All student data remains subject to the school/district's legal authority. Zonifyr receives only the rights necessary to provide the contracted service.
Zonifyr will not sell or rent student data or use school student data for advertising or unrelated commercial profiling.
Zonifyr will notify the school of a confirmed security incident without undue delay and within any specific timeframe required by applicable law.
At termination or on authorized request, data will be returned or deleted according to the executed agreement and applicable law.
1. Purpose and Instructions
Zonifyr will process covered school personal data only to provide the services documented in the applicable agreement, statement of work, or school-authorized instructions, and not for unrelated advertising or commercial profiling.
2. Data Governance
Education records and other school-controlled data remain subject to the school/district's legal authority and applicable student-privacy law. Zonifyr receives only the rights necessary to provide the contracted service and does not claim ownership of school student records.
3. Scope of Processing
- Student identifiers, school/grade association, and enrollment information necessary for the program
- Guardian relationships and contact information needed for acknowledgements and school communications
- Policy acknowledgements, compliance-method declarations, school eligibility states, school-observed incidents, parent notices, and audit records
- School policy versions, staff account/membership information, and administrative configuration
- Where separately contracted for legitimately institutionally managed devices, only the device-management data permitted by Apple's approved MDM framework or, where available, the applicable Android Enterprise enrollment mode
4. Restrictions
Zonifyr will not use covered school data to:
- Sell or rent student data
- Target advertising to students or create unrelated commercial profiles
- Provide Family Controls, Screen Time, app selections, restriction state, or personal-device usage telemetry to schools from Zonifyr Family
5. Confidentiality and Access
Personnel and subprocessors with access to covered data must be bound by appropriate confidentiality and data-protection obligations and receive access only as needed for their role.
6. Security Measures
- Encryption in transit and appropriate encryption at rest
- Server-side authorization, least-privilege access, and tenant/school isolation
- Audit logging for material changes and protections against sensitive data appearing in application logs
- Incident response, backup/recovery, credential management, and other security controls appropriate to the production deployment
7. Subprocessors
Zonifyr may use subprocessors necessary to provide the service. A current production subprocessor list and applicable notice/approval process should be maintained in accordance with the final agreement and applicable law.
8. Security Incidents
- Zonifyr will notify the school/district of a confirmed security incident involving covered data without undue delay and within any specific timeframe required by applicable law or the executed agreement.
- Zonifyr will provide reasonably available information needed to understand the incident and support legally required notifications.
- Zonifyr will take reasonable remediation and containment steps appropriate to the incident.
9. Data Retention, Return, and Deletion
- Covered data will be retained only as needed for the contracted service, legal obligations, and documented retention requirements.
- At termination or on authorized request, data will be returned or deleted according to the executed agreement, applicable law, technical feasibility, and documented retention exceptions.
10. Rights and School Requests
- Zonifyr will reasonably support school/district requests related to access, correction/amendment, deletion, or export of covered records as required by law and contract.
- Parent/eligible-student requests concerning education records may be routed through the school/district when required by the applicable legal relationship.
- Zonifyr will not independently alter school education records when it lacks authority to do so.
11. Audit and Documentation
Zonifyr will provide reasonable documentation regarding applicable privacy/security controls as required by the executed agreement. Formal audit rights, certifications, and assessment procedures should be defined in the final negotiated DPA.
12. Termination
Upon termination, covered data will be handled according to Section 9 and the executed agreement.
13. Governing Law
Governing law, venue, conflict provisions, and any state-specific student-data clauses should be finalized in the executed agreement with counsel.
14. Contact
Zonifyr Inc. | legal@zonifyr.com