Children's Privacy Notice
How data about children is handled, and how a parent reviews or deletes it.
Children's Privacy Notice is not yet published.
The text below is a draft awaiting legal review. It is not in force, no part of it creates any obligation or right, and nothing on this page should be relied on. Passages marked [TO BE CONFIRMED] are values that have deliberately been left blank rather than guessed.
Catomni Studio handles information about children, so these documents go to a lawyer before they take effect rather than being generated and published.
If you need answers about how your data is handled before these are published, contact your studio directly.
Draft revised: 2026-08-17
Notes for legal review
Open questions and drafting assumptions in this document. These notes are removed when the document goes into force.
- DRAFT for review, and the highest-risk document in the set. COPPA, GDPR Art. 8 and state student-privacy laws are all potentially in scope.
- Drafted on the assumption that the STUDIO obtains verifiable parental consent as controller and Catomni acts as processor. This is the open decision on SHA-883. If Catomni were instead to obtain consent directly, this document changes fundamentally and so does the product.
- The platform does support a "student" role, so a studio can issue a login to a student who may be a minor. This is stated accurately in section 4 rather than claiming children never have accounts. Consider whether the product should restrict or gate that role.
- Student photographs and milestone photographs of children are stored. They are currently served only to signed-in users. Confirm whether a media-release obligation should be a contractual requirement on studios rather than only a statement here.
- FERPA is drafted as generally inapplicable to a private studio. If any studio operates under contract to a school, that changes — confirm whether to address it.
1. Why this notice exists
Studios that use Catomni teach children, so the platform holds information about children. This notice explains what is held, who is responsible for it, and how a parent or guardian can see it, correct it or have it removed.
It supplements the Privacy Policy. Where the two differ on children's information, this notice governs.
2. Who is responsible — your studio
Your studio, not Shannon Cyber Services, LLC, decides what to record about your child and why. Your studio is responsible for obtaining any parental consent the law requires. We host and process that information on the studio's instructions, and we do not decide what is collected.
This means the fastest route for any request about your child is your studio. It can view, correct and delete the record directly. If you ask us, we will refer your request to the studio and help it respond — we are not able to judge who is entitled to make decisions about a particular child's record, so we do not act on such requests ourselves.
3. What is held about a child
- Identity — name and date of birth.
- Relationships — which guardians and which family account the child belongs to.
- Participation — enrolments, class schedule, attendance and check-in history.
- Progress — programme, rank or belt progression, milestones and achievements, and instructor notes.
- Health — allergy and medical notes, where the studio records them.
- Photographs — a student photograph, and photographs attached to milestones or achievements, where the studio uploads them.
- Billing — the family account the child is associated with, and its payment status. Children are not billed directly.
We do not collect more than the studio enters. We do not build advertising or behavioural profiles of children, do not track children across other websites, and do not disclose a child's information for marketing.
4. Accounts and children
The family portal is designed for parents, guardians and other adult account holders. We do not create accounts for children on our own initiative, and we do not knowingly collect personal information directly from a child through our website.
The platform does, however, support a student role, so a studio can choose to issue a login to a student — who may be a minor. Where a studio does that, the studio is responsible for obtaining any consent required first. If you believe a child has been given an account without the necessary consent, contact the studio, and you may also contact us at [TO BE CONFIRMED: privacy contact email].
5. Rights of parents and guardians
As a parent or guardian you may, subject to the studio's verification of who you are:
- Review the personal information held about your child.
- Have it corrected if it is wrong.
- Have it deleted, and have your child removed from the platform.
- Refuse to permit further collection or use of it, and withdraw a consent you previously gave.
- Ask for it in a portable form.
Exercising some of these rights may mean your child can no longer take part in classes managed through the platform, because the studio needs a record in order to enrol and register attendance. That is a consequence of deletion, not a penalty for asking.
Much of this is available to you immediately in the family portal, where you can see your children's schedule, attendance, progress and billing. For correction and deletion, contact your studio. Privacy Rights Requests describes the process if you need to come to us.
6. Who can see a child's record
- Studio staff, according to the permissions the studio configures for each role.
- Guardians linked to the child, through the family portal.
- Our service providers, as listed in the Sub-processor List, to the extent needed to host and deliver the Service.
A studio can set a family to a separated-guardian mode, which restricts what one guardian can see about the other guardians and about certain family details. Staff-only information, including internal notes and billing identifiers, is never shown in the family portal.
Where a child attends more than one studio using Catomni, only identity information is shared between those studios so the family can use a single account. Medical notes, allergies, emergency contacts, notes and progress records are kept separately per studio and are not visible across them.
7. Health and emergency information
Allergy and medical notes are stored so that a studio's staff can look them up. The platform does not alert anyone, does not check them against anything, and does not guarantee that any person will read them. Tell your studio directly about any condition that matters, and do not rely on a note in the platform to protect your child.
8. Photographs
Where a studio uploads a photograph of a child, it is stored on our behalf by Cloudflare and is served only to users who are signed in to the platform. Studios are responsible for having whatever photograph release or permission their own law and policies require, and for removing a photograph on request.
9. Schools and student-records law
Catomni is provided to private activity businesses rather than to schools, so the Family Educational Rights and Privacy Act ("FERPA") does not generally apply. Where a studio delivers programmes under an arrangement with a school or district, additional student-privacy obligations may apply to that studio, and it should tell us before recording information under such an arrangement.
10. Contact
Contact your studio first — it can act on your request immediately. To reach us: [TO BE CONFIRMED: privacy contact email], or Shannon Cyber Services, LLC, [TO BE CONFIRMED: registered address].