Folia Privacy Policy
This policy explains how personal data is handled in Folia, the communication platform operated by Cocoon Creations Services Limited. It covers parents and guardians using the app, staff using the back office, and visitors to this website.
If you are a parent or guardian: your school or parents association decides what information about you and your child is held in Folia and why. We run the platform for them. Section 5 explains what this means for you and who to contact about your rights.
Contents
- Who we are
- Scope of this policy
- Our two roles: processor and controller
- Data we handle for Organisations
- What this means for parents and guardians
- Children's data
- Data we handle as controller
- Cookies and similar technologies
- Who we share data with
- International transfers
- How long we keep data
- Security
- Your rights
- Automated decision making
- Data breaches
- Changes to this policy
- Contact and complaints
1. Who we are
| Company | Cocoon Creations Services Limited ("Cocoon", "we", "us") |
|---|---|
| Registration number | HE 304561 (Republic of Cyprus) |
| Office | 20 Ionos Street, 3rd Floor, 2406 Egkomi, Nicosia, Cyprus |
| Product | Folia, a communication platform for schools, parents associations and similar organisations |
| Privacy contact | [email protected] |
2. Scope of this policy
This policy applies to:
- the Folia mobile app for iOS and Android, used by parents and guardians;
- the Folia web back office, used by managers and administrators;
- the Folia website;
- emails and support communications relating to Folia.
It does not cover the websites, apps or practices of your school, your parents association, or any third party we link to. Those organisations have their own privacy notices.
3. Our two roles: processor and controller
Under the GDPR, the "controller" decides why and how personal data is used. The "processor" handles data on the controller's instructions. Folia involves both.
| Data | Controller | Our role |
|---|---|---|
| Child records, parent and guardian records, announcements, events, read and response records | The school or parents association that entered the data | Processor. We act only on their instructions. |
| Back office user accounts and access logs | The Organisation for its own staff, and Cocoon for security and platform integrity | Processor and, for security purposes, controller |
| Enquiries sent to us, support conversations, prospective customer contacts | Cocoon | Controller |
| Website visitor data, cookies and website analytics | Cocoon | Controller |
| Aggregated and anonymised usage statistics about the platform | Cocoon | Controller. No longer personal data once aggregated. |
4. Data we handle for Organisations
When a school or parents association uses Folia, we process the following on its behalf.
4.1 Categories of data
| Category | Examples | Source |
|---|---|---|
| Child records | Name, the school and entities the child belongs to, the class or group, the linked parents | Entered or imported by the Organisation |
| Parent and guardian records | Name, email address, the children linked to them, language preference | Entered or imported by the Organisation |
| Authentication data | One time login codes, the time they were issued and used, failed attempt counts | Generated by the platform |
| Device and notification data | Push notification token, device platform and app version, notification permission status | Generated by the app on the parent's device |
| Engagement data | Which announcements a parent opened and when, responses such as accept, decline, acknowledge and confirm | Generated by the parent's use of the app |
| Acceptance records | The date and version of the Terms and Privacy Policy accepted at first login | Generated by the platform |
| Content | Announcements and events, including any personal data an Organisation chooses to put in them, and attached images | Published by the Organisation |
| Technical logs | IP address, timestamps, request and error logs | Generated automatically |
We do not ask for, and Folia is not designed to hold, special category data such as health, religious or ethnic information. Organisations are instructed not to put such data into announcements or records. See section 6.
4.2 What we do with it
Only what is needed to run the platform for the Organisation:
- authenticate parents and keep accounts secure;
- work out which announcements and events each parent should see, based on their children's entities;
- send push notifications and login emails;
- record opens and responses, and show these back to the Organisation as reports;
- provide support, back ups, security monitoring and troubleshooting;
- meet our legal obligations.
We do not sell this data, use it for advertising, use it to train artificial intelligence models, or share it with anyone other than the sub processors listed in section 9.
4.3 Lawful basis
The lawful basis for holding this data is the Organisation's responsibility, not ours, because the Organisation is the controller. Typically an Organisation relies on performance of a contract with the parent, its legitimate interests in communicating about a child's education and activities, or a legal or statutory duty. Your Organisation's own privacy notice should tell you which. Our basis for processing is our contract with the Organisation, together with the Data Processing Agreement required by Article 28 of the GDPR.
What accepting the Terms means
When you accept the Terms and Conditions and this Privacy Policy the first time you log in, you are agreeing to a contract for the use of the app, and you are confirming that you have been told how your data is handled. That acceptance is not the legal ground on which your school or parents association holds your data or your child's data. That ground is set by the Organisation, which must decide it, document it and explain it to you in its own privacy notice. If you want to know which ground applies to you, ask your Organisation. Withdrawing from the app does not remove your records from the Organisation's systems, because those records exist independently of the app.
5. What this means for parents and guardians
Your account and your child's record belong to your school or parents association. So:
- To correct your details, change which children are linked to you, or have your account removed, contact your Organisation. They can make those changes directly in the back office.
- To exercise your GDPR rights, including access, erasure, objection and restriction, address your request to your Organisation as the controller. If you send it to us, we will forward it to them without undue delay and let you know we have done so. We cannot act on it ourselves without their instruction.
- What other parents can see. Other parents do not see your email address, your phone number or your child's record. Folia is one way communication from the Organisation to parents. Parents cannot message each other and cannot see the recipient list.
- What your Organisation can see. Your Organisation can see whether you opened each announcement and when, and your answer where a response was requested. It can also see whether you are receiving notifications.
6. Children's data
- Children are not users of Folia. The app is for parents and guardians, who must be adults.
- The child data held is deliberately minimal: enough to link a child to their parents and to the right entities, so the right announcements reach the right people.
- Organisations are contractually instructed not to include sensitive information about a child in announcements or records, including health conditions, dietary or medical needs, disciplinary matters, family circumstances, or anything else that is not necessary for the communication.
- Photographs of children published in announcements are the Organisation's responsibility. The Organisation must hold the appropriate permissions before publishing them.
- In the Republic of Cyprus, the age at which a child can consent to information society services is 14 under Law 125(I)/2018. Folia does not rely on a child's consent for anything, because children do not use the platform.
7. Data we handle as controller
7.1 Back office users
| What | Why | Lawful basis |
|---|---|---|
| Name, work email, role, Organisation, password hash | To give access to the back office and apply the right permissions | Performance of a contract, and our legitimate interest in operating the platform |
| Login records, IP address, audit log of sensitive actions | Security, abuse prevention, and being able to show who changed what | Legitimate interests in security and accountability, and legal obligation |
7.2 Website visitors and enquiries
| What | Why | Lawful basis |
|---|---|---|
| Name, email, organisation, message content | To answer your enquiry and follow up about Folia | Steps at your request before entering a contract, and our legitimate interest in responding |
| IP address, browser, pages viewed, referrer | To keep the site secure and understand how it is used | Legitimate interests for essential logs, consent for analytics cookies |
| Marketing emails about Folia | To tell you about the product where you asked us to | Consent, which you can withdraw at any time using the unsubscribe link |
7.3 Product usage analytics
We use analytics to understand how the platform performs and where it can improve, for example how many parents log in, how many open an announcement, and how many allow notifications.
8. Cookies and similar technologies
8.1 On the website
| Type | Purpose | Consent needed |
|---|---|---|
| Strictly necessary | Security, load balancing, remembering your cookie choice | No |
| Analytics | Understanding how visitors use the site. We use Google Analytics. | Yes |
| Marketing | Marketing tools such as cookies may be used for targeting and retargeting. | Yes |
We ask for your choice on your first visit through a cookie banner. You can change it at any time through your browser settings or by reopening the cookie banner. Declining non essential cookies does not affect your ability to use the site.
8.2 In the mobile app
The app does not use browser cookies. It uses local device storage to keep you logged in and to remember your language and filter preferences, and it holds a push notification token so notifications can reach your device. These are necessary for the app to work. Any non essential analytics are covered in section 7.3.
9. Who we share data with
We use a small number of service providers, each bound by a written contract that meets Article 28 of the GDPR and permits them to act only on our instructions.
| Provider | What it does | Data involved | Location |
|---|---|---|---|
| Heroku Inc. and Amazon Web Services | Hosting, storage, back ups | All platform data | European Union region. Heroku Inc. is incorporated in the United States. |
| Google Ireland Limited and Google LLC, for Firebase Cloud Messaging | Delivering push notifications | Device push token, notification title and short preview text | EU and United States |
| Amazon Web Services, for Amazon SES | Sending login codes and system emails | Email address, email content | European Union region |
| Google Ireland Limited and Google LLC, for Firebase Analytics and Google Analytics | Usage analytics | Pseudonymous identifiers, device and event data | EU and United States |
| Apple Inc. and Google LLC | App distribution and OS level notification delivery | Handled under their own terms, as independent controllers | United States |
We also disclose data where we must, for example to a court, regulator or law enforcement body acting lawfully, or to our professional advisers under a duty of confidentiality. If Folia is sold or transferred, data may pass to the buyer, and we will tell affected Organisations in advance.
An Organisation that wants to be notified before we add or change a sub processor can ask us to place it on the notification list. The terms of that notice and the right to object are set out in the Data Processing Agreement.
10. International transfers
Platform data is stored in the European Union region of our hosting providers. Some of our providers are incorporated in the United States, including Heroku Inc., Amazon Web Services and Google, and some services involve transfers to the United States, in particular push notification delivery and analytics. Where that happens we rely on:
- the European Commission's adequacy decision for the EU to US Data Privacy Framework, where the recipient is certified under it; and
- the European Commission's Standard Contractual Clauses, together with supplementary technical and organisational measures, as a fallback.
We keep the content of push notifications short and non sensitive so that the personal data leaving the EU is kept to a minimum. You can ask us for a copy of the transfer safeguards we rely on by writing to our privacy contact.
11. How long we keep data
| Data | Retention |
|---|---|
| Announcements and events | 1 year from publication, then deleted |
| Read and response records | 1 year from the related announcement, then deleted |
| Parent and child records | For as long as the child is linked to an active Entity of the Organisation, then deleted or anonymised within 18 months |
| Dormant parent accounts | Deleted 1 year after the parent stops having any active linked child. A parent who still has a child linked to an active Entity keeps their account, however long it is since they last opened the app. |
| One time login codes | 10 minutes, then invalid. Deleted within 90 days. |
| Push notification tokens | Until the app is uninstalled, the token is refused by the provider, or the account is closed |
| Security and audit logs | 18 months |
| Back office accounts | Deleted within 90 days of the user leaving the Organisation |
| Website enquiries | 24 months from the last contact |
| Contracts, invoices and accounting records | 6 years, as required by Cyprus tax and company law |
| Data after an Organisation terminates | Export available for 30 days, then deleted or anonymised within 60 days |
12. Security
We apply technical and organisational measures appropriate to the risk, including:
- encryption of data in transit using TLS, and encryption of personal data at rest;
- hosting in the European Union with daily back ups and tested restore procedures;
- passwordless login for parents using single use, time limited codes, with rate limits and attempt limits;
- role based access control in the back office, so a manager only reaches the entities they are assigned to;
- audit logging of sensitive back office actions;
- sanitisation of content published through the back office to prevent malicious markup;
- input validation and protection against common web attacks;
- access to production systems limited to named Cocoon personnel who need it, under confidentiality obligations.
No system is completely secure. If something goes wrong, section 15 explains what we do.
13. Your rights
Under the GDPR you have the right to:
- Access the personal data held about you, and receive a copy.
- Rectification of data that is wrong or incomplete.
- Erasure of your data, where there is no overriding reason to keep it.
- Restriction of processing in certain circumstances.
- Portability, to receive data you provided in a machine readable format.
- Object to processing based on legitimate interests, and to object to direct marketing at any time.
- Withdraw consent at any time, where processing is based on consent. This does not affect processing already carried out.
- Complain to a supervisory authority.
13.1 How to exercise them
| If you are | Where to send your request |
|---|---|
| A parent or guardian | Your school or parents association, which is the controller. We will forward anything sent to us. |
| A back office user | Your Organisation for your account data, and [email protected] for anything we control. |
| A website visitor or enquirer | [email protected] |
We respond within one month. If a request is complex we may extend this by up to two further months and will tell you why. We may ask for information to confirm your identity. Requests are free, unless they are manifestly unfounded or excessive.
14. Automated decision making
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you. Announcements are routed to you based on the entities your children belong to, which is simple record matching, not profiling.
15. Data breaches
If a personal data breach occurs, we notify the affected Organisation without undue delay and no later than 72 hours after becoming aware of it, and we support the Organisation in meeting its own notification duties to the Commissioner and to affected individuals. Where we are the controller, we notify the Commissioner within 72 hours where the breach is likely to result in a risk to individuals, and we tell affected individuals where the risk is high.
16. Changes to this policy
We update this policy when the platform or the law changes. The version number and date at the top always show the current version. For material changes we give Organisations at least 30 days' notice, and parents are asked to accept the updated version the next time they open the app. Previous versions are available on request.
17. Contact and complaints
17.1 Contact us
| Privacy enquiries | [email protected] |
|---|---|
| Post | Cocoon Creations Services Ltd, 20 Ionos Street, 3rd Floor, 2406 Egkomi, Nicosia, Cyprus |
17.2 Complain to the supervisory authority
If you are unhappy with how your personal data has been handled, you can complain to the Cypriot supervisory authority:
| Authority | Office of the Commissioner for Personal Data Protection |
|---|---|
| Address | Kypranoros 15, 1061 Nicosia, Cyprus. P.O. Box 23378, 1682 Nicosia, Cyprus |
| [email protected] | |
| Website | www.dataprotection.gov.cy |
If you live in another EU member state, you can complain to your local supervisory authority instead. We would rather hear from you first, so please contact us and give us the chance to put things right.