GDPR and data privacy

Understand how Arketa handles personal data under GDPR, and what it means for your studio as the data controller.

If you have clients, members, or users in the European Economic Area (EEA), the General Data Protection Regulation (GDPR) shapes how their personal data must be handled. This page explains how Arketa processes that data and what your responsibilities are as the studio or creator.

What GDPR is

The General Data Protection Regulation (GDPR) is a comprehensive privacy law governing how the personal data of individuals in the European Economic Area (EEA) is collected, used, and protected.

It applies to any business — whether located in Europe or not — that processes the personal data of individuals in the EEA. The GDPR sets strict requirements around:

  • Transparency
  • Security
  • Individual rights
  • Controller–processor relationships

Does it apply to you and Arketa?

Yes — if you have clients, members, or users in the EEA, or you process their personal data in Arketa, GDPR obligations apply.

Arketa processes personal data on behalf of studios and creators. Under GDPR definitions, that makes Arketa a processor and you (the business using Arketa) a controller.

Controller vs. processor

GDPR draws a clear line between the party that decides how data is used and the party that acts on those instructions.

  • You, the studio or creator, are the data controller. You decide what data you collect from your clients and how it's used.
  • Arketa is the data processor for the personal data you store or process through the platform. As processor, Arketa follows your instructions and applies appropriate safeguards to protect that data.
  • For data Arketa collects on its own behalf — such as platform analytics, website usage, or Arketa's own marketing — Arketa acts as an independent controller.

Where your data is stored and processed

Arketa processes data primarily in the United States, using:

  • AWS (us-east-2)
  • Google Cloud Platform (us-central-1)

For transfers from the EEA to the U.S., Arketa relies on the 2021 EU Standard Contractual Clauses (SCCs), which are incorporated into the Arketa Privacy Annex.

What personal data Arketa processes on your behalf

Arketa processes the information you collect from your clients, which may include:

  • Name, email address, and phone number
  • Birthday and gender (optional)
  • Waiver signatures
  • Shipping address
  • Payment history — not card numbers, which are stored by Stripe
  • Marketing preferences
  • Geolocation (opt-in)

How Arketa protects personal data

Arketa uses a combination of organizational and technical safeguards, including:

  • Encryption at rest and in transit
  • Role-based access control (RBAC) and least-privilege controls
  • SSO and MFA for internal access
  • Logging and monitoring through GCP
  • Daily encrypted backups
  • An on-call incident-response rotation and a formal breach-notification process
  • Strict employee confidentiality obligations

Full technical and organizational safeguards are listed in Annex 2 of the Arketa Privacy Annex.

Handling data-subject and privacy requests

As the controller, you're responsible for responding to your clients' data-subject requests — access, correction, deletion, and portability. Most client data can be viewed and edited directly in your Arketa dashboard.

If an EU individual exercises a GDPR right that you can't fulfill on your own, Arketa will assist you as your processor. You determine the appropriate response, and Arketa acts on your documented instructions. Send requests to support@arketa.com.

Reference documents

Frequently asked questions

Was this helpful?