Privacy Policy

What we collect, why, and the rights you have over it.

Privacy Policy is not yet published.

The text below is a draft awaiting legal review. It is not in force, no part of it creates any obligation or right, and nothing on this page should be relied on. Passages marked [TO BE CONFIRMED] are values that have deliberately been left blank rather than guessed.

Catomni Studio handles information about children, so these documents go to a lawyer before they take effect rather than being generated and published.

If you need answers about how your data is handled before these are published, contact your studio directly.

Draft revised: 2026-08-17

Notes for legal review

Open questions and drafting assumptions in this document. These notes are removed when the document goes into force.

  • DRAFT for review. The data inventory below was compiled from the database schema and code, so it reflects what the platform actually stores rather than a generic template.
  • Drafted on the assumption that the STUDIO is the controller for student and family data and obtains any required parental consent, with Catomni as processor. This is the central open product decision on SHA-883 and must be confirmed — much of this document and the whole Children's Privacy Notice follow from it.
  • All sub-processors are US-based. The transfer mechanism (Standard Contractual Clauses, UK Addendum, and whether to rely on the EU-US Data Privacy Framework) needs to be settled before serving UK/EU studios.
  • Retention periods are drafted as principles rather than fixed numbers, because studios have their own record-retention obligations. Confirm whether fixed maximum periods should be committed to.
  • Section 12 discloses that platform administrators can access customer data and can impersonate a user for support. This is accurate and deliberate; confirm the disclosure wording.

1. Scope, and the two roles we play

This policy explains how Shannon Cyber Services, LLC handles personal information in connection with the Catomni Studio platform and the https://shannoncyber.ai website.

Catomni Studio is sold to studios, gyms, dojos and academies (each a "Studio"). A Studio decides what information to record about its students and families and why. For that information, the Studio is the controller (or "business") and Shannon Cyber Services, LLC is the processor (or "service provider") acting on the Studio's instructions. For information Shannon Cyber Services, LLC handles for its own purposes — Studio staff accounts, platform billing, marketing enquiries and site security — Shannon Cyber Services, LLC is the controller.

If you are a parent, guardian or student, your studio decides what is recorded about you and for how long. We act on its instructions. Requests to see, correct or delete a student record should go to your studio first — it can act immediately, and we would have to refer your request to it in any case.

2. What we collect

CategoryExamplesWhere it comes from
Account and identityName, email address, phone number, password (stored only as a hash) or a Google account identifier, role and permissionsYou, or the studio that invited you
Profile and contactsBackup email address, emergency contact name and phone numberYou
Student recordsName, date of birth, guardian relationships, enrolments, programme and rank progression, milestones and achievements, attendance and check-in history, and free-text notesThe studio
Health informationAllergy and medical notes, where a studio chooses to record themThe studio, usually from a parent or guardian
Family and billingFamily and guardian records, a Stripe customer identifier, subscription and invoice status, payment historyThe studio, and Stripe
MessagesThe content of in-app, email and text messages sent through the platform, their recipients, and delivery statusThe studio
Uploaded filesStudent photographs, milestone and achievement photographs, studio logos, and announcement images and attachmentsYou, or the studio
Technical and securityIP address, browser and device information, timestamps, request and error logs, audit records of significant actionsCollected automatically when you use the Service
EnquiriesName, email address, studio name and message when you contact us through a form on our website, plus a bot-protection tokenYou

We do not receive or store full payment card numbers. Card details are entered directly into Stripe. We hold only an identifier that lets us ask Stripe about a payment.

3. Why we use it

  • To provide the Service — accounts, scheduling, enrolment, attendance, progression, messaging, reporting and payment collection.
  • To bill studios for their subscription, and to collect and record tuition on a studio's behalf.
  • To send transactional messages you would expect, such as sign-in, account, billing and schedule notifications.
  • To keep the Service secure — authentication, abuse and bot prevention, audit logging, and investigating incidents.
  • To support you, diagnose faults and fix defects.
  • To improve the Service, using aggregated or de-identified information wherever that is sufficient.
  • To comply with law, respond to lawful requests, and establish or defend legal claims.
  • To respond to a marketing enquiry you send us, and, with your consent where required, to follow up about Catomni.

Where the UK or EU GDPR applies to our own processing, we rely on performance of a contract (providing the Service and billing), legitimate interests (security, fault diagnosis, product improvement and responding to enquiries), consent (marketing where required, and any non-essential cookie were we to introduce one), and legal obligation. Where we act as processor for a studio, the studio is responsible for establishing the lawful basis.

4. What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.
  • We do not serve advertising, and we do not embed advertising networks or third-party analytics or tracking scripts. There are no advertising cookies on the platform.
  • We do not use Customer Data to train machine-learning models.
  • We do not profile children, and we do not use student information for marketing.
  • We do not make decisions about anyone by automated means alone that produce legal or similarly significant effects.

5. Who we share it with

  • Your studio and its authorised staff, according to the permissions the studio configures.
  • Guardians linked to a student, through the family portal. A studio can restrict what a separated guardian sees; see the Children's Privacy Notice.
  • Service providers that help us run the platform. Each one, and what it handles, is listed in the Sub-processor List.
  • Professional advisers, auditors and insurers, where necessary and under a duty of confidentiality.
  • Authorities or other parties where we are legally required to, or where it is necessary to protect someone's vital interests or to establish or defend legal claims.
  • A successor, in connection with a merger, acquisition or sale of assets — subject to this policy and with notice to affected studios.

We do not disclose Customer Data to anyone else without the studio's instruction.

6. International transfers

The platform is hosted on Cloudflare's global network, and our service providers are established in the United States. If you are in the UK, the EEA or Switzerland, your information will be transferred outside your country.

The safeguard we rely on for those transfers is [TO BE CONFIRMED: transfer mechanism — Standard Contractual Clauses, UK Addendum, and/or EU-US Data Privacy Framework certification]. Until that is settled, studios in the UK or EEA should treat this policy as incomplete on this point.

7. How long we keep it

  • Customer Data is kept while the studio's account is active, and then in accordance with the Data Processing Addendum — normally deleted or de-identified after the post-termination export window, allowing for backups to expire on their own cycle.
  • We delete or amend Customer Data when a studio instructs us to. Some records the studio may itself be required to keep, such as financial and attendance history, are for the studio to decide about.
  • Account and identity information is kept while the account exists.
  • Security, audit and error logs are kept for a limited period appropriate to investigating incidents.
  • Enquiry information is kept while we are in contact with you and for a reasonable period after.

8. How we protect it

Encryption in transit, encryption at rest, tenancy isolation, role-based permissions, multi-factor authentication for platform administrators and logged administrative access. The Security Overview describes our measures, our current certification status, and how to report a vulnerability.

9. Your rights

Depending on where you live you may have rights to access, correct, delete or receive a copy of your personal information, to object to or restrict processing, to withdraw consent, and to appeal a refusal. How to exercise them is set out in Privacy Rights Requests.

Where we act as processor for a studio, we will refer your request to that studio and assist it in responding. We will not delete or alter a studio's records on the instruction of someone other than the studio, because we are not in a position to judge who is entitled to ask.

10. Children

The platform holds information about children because studios teach children. The Children's Privacy Notice explains what is held, who obtains parental consent, and how a parent reviews or deletes it.

11. Text messages and email

Studios can send messages to families in the app, by email and by text message. Text messages are delivered by Twilio, and message rates may apply. A studio is responsible for obtaining the consent the law requires before sending text messages, and for honouring opt-out requests; see the Acceptable Use Policy. You can opt out of a studio's texts by replying with a standard opt-out keyword, or by asking the studio directly.

12. Our own access to your data

A small number of our personnel can access Customer Data where it is necessary to operate the platform, investigate a fault or respond to a support request. Access is limited to those who need it and is subject to confidentiality obligations.

The platform also allows an authorised administrator to view the Service as one of your users would see it, in order to reproduce a problem. Such a session is time-limited and recorded in our audit log. We use it for support and diagnosis, not to browse records.

13. Cookies

We use a small number of cookies, all of them necessary to sign you in, keep you signed in, protect forms from abuse, or remember your appearance preference. The Cookie Policy lists each one.

14. Changes to this policy

We will update this policy as the platform changes, and will note the date it was last revised at the top of this page. For a change that materially affects how we handle personal information, we will notify studios in advance.

15. Contact

Privacy questions: [TO BE CONFIRMED: privacy contact email]. Postal: Shannon Cyber Services, LLC, [TO BE CONFIRMED: registered address]. Whether we are required to appoint a Data Protection Officer or an EU/UK representative is [TO BE CONFIRMED: DPO / Art. 27 representative]. If you are in the UK or EEA you may also complain to your supervisory authority.