Your privacy matters to us. This policy sets out, in plain language, what data we handle, why we handle it, how long we keep it, and the rights you have over it under the UK GDPR and Data Protection Act.
Overview
This Privacy Policy explains how Arlo Studios ("we", "us"), a UK-based studio building custom Discord bots, automation, and community tools, collects, uses, and protects personal data. It applies to our website, our communications with you, and the software we develop and operate on your behalf.
We act as a data controller for our own website and client relationships, and typically as a data processorwhen operating bots and tools on behalf of a client's Discord community.
Data We Collect
Depending on how you interact with us, we may collect:
- Contact data — name, email, Discord username, and the contents of messages you send us.
- Project data — briefs, requirements, assets, and credentials you share to enable us to deliver a project.
- Discord data — when a bot we build runs in your server, it may process user IDs, usernames, roles, message content, and server configuration strictly as needed for its features.
- Usage data — basic analytics such as pages visited and approximate performance metrics from our website.
How We Use Your Data
We use personal data to:
- Respond to enquiries and provide quotes.
- Deliver, operate, and maintain the software and services you commission.
- Process payments and keep accurate business records.
- Improve our website, services, and security.
- Comply with our legal and regulatory obligations.
Legal Basis for Processing
Under the UK GDPR, we rely on the following lawful bases: performance of a contract (to deliver projects you commission), legitimate interests (to run and improve our business securely), consent (where you opt in, for example to marketing), and legal obligation (such as tax and accounting requirements).
Where we process data on behalf of a client as a processor, we do so under that client's instructions and the relevant project agreement.
Data Retention
We keep personal data only for as long as necessary for the purposes set out in this policy, including to satisfy legal, accounting, or reporting requirements.
Data processed by bots is retained according to each project's configuration. On project termination, we will delete or return client and end-user data on request, subject to any legal retention requirements.
Data Security
We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, and the principle of least privilege. Credentials such as bot tokens are stored securely and never shared beyond what is required to operate your services.
No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any security incident.
Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data ("right to be forgotten").
- Restrict or object to certain processing.
- Request portability of data you provided to us.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us via our homepage. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
Children's Privacy
Our services are intended for users who meet Discord's minimum age requirement and the age of majority in their jurisdiction. We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us and we will take appropriate steps to remove it.
International Transfers
Some of our service providers may process data outside the UK or European Economic Area. Where this happens, we ensure appropriate safeguards are in place, such as adequacy decisions or standard contractual clauses, to protect your data.
Updates & Contact
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. We encourage you to review this page periodically.
For any privacy questions or data requests, reach out through the contact options on our homepage.
Questions about this policy?
We're happy to clarify anything. Reach out and a member of the Arlo Studios team will get back to you.