
4. Who else may see your data
We keep the list of suppliers deliberately short, and each is bound by its own data protection terms. Rather than name companies we may change, here are the categories involved:
- A website host - serves this site and receives contact form submissions
- An email provider - routes and stores mail sent to contact@cordiq.xyz
- A content delivery network - serves code libraries to your browser
- Discord - where we speak to you there, the platform sees that conversation
- A payment provider, where you pay by a method that uses one. Bank transfers do not involve one, and the method used for your project is named on your invoice.
We never sell your data, and we never share it for anyone else's marketing. If you want to know exactly which suppliers we use today, email us and we will tell you.
We do not host client bots, so no bot runtime or database provider is involved on our side. Whichever provider you choose for your bot is your own sub-processor.
5. Your rights
If you are in the EU, UK, or a comparable jurisdiction, you have the right to access, correct, delete, restrict, port, or object to the processing of your personal data.
Email contact@cordiq.xyz and we will respond within 30 days. If your request concerns data held inside a client's bot, we will route it to that client as the controller and support them in answering it.
You also have the right to complain to the data protection authority where you live. Raising it with us first is usually faster, but it is your choice and you do not need our agreement.
6. Security
Credentials are stored in secret managers rather than source code. Access is limited to the two of us. Data is encrypted in transit, and at rest where the provider supports it. We rotate any credential that has been exposed.
7. Children
Our services are not directed at children under 13, or under 16 where local law sets a higher age. Discord's own Terms of Service set the minimum age for the platform.
8. Changes
Material changes will be posted here with an updated date. Active clients are notified by email.
9. Contact
Questions about this policy: contact@cordiq.xyz