GDPR and data privacy
Understand how Arketa handles personal data under GDPR, and what it means for your studio as the data controller.
If you have clients, members, or users in the European Economic Area (EEA), the General Data Protection Regulation (GDPR) shapes how their personal data must be handled. This page explains how Arketa processes that data and what your responsibilities are as the studio or creator.
This page is general information, not legal advice. GDPR compliance depends on your specific business, and you're responsible for meeting your own obligations. Consult your own legal counsel for guidance on your situation.
What GDPR is
The General Data Protection Regulation (GDPR) is a comprehensive privacy law governing how the personal data of individuals in the European Economic Area (EEA) is collected, used, and protected.
It applies to any business — whether located in Europe or not — that processes the personal data of individuals in the EEA. The GDPR sets strict requirements around:
- Transparency
- Security
- Individual rights
- Controller–processor relationships
Does it apply to you and Arketa?
Yes — if you have clients, members, or users in the EEA, or you process their personal data in Arketa, GDPR obligations apply.
Arketa processes personal data on behalf of studios and creators. Under GDPR definitions, that makes Arketa a processor and you (the business using Arketa) a controller.
Controller vs. processor
GDPR draws a clear line between the party that decides how data is used and the party that acts on those instructions.
- You, the studio or creator, are the data controller. You decide what data you collect from your clients and how it's used.
- Arketa is the data processor for the personal data you store or process through the platform. As processor, Arketa follows your instructions and applies appropriate safeguards to protect that data.
- For data Arketa collects on its own behalf — such as platform analytics, website usage, or Arketa's own marketing — Arketa acts as an independent controller.
Where your data is stored and processed
Arketa processes data primarily in the United States, using:
- AWS (us-east-2)
- Google Cloud Platform (us-central-1)
For transfers from the EEA to the U.S., Arketa relies on the 2021 EU Standard Contractual Clauses (SCCs), which are incorporated into the Arketa Privacy Annex.
What personal data Arketa processes on your behalf
Arketa processes the information you collect from your clients, which may include:
- Name, email address, and phone number
- Birthday and gender (optional)
- Waiver signatures
- Shipping address
- Payment history — not card numbers, which are stored by Stripe
- Marketing preferences
- Geolocation (opt-in)
Arketa does not intentionally collect special-category (sensitive) data or children's data under GDPR thresholds.
How Arketa protects personal data
Arketa uses a combination of organizational and technical safeguards, including:
- Encryption at rest and in transit
- Role-based access control (RBAC) and least-privilege controls
- SSO and MFA for internal access
- Logging and monitoring through GCP
- Daily encrypted backups
- An on-call incident-response rotation and a formal breach-notification process
- Strict employee confidentiality obligations
Full technical and organizational safeguards are listed in Annex 2 of the Arketa Privacy Annex.
Handling data-subject and privacy requests
As the controller, you're responsible for responding to your clients' data-subject requests — access, correction, deletion, and portability. Most client data can be viewed and edited directly in your Arketa dashboard.
If an EU individual exercises a GDPR right that you can't fulfill on your own, Arketa will assist you as your processor. You determine the appropriate response, and Arketa acts on your documented instructions. Send requests to support@arketa.com.
Reference documents
Arketa Privacy Annex
Article 28 processor clauses, the 2021 SCCs, security measures, transfers, retention, and sub-processors. Incorporated into the Arketa Terms of Service.
EU Standard Contractual Clauses
The full text of the EU Commission's 2021 SCCs, incorporated by reference into the Arketa Privacy Annex.