Folia Privacy Policy

Version: 1.0 Effective date: 19 September 2026 Last updated: 19 September 2026

This policy explains how personal data is handled in Folia, the communication platform operated by Cocoon Creations Services Limited. It covers parents and guardians using the app, staff using the back office, and visitors to this website.

If you are a parent or guardian: your school or parents association decides what information about you and your child is held in Folia and why. We run the platform for them. Section 5 explains what this means for you and who to contact about your rights.

Contents

  1. Who we are
  2. Scope of this policy
  3. Our two roles: processor and controller
  4. Data we handle for Organisations
  5. What this means for parents and guardians
  6. Children's data
  7. Data we handle as controller
  8. Cookies and similar technologies
  9. Who we share data with
  10. International transfers
  11. How long we keep data
  12. Security
  13. Your rights
  14. Automated decision making
  15. Data breaches
  16. Changes to this policy
  17. Contact and complaints

1. Who we are

CompanyCocoon Creations Services Limited ("Cocoon", "we", "us")
Registration numberHE 304561 (Republic of Cyprus)
Office20 Ionos Street, 3rd Floor, 2406 Egkomi, Nicosia, Cyprus
ProductFolia, a communication platform for schools, parents associations and similar organisations
Privacy contact[email protected]

2. Scope of this policy

This policy applies to:

It does not cover the websites, apps or practices of your school, your parents association, or any third party we link to. Those organisations have their own privacy notices.

3. Our two roles: processor and controller

Under the GDPR, the "controller" decides why and how personal data is used. The "processor" handles data on the controller's instructions. Folia involves both.

DataControllerOur role
Child records, parent and guardian records, announcements, events, read and response recordsThe school or parents association that entered the dataProcessor. We act only on their instructions.
Back office user accounts and access logsThe Organisation for its own staff, and Cocoon for security and platform integrityProcessor and, for security purposes, controller
Enquiries sent to us, support conversations, prospective customer contactsCocoonController
Website visitor data, cookies and website analyticsCocoonController
Aggregated and anonymised usage statistics about the platformCocoonController. No longer personal data once aggregated.

4. Data we handle for Organisations

When a school or parents association uses Folia, we process the following on its behalf.

4.1 Categories of data

CategoryExamplesSource
Child recordsName, the school and entities the child belongs to, the class or group, the linked parentsEntered or imported by the Organisation
Parent and guardian recordsName, email address, the children linked to them, language preferenceEntered or imported by the Organisation
Authentication dataOne time login codes, the time they were issued and used, failed attempt countsGenerated by the platform
Device and notification dataPush notification token, device platform and app version, notification permission statusGenerated by the app on the parent's device
Engagement dataWhich announcements a parent opened and when, responses such as accept, decline, acknowledge and confirmGenerated by the parent's use of the app
Acceptance recordsThe date and version of the Terms and Privacy Policy accepted at first loginGenerated by the platform
ContentAnnouncements and events, including any personal data an Organisation chooses to put in them, and attached imagesPublished by the Organisation
Technical logsIP address, timestamps, request and error logsGenerated automatically

We do not ask for, and Folia is not designed to hold, special category data such as health, religious or ethnic information. Organisations are instructed not to put such data into announcements or records. See section 6.

4.2 What we do with it

Only what is needed to run the platform for the Organisation:

We do not sell this data, use it for advertising, use it to train artificial intelligence models, or share it with anyone other than the sub processors listed in section 9.

4.3 Lawful basis

The lawful basis for holding this data is the Organisation's responsibility, not ours, because the Organisation is the controller. Typically an Organisation relies on performance of a contract with the parent, its legitimate interests in communicating about a child's education and activities, or a legal or statutory duty. Your Organisation's own privacy notice should tell you which. Our basis for processing is our contract with the Organisation, together with the Data Processing Agreement required by Article 28 of the GDPR.

What accepting the Terms means

When you accept the Terms and Conditions and this Privacy Policy the first time you log in, you are agreeing to a contract for the use of the app, and you are confirming that you have been told how your data is handled. That acceptance is not the legal ground on which your school or parents association holds your data or your child's data. That ground is set by the Organisation, which must decide it, document it and explain it to you in its own privacy notice. If you want to know which ground applies to you, ask your Organisation. Withdrawing from the app does not remove your records from the Organisation's systems, because those records exist independently of the app.

5. What this means for parents and guardians

Your account and your child's record belong to your school or parents association. So:

6. Children's data

7. Data we handle as controller

7.1 Back office users

WhatWhyLawful basis
Name, work email, role, Organisation, password hashTo give access to the back office and apply the right permissionsPerformance of a contract, and our legitimate interest in operating the platform
Login records, IP address, audit log of sensitive actionsSecurity, abuse prevention, and being able to show who changed whatLegitimate interests in security and accountability, and legal obligation

7.2 Website visitors and enquiries

WhatWhyLawful basis
Name, email, organisation, message contentTo answer your enquiry and follow up about FoliaSteps at your request before entering a contract, and our legitimate interest in responding
IP address, browser, pages viewed, referrerTo keep the site secure and understand how it is usedLegitimate interests for essential logs, consent for analytics cookies
Marketing emails about FoliaTo tell you about the product where you asked us toConsent, which you can withdraw at any time using the unsubscribe link

7.3 Product usage analytics

We use analytics to understand how the platform performs and where it can improve, for example how many parents log in, how many open an announcement, and how many allow notifications.

8. Cookies and similar technologies

8.1 On the website

TypePurposeConsent needed
Strictly necessarySecurity, load balancing, remembering your cookie choiceNo
AnalyticsUnderstanding how visitors use the site. We use Google Analytics.Yes
MarketingMarketing tools such as cookies may be used for targeting and retargeting.Yes

We ask for your choice on your first visit through a cookie banner. You can change it at any time through your browser settings or by reopening the cookie banner. Declining non essential cookies does not affect your ability to use the site.

8.2 In the mobile app

The app does not use browser cookies. It uses local device storage to keep you logged in and to remember your language and filter preferences, and it holds a push notification token so notifications can reach your device. These are necessary for the app to work. Any non essential analytics are covered in section 7.3.

9. Who we share data with

We use a small number of service providers, each bound by a written contract that meets Article 28 of the GDPR and permits them to act only on our instructions.

ProviderWhat it doesData involvedLocation
Heroku Inc. and Amazon Web ServicesHosting, storage, back upsAll platform dataEuropean Union region. Heroku Inc. is incorporated in the United States.
Google Ireland Limited and Google LLC, for Firebase Cloud MessagingDelivering push notificationsDevice push token, notification title and short preview textEU and United States
Amazon Web Services, for Amazon SESSending login codes and system emailsEmail address, email contentEuropean Union region
Google Ireland Limited and Google LLC, for Firebase Analytics and Google AnalyticsUsage analyticsPseudonymous identifiers, device and event dataEU and United States
Apple Inc. and Google LLCApp distribution and OS level notification deliveryHandled under their own terms, as independent controllersUnited States

We also disclose data where we must, for example to a court, regulator or law enforcement body acting lawfully, or to our professional advisers under a duty of confidentiality. If Folia is sold or transferred, data may pass to the buyer, and we will tell affected Organisations in advance.

An Organisation that wants to be notified before we add or change a sub processor can ask us to place it on the notification list. The terms of that notice and the right to object are set out in the Data Processing Agreement.

10. International transfers

Platform data is stored in the European Union region of our hosting providers. Some of our providers are incorporated in the United States, including Heroku Inc., Amazon Web Services and Google, and some services involve transfers to the United States, in particular push notification delivery and analytics. Where that happens we rely on:

We keep the content of push notifications short and non sensitive so that the personal data leaving the EU is kept to a minimum. You can ask us for a copy of the transfer safeguards we rely on by writing to our privacy contact.

11. How long we keep data

DataRetention
Announcements and events1 year from publication, then deleted
Read and response records1 year from the related announcement, then deleted
Parent and child recordsFor as long as the child is linked to an active Entity of the Organisation, then deleted or anonymised within 18 months
Dormant parent accountsDeleted 1 year after the parent stops having any active linked child. A parent who still has a child linked to an active Entity keeps their account, however long it is since they last opened the app.
One time login codes10 minutes, then invalid. Deleted within 90 days.
Push notification tokensUntil the app is uninstalled, the token is refused by the provider, or the account is closed
Security and audit logs18 months
Back office accountsDeleted within 90 days of the user leaving the Organisation
Website enquiries24 months from the last contact
Contracts, invoices and accounting records6 years, as required by Cyprus tax and company law
Data after an Organisation terminatesExport available for 30 days, then deleted or anonymised within 60 days

12. Security

We apply technical and organisational measures appropriate to the risk, including:

No system is completely secure. If something goes wrong, section 15 explains what we do.

13. Your rights

Under the GDPR you have the right to:

13.1 How to exercise them

If you areWhere to send your request
A parent or guardianYour school or parents association, which is the controller. We will forward anything sent to us.
A back office userYour Organisation for your account data, and [email protected] for anything we control.
A website visitor or enquirer[email protected]

We respond within one month. If a request is complex we may extend this by up to two further months and will tell you why. We may ask for information to confirm your identity. Requests are free, unless they are manifestly unfounded or excessive.

14. Automated decision making

We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you. Announcements are routed to you based on the entities your children belong to, which is simple record matching, not profiling.

15. Data breaches

If a personal data breach occurs, we notify the affected Organisation without undue delay and no later than 72 hours after becoming aware of it, and we support the Organisation in meeting its own notification duties to the Commissioner and to affected individuals. Where we are the controller, we notify the Commissioner within 72 hours where the breach is likely to result in a risk to individuals, and we tell affected individuals where the risk is high.

16. Changes to this policy

We update this policy when the platform or the law changes. The version number and date at the top always show the current version. For material changes we give Organisations at least 30 days' notice, and parents are asked to accept the updated version the next time they open the app. Previous versions are available on request.

17. Contact and complaints

17.1 Contact us

Privacy enquiries[email protected]
PostCocoon Creations Services Ltd, 20 Ionos Street, 3rd Floor, 2406 Egkomi, Nicosia, Cyprus

17.2 Complain to the supervisory authority

If you are unhappy with how your personal data has been handled, you can complain to the Cypriot supervisory authority:

AuthorityOffice of the Commissioner for Personal Data Protection
AddressKypranoros 15, 1061 Nicosia, Cyprus. P.O. Box 23378, 1682 Nicosia, Cyprus
Email[email protected]
Websitewww.dataprotection.gov.cy

If you live in another EU member state, you can complain to your local supervisory authority instead. We would rather hear from you first, so please contact us and give us the chance to put things right.