Pharos Up logo

Privacy policy

Effective date: 20 July 2026

← Go back

1. Introduction

This Privacy Policy explains how Pharos Schools of Foreign Languages, (“Pharos”, “we”, “us”, or “our”), collects, uses, stores, and protects personal data when users access the Pharos Up mobile application and the related Pharos online platform.

Pharos Up is intended for authorised students, parents or guardians, teachers, school directors, and other authorised staff. Access is provided through an account created, assigned, or approved by the relevant Pharos school or branch.

2. Data Controller

The organisation responsible for the processing of personal data is:

Legal name: Pharos Schools of Foreign Languages

Registered address: Sofia Center, bul. "Vitosha" 65, 2nd floor

Email: centraloffice@pharos.bg

Telephone: +359 2 980 10 73

Questions concerning privacy or personal data may be submitted using the contact information above.

3. Personal Data We Process

Depending on the user’s role and use of the platform, we may process the following categories of personal data.

Account and identification information

  • First name and surname
  • Username and email address
  • Telephone number, where provided
  • Profile picture or avatar
  • User role and assigned school branch
  • Account status and authentication information
  • Session cookies and authentication identifiers needed to keep the user securely signed in

Educational information

  • Academic year, class, level, and group
  • Homework and related educational activities
  • Attendance information
  • Assessments, grades, reports, and teacher feedback
  • Student progress and learning-journey information
  • Student self-assessment information
  • Announcements and educational communications

Parent or guardian information

Where a parent or guardian accesses information connected with a student, we may process the information required to associate that person with the relevant student account.

Technical and device information

  • Device type and operating system
  • Application installation identifier
  • Firebase Cloud Messaging registration token
  • Notification preferences
  • Date and time of the most recent application or device-registration activity
  • IP address, technical logs, error information, and security-related information, where generated by the platform or its infrastructure

The Firebase registration token and installation identifier are used to deliver push notifications to the correct application installation. They are not used for advertising.

4. How We Use Personal Data

We may use personal data for the following purposes:

  • To provide and operate the Pharos Up application and platform
  • To authenticate users and manage accounts
  • To display information relevant to each user and their assigned role
  • To support teaching, attendance, homework, assessment, reporting, and student progress
  • To send announcements, email notifications, and push notifications
  • To apply and respect users’ notification preferences
  • To maintain the security and integrity of the platform
  • To diagnose technical problems and improve application reliability
  • To prevent unauthorised access, misuse, and fraud
  • To respond to support, privacy, and data-protection requests
  • To comply with applicable legal and regulatory obligations

We do not sell personal data and we do not use personal data collected through Pharos Up for third-party targeted advertising.

5. Legal Bases for Processing

Where the General Data Protection Regulation or similar data-protection legislation applies, we may process personal data on one or more of the following legal bases:

  • The performance of a contract or the provision of educational services
  • Compliance with legal obligations
  • The legitimate interests of Pharos in operating, securing, and improving its educational services
  • Consent, where consent is required by applicable law
  • The protection of the vital interests of a user or another person, where applicable

The applicable legal basis may depend on the user’s role, the relevant school relationship, and the specific processing activity.

6. Children and Students

Pharos Up may process information relating to children and young students as part of the educational services provided by Pharos Schools.

Student accounts are not intended to be created independently by children through open public registration. Accounts are created, assigned, or authorised through the relevant school or branch.

Where required by applicable law, the relevant school or organisation is responsible for obtaining any necessary permission from a parent or legal guardian.

Children’s personal data is processed only for legitimate educational, administrative, communication, safety, security, and platform-operation purposes.

7. Push Notifications

Pharos Up uses push notifications to inform users about relevant platform activity, which may include:

  • Homework
  • Announcements
  • Reports and assessments
  • Attendance-related information
  • Student progress
  • Other educational or administrative updates

Push notifications are delivered using Google Firebase Cloud Messaging.

For this purpose, the application sends a Firebase registration token, an installation identifier, the device platform, and the associated authenticated user account to the Pharos platform.

Users may disable push notifications through their Pharos profile preferences or through the notification settings of their device.

Disabling push notifications does not prevent the user from viewing notifications and information directly within the Pharos platform.

8. Service Providers and Data Recipients

Personal data may be accessed by authorised Pharos personnel, teachers, directors, administrators, or other authorised school personnel, according to their assigned role and responsibilities.

We may also use trusted service providers to operate and support Pharos Up, including providers of:

  • Cloud hosting and data storage
  • Email delivery
  • Push-notification delivery
  • Database, infrastructure, backup, and security services
  • Technical support and system maintenance

Google Firebase Cloud Messaging is used for push notification delivery. Firebase services are operated by Google and are subject to Google’s applicable privacy, security, and data-processing terms.

Service providers may process personal data only to the extent necessary to provide their services and subject to appropriate confidentiality, security, and data-protection obligations.

Personal data may also be disclosed where required by law, a court order, or a competent public authority.

9. International Data Transfers

Some service providers may process or store information outside the country in which the user is located.

Where personal data is transferred outside the European Economic Area, appropriate safeguards are applied or required in accordance with applicable data-protection law. Such safeguards may include adequacy decisions, standard contractual clauses, or other recognised transfer mechanisms.

10. Data Retention

Personal data is retained only for as long as necessary for:

  • The provision of educational services
  • The operation of the user account
  • Academic, administrative, and reporting purposes
  • Compliance with legal and contractual obligations
  • Security, dispute resolution, and legitimate record-keeping purposes

Device-registration records may be deactivated when:

  • The user logs out
  • The application installation is no longer valid
  • Firebase reports that the notification token is invalid
  • The application has not contacted the platform for an extended period

Inactive or obsolete device records may subsequently be deleted.

The precise retention period for educational records may depend on the relevant school, the type of record, the contractual relationship, and applicable legal requirements.

11. Data Security

We use appropriate technical and organisational measures designed to protect personal data from:

  • Unauthorised access
  • Accidental loss
  • Alteration
  • Disclosure
  • Destruction
  • Misuse

These measures may include authentication controls, role-based access, encrypted network communication, access restrictions, monitoring, backups, and secure infrastructure.

No electronic system can be guaranteed to be completely secure. Users are responsible for keeping their login credentials confidential and for notifying Pharos if they suspect unauthorised access to their account.

12. User Rights

Subject to applicable data-protection law, users or their authorised representatives may have the right to:

  • Request access to their personal data
  • Request correction of inaccurate or incomplete data
  • Request deletion of personal data
  • Request restriction of processing
  • Object to certain processing activities
  • Request data portability, where applicable
  • Withdraw consent where processing is based on consent
  • Submit a complaint to the competent data-protection authority

Some requests may be subject to legal, educational, contractual, or administrative retention requirements.

Requests may be submitted to: centraloffice@pharos.bg

We may need to verify the identity and authority of the person making a request before responding.

13. Account and Data Deletion Requests

Users who wish to request account deletion or the deletion of associated personal data should contact:

centraloffice@pharos.bg

Where the account belongs to a student, a request may need to be submitted or confirmed by the relevant parent, guardian, school, or authorised representative.

Deleting an account may not result in the immediate deletion of every record where retention is necessary for legal, academic, contractual, security, or legitimate administrative purposes.

14. Notification Preferences

Users may manage whether they receive email or push notifications through the available profile settings.

Changing notification preferences applies to future notifications. It does not delete notifications or educational records that already exist within the platform.

Users may also disable notifications through the operating-system settings of their mobile device.

15. Links and Web Content

Pharos Up provides access to the Pharos online platform through an integrated web interface.

Where the platform contains links to independent third-party websites or services, those third parties may apply their own privacy policies. Pharos is not responsible for the privacy practices of independent third-party websites.

16. Changes to This Privacy Policy

We may update this Privacy Policy when necessary to reflect:

  • Changes to the application or platform
  • New functionality
  • Changes to service providers
  • Legal or regulatory requirements
  • Changes to our data-processing practices

The updated version will be published with a revised effective date.

Material changes may also be communicated through the application, the platform, email, or another appropriate method.

17. Contact Us

For questions, requests, or concerns regarding this Privacy Policy or the processing of personal data, contact:

Pharos Schools of Foreign Languages

Address: Sofia Center, bul. "Vitosha" 65, 2nd floor

Email: centraloffice@pharos.bg

Telephone: +359 2 980 10 73

Users also have the right to contact or submit a complaint to their competent national data-protection authority.