GATLING — Privacy
Introduction
Beta Notice: Gatling is currently in an active development and testing phase (beta). Access to the platform is exclusively available to employees and authorized personnel of Arcade Estudio. This Privacy Policy is provided proactively to establish our data protection practices before the platform is made available to the general public. Once Gatling enters public availability, this policy will govern all user data processing.
At Gatling ("the Application", "the Platform" or "Gatling"), operated by Arcade Estudio (hereinafter, "the Controller", "we" or "our"), we are committed to protecting your privacy and complying with current data protection regulations.
This Privacy Policy describes in a clear, detailed, and transparent manner how we process your personal data when you use Gatling, a platform for managing and publishing content simultaneously across multiple social networks. This policy complies with Regulation (EU) 2016/679 (GDPR), Argentina's Personal Data Protection Act No. 25.326, Brazil's Lei Geral de Proteção de Dados (LGPD) No. 13.709/2018, and the Meta Platform Terms applicable to applications that integrate with Instagram, Facebook, and Threads.
By registering, accessing, or using Gatling, you confirm that you have read, understood, and expressly accept this Privacy Policy.
About Arcade Estudio
Arcade Estudio is a software development studio specializing in building digital products for social media management, automation, and content publishing. Our mission is to create tools that empower businesses and creators to manage their digital presence efficiently and securely.
Gatling is one of our flagship products — a platform designed to connect multiple social media accounts and publish content simultaneously across all of them, similar to enterprise tools like Hootsuite or Buffer, but built with a focus on privacy, security, and user control.
- Core expertise: Full-stack web development (Go, Next.js, React, TypeScript), API integrations, OAuth 2.0, and social media platform APIs
- Privacy-first approach: We build with GDPR, LGPD, and Argentina's Law 25.326 compliance from day one, not as an afterthought
- Multi-platform support: Instagram, Facebook, Threads, YouTube, TikTok, LinkedIn, X/Twitter, Pinterest, Telegram, Mastodon, and Google Business Profile
- Security infrastructure: Distributed across AWS, Azure, GCP, Supabase, MongoDB Atlas, and other providers for redundancy and resilience
For more information about Arcade Estudio and our products, visit arcadeestudio.com.
Data Controller
- Entity: Arcade Estudio
- Privacy contact email: gatling@arcadeestudio.com
- Website: arcadeestudio.com
- Operating jurisdictions: Argentine Republic, Federative Republic of Brazil, and international clients
For any questions related to your personal data, you may contact us at any time via the email address provided above. We will respond to your request within a maximum of 15 business days.
1. Personal Data We Collect
1.1 Data provided directly by the user
During the registration process and use of the Platform, we collect the following data:
- Email address
- Chosen username
- Profile photo (if you choose to upload one)
- Password (stored using cryptographic hash, not in plain text)
1.2 Data obtained through third-party APIs (OAuth)
When you connect your social media accounts to Gatling via the OAuth 2.0 protocol, we collect the following data from each platform:
- Access tokens required to publish content on your behalf
- Unique user identifier on each platform
- Public profile name and photo
- List of pages, groups, or accounts you have access to and explicitly authorize
Important: We only request the strictly necessary permissions for the publishing functionality (typically the pages_read_engagement, pages_manage_posts, instagram_basic, instagram_content_publish scopes or other equivalents depending on the platform). We do not request permissions to read private messages, post on others' walls, or access friends' or contacts' data.
1.3 Content data
- Text, images, videos, and multimedia files that you upload or schedule for publication through Gatling
- Associated metadata: scheduled date and time, target platforms, publication status
- Performance metrics provided by each platform's APIs (reach, impressions, interactions, clicks)
1.4 Technical data collected automatically
- IP address
- Browser type and version
- Operating system and version
- Pages visited within the Application and duration of visit
- Visual theme preference (light/dark), stored in localStorage
- Session identifiers
Important notice for Meta review: Gatling does not collect, store, or process sensitive data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning sex life or sexual orientation). We also do not collect users' friends, followers, or contacts data.
2. Purpose of Data Processing
We process your personal data exclusively for the following purposes:
| Purpose | Description | Legal Basis |
|---|---|---|
| Service provision | Schedule, manage, and publish content on the social networks the user connects. | Contract performance (GDPR art. 6.1.b) |
| Account management | Create, maintain, and manage your user account. | Contract performance (GDPR art. 6.1.b) |
| Service improvement | Analyze aggregated usage patterns to improve functionality and user experience. | Legitimate interest (GDPR art. 6.1.f) |
| Communications | Send technical notifications, service updates, changes to terms or policies. | Legal compliance / Legitimate interest |
| Security | Detect, prevent, and mitigate unauthorized access, fraudulent use, or security breaches. | Legitimate interest (GDPR art. 6.1.f) |
We do not use your data for advertising purposes, commercial profiling, data selling, or any other purpose other than those described here.
3. Legal Basis for Processing
The processing of your personal data is based on the following legal grounds:
- Contract performance (GDPR art. 6.1.b / LGPD art. 7, V): Processing is necessary for the provision of the social media management service you request when registering and accepting our Terms of Service.
- Consent (GDPR art. 6.1.a / LGPD art. 7, I): When you connect a social media account, you grant explicit consent for Gatling to access the authorized data via OAuth and publish content on your behalf.
- Legitimate interest (GDPR art. 6.1.f / LGPD art. 7, IX): For continuous platform improvement, aggregated (non-individual) usage analysis, and security measures.
- Legal compliance (GDPR art. 6.1.c / LGPD art. 7, II): To comply with obligations established by applicable legislation, including Argentina's Law 25.326, Brazil's LGPD, and obligations derived from Meta Platform Terms.
4. Data Recipients (Disclosures and Transfers)
Gatling does not sell, rent, or disclose personal data to third parties for commercial purposes. We only share data in the following cases:
4.1 Social media platforms
When you use Gatling to publish content, your data is transferred to the social media platforms you have selected, exclusively through their official APIs and under the OAuth permissions you have previously authorized. These platforms act as independent data controllers:
- Meta Platforms, Inc. (Instagram, Facebook, Threads) — Privacy Policy
- Google LLC (YouTube, Google Business Profile) — Privacy Policy
- ByteDance Ltd. (TikTok) — Privacy Policy
- Microsoft Corporation (LinkedIn) — Privacy Policy
- X Corp. (X / Twitter) — Privacy Policy
- Pinterest, Inc. — Privacy Policy
- Telegram — Privacy Policy
- Mastodon (decentralized servers) — Each instance has its own privacy policy
Each platform has its own data protection policies and terms of service. We encourage you to review them. Gatling only accesses the minimum data necessary for content publishing functionality (profile name, photo, and publish permissions). We do not access private messages, contacts lists, or any data beyond what is strictly required for the service.
4.2 Infrastructure providers
Arcade Estudio distributes its infrastructure across multiple independent third-party providers to ensure redundancy, availability, and security through distribution. Your data may transit through any of the following services during normal platform operation:
- Cloud Platforms: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform
- Hosting & Deployment: Hostinger, Netlify, Vercel, Cloudflare Pages, GitHub Pages, Render, Railway
- Cloud Databases: Supabase, MongoDB Atlas, Firebase (Google Cloud), AWS RDS, Azure Cosmos DB, PlanetScale, Neon
- Code & Version Control: GitHub (Microsoft), GitLab, Bitbucket
- VPS & Compute: DigitalOcean, Linode, Vultr, Hetzner, various VPS providers as required
- DNS & CDN: Cloudflare, AWS CloudFront, Hostinger CDN, Fastly
- Email & Communication: SendGrid, Mailgun, AWS SES
This list is updated publicly as we adopt or migrate to new providers. Data may transit through these third-party services during normal operation of the platform, even if they do not store it persistently. Each provider operates under its own data protection policies and terms of service.
4.3 Legal obligations
We may disclose your personal data if required by law, a judicial process, a competent authority request, or to protect our rights, property, or safety, as well as those of our users or third parties.
4.4 Cybersecurity and internal audit
Arcade Estudio maintains a proactive cybersecurity posture through proprietary audit tools and internal security protocols. These measures include, but are not limited to:
- Proprietary audit tools: Custom-built security auditing software for continuous monitoring of data flows, access patterns, and system integrity across all infrastructure layers.
- Access control enforcement: Automated verification that only authorized personnel access user data, with audit trails for all privileged operations.
- Vulnerability scanning: Regular internal scans of all endpoints, APIs, and database interfaces to identify and remediate potential attack vectors before exploitation.
- Data encryption verification: Internal checks ensuring encryption-at-rest and encryption-in-transit are correctly applied across all storage and communication layers.
- Incident response protocols: Documented and tested procedures for detecting, containing, and notifying affected parties in the event of a data breach, in compliance with Argentina's Law 25.326, LGPD, and GDPR breach notification requirements.
- Third-party provider auditing: Periodic review of third-party provider security certifications and compliance status (SOC 2, ISO 27001, GDPR compliance documentation).
These internal security measures are maintained independently of the third-party providers listed in section 4.2. Arcade Estudio retains full control over audit methodology and frequency.
5. Data Retention
We retain your personal data for as long as you maintain an active account on Gatling. Once you request account deletion, all your personal data, access tokens, scheduled content, and associated metrics are permanently and irreversibly deleted within a maximum of 30 days, unless there is a legal obligation requiring their retention for an additional period.
Aggregated technical data (not associated with an identifiable user) may be retained in anonymized form for statistical purposes.
6. User Rights
In accordance with the GDPR (EU), Law 25.326 (Argentina), and LGPD (Brazil), you have the following rights over your personal data:
- Right of access: You may request confirmation as to whether we are processing your personal data and, if so, access to it.
- Right to rectification: You may request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): You may request deletion of your data when it is no longer necessary for the purposes for which it was collected.
- Right to restriction of processing: You may request that we restrict the processing of your data under certain circumstances.
- Right to data portability: You may request to receive your data in a structured, commonly used, and machine-readable format.
- Right to object: You may object to the processing of your data based on legitimate interest.
- Right to withdraw consent: You may withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, send a request to gatling@arcadeestudio.com. We will respond within a maximum of 15 business days. Additionally:
- If you are a resident of the European Union, you have the right to lodge a complaint with your competent supervisory authority.
- If you are a resident of Brazil, you may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
- If you are a resident of Argentina, you may file a complaint with the Agencia de Acceso a la Información Pública (AAIP).
7. Data Deletion and Account Deactivation
Deletion effects: When you delete your account: (i) all your personal data is permanently erased; (ii) OAuth access tokens are revoked and destroyed; (iii) pending scheduled content is cancelled; (iv) historical metrics associated with your account are deleted. This action is irreversible.
Request Account Deletion
Fill out the form to request the permanent deletion of your account and all associated data.
Other request channels:
- From the Application: Access your profile within the control panel and select the "Delete my account" option. The process is immediate and irreversible.
- By email: Send an email to gatling@arcadeestudio.com requesting the deletion of your account. Include the same email you use in Gatling. We will process the request within a maximum of 7 business days.
Meta data deletion (Instagram / Facebook / Threads): In addition to deleting your account on Gatling, you can disconnect your account from each Meta platform at any time from the "Accounts" section of the control panel. You can also manage and revoke Gatling permissions directly from your Meta account settings: Settings > Apps and websites.
8. Security Measures
We implement the following technical and organizational measures to ensure an adequate level of security appropriate to the risk:
- Encryption in transit: All communications between your browser and our servers use TLS 1.3 (HTTPS).
- Encryption at rest: OAuth access tokens are stored encrypted using AES-256. Passwords are stored using bcrypt hashing with salt.
- Database security: The SQLite database is protected with file-level encryption and restricted access permissions.
- Access control: Access to data is restricted exclusively to authorized Arcade Estudio personnel under the principle of least privilege.
- Auditing: We maintain access logs for systems that store personal data.
- Updates: All system components are kept up to date with the latest security patches.
9. Cookies and Similar Technologies
Gatling exclusively uses the following local storage technologies:
- Browser localStorage: To store your theme preference (light/dark) and the session tokens necessary to maintain your logged-in session. This data is not shared with third parties and remains only in your browser.
- Technical cookies: Strictly necessary for login functionality and session security.
We do not use tracking cookies, advertising cookies, third-party analytics cookies, tracking pixels, or any other technology that allows tracking of your activity outside of Gatling.
10. International Data Transfers
Gatling is operated from the Argentine Republic and Brazil. If you access from outside these countries, your data may be transferred and processed on servers located in Argentina or Brazil.
- Argentina: Argentine data protection legislation (Law 25.326) has been recognized by the European Commission as providing an adequate level of protection (Implementing Decision (EU) 2023/488), so transfers from the EU to Argentina do not require additional safeguards.
- Brazil: Brazil's LGPD (Law 13.709/2018) provides adequate protections for international data transfers. Transfers to countries with adequate protection levels are permitted under LGPD art. 33.
By using Gatling, you expressly consent to this data transfer for the provision of the contracted service.
11. Minors
Gatling is not directed at children under 13 years of age (or 16 years in the European Economic Area, or 12 years in Brazil under LGPD, depending on applicable legislation). We do not knowingly collect personal data from minors. If we become aware that a minor has created an account on Gatling, we will proceed with the immediate deletion of all their data and deactivation of their account. If you are a parent, guardian, or tutor and detect that a minor has provided data to Gatling, contact us immediately at gatling@arcadeestudio.com.
12. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or the terms of the platforms we integrate with. We will notify significant changes through the Application or via email with at least 15 days' notice before they take effect. Continued use of Gatling after the changes take effect constitutes your acceptance of the updated policy.
We recommend reviewing this page periodically to stay informed about how we protect your information. The date of the last update is indicated at the beginning of this document.
13. Contact
If you have questions, concerns, or wish to exercise your rights regarding this Privacy Policy or the processing of your personal data, you may contact us through the following channels:
- Privacy contact email: gatling@arcadeestudio.com
- Controller: Arcade Estudio
- Website: arcadeestudio.com
Applicable legislation: This Privacy Policy is governed by the legislation of the Argentine Republic (Personal Data Protection Act No. 25.326), the Federative Republic of Brazil (Lei Geral de Proteção de Dados No. 13.709/2018), and complementarily by the European Union's General Data Protection Regulation (GDPR) for users domiciled in the European Economic Area.
Meta compliance: Gatling complies with Meta Platform Terms, Meta Data Policy, and Meta Platforms, Inc. App Review requirements.
Gatling — Social Media Management by Arcade Estudio
arcadeestudio.com · gatling@arcadeestudio.com
© Arcade Estudio. All rights reserved.