Privacy Policy
This Privacy Policy applies to the TicketWave website, the dashboard, as well as the connected Discord bot (ticket system), including the AI features of LunAI. It describes which personal data we process, for what purposes, and on which legal basis.
Table of Contents
- 1. Controller
- 2. Types of Data and Purposes
- 3. Legal Bases
- 4. Recipients and Processors
- 5. Third Country Transfers
- 6. Storage Duration
- 7. Cookies and Similar Technologies
- 8. Web Analytics (Google Analytics 4)
- 9. Error Analysis and Monitoring (Sentry)
- 10. Payment Processing (Stripe)
- 11. Login with Discord
- 12. Tickets, Logs and Transcripts
- 13. AI Features (LunAI)
- 14. Data Security
- 15. Your Rights
- 16. Version and Changes
1. Controller
The controller within the meaning of the GDPR is:
Viority Inh. Alessio Carnevale
Emsdettener Str. 10, c/o Postflex #3253, 48268 Greven, Germany
Email: business@ticketwave.dev
Further details can be found in the legal notice.
Server operators: TicketWave is set up by the operators of the respective Discord servers. They decide whether the bot runs on their server and which features - in particular which AI features - are active there. Where server operators themselves decide on the purposes and means of processing on their server, they are responsible for it alongside us. You can always exercise your rights against us as well.
2. Types of Data and Purposes
We process personal data only to the extent necessary for the operation of our services.
- Technical access data: IP address, timestamp, URL, referrer, browser and device information for the provision and security of the website.
- Account and profile data: Discord ID, username, global name, avatar, as well as session data for login, dashboard usage, and authorization checks.
- Operational and configuration data: server/guild data, roles, settings, module configuration, ticket metadata, blacklist and log data for the provision of bot functionalities.
- Communication and ticket content: content within support tickets as well as transcripts generated from them.
- AI data:ticket content processed by LunAI, the results generated from it (priority, summary, replies, moderation assessments) and a server's knowledge base. Details in section 13.
- Payment data (via Stripe): Stripe customer ID, subscription ID, plan, payment status, payment events, and billing-related metadata.
- Analytics data: usage data via Google Analytics 4, provided you have given consent.
- Error and diagnostic data: technical error data, stack traces, timestamps, accessed URLs, referrer, browser and device information, as well as, where applicable, truncated or otherwise technically transmitted IP/request metadata for the detection, analysis, and resolution of errors and to ensure stability and security. Subject to separate consent, performance data and session replay data in the browser may also be processed.
3. Legal Bases
- Art. 6(1)(b) GDPR (contract / pre-contractual measures), e.g. for account, bot, and payment functions towards server operators.
- Art. 6(1)(f) GDPR (legitimate interest), e.g. for operating the ticket system towards server members, the AI features of LunAI, IT security, stability, abuse prevention, and technical optimization.
- Art. 6(1)(a) GDPR (consent), e.g. for non-essential cookies and Google Analytics.
- Art. 6(1)(c) GDPR (legal obligation), e.g. for commercial and tax retention obligations.
4. Recipients and Processors
For the provision of our services, we use the following categories of external recipients:
- Hosting/infrastructure providers for the operation of the website, APIs, and databases.
- Discord (Discord Inc.) for OAuth login, guild/member verification, and bot interactions.
- Stripe (Stripe Payments Europe Ltd./Stripe Inc.) for checkout, subscription management, customer portal, and webhooks.
- OpenAI (OpenAI Ireland Ltd. / OpenAI OpCo, LLC) as a processor for the AI features of LunAI (see section 13).
- Google (Google Ireland Limited) for Google Analytics 4 (only with consent).
- Sentry (Functional Software, Inc.) for error analysis, monitoring, and technical stability.
5. Third Country Transfers
When using Discord, Stripe, OpenAI, Google, and Sentry, data may be transferred to third countries, in particular the United States. These transfers are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
6. Storage Duration
- Session and authentication data are stored only for the duration of the valid session or as long as necessary for login.
- Ticket, log, and configuration data are stored as long as necessary for bot operation.
- Transcripts are retained until deletion by us or the respective operator, unless statutory obligations prevent this.
- Entries of the LunAI knowledge base are kept until the server team removes them. Removed entries are neither shown nor used for replies.
- According to OpenAI, content sent to its API is kept for up to 30 days for abuse monitoring and deleted afterwards.
- Billing and tax-relevant data are stored in accordance with statutory retention periods.
- Analytics data are stored according to the retention periods configured in Google Analytics (if consent is given).
- Error and monitoring data are stored only as long as necessary for troubleshooting, abuse prevention, and secure operation, or as long as the retention periods configured with the respective provider apply.
7. Cookies and Similar Technologies
We use technically necessary cookies, in particular for:
- Session management (login status),
- Language selection (e.g. lang),
- UI settings (e.g. sidebar status).
Non-essential cookies (in particular for analytics) are used only with your consent. You can withdraw your consent at any time with effect for the future.
If browser-side Sentry features for performance measurement or session replay are used, these are also loaded only after your consent via our consent banner.
8. Web Analytics (Google Analytics 4)
If you have given your consent, we use Google Analytics 4 for the statistical analysis of the use of our website. In particular, usage and device data may be processed. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Further information: Google Privacy Policy
9. Error Analysis and Monitoring (Sentry)
We use Sentry as a service for technical error analysis, logging of exceptions, and performance and stability monitoring of our website, API, and connected services. In particular, technical diagnostic data such as error messages, stack traces, timestamps, request and header information, browser and device data, as well as IP-related metadata may be processed.
Where Sentry is used exclusively server-side for the detection, analysis, and resolution of technical issues and to ensure stability and security, processing is carried out on the basis of Art. 6(1)(f) GDPR. Where additional Sentry features for performance measurement or session replay are activated in the browser, this is done only with your consent pursuant to Art. 6(1)(a) GDPR.
Provider: Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Further information: Sentry Privacy Notice
10. Payment Processing (Stripe)
For paid premium features, we use Stripe. Depending on the selected payment method (including card, SEPA direct debit, PayPal via Stripe), payment and identification data may be processed.
- Checkout sessions are created via Stripe.
- Changes to subscriptions are processed via Stripe webhooks.
- For existing customers, we use the Stripe Customer Portal for self-management of subscriptions.
Legal basis: Art. 6(1)(b) GDPR. Provider information: https://stripe.com/de/privacy
11. Login with Discord
We offer login via Discord OAuth2. In particular, we process Discord account data (e.g. user ID, username, global name, avatar, email if provided by Discord) in order to enable access to the dashboard and bot functions.
Legal basis: Art. 6(1)(b) GDPR. Provider information: https://discord.com/privacy
12. Tickets, Logs and Transcripts
Within the scope of the ticket system, we process ticket content, process data (e.g. ticket ID, status, timestamps, involved users), as well as optional feedback data. Transcripts are stored as HTML files and are only made available to authorized persons.
When accessing transcripts, permissions are checked (including ticket owner, support roles, or admin rights on the respective Discord server).
Server operators can enable ticket rules that check messages automatically (e.g. for links, spam or sensitive data such as email addresses or card numbers) and log violations. The check for abusive language is carried out by LunAI (see section 13).
13. AI Features (LunAI)
LunAI is TicketWave's AI assistant. Its features are off by default and only become active when the operator of a Discord server switches them on in the dashboard. LunAI uses language models from OpenAI.
13.1 Features and data processed
- Prioritization and summary: The first messages of a ticket, the answers to ticket steps and the chosen category are sent to OpenAI to create a priority and a short summary for the support team. Discord IDs and usernames are not sent, only the role of the author (ticket owner, staff, other).
- Auto-reply:The first message of a ticket is matched against the server's knowledge base. For this, a so-called embedding vector is calculated from the text. If LunAI finds a matching answer, it posts it in the ticket. You can request a team member at any time with the "I need a human" button.
- Learning from tickets (optional): If the server operator enables this feature, a closed ticket is analysed to propose a general knowledge entry (question and answer). Before anything is sent to OpenAI we remove mentions, email addresses, links, IP addresses, IBANs, credentials and longer numbers (e.g. phone, order or Discord IDs). A proposal is only used after a team member has reviewed and approved it.
- Check for abusive language (ticket rule): Individual messages are sent to OpenAI to detect insults, harassment, hate speech or threats.
- Documentation import: Server operators can import their own publicly available documentation. We fetch the pages, respect robots.txt and text and data mining reservations, and have knowledge entries created from them.
13.2 Labelling
Every LunAI message is labelled as AI-generated and sent under the name "LunAI" (Art. 50 EU AI Act). AI-generated content may be inaccurate.
13.3 Legal basis
Processing is based on Art. 6(1)(f) GDPR. Our legitimate interest and that of the server operators is to handle support requests faster and more reliably, to answer recurring questions immediately and to protect the support team from abuse. We limit the data sent to what is necessary, remove identifiers where they are not needed, and have learned content reviewed by humans.
13.4 Automated decisions
The check for abusive language can automatically trigger a notice in the ticket, a direct message, the removal of the message and a notification of the team. A ban from opening new tickets (blacklist), however, is never imposed by the AI alone: LunAI submits it to the server team, and only the confirmation of a team member blocks you. There is therefore no decision based solely on automated processing within the meaning of Art. 22 GDPR. If you believe an assessment is wrong, you can tell the team in the ticket.
13.5 Recipient
The recipient is OpenAI (OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland, and OpenAI OpCo, LLC, San Francisco, USA) as a processor under a contract pursuant to Art. 28 GDPR. According to OpenAI, data sent via the API is not used to train its models. For third country transfers see section 5. Further information: OpenAI Privacy
14. Data Security
We implement technical and organizational security measures to protect data against loss, unauthorized access, manipulation, and misuse. These include in particular access restrictions, authorization checks, secure transmission, and secured API communication.
15. Your Rights
You have the following rights under the GDPR in particular:
- Access (Art. 15 GDPR),
- Rectification (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Objection to certain processing (Art. 21 GDPR),
- Withdrawal of consent at any time with effect for the future (Art. 7(3) GDPR),
- Lodging a complaint with a supervisory authority (Art. 77 GDPR).
Right to object under Art. 21 GDPR
Where we process data on the basis of Art. 6(1)(f) GDPR - in particular for the AI features of LunAI - you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests. An informal email to business@ticketwave.dev or a message to the team of the respective server is sufficient.
16. Version and Changes
Version of this Privacy Policy: September 23, 2026.
We reserve the right to amend this Privacy Policy if legal requirements, data processing activities, or technical processes change.
