This policy is written for Arlo Hosting and is intended to explain our approach under the UK GDPR and the Data Protection Act 2018. It is not a substitute for advice about your own compliance obligations when hosting other people’s data.
Controller & Scope
Arlo Studios is a UK-based hosting provider. This Privacy Policy explains how we handle personal data when you visit our website, create or manage an Arlo Hosting account, purchase credits, run a server, contact support, or use our dashboard and panel integrations.
We act as a controller for account, billing, website, security, and support data. Where a customer uses our infrastructure to host content belonging to other people, the customer may be the controller and we may act as a processor, subject to the relevant arrangement.
Information We Handle
Depending on your use of the Services, we may handle:
- Account information — name, email address, username, authentication records, preferences, and account status.
- Billing information — payment status, invoices, transaction references, credits, subscriptions, and limited billing details. Payment card data is handled by our payment provider, not stored by us.
- Server and usage information — server identifiers, plan, resource allocation, configuration, activity, resource usage, and hosted service metadata.
- Technical data — IP addresses, timestamps, browser/device information, access logs, error logs, and security events.
- Support data — tickets, messages, attachments, and information you provide while requesting help.
- Discord information — if you connect Discord or use a Discord-related service, we may receive your Discord user ID, username, guild/server identifiers, and permissions needed for that connection.
Why We Collect Data
We use data to create and secure accounts, provision and operate servers, apply resource and abuse controls, process payments and credits, provide support, monitor reliability, prevent fraud and attacks, communicate service changes, improve the Services, and comply with legal obligations.
UK GDPR Lawful Bases
Under the UK GDPR and the Data Protection Act 2018, our lawful bases may include performance of a contract (account, hosting, and billing), legitimate interests (security, service improvement, fraud prevention, and business administration), legal obligation (tax, accounting, and lawful requests), and consent (where we ask for it, such as non-essential cookies or optional marketing).
Where we rely on legitimate interests, we balance those interests against your rights and expectations.
International Transfers
Some providers may process data outside the UK. Where personal data leaves the UK, we use a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or another lawful safeguard as applicable.
Retention
We retain account and transaction records for as long as needed to provide the Services and meet tax, accounting, fraud-prevention, dispute, and legal requirements. Technical logs are generally retained for a limited period appropriate to security and troubleshooting. Support records are kept while needed to resolve issues and maintain service history.
When an account closes, we delete or anonymise data when no longer required, subject to backups, legal retention, fraud prevention, and unresolved disputes.
Your UK Data Rights
Subject to legal exemptions, UK GDPR gives you rights to access, correct, erase, restrict, or object to processing, and to receive certain data in a portable format. Where processing is based on consent, you can withdraw it at any time. You also have the right to object to direct marketing.
To exercise a right, contact support@arlostudios.dev. We may need to verify your identity. You can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Data Security
We use access controls, least-privilege practices, encryption in transit, monitoring, and appropriate organisational measures to protect personal data. No system is completely secure. You are responsible for protecting your account credentials and any secrets placed in your server.
If you believe your account or data has been compromised, contact us promptly.
Children’s Data
The Services are not directed at children. You must meet the age requirements of applicable law and any payment or platform provider. We do not knowingly collect children’s data for our own purposes. Contact us if you believe this has occurred.
Changes & Contact
We may update this policy when our Services, providers, or legal obligations change. We will update the date above and take reasonable steps to highlight material changes.
For privacy questions, data requests, or concerns, email support@arlostudios.dev or visit our homepage.
Questions about this policy?
We're happy to clarify anything. Reach out and a member of the Arlo Studios team will get back to you.