---
title: "Privacy Policy - Discord Server | DonQuaan"
description: "How the Server collects, stores, protects and returns Members' personal data (Law 91/2025/QH15 and Decree 356/2025/ND-CP on personal data protection)."
image: "https://donquaan.com/og-hero.png"
url: "https://donquaan.com/en/discord/privacy"
lang: "en"
---

[DonQuaan Community Legal Framework](https://donquaan.com/en/discord)

PRV Privacy Policy

# Privacy Policy

Version 4.0 · Issued 11/08/2026 · Effective 18/08/2026 · Legacy ref: VK-04 · P.II

This English text is a courtesy translation. The Vietnamese version is the sole authoritative text (Article on Language).

This instrument is the Privacy Policy (cite code PRV) of the DonQuaan Community Legal Framework. It governs the collection, use, retention, sharing, protection and deletion of personal data within the scope of the Discord Server bearing identifier 1342729473245577267. PRV is the canonical instrument on data within the Community Legal Framework: where other instruments touch upon data, they shall cross-refer to this instrument. This instrument shall be binding upon Members, Staff and the Owner from the effective date posted in the document control block.

---

# CHAPTER I - GENERAL PROVISIONS

### Article 0. Scope and principles of interpretation

0.1. This instrument determines how the Server collects, retains, protects and returns the personal data of Members, in accordance with Luật 91/2025/QH15 (the Law on Personal Data Protection) and Nghị định 356/2025/NĐ-CP (the Decree on personal data protection). The allocation of responsibility between the Server, the operating team and Members is set out in [DIS](https://donquaan.com/discord/disclaimer), issued as a separate instrument.

0.2. Principle of conditional disclaimer. Any disclaimer clause relating to this instrument shall take effect only where the Server simultaneously performs the accompanying affirmative duty stated in that same clause (issuing warnings, removing infringing content, directing victims to the correct legal channel). A disclaimer may not be invoked to refuse duties mandated by Vietnamese law or by Discord; a disclaimer clause whose accompanying affirmative duty has not been performed shall have no effect in respect of the corresponding matter.

0.3. Principle of interpretation in favour of the weaker party. Where a clause admits of two readings, the reading more favourable to the Member shall prevail, unless that reading would result in a breach of law or of the [Discord ToS](https://discord.com/terms).

0.4. Principle of equality before the instrument. This instrument binds Members, Moderators, Admins, Head Admins and the Owner alike. No clause confers upon the Owner or the team any privilege beyond the written framework. The anti-impersonation provisions at DIS Section 8 create no privilege for the Owner; the limits of those provisions are stated at DIS Section 8.4.

0.5. Hierarchy. This instrument ranks below (a) Vietnamese law and (b) the [Discord Terms of Service](https://discord.com/terms) together with the [Discord Community Guidelines](https://discord.com/guidelines); it ranks equally with the other instruments of the Community Legal Framework: [TOS](https://donquaan.com/discord/tos), [CoC](https://donquaan.com/discord/rules), [ENF](https://donquaan.com/discord/rules/enforcement), [APL](https://donquaan.com/discord/rules/appeals), [DIS](https://donquaan.com/discord/disclaimer), [STF](https://donquaan.com/discord/rules/staff), [OWN](https://donquaan.com/discord/rules/owner) and the annexes. In areas of overlap: PRV is canonical on data; discipline and evidentiary standards follow the ENF canon; appeals follow the APL canon; the register of Official Channels follows the TOS canon. Other instruments shall cross-refer only and must not restate details divergently. Everything Discord prohibits is prohibited on the Server, even where this instrument does not repeat it. Any clause conflicting with the law or with the Discord ToS shall be void as to that clause alone, and the remaining clauses shall remain in force.

0.6. Consent. Members confirm that they have read and agreed to this instrument through Discord's rules screening mechanism upon joining the Server. Continued participation in the Server after the effective date of an amendment shall be deemed acceptance of that amendment, provided that the Server has given public notice in accordance with Article 22. Consent to the processing of a minor's data applies in accordance with Article 18.1(e).

---

# CHAPTER II - PROCESSING OF PERSONAL DATA

### Article 10. Data processing principles

10.1. The Server shall process personal data according to five principles: (a) minimisation - collecting only what is genuinely necessary for the stated purpose; (b) purpose limitation - data collected for a given purpose may be used only for that purpose; (c) time limitation - data shall be deleted upon expiry of its retention period, the sole exception being the Special Log category under Article 11.1, which is confined to a stated basis and a narrow scope; (d) access limitation - the number of persons able to view data shall be kept to the lowest level, by role and by matter; (e) transparency - Members are entitled to know what the Server holds about them.

10.2. Prohibition on sale, lease or exchange of data. The Server shall not sell, lease or exchange the personal data of Members to any party, for any commercial purpose, without exception. This undertaking is unconditional and unlimited in time. Any person, including a member of the team, who sells or disseminates Member data commits a personal breach of the law (Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree); Article 288 of the Bộ luật Hình sự (the Penal Code) where the constituent elements are met). The Server shall support victims in exercising their rights of complaint and denunciation against the offender, including where that person is or was a member of the team.

10.3. Two tiers of data are distinguished: (a) data held by Discord (registration email, IP address, verified telephone number, private message content), which is governed by Discord's privacy policy and to which the Server has no access; (b) data held by the Server, comprising only what is listed in Article 11. Requests concerning tier (a) data must be addressed to Discord.

10.4. Boundary with the official web platform. Data provided by Members when registering for or using the ecosystem's official web platform ([donquaan.com website](https://donquaan.com/)) - for example account information or a registered telephone number - is governed by that platform's own privacy policy, published on that website. This instrument governs only data within the scope of the Discord Server. The two systems shall not commingle data for purposes outside each party's published statements; the prohibition on the sale of data at Article 10.2 covers both. Questions or rumours about the web platform's data shall be answered publicly by reference to that platform's policy; the Server shall not delete the post and shall not take action against the person asking (Article 16.7).

### Article 11. Scope of collection, purpose, retention period and viewing rights

11.1. Data map. The Server shall process only the following data categories. Data not appearing in this table shall not be collected; any additional collection requires a prior amendment to this instrument.

| # | Data category | Content | Purpose | Retention period | Who may view |
| --- | --- | --- | --- | --- | --- |
| 1 | Platform identity | Username, user ID, display name, avatar, join date | Operations, permissioning, identification when handling matters | For as long as the person is a Member | Public in accordance with Discord's mechanism |
| 2 | Public content | Messages and posts in Server channels | Community operations, moderation | Per Discord's retention mechanism; the Server does not perform bulk backups beyond category 4 | Members with permission to view the channel |
| 3 | Moderation log (mod log) | Sanction records: user ID, conduct, clause invoked, evidence (message ID or link), handler, timestamp | Fair enforcement of discipline, resolution of appeals, anti-bias statistics | 24 months, then deleted or anonymised, save for the portion transferred to category 10 | The team, per the tiers at Article 13 |
| 4 | Bot message logs, including messages deleted or edited in public channels | Content, ID, timestamp | Investigation of violations (spam, fraud, doxxing, systematic provocation), prevention of evidence destruction | 90 days; messages forming part of a case file follow category 5 | All serving Staff (Tier 1, Article 13.2); logs of the confidences channel fall under Tier 2 - Head Admin and above and the Owner (Article 11.3) |
| 5 | Case files with a legal dimension (doxxing, fraud, threats, child abuse) | Metadata, extracted evidence, timestamped handling records | Legal obligations, service of appeals, provision to competent authorities | Until the relevant legal obligation or limitation period expires | A narrow group of 02-03 pre-identified, named persons per matter (Tier 3, Article 13.2) |
| 6 | Prize award information | Full name, bank account number, address and telephone number of the winner, only where the prize so requires | Award of the prize | Deleted within 30 days after the award is completed | Exactly 02 persons designated in the prize rules |
| 7 | Emergency contact details of the team | 01 contact channel outside Discord, provided voluntarily upon assuming a role | Solely: crisis situations concerning human safety | Until departure from the team; deleted at offboarding | Head Admin; the Owner acts as fallback where the Head Admin is absent or is a party |
| 8 | Complaints, reports and denunciations | The content of the submission and accompanying data | Correct resolution of the matter | Per the period for category 3 or category 5, according to its nature | The handling officer under the single-window procedure |
| 9 | Fund and donation records | Transaction identifiers on the bank statement (bank display name, amount, time) | Transparent fund reconciliation under DIS Section 5.7 | 24 months | 02 fund custodians; periodic public statements must redact donor identifiers |
| 10 | Special Logs (narrow, closed list) | Team personnel logs; permission grant and revocation logs; records of especially serious violations; special context serving exoneration or long-term corroboration | Continuity of governance, prevention of serious recidivism, exoneration and corroboration, legal obligations | Indefinite, held internally; published only in anonymised or summary form, save for the duty to provide to competent authorities under Article 14.1.2 | Head Admin and above and the Owner only (Tier 2, Article 13.2) |

11.2. The Server does not collect: private message content; passwords or login credentials for any service; biometric data; location; contact lists. The Server does not require identity documents in ordinary activity; the sole situation in which this may arise is verification of a guardian when awarding a prize to, or refunding a donation from, a minor, collected to the minimum extent and deleted per category 6. Prize award information shall be received only through the Official Channels at DIS Section 6.3.3; under no circumstances shall it be received through the private messages of a team member.

11.3. Scope of logging. Messages posted in Server channels may be logged by bots, including after the poster deletes them, for the periods stated at Article 11.1. The purposes of such logs are confined to the purposes stated at Article 11.1 categories 3 and 4: exonerating persons falsely accused, demonstrating a systematic pattern of infringing conduct, and providing evidence for appeals and reports to authorities. All Server channels, including the confidences channel, are logged, without exception. Three mandatory safeguards accompany this: (a) the description of the confidences channel must state clearly that the channel is logged like any other; (b) the right to view logs of the confidences channel falls under Tier 2 - Head Admin and above and the Owner only (Article 13.2) - and is not open to all Staff as ordinary channel logs are; (c) the description of the confidences channel must pin a caution against sharing sensitive identifying information (full real name, address, specific school or workplace, telephone number, financial information).

### Article 12. Legal bases for processing

12.1. The Server processes data on the following bases under Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree): (a) the Member's consent given on accepting this instrument upon joining; (b) obligations under the law (removal and retention of traces of infringing content under NĐ 147/2024 (the Decree on management of internet services and online information), and provision to competent authorities); (c) protection of the lawful rights and interests of other Members and of the Server (resolution of complaints, prevention of fraud); (d) emergencies involving life or health (self-harm protocols, child protection).

12.2. Because bases (b), (c) and (d) exist, certain data shall be retained even where a Member withdraws consent or requests deletion; the scope of, and grounds for, a reasoned refusal are set out at Article 16.5.

### Article 13. Access limitation and sanctions for abuse of authority

13.1. Data access rights are granted by role and by purpose. The rights of Moderators and Admins are tools for handling violations that are the subject of a report or of indicia, and are not a licence to browse freely.

13.2. Three-tier log access. This is the originating provision of the Community Legal Framework on log access; other instruments shall cross-refer to it.

- Tier 1 - Ordinary logs (moderation logs under category 3; bot message logs under category 4, save for logs of the confidences channel, which fall under Tier 2 pursuant to Article 11.3; Member sanction records): open to all serving Staff; the right ends when the role ends, per the revocation checklist at Article 13.4.
- Tier 2 - Special Logs (category 10: team personnel logs; permission grant and revocation logs; internal investigation files): Head Admin and above and the Owner only.
- Tier 3 - Safety and child files (category 5: case files with a legal dimension and all files involving minors): a narrow group of 02-03 pre-identified, named persons per matter, not to be widened; for matters involving minors specifically: a maximum of 02 persons (Article 18.1(a)).

Beyond the three tiers above: prize award information is viewed by exactly the persons named in the prize rules; emergency contact details of the team follow category 7 of Article 11.1. All access at every tier remains subject to the role-based and purpose-based constraints at Article 13.1; a tier determines only who may be granted access, and is not a licence to browse freely.

13.3. Internal violations through misuse of authority. This applies to every level of the team and includes, without limitation: using log or history access to monitor a Member's private life for personal reasons; recounting a Member's affairs outside the Server; capturing or copying data from restricted channels; retaining data after leaving the team. Sanctions: immediate removal from role; a ban where dissemination has occurred; transfer of the file and support for the victim in reporting to competent authorities where there are indicia of a breach of Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree) or indicia of a criminal offence (extortion, humiliation, infringement of personal privacy). This Article applies to former team members as it does to serving members.

13.4. Upon assuming a role, a team member must sign the data confidentiality undertaking in form B5 at Annex B; the undertaking has full internal disciplinary force from the moment of signature. Upon leaving the role, the access revocation checklist (roles, bots, webhooks, integrations, access to shared repositories outside Discord, rotation of shared keys and secrets) shall be executed within 24 hours.

13.5. The Server does not conduct covert surveillance: no anonymous plants listening in voice channels, and no recording without prior notice. Moderators on duty in voice channels are openly present and may mute or disconnect immediately where a violation is in progress. Voice events that are recorded must be announced at the very start of the session; those who remain are deemed to consent. All proceedings concerning sanctions shall by default be conducted in writing in a channel of record, not by voice, because voice channels cannot prevent covert recording.

13.6. Principle of recusal. A team member who is a party to a matter, or who has a romantic relationship, close personal relationship or personal conflict with a party to a matter, must disclose this and may not access the file for that matter, may not participate in handling it, and may not hold approval authority in connection with it. This applies up to the highest level: where the Head Admin is a party, the matter passes to the Owner together with a substitute; where the Owner is a party (a denunciation directed at the Owner), the Owner shall stand wholly outside the file, and the Head Admin together with an independent responsible person shall take carriage under the mechanism for receiving denunciations directed at the Owner set out in ENF and OWN. Breach of recusal shall be handled as misuse of authority under Article 13.3.

### Article 14. Sharing data with third parties

14.1. The Server shall share personal data in four cases only, and there is no fifth:

- 14.1.1. Discord Trust and Safety - when reporting violations through the platform's mechanism, including proactive reporting of serious content;
- 14.1.2. Competent State authorities - upon a lawful written request; the Server shall provide exactly within the scope requested and shall keep a record of the provision;
- 14.1.3. Bots and operational services - within the minimum technical scope necessary for the bot to function (Article 15);
- 14.1.4. Victims of infringing conduct - only the minimum data necessary for the victim to exercise a lawful right of report or complaint, approved case by case by the persons with authority under Article 13.2.

14.2. Prohibition on publishing logs in self-defence. Where the Server is publicly accused, defamed or quoted out of context, the team may not publicly post raw chat logs containing Members' personal data by way of explanation. Public responses may use only: confirmation of the existence or non-existence of the content; a description of the process followed; extracts with third-party identities redacted. Where it is necessary to verify an allegation of fabricated evidence (falsified screenshots, deepfakes), the Server may provide the original logs to a forensic examiner or a neutral intermediary bound by a confidentiality undertaking, approved case by case by the group under Article 13.2. Original logs are reserved for the recipients under Article 14.1 and the forensic case described above.

### Article 15. Bots, third-party integrations and data

15.1. Before installing any bot or integration capable of touching Member data, the Server must: (a) read the bot's privacy policy; (b) refuse any bot that requires Members to verify through an external website collecting data beyond what is necessary; (c) grant minimum permissions, and never grant Administrator permission to a bot, including self-developed bots; (d) enter the bot or webhook in the register (name, developer, permissions, categories of data touched, approver, date of approval) under a two-person approval rule, applicable to every addition of a bot or webhook and every grant of further permissions, including bots donated by Members and including where the proposer is the Owner.

15.2. All running bots shall be re-assessed every 06 months; the quarterly audit performs a rapid review, and the 06-month cycle performs a deep review of OAuth scopes and ownership. This provision applies even to bots that have never had an incident, because a bot may change owner or change behaviour without notice. The Server shall prefer bots that offer a data deletion mechanism on request.

15.3. Where a bot is found to collect or leak data beyond its published scope: remove the bot immediately, run the incident procedure at Article 17, and notify affected Members. The Server bears responsibility as the party that selected and designated the bot; ignorance of the bot's behaviour shall not constitute a ground for disclaiming that responsibility.

15.4. A Member running a self-bot or scraper to collect other Members' data (scraping member lists, copying content from restricted channels to the outside, compiling personal dossiers) commits a serious violation: permanent ban, report to Discord because self-bots breach the Discord ToS, notification of affected persons, and support for victims in reporting under Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree).

### Article 16. Rights of data subjects and how to exercise them

16.1. Every Member and former Member holds the rights conferred by Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree) in respect of the data held by the Server under Article 11: the right to be informed; the right of access; the right to request rectification; the right to withdraw consent; the right to request erasure; the right to restrict processing; the right to complain.

16.2. Single intake point. Data requests shall be submitted through the [Single-Window Channel](https://discord.com/channels/1342729473245577267/1343099398720065559) (the preferred channel) or [support@donquaan.com](mailto:support@donquaan.com); where anonymity vis-à-vis the standing team is required: [private@donquaan.com](mailto:private@donquaan.com). A valid submission shall include: username, user ID, a clearly stated request, evidence if any (avoid blurred screenshots or crops lacking context) and a clear purpose, so that the Server may verify the requester against the user ID. The Server shall not require identity documents unless strictly necessary to prevent false claims of identity. Where a submission lacks information or states no clear purpose: Staff shall request supplementation once before proceeding further. Sanctions for junk submissions, spam or deliberate harassment apply under the ENF disciplinary canon; a person who presents a matter clumsily but in good faith shall not be sanctioned, in accordance with the protection of good-faith reporters at Article 19.3. A request sent through the private messages of a team member shall not be treated as validly received; the recipient has a duty to direct the person to the correct intake point. Private messages are valid only where Staff have arranged them in advance within a ticket, in accordance with DIS Section 8.1.2.

16.3. Response times. The Server shall acknowledge receipt within 72 hours; 72 hours is the ceiling of the undertaking, and the support mailbox typically responds within 24 hours. For rectification or erasure requests, the Server shall act within 72 hours of the request as regards what is feasible, in accordance with the time limits of Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree); the Server's internal time limits may not exceed the statutory ones. Where a matter requires complex verification or is technically infeasible: the Server shall notify progress within 72 hours and complete as soon as possible and in any event within 15 (fifteen) days, stating reasons; complex assessments ordinarily require 01-03 days or 03-07 days depending on the case.

16.4. Feasible scope of compliance and technical limits. The Server shall comply with erasure requests in respect of: the requester's own posts that the Server has authority to delete; records within bots controlled by the Server; prize award information; sanction records whose retention period has expired. The Server has no technical capacity to erase: other persons' messages quoting the requester; data held by Discord, which must be requested from Discord; screenshots already disseminated by third parties off-platform. The written response shall state clearly what has been erased, what is infeasible and why; the Server gives no undertaking to erase data already outside its technical control.

16.5. Reasoned refusal. The Server shall refuse erasure of data currently serving: (a) resolution of a complaint or of an open matter; (b) legal obligations and provision to competent authorities; (c) protection of the lawful rights of a third party, for example a doxxing victim who needs the logs in order to report - such logs shall be retained, relying on the correct exception under Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree), with access frozen to a narrow group and erasure once the basis lapses; (d) the portion falling within the Special Logs at Article 11.1 category 10, within the published narrow list. Rule for resolving conflict between an offender's erasure request and a victim's need to preserve evidence: evidence of a violation follows the case file, not the offender's request. Every refusal shall be issued in writing in form B1 at Annex B, stating the basis and the date by which the data will be erased.

16.6. A Member who disagrees with the handling of a matter may complain through the single-window appellate mechanism of the APL canon; no separate appellate instance shall be created for data complaints. Members have the right to raise the matter with the specialised personal data protection authority (Cục An ninh mạng và phòng, chống tội phạm sử dụng công nghệ cao - A05, Bộ Công an (the Department of Cybersecurity and High-Tech Crime Prevention, Ministry of Public Security)).

16.7. Questioning data practices is a right, not a violation. A Member who asks what the Server collects and whether it sells data shall be answered publicly by reference to this instrument, and by reference to Article 10.4 as regards the web platform; the post shall not be deleted and the person asking shall not be sanctioned. Only the repeated assertion of fabricated claims after an official public answer has been given may be considered under the misinformation clause of the CoC.

### Article 17. Data incidents and security vulnerability reports

17.1. Where a data breach occurs or is suspected (a leaked token, a compromised bot, dissemination by a team member, a scraper), the Server shall run a timestamped four-step procedure: (a) containment - revoke tokens, revoke permissions, remove the bot at the earliest opportunity; (b) scope assessment - what data, whose, and how sensitive; (c) notification - inform affected Members truthfully about the data exposed and the steps to take, and notify the specialised authority within 72 hours under the mechanism of Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree) for incidents subject to reporting, using forms B2 and B3 at Annex B; (d) remediation and lessons learned - with a complete record retained.

17.2. Prohibition on concealing data incidents. Concealing a data incident is a more serious violation than the incident itself; the concealing party shall receive the highest sanction within the team disciplinary framework.

17.3. Receipt of security vulnerability reports (responsible disclosure). Any person discovering a technical vulnerability in the Server or in a bot operated by the Server is invited to report it through the official channel at Article 21.2. The Server shall not retaliate against good-faith reporters, shall respond within a defined time with acknowledgement of receipt in 72 hours, and shall give public credit if the reporter so wishes. The Server shall not negotiate and shall not pay any demand accompanied by a threat; a demand for payment in exchange for disclosing, withholding disclosure of, or removing content bears the indicia of extortion of property (Article 170 of the Bộ luật Hình sự (the Penal Code)), and the Server shall preserve the evidence and report to the police. The principle of non-payment for extortion applies to every form of extortion directed at the Server, including planting unlawful content and then threatening to report it; such cases shall be handled under Annex C item 1.

### Article 18. Data of minors

18.1. The Server acknowledges the reality that Members aged 13-17 are present and applies a higher-than-default standard of protection: (a) every case file involving a minor shall be handled entirely in closed session, with an access group of no more than 02 pre-identified, named persons (Tier 3, Article 13.2, at the stricter level reserved for matters involving minors), and details shall not be published in any circumstance, including where transparency is invoked as the reason; (b) no data of a minor shall be collected beyond Article 11; (c) prizes awarded to a minor shall pass through the guardian; a prize exceeding VND 500,000 requires confirmation by a parent or guardian and 02 approvers at the time of the award, in accordance with DIS Section 6.3.6; (d) data arising from child protection procedures (suspected grooming or abuse) is the most sensitive category within the Server's scope: only the necessary metadata shall be recorded, abusive content shall never be stored and shall never be downloaded in any circumstance, the matter shall be reported to Discord Trust and Safety, and the family shall be guided to report to the police under the procedure of the Community Legal Framework; (e) Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree) require the consent of a parent or guardian for the processing of the data of children under 16. The Server has no technical capacity to verify the age of all Members; the mandatory mitigating measure is data minimisation at the strictest level for all Members. Where a Member is determined to be under 16 and processing arises beyond default operations (prize awards, donation refunds, case files), guardian confirmation must be obtained before processing.

18.2. Persons under 13 may not use Discord under the Discord ToS. Upon discovery, the Server shall act consistently with the CoC (report to Discord, remove from the Server, give age-appropriate notice) and shall immediately erase all data recorded about that person, save for the minimum forming part of the handling record.

18.3. A parent or guardian may exercise the rights under Article 16 on behalf of a minor, through the correct intake point, subject to reasonable verification of the guardianship relationship.

### Article 19. Self-published data, restricted channels and the duty of self-protection

19.1. Information a Member posts themselves in a public channel (real name, photographs, school or workplace, personal matters in the introductions channel or in conversation) is public to everyone with permission to view that channel; the Server has no capacity to retrieve such information from the memory or devices of others. The Server warns of this in the introductions channel and recommends against posting: telephone numbers, addresses, specific schools or workplaces, or financial information.

19.2. The fact that information was self-published does not remove the Server's protection: compiling a Member's public information into a hostile, mocking or attack-inciting context constitutes doxxing as defined by the CoC, determined by context and intent rather than by the source of the information, and shall be sanctioned at the most severe level, together with a trace-removal procedure measured in minutes and a victim support package (guidance on locking accounts, reporting to external platforms, and the right to report under Luật 91/2025 (the Law on Personal Data Protection) and NĐ 356/2025 (the implementing Decree)).

19.3. Restricted channels carry a higher expectation of privacy. Content in channels with restricted viewing permissions (role-gated channels, the confidences channel, staff channels, closed events) carries a reasonable expectation of privacy on the part of participants. Capturing, recording audio or video, livestreaming or forwarding content from a restricted channel beyond that channel without permission is an independent serious violation, irrespective of the content disseminated, and shall be sanctioned severely, applying equally to serving and former team members under Article 13.3. Protected exception: submitting evidence of infringing conduct to the Server's correct official intake point or to a competent authority (good-faith reporting) does not constitute dissemination and shall not be sanctioned. This instrument prohibits silencing whistleblowers; it prohibits only publication to the public instead of using the correct channel.

---

# CHAPTER III - IMPLEMENTING PROVISIONS

### Article 20. Relationship with Discord and with Vietnamese law

20.1. This instrument does not replace, does not reinterpret and may not be invoked to dilute: the [Discord Terms of Service](https://discord.com/terms), the [Discord Community Guidelines](https://discord.com/guidelines), the Discord Privacy Policy; or Vietnamese law in force, in particular Luật 91/2025/QH15 (the Law on Personal Data Protection) and Nghị định 356/2025/NĐ-CP (the implementing Decree), Nghị định 147/2024/NĐ-CP (the Decree on management of internet services and online information), the Bộ luật Dân sự (the Civil Code) and the Bộ luật Hình sự (the Penal Code).

20.2. Where a change in the law or in Discord policy renders a clause non-compliant, that clause shall automatically be applied in the manner that complies with the new requirement until the instrument is formally amended.

### Article 21. Responsible persons and points of contact

21.1. The Server's data protection point of contact is the Owner, with the Head Admin as fallback, applicable for the period before the role is transferred to a legal entity under Article 21.3. The Head Admin position is appointed by the Owner and announced in the [official announcements channel](https://discord.com/channels/1342729473245577267/1529782982016110642); where no one holds the position, all of its powers and duties vest in the Owner. During the period before Staff exist, the Owner shall temporarily discharge the operational roles; mechanisms requiring several persons (two-person approval, panels) shall be activated progressively in line with the recruitment roadmap, and each activation shall be announced publicly.

21.2. Official contact channels for all matters under this instrument: the [Single-Window Channel](https://discord.com/channels/1342729473245577267/1343099398720065559) (the preferred channel) and [support@donquaan.com](mailto:support@donquaan.com); anonymous channel: [private@donquaan.com](mailto:private@donquaan.com); general contact: [contact@donquaan.com](mailto:contact@donquaan.com). These are the sole intake points; exchanges outside them carry no binding commitment of the Server. The full register of Official Channels and the anti-impersonation conventions are at DIS Section 8.1.2 and in TOS, which is canonical on Official Channels.

21.3. When the Server establishes a legal entity, the role of data controller and all undertakings in this instrument shall transfer to the entity of record; the instrument shall be reviewed in full by a lawyer before re-publication.

21.4. Continuity of obligations. Where the primary point of contact is unreachable for more than 7 days, the fallback shall automatically assume all obligations under this instrument; the time limits at Article 16.3 and Article 17.1 continue to run and absence of personnel may not be invoked as a reason. Where the Owner is unreachable, the person assuming carriage may only be Staff of Head Admin level or above, or a person holding a valid written confirmation from the Owner; the scope of that person's authority is that of a temporary Head Admin and may not be exceeded, confers no Owner authority, and in particular does not include expenditure approval under DIS Section 5.7. Where the Owner is subject to long-term incapacity or force majeure: the matter shall be handled under the OWN governance and succession instrument; as regards data obligations specifically, the fallback under Article 21.1 has the authority and the duty to perform them in full during the transition.

### Article 22. Amendment and effect

22.1. This instrument may be amended only by the following procedure: a draft published for Member comment, approval by the Owner, publication in the [official announcements channel](https://discord.com/channels/1342729473245577267/1529782982016110642) together with a summary of changes, and entry into force after a minimum notice period of: 7 days for minor amendments; 30 days for major amendments, being amendments affecting Members' rights, for example narrowing data rights, expanding the scope of collection, changing the complaints mechanism, or extending retention periods. The sole exception is an emergency amendment made to comply with the law or with Discord policy: such an amendment takes effect immediately together with a public explanation of the urgency; emergency amendments may not be used for changes adverse to Members beyond the scope of compliance.

22.2. Amendments are not retroactive. A new version shall not be used to sanction conduct occurring before its effective date; nor shall a new version be used to expand the processing of data collected under an earlier version without fresh notice.

22.3. All earlier versions shall be publicly archived for comparison. The version history forms part of the Server's compliance record.

22.4. Partial invalidity: a clause held void shall not carry with it the remaining clauses.

22.5. Permanent closure of the Server must be announced at least 30 days in advance in the [official announcements channel](https://discord.com/channels/1342729473245577267/1529782982016110642) and on the [donquaan.com website](https://donquaan.com/). During the notice period, all obligations under this instrument continue to apply in full; after closure, the data under Article 11 shall be erased in accordance with the published periods or sooner, save for the portion still subject to legal obligations under categories 5 and 10, with the erasure schedule published together with the closure notice.

---

## Annex A - Quick reference table on data (does not replace the full text)

This Annex summarises the data provisions for quick reference; in the event of any discrepancy, the full text of the corresponding Articles shall apply. Provisions on disclaimers, Official Channels, anti-impersonation and donations are set out in DIS, TOS, [ANX-2](https://donquaan.com/discord/verify) and [ANX-3](https://donquaan.com/discord/donate).

| # | Subject | Provision | Article referenced |
| --- | --- | --- | --- |
| 1 | What the Server holds about a Member | Moderation logs 24 months; public channel message logs 90 days; prize award information erased after 30 days | Article 11.1 |
| 2 | Scope of logging | All channels, including the confidences channel, are logged; logs of the confidences channel may be viewed only by Head Admin and above and the Owner; Members are cautioned not to share sensitive identifying information | Article 11.3, Article 13.2 |
| 3 | Limits of the Server | The Server does not access private message content and does not sell Member data | Article 10.2, Article 10.3 |
| 4 | Rights of Members | To ask, view, rectify and request erasure of data through the [Single-Window Channel](https://discord.com/channels/1342729473245577267/1343099398720065559) or [support@donquaan.com](mailto:support@donquaan.com), stating username, user ID, request, evidence and purpose; the Server answers within defined time limits; refusals must be reasoned; Members may complain further | Articles 16.1-16.6 |
| 5 | Questioning data practices | Asking whether the Server sells data is a Member's right and shall not be sanctioned | Article 16.7 |
| 6 | Restricted channel content | May not be taken beyond the channel; submitting evidence of violations to the correct intake point is always protected | Article 19.3 |

## Annex B - List of accompanying model documents

The forms in this Annex are issued as separate instruments; only versions issued by the Owner may be used.

- B1. Written response to a data access or erasure request (full grant, partial grant, reasoned refusal).
- B2. Notice of a data incident to affected Members.
- B3. Instrument for providing data to competent authorities, with an accompanying record.
- B4. Letter of response to a parent or guardian.
- B5. Data confidentiality undertaking signed by a team member on assuming a role, with the access revocation record on leaving the role.
- B6. Neutral notice warning the community of a fraud or impersonation incident, disclosing no personal data beyond what is necessary.
- B7. Interim statement during a communications crisis, for use where the press, community pages or influencers pose questions under a pressing deadline.
- B8. Model acknowledgement of a security vulnerability report under Article 17.3.
- B9. Model instrument of the Owner authorising expenditure item by item under DIS Section 5.7, together with the instrument confirming temporary assumption of carriage under Article 21.4.

## Annex C - Rapid response card for duty officers

This card is an operational summary of the corresponding Articles; in the event of conflict, the full text shall apply. Every step must be recorded as 01 timestamped line in the record channel within the Staff log channel register.

| # | Situation | Do immediately, in order | Must not do |
| --- | --- | --- | --- |
| 1 | Criminal content, child sexual abuse material or terrorist content appears | (1) do not download, do not forward; (2) preserve identifiers (message ID, poster ID, time) through the report function; (3) report to Discord Trust and Safety; (4) delete from the channel; (5) escalate by ping chain: ping the duty Moderator; because this is the most severe class of case (criminal conduct, child sexual abuse material, threat to life), additionally ping any Admin online; the Head Admin may be pinged only where the matter is simultaneously dangerous, urgent and serious; the Owner may not be pinged in any situation | Comment publicly; keep the content on a personal device; pay any extortion demand, contrary to Article 17.3 |
| 2 | A Member alludes to self-harm or suicide | (1) respond using the prepared template including the numbers 111 and 115; (2) do not delete the call for help, limit its visibility if the tooling allows; (3) report to Discord under the self-harm category; (4) ping the person responsible for the protocol | Diagnose or advise treatment; make jokes; delete the post without a record; promise unlimited confidentiality; direct the person to the support mailbox instead of the hotline |
| 3 | Suspected grooming or abuse of a minor | (1) apply a protective temporary ban on the suspected person; (2) report to Discord Trust and Safety; (3) only the group of no more than 02 persons under Article 18 may touch the evidence; (4) guide the family to report to the police | Name anyone publicly; download the content; hold a public confrontation; delay action pending completion of verification |
| 4 | Suspected data leak, compromised bot or unknown webhook | (1) remove the bot, revoke the webhook, tokens and permissions; (2) record the timestamp; (3) ping the persons responsible for security and bots; (4) run Article 17 | Conceal the incident; investigate alone for more than 1 hour without reporting |
| 5 | Impersonation of the Owner or Staff to defraud | (1) post a neutral warning in the [official announcements channel](https://discord.com/channels/1342729473245577267/1529782982016110642) and on the [donquaan.com website](https://donquaan.com/); (2) report the fake account to Discord; (3) guide victims to report to the police | Promise compensation; argue with the impersonator; post raw logs containing personal data, in breach of Article 14.2 |

---

Any proposal to amend this instrument shall follow the procedure at Article 22. A proposal to narrow the scope of a clause must be accompanied by a risk assessment of the situations that clause is designed to prevent.

```json
{ "@context": "https://schema.org", "@graph": [ { "@type": "Person", "@id": "https://donquaan.com/#person", "name": "Nguyen Vu Dong Quan", "alternateName": "DonQuaan", "url": "https://donquaan.com/", "image": "https://donquaan.com/og-hero.png", "jobTitle": "Gemini Certified Faculty · Google AI Specialist", "description": "I believe in people, not tools. Teaching and applying Google AI; running Discord communities and systems; design and development for Roblox, Minecraft and the web; systems testing.", "email": "mailto:contact@donquaan.com", "knowsAbout": [ "Google AI", "Gemini", "Community operations", "Discord", "Roblox", "Minecraft modpacks", "Web development", "Systems testing" ], "knowsLanguage": [ "Vietnamese", "English" ], "hasCredential": [ { "@type": "EducationalOccupationalCredential", "credentialCategory": "certification", "name": "Gemini Certified Faculty", "recognizedBy": { "@type": "Organization", "name": "Google" }, "url": "https://edu.google.accredible.com/529911e4-a7fb-42b6-9c9f-50d29e633430" }, { "@type": "EducationalOccupationalCredential", "credentialCategory": "certification", "name": "Kaggle Learn certificates (17) and the Data Science graduate badge, 18 images", "recognizedBy": { "@type": "Organization", "name": "Kaggle" }, "url": "https://www.kaggle.com/nguyenvudongquan" }, { "@type": "EducationalOccupationalCredential", "credentialCategory": "certification", "name": "HubSpot Academy certifications (15)", "recognizedBy": { "@type": "Organization", "name": "HubSpot Academy" }, "url": "https://app.hubspot.com/academy-profile/member/94801453" } ], "address": { "@type": "PostalAddress", "addressLocality": "Da Nang", "addressCountry": "VN" }, "sameAs": [ "https://www.facebook.com/NguyenDonQuaan", "https://x.com/DonQuaanVN", "https://www.youtube.com/channel/UCvqlcKf1nm9i2LeH9hFQQYA", "https://github.com/DonQuaan", "https://www.linkedin.com/in/donquaan", "https://www.twitch.tv/donquaan_tkz", "https://open.spotify.com/user/31xr7kgwysteud3urdhzrv5ixc2q", "https://www.curseforge.com/members/yangdawn", "https://www.kaggle.com/nguyenvudongquan", "https://app.hubspot.com/academy-profile/member/94801453", "https://discord.com/invite/sangtraan" ] }, { "@type": "WebSite", "@id": "https://donquaan.com/#website", "url": "https://donquaan.com/", "name": "DonQuaan", "alternateName": "Nguyen Vu Dong Quan", "description": "Nguyen Vu Dong Quan, Gemini Certified Faculty · Google AI Specialist, Da Nang. I believe in people, not tools. Shipped work, real certificates, the Sangtraan Discord community.", "inLanguage": [ "vi", "en" ], "publisher": { "@id": "https://donquaan.com/#person" } }, { "@type": "ProfilePage", "@id": "https://donquaan.com/#webpage", "url": "https://donquaan.com/", "name": "DonQuaan | Nguyen Vu Dong Quan", "isPartOf": { "@id": "https://donquaan.com/#website" }, "about": { "@id": "https://donquaan.com/#person" }, "mainEntity": { "@id": "https://donquaan.com/#person" }, "primaryImageOfPage": "https://donquaan.com/og-hero.png", "inLanguage": "en" } ] }
```
