MARCO — Privacy Policy
1. Who we are
MARCO is operated by Dotsoft S.A. (“Dotsoft”, “we”, “us”), Poseidonos 71, Pilea 555 35, Thessaloniki, Greece and PRAGMA-IoT, Ganas & Ganas Building, Office B14, Thermi 570 01, both acting as data controller for the personal data described in this policy.
For any question about your data, write to [email protected].
MARCO is delivered as part of a time-limited pilot project in one school in Pilsen, Czechia, co-ordinated by the City of Pilsen and SITMP.
2. What this policy covers
This policy covers the MARCO mobile application for iOS and Android, and the backend service behind it. It applies to two kinds of user:
- Parents and guardians, who register themselves.
- Students, who join only after a parent or guardian has registered them and shared a single-use unlock code.
The MARCO Teacher web dashboard is a separate service with its own notice.
3. What data we collect
| Category | Data | Source |
|---|---|---|
| Parent / guardian | Full name | Entered |
| Parent / guardian | Email address | Entered |
| Parent / guardian | Password — kept only as a secure hash | Chosen |
| Parent / guardian | Mobile phone number | Entered |
| Parent / guardian | Home neighbourhood — never a street address | Selected |
| Student | Nickname — chosen by the child, who is told not to use a real name | Chosen |
| Student | Avatar (an emoji) | Chosen |
| Student | Age, class and school | Entered by parent |
| Student | School-year band — derived, selects age-appropriate content | Derived |
| Student | Sign-in PIN — created on activation | Generated |
| Account linking | Single-use unlock code, and whether and when it was claimed | Generated |
| Trip logs | Date, school-day flag and travel mode from seven options — self-reported, never detected | Entered |
| Routes | Waypoints placed manually. A parent may save one route per child. | Entered |
| Learning | Lesson progress, quiz answers, eco-points, badges, streaks | Generated by use |
| Survey | Five closed questions at onboarding and again at week 8. No free text. | Answered |
| Technical | IP address, app version, operating system version, language | Automatic |
What we do not collect
Each statement below was checked in the application source.
- No GPS and no location permission. MARCO never asks for your device’s position. Every trip is something you tell us.
- No advertising, and no advertising identifiers. No Android Advertising ID, no IDFA.
- No third-party analytics and no crash-reporting tools.
- No in-app purchases and no payment data.
- No third-party login. No Google, Apple or Facebook sign-in.
- No photographs, no free-text survey answers, and no messaging between users.
- No special category data — no health, biometric, ethnic, religious or political data.
- No legal name and no phone number for a student.
4. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account | Contract — Art. 6(1)(b) |
| Logging trips, showing your impact, awarding points and badges | Contract — Art. 6(1)(b) |
| Processing a student’s data | Consent of the holder of parental responsibility — Art. 6(1)(a) with Art. 8 |
| Showing public city data — traffic, air quality and noise — on the map | Consent — Art. 6(1)(a). A toggle in Profile → Privacy. |
| Morning alerts when a public sensor crosses a threshold near a saved route | Consent — Art. 6(1)(a). A notification toggle. |
| Baseline and week-8 survey, and pilot evaluation | Consent — Art. 6(1)(a) |
| Publishing aggregated, non-identifying statistics | Consent — Art. 6(1)(a). Separate and optional. |
| Keeping the service secure and diagnosing faults | Legitimate interests — Art. 6(1)(f) |
Each consent is given separately and can be withdrawn at any time in Profile → Privacy, without affecting the lawfulness of what we did before you withdrew it.
5. Children
MARCO is designed for school children and their families, and we treat children’s data as the most sensitive thing we hold.
Who can and cannot sign in
Children in school years 1 to 5 cannot sign in to MARCO at all. They are issued no unlock code and no sign-in PIN, and they use no device. A parent or guardian can add them to their own account so the child is linked to their class, but the child has no access to the app. These children take part through their classroom, on a shared display, facilitated by their teacher.
Only children in school years 6 to 9 can hold a MARCO account. They receive a single-use unlock code from their parent or guardian and then sign in with their own PIN.
Consent and control
- In Czechia the digital age of consent is 15. A student under 15 cannot consent for themselves. A parent or guardian must register first and consent on the child’s behalf. No child can create an account without a code issued by their guardian.
- Consent covers each purpose separately: trip data, city data on the map, morning alerts, the survey, and the optional aggregated statistics.
- A parent or guardian can at any time see which consents are active, withdraw any of them, and delete their child’s account.
- Students never see individual rankings against other named students. Leaderboards compare classes only, and no individual student’s name appears in them.
- The school and the City of Pilsen receive no individually identifiable student data. They see class-level aggregates only.
- Learning content is selected by school year, so younger children are never shown material written for older ones.
6. Who we share data with
We do not sell personal data, and we do not share it for advertising. We share it only with:
| Recipient | What they receive | Where |
|---|---|---|
| Pragma-IoT — our backend platform | Storage and processing of all account, trip, learning and survey data | European Union, Greece |
| OpenStreetMap Foundation — map tiles | Your IP address and which map area you are viewing, each time a map loads | United Kingdom |
| TomTom — live traffic layer, only when switched on | Your IP address and which map area you are viewing | Netherlands |
| The school and the City of Pilsen / SITMP | Class-level aggregates only. No individual student data. | Czechia |
Map data is © OpenStreetMap contributors, used under the Open Database Licence.
If you use the app’s Share action to send a child’s unlock code, the code passes to whichever app you choose. That transfer is yours, not ours, and the message contains only the code.
Transfers outside the EU and EEA
Your account data stays in the European Union. Map tile requests reach the OpenStreetMap Foundation in the United Kingdom, which the European Commission has recognised as providing an adequate level of data protection, so no additional safeguards are required. We do not transfer data anywhere else.
A current list of our processors is available on request from [email protected].
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | Until the account is deleted, or one month after the project completes. |
| Trip logs, learning progress, survey answers | As for account data; then deleted or irreversibly anonymised for the project’s final evaluation |
| Technical logs | We do not store any technical logs |
| Consent records | 1 year after withdrawal, as evidence that consent was properly obtained |
At the end of the pilot we delete or irreversibly anonymise all personal data. Anonymised, aggregated results may be retained and published as project outcomes; once anonymised, that data can no longer be linked back to any person.
8. Your rights
Under the GDPR you may ask us to: give you a copy of your data; correct it; delete it; restrict or stop our use of it; give you your data in a portable form; or withdraw a consent you previously gave. Where the data belongs to a child, the parent or guardian exercises these rights.
Write to [email protected]. We reply within one month. You can also export your own route data as a GPX file at any time from within the app.
If you are unhappy with how we respond, you can complain to the Czech data protection authority, Úřad pro ochranu osobních údajů (uoou.gov.cz), or to the authority where you live.
9. Deleting your account
You can delete your account, and any child account you created, from Profile → Settings → Delete account inside the app. You can also request deletion at https://marco.dotsoft.gr/delete-account or by writing to [email protected].
Deletion removes your account and all personal data associated with it within 60 days, except consent records and anything we must keep by law. Statistics already irreversibly anonymised cannot be traced back to you and are not affected.
10. How routes, city data and morning alerts work
- You build your route yourself, by tapping waypoints on the map. You can also start from one of a small set of fixed, pre-drawn templates, which are the same for everyone and are not selected or personalised using your data.
- City sensors are shown for information only. Where the city publishes traffic, air-quality or noise readings, we display them on the map. They are not used to generate, rank, score or recommend a route.
- Morning alerts are simple threshold rules. If a public sensor near a route you saved crosses a published threshold during the morning window, we send you a heads-up. It is a fixed rule applied to public data — not a prediction, and not a profile of you.
No automated decision-making
Nothing in MARCO makes a decision about you by automated means. Your points, badges, challenge progress and class totals are calculated arithmetically from the trips you tell us about, and no decision with a legal or similarly significant effect on you is taken automatically. There is no profiling for advertising, ranking or assessment of any kind.
If we ever add a feature that generates or recommends content for you, we will update this policy and tell you in the app before you use it.
11. Security
Data is encrypted in transit and at rest. Access is limited to the Dotsoft staff who need it, and administrative access is logged. Authentication tokens are held in the device’s secure storage, and passwords are stored only as secure hashes. No system is perfectly secure, but if a breach affects your rights we will notify the Czech data protection authority within 72 hours and tell you where the law requires it.
12. Changes to this policy
If we make a material change we will notify you in the app and, where the law requires it, ask for your consent again. The version and date at the top of this document always tell you which text is current.
13. Contact
| Controller | Dotsoft S.A. and PRAGMA-iot |
|---|---|
| Address | Poseidonos 71, Pilea 555 35, Thessaloniki, Greece |
| [email protected] | |
| Web | https://marco.dotsoft.gr |
| Supervisory authority | Úřad pro ochranu osobních údajů (uoou.gov.cz) |