Privacy Notice
What this Privacy Notice covers
coc00n Cyber Limited (referred to in this Privacy Notice as either “coc00n” "We", "Us" or "Our") respects your privacy and is committed to protecting your Personal Data.
We are the controller of your Personal Data. For more information on controllers and their responsibilities please see the guidance from the Information Commissioner’s Office on data protection principles, definitions, and key terms.
This document is our privacy policy. We call it a Privacy Notice because that is the term used by UK and EU data protection law, but it serves as our privacy policy for all purposes required by relevant application stores.
It explains what information we collect through our Services, why we use it, who we share it with, how long we keep it, and what rights you have. We want to make sure you know what happens to your Personal Data, what your rights are and how the law protects you.
Who and what this notice applies to
This notice applies to our Application, the Client Portal and our services, including Device Protection, Location Tracking, Private Residence Reviews, Digital Exposure Reports and the Concierge. Some sections apply only if you use a particular Service, and we say so where that is the case.
We process your information only on the basis of applicable legislation, including the UK General Data Protection Regulation (“GDPR”), the Data Protection Act 2018 (“DPA”), the Data (Use and Access) Act 2025 (“DUAA”) and the Privacy and Electronic Communications Regulations (“PECR”).
This notice contains the following sections:
Who we are and how to contact us
Terms used in this notice
What Personal Data we collect and why
Special category and criminal offence information
Corporate, employer-managed and licensed arrangements
If you do not provide information we need
Who we share your Personal Data with
International transfers
How we keep your Personal Data secure
How long we keep your Personal Data
Your rights relating to your Personal Data
How to exercise your rights, including deleting your account
Marketing communications preferences
Complaints
Change of purpose
Cookies and similar technologies
Third-party links
Changes to this Privacy Notice
1. Who we are and how to contact us
coc00n Cyber Limited is registered in England and Wales with company number 14466209. Our registered office is at 167–169 Great Portland Street, 5th Floor, London, W1W 5PF.
Our Data Protection Officer would welcome communication from you on any matter relating to data protection, however small. You can contact them at privacy@coc00n.com or through the Concierge chat in the App or the Client Portal.
2. Terms used in this notice
Some words in this notice have a particular meaning. Where a term below is used, it has the meaning given here. If anything is unclear, please ask us at privacy@coc00n.com and we will explain it.
coc00n, we, us, our: coc00n Cyber Limited, a company registered in England and Wales with company number 14466209, whose registered office is at 167–169 Great Portland Street, 5th Floor, London, W1W 5PF. We are the controller of your Personal Data except where this notice says otherwise.
you, your: The person reading this notice. Depending on how you use our Services, that may be the person who set up your coc00n, a Member of someone else's coc00n, a family member whose device is protected, an employee whose device is managed by their employer, or someone who has bought a single Service such as a Digital Exposure Report. Some sections of this notice only Apply to some of those people, and we say so where that is the case.
your coc00n: Your protected account with us. The place where your Members, Registered Devices, billing and security settings sit together. There is one coc00n per family or group.
Member: A person who belongs to a coc00n and signs in with their own login.
Account Holder: The Member who set up your coc00n, or who is responsible for it and for paying for it.
Administrator: A Member who has been given a role that allows them to manage your coc00n, or to see information about other Members. Roles include Account Admin, Member Admin, Billing Admin, Network Admin, Report Reader and Location Reader. Different roles give access to different information, and we explain in each section what an Administrator can see.
Protected User: The role that allows a Member to register a device for Device Protection.
Service, Services: Everything we provide: the App, the Client Portal, Device Protection, Location Tracking, Private Residence Reviews, Digital Exposure Reports, Digital Privacy Uplift and the Concierge. You may use any number of these.
App, Application: Our mobile and desktop application, installed on your Registered Devices.
Client Portal: The website where you manage your coc00n, your Members and your Registered Devices.
Registered Device: A device you have added to your coc00n so that we can protect it.
Device Protection: Our core security Services: coc00n VPN, coc00n DNS, and the management of your Registered Devices.
coc00n VPN: A virtual private network: an encrypted connection between your Registered Device and the internet, which we operate ourselves. It hides your traffic from others on the same network and masks your device's location from the websites you visit.
coc00n DNS: The Service that checks each web address your Registered Device asks for and blocks the ones we have identified as malicious. Your devices make those requests using DNS over HTTPS, which means the request itself is encrypted in transit.
Location Tracking: The optional feature that records the location of Registered Devices you choose to enable it for. It is switched off unless you turn it on.
Network Profile: A template of DNS and content filtering settings that an Administrator can Apply to Members of your coc00n. It determines which categories of website are blocked, and which specific domains are allowed or blocked. A Protected User may also be able to add overrides, if allowed by their admin.
Private Residence Review: A Service you can purchase in which we visit a property, review the connected devices and network there, and give you a written report advising on the cyber security risks we find.
Digital Exposure Report: A Service you can purchase in which we search publicly available sources to identify what information about you is available online, assess the risks that creates, and report to you on what you can do about it.
Digital Privacy Uplift: A Service you can purchase which includes a one-to-one session, in person or online at your convenience, reviewing the security and privacy settings on your devices and online accounts and configuring them with you so that they are properly protected.
Report: A report we produce and publish to your coc00n. This may include quarterly/annual updates we may provide about your Device Protection, or a Private Residence Review report or Digital Exposure Report you have purchased.
Concierge: Our support Service, including the instant chat available in the App and the Client Portal.
Personal Data: Any information relating to an identified or identifiable living individual, including information that identifies you only when combined with other information we can reasonably access. It does not include Aggregated Data.
Data Category: A grouping we use to describe the kinds of information we hold, rather than each individual item of information. The categories are listed in “What Personal Data we collect and why”.
Special Category Data: Information that data protection law treats as more sensitive: information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, and genetic and biometric data.
Criminal Offence Data: Information about alleged or actual criminal offences, proceedings, convictions, cautions and related public records. Data protection law imposes additional conditions on this information.
Lawful Basis: The legal ground we rely on to use your Personal Data. The bases we rely on are Contractual Necessity, Legitimate Interests, Compliance with Law and Consent (or Explicit Consent for Special Category Data).
controller / processor: These are legal terms defined by the GDPR. When we use them in this notice, we use them with the meanings given in the GDPR. In summary, a controller determines the purposes and means of processing Personal Data and is accountable for it, while a processor processes Personal Data only on behalf of and in accordance with the instructions of a controller.
Data Protection Law: The UK General Data Protection Regulation, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced.
ICO: The Information Commissioner's Office (or Information Commission, when the transition is complete), the UK's independent regulator for data protection.
3. What Personal Data we collect and why
The list below sets out the categories of Personal Data we collect, what each category covers, how and why we use it, and the Lawful Basis we rely on.
Some categories apply only if you use a particular Service. We only collect Property and Residence Data if you purchase a Private Residence Review (or if you choose to register a residence within your coc00n), Exposure Research Data if you purchase a Digital Exposure Report or breach monitoring, and Location Data if you choose to turn Location Tracking on.
We will only collect and use your Personal Data where we have a Lawful Basis to do so. The bases we rely on are Contractual Necessity, Compliance with Law, Legitimate Interests and Consent (or Explicit Consent, where the information is Special Category Data).
It is important that the Personal Data we hold about you is accurate and current. Please keep us informed if your details change.
Identity Data
What this category covers
o Your name, and the name of any Member you add to your coc00n.
o Basic details about you such as title, gender and date of birth, and your occupation or signature where a Service requires it.
o The username and credentials you use to sign in. Passwords are only ever stored in hashed form.
How and why we use this data:
o Setting up, verifying and administering your coc00n.
o Providing the Services to you and to the Members of your coc00n.
o Confirming your identity before we act on a request to exercise your rights.
Lawful basis:
o Contractual Necessity
o Compliance with Law: where we must verify identity before acting on a rights request
Contact Data
What this category covers:
o Your home address and billing address
o The email addresses and telephone numbers you give us, including any additional addresses you register; and
o The same details for any Member you add to your coc00n.
How and why we use this data:
o Administering your coc00n and your subscription.
o Delivering the Services
o Sending you Service messages, security alerts and notifications.
o Arranging a Private Residence Review visit.
Lawful basis:
o Contractual Necessity
Payment and Transaction Data
What this category covers:
o Card details are collected directly by our payment processor. We never receive or store them.
o Records of payments to and from you, and of your subscription and plan, including which Services you have bought and how many devices you protect.
o Invoices, receipts and refund records.
How and why we use this data:
o Taking payment and administering refunds.
o Managing your subscription and billing.
o Maintaining our accounting records.
o Dealing with queries, disputes and complaints.
Lawful basis:
o Contractual Necessity
o Compliance with Law: tax, accounting and record-keeping obligations
o Legitimate Interests: establishing, exercising or defending legal claims
Service Data
What this category covers:
o Networking information about your Registered Devices use of Device Protection.
o Data breaches affecting you and the types of information exposed.
o Records of the threats, domains, files we have blocked.
How and why we use this data:
o Securing your Registered Devices.
o Blocking malicious and suspicious activity.
o Telling you when your information appears in a known breach.
o Checking retrospectively whether you were exposed to a threat we have newly identified, and advising you.
o Providing you with statistics on what we have blocked.
o Investigating faults and problems connecting to the Services.
Lawful basis:
o Contractual Necessity: this is the Service you have purchased
o Legitimate Interests: keeping our own products, systems and networks secure
Technical Data
What this category covers:
o Your IP address
o Device make, model, operating system and version, and the VPN peer identity of a Registered Device.
o The identifiers we generate for your devices and installations, and your push notification token.
o Sign-in records for your account, including when each sign-in happens.
o Crash and diagnostic records.
How and why we use this data:
o Delivering and securing the App and the Client Portal.
o Troubleshooting technical issues.
o Detecting and preventing fraud, misuse and unauthorised access.
Lawful basis:
o Contractual Necessity
o Legitimate Interests: the security, integrity and proper operation of our products and systems
Location Data
What this category covers:
o The approximate location of a Registered Device you have turned tracking on for. How precise it is depends on that device’s own settings.
o The date and time of each location record, and the identifier of the device it relates to.
o Location Tracking is off unless you switch it on for a specific device.
How and why we use this data:
o Showing you where your Registered Devices are.
o Helping you find a device that is lost or stolen.
o Sharing a device location with Members of your coc00n who hold a role that permits it.
o Sending you location-sensitive security alerts
o We do not use location information for any other purpose, and never for marketing or profiling.
Lawful basis:
o Consent: given by turning the feature on for a specific device, and withdrawable at any time in the App
Property and Residence Data
What this category covers:
o The address of the property, how to access it, and the appointment details.
o An inventory of the connected devices at the property: make, model, operating system, firmware version, configuration, and where in the property they sit.
o Details of the network there, including equipment models, network configuration and connected services.
o The security weaknesses we identify and the recommendations we make.
o Our consultant’s notes and, where you agree, photographs or diagrams of the set-up we saw.
o Limited information about other people at the property, where it is relevant to our advice.
o Private Residence Reviews only.
How and why we use this data:
o Carrying out the Private Residence Review you have purchased.
o Producing your written report and answering your questions about it afterwards.
Lawful basis:
o Contractual Necessity
o Consent: for photographs, and for anything beyond what is strictly needed for the review
Exposure Research Data
What this category covers:
o The identifiers you ask us to search on, for example your name and any former or alternative names, current and previous addresses, contact details, usernames, date of birth, employer and job title, and social media accounts.
o The same details for any family member you ask us to include, where they have separately given explicit consent or you are legally able to consent for them.
o What our searches return from publicly available sources: social media profiles and posts, data broker and people-search listings, public registers, property records, news, court and other public records, images and video, and information others have posted about you.
o Information about you appearing in leaked or breached datasets circulating online.
o The risk assessment and recommendations we produce.
o Digital Exposure Reports and breach monitoring only.
How and why we use this data:
o Producing the Digital Exposure Report you have purchased.
o Advising you of the risks arising from information about you that is publicly available, and how to remove or reduce them.
o Supporting you afterwards in acting on the report.
Lawful basis:
o Contractual Necessity
o Explicit Consent: where the research returns Special Category Data
Special Category Data and Criminal Offence Data
What this category covers:
o Special Category Data means information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, and genetic or biometric data.
o Criminal Offence Data means information about alleged or actual offences, proceedings, convictions, cautions, disqualifications and related public records.
o We do not ask you for Special Category Data or Criminal Offence Data, and we never collect it deliberately. In certain circumstances we may collect it incidentally within exposure research from sources that are already public.
How and why we use this data:
o Producing a Digital Exposure Report, and advising you where sensitive information about you is publicly visible.
o We do not use it for any other purpose, and never for marketing or profiling.
Lawful basis:
o Article 6: Contractual Necessity
o Article 9(2)(a): Explicit Consent
Information about other people
What this category covers:
o The name, contact details and device details of any other Member you add to your coc00n.
o Device information relating to other occupants of a property we review, or to people who work there.
o Information about other people that appears in the findings of a report.
How and why we use this data:
o Providing the Services to the people covered by your coc00n.
o Giving you accurate security advice about your household and your devices.
Lawful basis:
o Contractual Necessity
o Legitimate Interests: providing the Services the Account Holder has asked for, in a way that keeps information about other people to a minimum.
Marketing and Communications Data
What this category covers:
o Your marketing and communication preferences.
o Our record of any consent you have given, and of any opt-out.
o Your engagement with our marketing emails, such as whether you open or forward them.
How and why we use this data:
o Sending you marketing you have consented to receive, and honouring your opt-out.
o Keeping a record that demonstrates we had your consent.
o Making sure the products and offers we tell you about are relevant.
Lawful basis:
o Consent
o Compliance with Law: retaining proof of consent
Support Data
What this category covers:
o Your Concierge chat transcripts.
o Emails, calls and other correspondence with our support team, including any enquiry you made before becoming a client.
o Technical records of a small sample of user interactions with the App, which show us where a journey is failing.
o Complaints and the records of how we handled them, and your feedback and survey responses.
How and why we use this data:
o Providing support and responding to your queries.
o Identifying problems in user journeys and improving the quality of the Services.
o Handling complaints, and establishing, exercising or defending legal claims.
Lawful basis:
o Contractual Necessity: providing support to you as a client
o Legitimate Interests: improving our Services, and handling complaints and claims
How we collect this information
Directly from you: when you enquire, sign up, buy a Service, choose your settings, or contact us through the Concierge, by email or by telephone.
Automatically: from your Registered Devices and from your use of the App and Client Portal, including through cookies and similar technologies.
From our research providers: when you have purchased a Digital Exposure Report, who collect information on our instructions in order to deliver the Services, as described in “Who we share your Personal Data with”.
From publicly available sources: when we produce a Digital Exposure Report, or verify identity.
From social media platforms: where you contact us through them.
Where we rely on Legitimate Interests, we have carried out an assessment balancing our interests against your rights. You can ask us for a summary of that assessment for any use described above by emailing privacy@coc00n.com.
Personal Data does not include anonymous or aggregated data, where the identity of the individual has been permanently removed. It does include indirect identifiers or pseudonymous data — information which alone does not identify you, but which could be attributed to you if combined with other information that is reasonably available. If we ever combine anonymous or aggregated data with your Personal Data so that you can be identified, we treat the combined information as Personal Data.
What leaves your device
Because we protect your devices, some information necessarily leaves them. We think you should know exactly what:
When you register a device on the Application, the details of the device make and model, as well as the OS name and version number will be sent to us.
When coc00n DNS filtering is enabled, the DNS requests are sent from your device to us. However, the content of the pages you visit is not sent, and we do not see it.
When coc00n VPN is enabled, your internet traffic is routed through an encrypted tunnel to our VPN endpoint. Traffic is encrypted between your device and that endpoint. We record the fact and duration of connections and your external IP address at the time, as well as the volume of traffic. We do not record the content of what you do.
When you have enabled location tracking for a Registered Device, the Registered Device location information is sent to us at regular intervals.
Crash and diagnostic information, so that we can fix problems with the Services.
Nothing else is sent from your device to us. We do not read your files, we do not record your keystrokes, and we do not access your camera or microphone. Please see the How long we keep your Personal Data section of this Privacy Notice for more information.
4. Special category and criminal offence information
We do not ask you for Special Category Data or Criminal Offence Data, we may collect it incidentally.
We do not sell any Personal Data, including Special Category Data or Criminal Offence Data, and we do not share it with anyone for their own purposes. We share it only with a small number of providers who process it strictly on our instructions so that we can deliver the Service you have asked for.
Digital Exposure Reports
When you have purchased a Digital Exposure Report, we may incidentally collect special category data about you from public sources when completing our research online. We may also receive such data from the data sources we use to help our research.
We use it only to produce your report, to tell you that the information is publicly visible, and to advise you on reducing the risk. We delete the underlying search material as soon as your report is complete. Your report may refer to or include a redacted example of what we found; you can ask us to delete our copy of the report at any time.
coc00n DNS records
When we protect your devices with coc00n DNS filtering, we keep a record of the requests your devices make. In some circumstances, such records could be used to infer sensitive information about a person. We do not intend to and will never attempt to infer anything of that kind from them. These records are held in a pseudonymised database kept separate from other Personal Data, and at the end of the retention period the DNS requests and responses are stripped out, leaving only a device identifier and whether the request was allowed or blocked, so that we can continue to show you your protection statistics. You can turn DNS filtering off in the App at any time, and no records are kept for periods when it is off.
5. Corporate, employer-managed and licensed arrangements
This section applies if your coc00n was arranged by your employer, or by an organisation that provides coc00n to you as part of its own service
Where your employer provides coc00n
Who is responsible for your information
Where your employer buys coc00n for you, your employer decides what devices are covered, who within the organisation can see information about you, and how long it is kept[LS6] . This is because the Account Holder can assign roles to Members to make them Administrators within your coc00n. The information they see will depend on which role was assigned.
When they do so, your employer is the controller of that information, and we act as its processor, we handle it on your employer's instructions and not for our own purposes. Where it is possible within the Application, you will able to choose whether your data is removed.
We remain the controller for a limited set of things we do for our own purposes: keeping our own products and systems secure, preventing fraud and misuse of the Services, meeting our legal obligations, billing your employer, and improving our Services using aggregated information. The rest of this notice explains those.
What your employer can see
This depends on which features your employer has made available and which roles it has given to its Administrators or Members. It can include:
• which devices are enrolled, and who each one is assigned to;
• coc00n DNS and coc00n VPN connection status;
• the location history of your device, where you have enabled the location tracking feature; and
• any Reports published to the coc00n.
Through coc00n, your employer cannot see the content of your personal messages, files or personal accounts, your passwords, your keystrokes, or what is on your screen.
When you leave, or your device is removed
Your employer can remove you from its coc00n at any time. When it does, your member record is retained for 7 days so that an accidental removal can be reversed and is then permanently deleted. Please see the How long we store your Personal Data section for more information.
Where an organisation provides coc00n to you under a licence it has bought
Some organisations buy coc00n Device Protection licences in volume and provide them to their own clients, who could be individuals, families or businesses. Who is responsible for your information depends on whether that organisation administers your coc00n or simply gave you a licence for it.
If you set up and manage your own coc00n
We are the controller and this notice applies to you in full, in the same way as it would if you had bought coc00n directly. The organisation that provided your licence does not have access to your coc00n, your Members, your devices, your location or your Reports. It knows only that a licence has been assigned and whether it is being used.
If the organisation administers your coc00n for you
Where the organisation sets up and manages your coc00n on your behalf, and its staff hold Administrator or other roles in it, that organisation is the controller and we act as its processor; the same position as an employer, described above. Its Administrators can see the same categories of information as an employer's Administrators, and you should ask that organisation for its own privacy notice.
If the organisation provides a licence to a business you work for
Where the licence is provided to a business and that business administers its own coc00n, the business you work for is the controller of your information, and the section above applies to you. The organisation that supplied the licence can see the quantity of licences supplied and when they renew. Billing management would remain with the organisation that supplied the license.
What the licensing organisation receives
In every case, we share with the licensing organisation only what it needs to manage its licences and be paid: which licences have been assigned and to which client, whether they are in use, and the name and contact details of its client contact.
Your rights
Where we are the controller, make your request to us; please see the How to exercise your rights, including deleting your account section for more information. Where the organisation that provided your licence administers your coc00n, make your request to that organisation and we will help it to respond. You retain your right to complain to the ICO in either case.
6. If you do not provide information we need
Where you do not provide Personal Data that we need in order to perform the contract we have with you or are trying to enter with you, or to comply with the law, we may not be able to provide the Services. For example, we may not be able to open your coc00n, protect a device, carry out a review or produce a report, and in some cases we may have to close your coc00n. We will always tell you what we need and why before we ask for it, and if declining to provide something would reduce the protection we can give you, we will tell you that too.
7. Who we share your Personal Data with
We share your Personal Data with a limited number of organisations so that we can deliver the Services. The list below describes them by type, together with what we share, why, and where they are located. The exception to this is our payment processor, Stripe, which we name because in certain specific circumstances it uses payment information for its own purposes as well as ours.
Cloud hosting
Services it relates to:
o All Services
What we share and why:
o Hosting our systems and storing the information we hold. In practice this involves all categories of Personal Data we hold, because these providers host the environment our systems run in.
Where they are:
o United Kingdom
o European Economic Area
Productivity suite providers
Services it relates to:
o All Services
What we share and why:
o Providing our email Services, and providing productivity software we use to conduct business and deliver the Services and Additional Services.
Where they are:
o United Kingdom
o European Economic Area
o United States of America
Customer relationship and communications providers
Services it relates to:
o Website enquiries, the Concierge and marketing
What we share and why:
o Managing our relationship with you before and after you become a client, providing the Concierge chat, and sending marketing you have consented to receive. Involves Identity, Contact, Support and Marketing and Communications Data.
Where they are:
o United Kingdom
o European Economic Area
Stripe (payment processor)
Services it relates to:
o Card payments and Bank Transfers
What we share and why:
o Taking payment by credit or debit card. Card details are collected directly by Stripe and we never receive them. Stripe also uses payment information for its own fraud prevention and to meet its own legal and financial regulatory obligations, and acts as a controller for those purposes: its own privacy notice explains what it does. We name Stripe because it is not acting solely on our instructions.
Where they are:
o United States of America
Breach monitoring and open-source intelligence research provider
Services it relates to:
o Digital Exposure Reports and breach monitoring only
What we share and why:
o Searching available sources and known breach datasets, on our instructions, so that we can identify what information about you is exposed and advise you. Involves Exposure Research Data only.
Where they are:
o Inside and outside the United Kingdom, depending on the provider
Security and threat intelligence providers
Services it relates to:
o Device Protection
What we share and why:
o Identifying malicious domains, messages and files so that we can block them. This generally involves Technical and Service Data rather than information that identifies you.
Where they are:
o Inside and outside the United Kingdom, depending on the provider
Professional advisers
Services it relates to:
o All Services
What we share and why:
o Obtaining legal, accounting, insurance and audit advice, and establishing, exercising or defending legal claims. Limited in each case to what is necessary.
Where they are:
o United Kingdom
Law enforcement, regulators and courts
Services it relates to:
o All Services
What we share and why:
o Complying with a legal obligation, court order or other lawful request, and reporting a personal data breach to the Information Commissioner’s Office where we are required to do so. Any category of Personal Data, limited to what is legally required. We only disclose where we are satisfied the request is lawful and the disclosure is necessary.
Where they are:
o United Kingdom, or the jurisdiction making a lawful request
Prospective buyers, and parties to a merger or reorganisation
Services it relates to:
o All Services
What we share and why:
o Where we sell, transfer or merge all or part of our business. Any new owner may use your Personal Data only as set out in this notice.
Where they are:
o Assessed at the time of the transaction
The protections that apply to every recipient
We require all third parties to keep your Personal Data secure and to treat it in accordance with the law.
Except for Stripe, all our providers act as our processors. That means they may use your Personal Data strictly on our instructions, only for the purposes we specify, and never for their own purposes.
Each is required to keep your Personal Data confidential, to apply security measures at least equivalent to our own, to assist us in responding to your requests and to any security incident, to obtain our authorisation before engaging anyone else, and to delete or return your Personal Data at the end of our contract.
We assess each provider before we appoint it and keep that assessment under review.
We keep the list of organisations that can touch your information as short as we can, and we do not add to it lightly. Each one is there because a Service you use requires it. We do not sell your Personal Data, we never will, and we do not allow our providers to use it to build profiles, to train their own products or for advertising.
If you make a subject access request, we will tell you the identity of the specific organisations that have received your Personal Data, where you ask us to.
8. International transfer
The information we collect from you is stored within the United Kingdom and the European Economic Area, unless one of the transfers described in this section applies.
Where Personal Data is transferred outside the United Kingdom, including where a provider accesses it for support purposes, we always use a legal transfer mechanism recognised by UK data protection law. In practice that means one of the following:
the transfer is to a country, territory or scheme covered by UK adequacy regulations; or
the transfer is made under the ICO’s International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment; or
an exception permitted by law applies to the particular transfer.
We also apply technical protections to transferred information, including encryption in transit and at rest. We will not transfer your Personal Data outside the United Kingdom where we cannot put an appropriate mechanism in place. You can ask us which mechanism applies to a particular transfer by emailing privacy@coc00n.com.
9. How we keep your Personal Data secure
We have implemented technical and organisational measures to protect your Personal Data against loss, misuse and unlawful processing. Information is encrypted in transit using modern cryptography and encrypted at rest, and traffic between your device and our systems, including our VPN endpoints, is encrypted. Sensitive data, such as DNS records, are stored in a separate database, pseudonymised, and stripped of detail at the end of the retention period, as soon as it has served its purpose.
Personal Data is accessible only to those people who need it in order to do their work in connection with delivering the Services. They process it only on our instructions and are subject to a duty of confidentiality. Where a member of our staff is given access to your coc00n in order to help you, that access is time-limited and we record who was given access, why, when and what they did.
If something goes wrong
We have procedures for dealing with a suspected personal data breach. Where we are required to, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will tell you without undue delay.
10. How long we keep your Personal Data
We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the Appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the Applicable legal, regulatory, tax, accounting or other requirements.
The list below sets out how long we keep each kind of information, when the period starts, why we have chosen that period, and what happens at the end of it.
Where a period is described as running from when your membership ends, that means when you are removed from a coc00n or when the coc00n is closed. Where we say information is anonymised rather than deleted, we mean that we permanently remove the details that identify you and keep only a record that the event happened.
We may keep information for longer where there is a complaint, or where we reasonably believe there is a prospect of litigation. We may also keep information for longer that stated below if after leaving your coc00n, you remain a client of ours due to being a Member of more than one coc00n or because you have accessed our Services on a different basis.
Your coc00n and Member records: For as long as you are a Member. If you are removed, your record is kept for a short restore window (currently 7 days) so that an accidental removal can be reversed, and is then permanently deleted.
Security, protection and device records: including filtering and connection records, Registered Device records; and in-App notifications: Short periods set by what each record is for, currently ranging from a matter of hours to 12 months. These periods may be configurable in the App and we will tell you the current period for any record if you ask. At the end of the period the record is deleted, or the details that identify you are removed and only anonymous statistics are kept.
DNS and VPN protection logs: These are stored for 60 days so that we can filter and block malicious domains, to show you what we have blocked, to check retrospectively whether you visited a domain we have newly identified as malicious, and to investigate connection problems with the coc00n VPN. After this period, we remove the DNS queries and responses from the database, leaving just the pseudonymised identifier, and whether we blocked or allowed the request, which allows us to provide statistics to you.
Network and filtering settings: These are kept for as long as you are a member of your coc00n. We keep them so that your protection stays consistent. After you leave your coc00n these settings are permanently deleted.
Location history: This is kept until you ask us to delete your location history or leave the coc00n. We stop collecting records as soon as you turn tracking off or remove the device. You can ask us to delete this history via the Concierge, if you no longer wish to keep it.
Reports we produce for you: Until you delete your coc00n account or ask us to delete the report, whichever comes first. You can ask us to delete a report at any time and we will do so.
Exposure research material and property records: The raw material behind a report is deleted as soon as your report is complete. Property records are deleted on request, after a short grace period in case of accidental deletion.
Support, enquiry and complaint records: For as long as we need them to deal with follow-up questions and to understand the history of your account. Enquiries from before you became a Client will be kept for up to 2 years from your last contact. Support records will be kept for up to 2 years. Complaint records are kept for the period in which a related legal claim could be brought (usually 6 years).
Invoices, payments and subscription records: 7 years from the date of the last invoice, because UK tax, accounting and audit law requires it.
Marketing consent and opt-out records: For as long as we rely on your consent, and then for the period in which we may need to demonstrate that we had it (up to 2 years). If you opt-out, we keep a minimal suppression record for as long as necessary so that we do not contact you again by mistake.
Records of our staff accessing your coc00n, and of significant security and administrative events: 2 years, for security and accountability, after which the record is anonymised or deleted.
Anything needed for a live complaint, dispute or legal claim: Until the matter is resolved, and then for the period in which a claim could still be brought.
11. Your rights relating to your Personal Data
Under data protection law you have the following rights. Some apply only in particular circumstances, and we will tell you if an exemption applies to your request.
Access: you can ask for a copy of the Personal Data we hold about you, and for information about where we got it and who we have shared it with. Read more about the right of access.
Rectification: you can ask us to correct or complete information that is inaccurate or incomplete. Read more about the right to rectification.
Erasure: you can ask us to delete your Personal Data. We may refuse where we still need it to provide a Service to you under our contract, where the law requires us to keep it, or where we need it to establish, exercise or defend legal claims. Read more about the right to erasure
Restriction: you can ask us to limit how we use your Personal Data: while we check its accuracy, where our use is unlawful but you do not want it erased, where you need us to keep it for a legal claim, or while we consider an objection you have made. Read more about the right to restriction of processing.
Objection: you can object to our use of your Personal Data where we rely on Legitimate Interests and there is something about your situation that makes you want to object. You can always object to direct marketing. In some cases we may be able to show compelling grounds that override your objection. Read more about the right to object to processing.
Portability: you can ask us to provide the Personal Data you gave us, to you or to another organisation, in a structured, commonly used, machine-readable format. This applies to automated information you provided on the basis of consent or under our contract. Read more about the right to data portability.
Withdrawing consent: where we rely on consent, you can withdraw it at any time. That does not affect processing carried out beforehand, and we will tell you if withdrawing consent means we can no longer provide part of the Services. Read more about the right to withdraw consent
Complaining: you can complain at any time if you are unhappy with how we have handled your Personal Data. Please see our Complaints section for more information.
12. How to exercise your rights, including deleting your account
To exercise any of these rights, contact us at privacy@coc00n.com or through the Concierge chat in the App or the Client Portal.
You will not usually have to pay a fee. We may charge a reasonable fee, or refuse to act, where a request is clearly unfounded, repetitive or excessive. We may need to ask you for information to confirm your identity before we act. We try to respond to all legitimate requests within one month and will tell you if a request is complex enough to take longer.
Deleting your account
You can ask us to delete your coc00n account at any time. Account deletion is handled by our team rather than by a self-service button, so that we can confirm who is asking and delete the right records. To delete your account
• Ask your Account Administrator (for your coc00n) to remove you from the coc00n
• Ask us through the Concierge chat in the Application or the Client Portal; or
• Email us at privacy@coc00n.com.
An Account Administrator can:
• Delete a Member’s account via the Client Portal; or
• Request that we delete your entire coc00n via the Client Portal by clicking on your profile image and then selecting the “request deletion” button. Please note that this is only available to account administrators because it affects your entire coc00n.
If you have requested that we delete your coc00n account, we will confirm your identity, then an administrator will delete the account and the information associated with it, and we will confirm when this has been done. We aim to complete deletion within seven days of confirming your identity.
What happens when you delete your account
We delete your account and the information associated with it, this includes: your profile and contact details, your Registered Device records, your location history, your network and filtering settings, your reports, your in-App notifications and your Concierge chat history. Your protection stops working when the account is deleted.
Deleting your account is permanent. It is not the same as switching off a feature, closing the App or cancelling your subscription. If you are removed from a coc00n by an Administrator, your record is kept for a short restore window so that an accidental removal can be undone, and is then permanently deleted. You can ask us to delete it immediately instead.
What we have to keep, and for how long
A small amount of information survives account deletion, because the law requires us to keep it or because we need it to protect you and other customers
Invoices, payments and subscription records
Why:
o UK tax, accounting and audit law
For how long:
o 7 years from the last invoic
A record that you asked us not to send you marketing
Why:
o So that we do not contact you again by mistake
For how long:
o Until you tell us otherwise
Records of significant security events, with the details that identify you removed
Why:
o Security and accountability
For how long:
o Up to 2 years
Information needed for a live complaint, dispute or legal claim
Why:
o To resolve it, and to defend a claim
For how long:
o Until it is resolved
Everything else is permanently deleted. The full picture is in “How long we keep your Personal Data”.
If you only want to stop one thing rather than everything, you do not need to delete your account. Within the Application you can disable Location Tracking, disable coc00n DNS, disable coc00n VPN, unsubscribe from marketing, and remove a Registered Device. You can ask us to delete a Report by contacting us through the Concierge or by email at privacy@coc00n.com.
13. Marketing communications preference
You can ask us to stop sending you marketing at any time by:
using the unsubscribe link in any marketing message
changing your settings within the Application or Client Portal; or
or by contacting us at privacy@coc00n.com or through the Concierge.
Where you opt-out of receiving these marketing messages, this opt-out will not apply to essential Services-related communications [SR13][SW14][SW15][LS16] (and any processing of your Personal Data involved in sending such communications). As a non-exhaustive list of what these essential Services-related communications may include, they might be emails or notifications:
relating to the management of your account on the Services;
concerning Billing; and
concerning updates to this Privacy Notice or our Terms of Service
14. Complaints
If you would like to make a complaint regarding this Privacy Notice or our practices in relation to your Personal Data, please contact us at: privacy@coc00n.com
We will reply to your complaint as soon as we can.
If you feel that your complaint has not been adequately resolved, please note that the GDPR gives you the right to contact your local data protection supervisory authority, which for the UK, is the Information Commissioner's Office. You can contact them online on their website: https://www.ico.org.uk/make-a-complaint; by calling their helpline +44 303 123 1113, or by writing to them at their address below:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
15. Change of purpose
We will only use your Personal Data for the purposes we collected it for. If we need to use your Personal Data for a new, unrelated purpose, we will notify you and explain the legal basis that allows us to do so. We may process your Personal Data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law, for example where we must respond to a court order. If you would like an explanation of why we consider a new purpose compatible with the original one, please contact us at privacy@coc00n.com
16. Cookies and similar technologies
Cookies are small files stored on your device.
We do not use cookies ourselves, though in our App and Client Portal we do use equivalent technologies, including device identifiers, local storage and push notification tokens.
We want to make clear that we do not use advertising or targeting cookies, and we do not share information from cookies with advertising networks. If we introduce any non-essential cookies or similar technologies, we will ask for your consent first and update this notice.
For coc00n clients, the following third parties may also use cookies, over which we have no control. The cookies that these named third parties set are all essential for the operation of the client Application and Client Portal.
Third Parties that Set Cookies
Microsoft
HubSpot
Stripe
Auth0
You can refuse or delete cookies through your browser settings, but if you block strictly necessary cookies, some parts of the Services may not work properly.
17. Third-party links
The Services may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites or application and are not responsible for their privacy statements. When you leave our Services, we encourage you to read the privacy notice of every website or application you visit.
18. Changes to this Privacy Notice
We keep this notice under regular review and will tell you when we change it, by a notification in the App and a note on the store page for the App. We may also contact you directly.
We will always update it before we introduce a new purpose, a new Lawful Basis, a new category of Personal Data or a new type of recipient.