Privacy Policy

Last updated: 16 July 2026

ZensConnect is a video-meeting and virtual-classroom platform for schools, academies, businesses, and the teams that build on it. This policy explains what personal data we collect, why, how long we keep it, and the rights you have over it. When your organization uses ZensConnect, the organization is the controller of its data and ZensConnect is its processor — we handle data on the organization’s instructions and never for advertising.

Who this policy covers

  • Organizations — schools, institutes, and businesses that hold a ZensConnect account.
  • Members — admins, teachers, and students who sign in under an organization.
  • Guests — people who join a meeting by link without an account.
  • Integrators — developers who embed ZensConnect or call its API for an organization.

Data we collect

  • Account & profile: name, email, role, and organization membership. Optional fields (phone, avatar) can be disabled per organization and are off by default for minor accounts.
  • Meeting data: titles, schedules, participant lists, join/leave times, and attendance logs.
  • In-meeting content: chat, questions & answers, poll responses, whiteboard content, and shared files.
  • Recordings & transcripts: when an organization enables recording, the audio, video, and generated captions.
  • Consent records: each participant’s recording-consent decision, the mode in force, a timestamp, and client context.
  • Network & device data: the connecting IP address and basic technical details such as browser user agent.
  • Audit data: a record of security-relevant and education-record-disclosure actions.
  • Billing data: subscription and payment-reference data processed through our payment provider. We never store full card numbers.

Why we process data

  • Provide the service — host meetings, track attendance, deliver recordings (performance of contract).
  • Keep the service secure — detect abuse, investigate incidents, enforce access controls (legitimate interest).
  • Meet legal & education obligations — retain records, honor data-subject requests, capture consent (legal obligation).
  • Bill paid organizations — process subscriptions and payments (performance of contract).

ZensConnect never uses personal data for behavioral advertising, and never uses it to train machine-learning models beyond an organization’s explicit configuration.

How we share data

  • Within the organization — education records are visible only to roles with a legitimate educational interest, enforced by the permission system.
  • With subprocessors — third-party infrastructure providers that process data on our instructions under contract.
  • With integrators you authorize — data exposed through embeds, webhooks, or the API you enable. These disclosures are logged.
  • For legal reasons — where required by law, or to protect users’ rights and safety.

ZensConnect does not sell personal data.

Third-party integrations & Google user data

When you connect an optional integration, ZensConnect accesses only the data needed to provide that feature, and only while the integration is connected. You can disconnect an integration at any time from your settings, which revokes ZensConnect’s access.

Google Calendar. If you connect your Google account to sync meetings, ZensConnect requests calendar access to create and update calendar events for the meetings you choose to sync. We use this access solely to provide the calendar-sync feature you asked for.

ZensConnect’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not transfer it except as needed to provide or improve the calendar-sync feature, to comply with law, or as part of a merger with your prior notice. We do not use Google user data to train generalized AI/ML models.

IP address retention

When you join a meeting we record the connecting IP address for security, abuse detection, and incident response. IP addresses are automatically erased 90 days after the meeting and are never written to debug logs.

Data retention

We keep each category of data only as long as needed, then delete or anonymize it. Organizations can configure the windows below; deletions run as automated background jobs and are recorded in the audit log. A legal hold suspends deletion for the affected records.

Data typeDefaultConfigurable range
Chat messages365 days30 days – 7 years
Recordings & transcripts365 days30 days – 7 years
Attendance logs7 years1 – 10 years
Q&A and polls365 days30 days – 7 years
Audit logs7 yearsNot below 1 year
Notifications90 days30 – 365 days
Participant IP address90 daysConfigurable

Your privacy rights

Data-subject rights are exercised through the organization that holds the account; ZensConnect provides the tooling to respond.

  • Access & export — request a complete, machine-readable export of one person’s personal data.
  • Erasure — request deletion or anonymization, subject to legal hold and the retention rules above.
  • Tracking — every data-subject request is recorded with its type, requester, status, and a 30-day default deadline.

To make a request, contact your organization administrator, or email privacy@zenszoom.com.

Children & minors

ZensConnect supports a minor-handling mode designed for COPPA and similar rules. Organizations declare whether they serve users under 13; parental consent is captured before a minor account is activated; minor accounts collect less data by default; and no behavioral advertising or third-party analytics run on student-facing surfaces.

Education records (FERPA)

For U.S. organizations, ZensConnect treats attendance, recordings, chat, Q&A, poll answers, and participation data as education records and acts as a “school official” service provider — processing them only to provide the service, never for advertising. Disclosures to third parties are logged.

International users (GDPR)

For organizations and users in the EEA and UK, ZensConnect acts as a processor under the GDPR; the organization is the controller. We process data only on documented instructions, provide access/export/erasure tooling, make a Data Processing Agreement available, and list our subprocessors.

Data security

  • Tenant isolation — database row-level security pins every request to a single organization.
  • Access control — a role and permission system restricts records to those with a legitimate need.
  • Encryption — HTTPS in transit; stored recordings and objects encrypted at rest.
  • Secret management — production credentials held in a managed store and rotated.
  • Optional end-to-end encryption — a server-blind meeting mode (which disables recording and captions).

Breach notification

If ZensConnect confirms a personal-data breach, it notifies each affected organization within 72 hours of confirmation, following an incident- response procedure with severity classification.

Recording consent

Recordings are off until an organization enables them. Each organization chooses a consent mode — notice-only or explicit-consent. Participants are warned before recording starts and can leave, or join muted with camera off. Every decision is stored as a consent record.

Changes to this policy

We may update this policy as the service and the law change. Material changes are communicated to organization administrators; the date above shows when the current version took effect.

Contact

For privacy questions or to exercise a data-subject right, contact your organization administrator, or reach ZensConnect at privacy@zenszoom.com.