Privacy Policy — Web Portal & Discord Bot

Effective date: 7 June 2026
Last updated: 7 June 2026

1. Who we are

1.1 This Privacy Policy applies to the website at https://btpbot.co.uk (the “Site”), associated web applications, and the Discord bot operated for the British Transport Police roleplay community (together, the “Services”).

1.2 The Services are community tools for a roleplay organisation. They are not operated by the real-world British Transport Police or any government body.

1.3 For the purposes of UK GDPR and the DPA 2018, the data controller is the community operator administering the Services (“we”, “us”, “our”). Day-to-day data protection enquiries are handled by the BTP Digital Information Team.

2. Contact and data protection requests

2.1 To exercise your data protection rights or ask questions about this policy, contact us via Discord:

2.2 We will respond to valid requests without undue delay and within one month, as required by UK GDPR. We may extend that period by up to two further months where requests are complex or numerous; we will tell you if an extension applies.

2.3 You have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint.

3. Scope

3.1 This policy covers personal data we process about:

3.2 Your use of Discord itself is governed by Discord’s Privacy Policy. We do not control Discord’s processing of your data on their platform.

3.3 Our Terms of Service govern use of the Services and should be read alongside this policy.

4. Personal data we collect

4.1 Depending on how you use the Services, we may process:

Category Examples Source
Identity & account Discord user ID, Discord username, display name, server nickname, portal username Discord API, member sync, account creation
Authentication Password hash (staff portal), OAuth tokens during login (employee portal), session identifiers You / Discord OAuth
Service & employment records Divisions, qualifications, shifts, LOA dates and reasons, probationary status, PIN (if used) Bot commands, web portals, staff input
Self-service profile Roblox username (if you choose to link it) Employee portal
PSD & disciplinary Case references, notes, disciplinary outcomes, interview records, linked messages where logged Staff workflows, Bot, web portal
Training & CoP Training attendance, exam results, instructor notes College of Policing portal / Bot
Communications Direct messages sent by the Bot (e.g. LOA confirmations, password notices), content you submit in forms Bot / Site
Technical & security IP address, browser user agent, request timestamps, application logs, audit entries Server / hosting infrastructure

4.2 We do not intentionally collect special category data (e.g. health information) unless you voluntarily include it in free-text fields (such as an LOA reason). Please avoid submitting unnecessary sensitive information.

4.3 We do not sell your personal data.

5. How and why we use personal data (purposes & legal bases)

5.1 Under UK GDPR we must have a lawful basis for processing. We rely on the following, as applicable:

Purpose Lawful basis (UK GDPR Art. 6)
Providing the Bot, web portals, and account access Performance of a contract or steps at your request before entering a contract (community membership / staff role)
Managing staff records, LOA, training, and community operations Legitimate interests (running and administering the roleplay community) — balanced against your rights
Employee self-service login via Discord OAuth Legitimate interests and, where required, consent by continuing after authorisation
PSD cases, disciplinary records, and audit trails Legitimate interests (community standards, record-keeping, dispute resolution)
Security monitoring, fraud prevention, and abuse investigation Legitimate interests and, where applicable, legal obligation
Compliance with law, regulatory requests, or court orders Legal obligation

5.2 Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights. You may object to processing based on legitimate interests (see Section 10).

5.3 We process data only for purposes that are compatible with those for which it was collected, unless we notify you otherwise or another lawful basis applies.

6. Who we share data with

6.1 We may share personal data with:

6.2 Processors acting on our instructions are required to protect personal data appropriately. We do not permit them to use your data for their own marketing.

6.3 We may disclose aggregated or anonymised statistics that cannot reasonably identify you.

7. International transfers

7.1 Some service providers (including Discord and certain hosting providers) may process data outside the UK. Where personal data is transferred internationally, we ensure appropriate safeguards are in place as required by UK GDPR Chapter V (for example adequacy regulations, UK International Data Transfer Agreement, or equivalent mechanisms).

7.2 You may request further information about safeguards by contacting @adamratty on Discord.

8. Retention

8.1 We keep personal data only for as long as necessary for the purposes set out in this policy, including:

8.2 When data is no longer required, we delete or anonymise it unless we must retain it to comply with legal obligations or establish, exercise, or defend legal claims.

9. Security

9.1 We implement appropriate technical and organisational measures to protect personal data, including access controls, permission-based portal access, hashed passwords, and secured hosting.

9.2 No method of transmission or storage is completely secure. You are responsible for keeping your portal credentials confidential and using Discord account security features.

9.3 Report suspected security incidents to @adamratty on Discord promptly.

10. Your rights under UK GDPR and the DPA 2018

10.1 Subject to conditions and exemptions in UK law, you have the right to:

10.2 To exercise any right, contact @adamratty on Discord. We may need to verify your identity (e.g. by confirming your Discord user ID matches our records).

10.3 We may refuse requests that are manifestly unfounded, excessive, or where an exemption applies under the DPA 2018.

10.4 You may also complain to the ICO (see Section 2.3).

11. Cookies and similar technologies

11.1 The Site uses session cookies (or equivalent session storage) to keep you logged in and to protect forms (e.g. CSRF tokens). These are strictly necessary for the Service to function.

11.2 We do not use third-party advertising cookies on the portal. If this changes, we will update this policy.

12. Children

12.1 The Services are intended for users who meet Discord’s minimum age requirements in their region (typically at least 13, and 16 where applicable). We do not knowingly collect personal data from children below the minimum age without appropriate parental consent where required.

12.2 If you believe we have collected data from a child inappropriately, contact @adamratty and we will take appropriate steps.

13. Changes to this policy

13.1 We may update this Privacy Policy from time to time. We will post the revised version on the Site and update the “Last updated” date.

13.2 For material changes, we may also notify you via Discord or a notice on login. Continued use after the effective date indicates acceptance of the updated policy where permitted by law.

14. Contact

For privacy and data protection enquiries: