Zonifyr Inc. ("Zonifyr," "we," "our") provides distinct products for school phone-policy operations, parent-controlled personal-device tools, institutionally managed devices, and community recognition. This policy describes those products separately because they involve different users, data, and authority relationships.
1. Product Roles and Data Boundaries
Zonifyr does not operate under a single data role across every product. The role depends on the product and relationship involved.
- Zonifyr Schools processes school-authorized records used to operate a school phone-policy program and related school workflows.
- Zonifyr Family is a separate parent-controlled product for personally owned devices. Family Controls, Screen Time, app selections, restriction state, and personal-device usage telemetry are not transmitted to Zonifyr Schools.
- Zonifyr Managed is a separate enterprise product for school-owned or legitimately institutionally managed devices. It is built within Apple's approved MDM framework. Android Enterprise support is in development subject to applicable enrollment modes and platform requirements.
2. Student Privacy and Education Records
Zonifyr is being designed so school deployments can satisfy applicable student-privacy obligations, including FERPA, COPPA where applicable, and applicable state requirements. Final production practices and contracts remain subject to formal legal and security review.
- School student records are used only for authorized school-program purposes and are not intended for unrelated advertising or commercial profiling.
- Access to school records is designed to be role-based, school/tenant scoped, and auditable.
- Parent/guardian access to school records is designed to require a verified guardian-student relationship.
3. Children Under 13 / COPPA
- Where children under 13 use a Zonifyr product, the applicable consent and notice model depends on the product, purpose, and legal relationship.
- School authorization for educational use is not treated as permission to reuse children's information for unrelated commercial purposes.
- Where verifiable parental consent is legally required, Zonifyr will implement the applicable consent process before production use of the relevant feature.
4. Information We Expect to Process
A. Zonifyr Schools
- School-issued or internal student identifiers and school/grade associations as needed for the program
- Guardian relationships and contact information needed for policy acknowledgement and school communication
- Policy acknowledgements, compliance-method declarations, and school-defined eligibility states
- School-observed incident records, parent-facing summaries, internal staff notes, and audit records, with access controls appropriate to each record type
- Policy configurations, policy versions, staff accounts, and school/district administrative settings
Zonifyr Schools does not receive Family Controls, Screen Time, app selections, personal-device restriction state, or personal-device usage telemetry from Zonifyr Family.
B. Zonifyr Family
- Parent/guardian-controlled configuration needed to provide the Family product, such as local onboarding state, supported parental-control selections, and recurring schedule configuration
- Family-device information should remain local or within the Family product boundary wherever practical and is not provided to schools
- Any future family-only synchronization or service-provider processing must be separately documented and limited to the Family product purpose
C. Zonifyr Managed
- For legitimately institutionally managed devices, Zonifyr may process device-management identifiers, enrollment state, configurations, compliance information, and administrative data that the applicable Apple/Android management framework permits for that enrollment mode
- Managed-device data is separate from ordinary personally owned student-device data and is not used to create a workaround for unauthorized personal-device management
D. SchoolSafeZone
SchoolSafeZone is designed to use the minimum information necessary for positive recognition and reward redemption. Local businesses should receive only what is needed to validate a reward, not discipline records, personal-device data, or sensitive education records.
5. How Information Is Used
- Operate school phone-policy and related school-authorized workflows
- Provide parent-controlled Family features within the applicable platform rules
- Provide legitimate institutional device-management functions where Zonifyr has the required vendor access and the customer has authority to manage the device
- Support privacy-preserving recognition and reward redemption through SchoolSafeZone
- Maintain security, reliability, support, auditing, and legal compliance
6. Location and Device Data
- Zonifyr Schools does not collect continuous location data from personally owned student devices. Zonifyr Family does not provide personal-device location telemetry to schools.
- If a future Zonifyr Managed deployment uses device-management location or device-status capabilities, such processing will be limited to legitimately managed devices and the capabilities permitted by the applicable platform and customer authorization.
7. Retention and Deletion
- Retention periods will be defined by product, school contract, legal requirements, and operational need.
- Deletion, return, and account-termination workflows will be documented and tested before production school deployment. Parent/student rights requests will be handled according to the applicable legal and contractual process.
8. Security
- Encryption in transit and, where appropriate, at rest
- Server-side role-based authorization and tenant/school isolation for school records
- Audit logging for material school-record mutations and restricted internal access
- Data minimization, secure secrets management, and controls intended to prevent sensitive information from appearing in logs
9. Sharing and Service Providers
- School records may be shared with the applicable school/district and authorized service providers only as needed to provide the service and subject to applicable contractual/privacy requirements.
- Zonifyr does not intend to sell student data or use school student data for advertising. SchoolSafeZone merchants are not given student discipline records or personal-device telemetry.
- A current subprocessor list and product-specific disclosures should be maintained as the production architecture is finalized.
10. Rights of Parents and Eligible Students
- Access rights are handled according to the applicable product, law, and school relationship.
- Correction/amendment requests for school education records may require coordination with the school or district that controls the record.
- Deletion requests are handled according to applicable law, contract, retention obligations, and the product involved.
Zonifyr will provide clear request channels before production deployment.
11. Changes to This Policy
Zonifyr may update this policy as products, platform approvals, laws, and data practices evolve. Material changes will be communicated as required by applicable law or contract.
12. Contact
Zonifyr Inc. | privacy@zonifyr.com