Privacy Policy
1. INTRODUCTION
Last updated: September 18, 2026
Apptegy, Inc. (including its subsidiaries and affiliates, "Apptegy," "we," "us," or "our") provides communication and engagement tools for schools and their communities. This Privacy Policy ("Policy") describes how we collect, use, share, and protect Personal Information through our Services, as defined in Section 2.1 below.
What You Should Know
We do not sell your Personal Information.
Clients control Student Data. We process it only as directed by the Client.
We do not use Personal Information to train AI models, and we require the same of our AI providers.
We do not build advertising profiles from Student Data or child data, and we do not use behavioral tracking to serve ads to students, children, or parents.
You have rights regarding your Personal Information, which vary by jurisdiction. See Section 12 for details.
By using our Services, you agree to the practices described in this Policy. If you do not consent, please do not use the Services.
If you have questions about this Policy or our privacy practices, contact us at:
Email: privacy@apptegy.com
Phone: 1-888-501-0024
Mail: Apptegy, Inc., c/o Data Protection Officer, 2201 Brookwood Drive, Suite 115, Little Rock, AR 72202
2. WHO AND WHAT THIS POLICY APPLIES TO
2.1 Definitions. This Policy applies to all individuals who access or use the Services ("Users"). The following terms are used throughout this Policy:
"Client" means an entity that has a direct business relationship with Apptegy.
"End User" means an individual invited or added by a Client to use the Services.
"Personal Information" means any information that identifies, relates to, or could reasonably be used to identify an individual.
"School" means an education institution, school district, or other educational organization that is a Client.
"School-Created User Account" means an individual End User account created and managed by a School within the Services.
"Visitor" means an individual who browses the public portions of the Services without logging in or being invited by a Client.
References to "Users" and "you" refer to you individually and to all Users collectively, unless stated otherwise. End Users may access the Services through a Client's separate website or mobile application, and this Policy applies whether you use the Services directly or through a Client site or app.
All End User accounts are controlled and managed by the Client that creates them.
2.2 Services Covered
This Policy applies to all of our products and services, including:
(a) our websites, including www.apptegy.com, www.thrillshare.com, and www.edurooms.com (collectively, the "Sites");
(b) our platform and all products and tools available through it; and
(c) any website or mobile application that provides access to or use of any of the foregoing
(collectively, the "Services").
If you are a California resident, see Section 12.1. If you are a European Union or United Kingdom resident, see Section 12.2. If you are a Canadian resident, see Section 12.3.
3. WHAT WE COLLECT AND HOW
3.1 Personal Information from Clients and Under School-Created User Accounts
The Personal Information we collect is provided to us either by a Client on behalf of its End Users, or by End Users using the Services under School-Created User Accounts. All End User accounts are controlled and managed by the Client that creates them.
In these circumstances, the Client determines and controls what Personal Information is collected, the purpose for which it is collected, and how it is used. The Client is the data controller. Apptegy is the data processor, acting only on behalf of and under the direct control of the Client.
Because of this, if you are an End User, the Client that added you to the Services is primarily responsible for the Personal Information we collect about you. We use that information only to provide the Services as directed by the Client. If you have questions or requests about your Personal Information, please contact the Client that manages your account directly.
The following categories of Personal Information may be collected in connection with the Services. Not all categories will be collected for every individual; what we collect depends on the Services being used by the Client and its End Users.
(a) Information provided by Clients and End Users:
Contact details (such as name, phone number, email address), user ID, school ID, profile information, login credentials, and communication preferences
Demographic data: gender, age or birthday, race or ethnicity, language, and disability status
Education records: school year, classes and groups, activities and clubs, assignments, grading and assessment data, achievements, attendance, consents and forms, dietary requirements, transportation preferences, and parent/student associations
Absence-related information, including reasons for absence and supporting documentation submitted by parents or guardians
Billing and payment information
Other information uploaded by the Client or End User
(b) Information collected automatically from use of the Services:
IP addresses, web browsers, operating systems, device makes, models, and identifiers
General geographic location (not precise geolocation), time zone, and language
Pages viewed, features and functions used, and other information about how Users interact with the Services
Information provided during customer support requests
(c) Information from third parties:
Analytics and usage data from third-party tools we use to measure and improve the Services (see Section 13 for more details)
We do not collect or scrape additional Personal Information from the computers, contacts, email accounts, or other personal sources of Users.
3.2 Visitor Personal Information
If you are a Visitor, we collect limited Personal Information from and about you, including:
IP addresses, web browsers, operating systems, device makes, models, and identifiers
General geographic location (not precise geolocation), time zone, and language
Pages viewed, features and functions used, and other information about how Visitors interact with the Services
If you choose to contact us (for example, by sending a message via the Sites), we collect the Personal Information you provide, such as your name, phone number, email address, and the content of your message.
3.3 De-Identified and Aggregate Information
We may collect and use de-identified or aggregated information that cannot reasonably be used to identify any individual. We use commercially reasonable methods to de-identify data, consistent with industry best practices.
4. HOW WE USE YOUR INFORMATION
We use Personal Information collected through the Services for the following purposes:
(a) To provide, operate, and maintain the Services as directed by the applicable Client or End User.
(b) As directed by you or with your consent.
(c) To enable and transmit communications through available channels.
(d) To maintain the security, integrity, and availability of the Services.
(e) To comply with applicable law, detect and prevent fraud, protect the safety and rights of individuals, and enforce our agreements.
(f) To contact Schools and school staff about other Apptegy services, resources, and events. We will not contact parents, guardians, or students for this purpose.
(g) To service and maintain accounts.
(h) To measure and improve engagement with the Services using third-party analytics tools. Information about the analytics tools we use and links to their privacy policies is available at https://trust.apptegy.com.
(i) For corporate business purposes, including those described in Section 9 (Change of Control).
5. HOW WE SHARE YOUR INFORMATION
This section describes the circumstances under which we share Personal Information.
5.1 Subprocessors
We use third-party service providers ("Subprocessors") to assist in delivering the Services. Subprocessors act on our behalf and under our direction.
We maintain written agreements with each Subprocessor requiring them to maintain the confidentiality, integrity, and security of Personal Information and comply with our data protection requirements. Apptegy remains responsible for a Subprocessor's handling of Personal Information to the same extent Apptegy would be liable if performing the services directly.
Before sharing Personal Information with a Subprocessor, we assess the Subprocessor's privacy and security practices. When a Subprocessor handles children's or student data, we inform the Subprocessor that the Services may be used by children and provide our data privacy and security requirements. We repeat these assessments annually or when our policies change.
A current list of our Subprocessors is available at https://trust.apptegy.com/subprocessors.
5.2 Third-Party Services
The Services may integrate with or provide access to services, platforms, or solutions provided by third parties ("Third-Party Services"). Third-Party Services are distinct from Subprocessors. Subprocessors act on our behalf; Third-Party Services operate independently and are governed by their own terms and privacy policies.
Apptegy does not control Third-Party Services, and their practices may differ materially from ours. Access to and use of Third-Party Services is at your own risk. The Client and its authorized End Users control whether and how Third-Party Services are used through the platform.
5.3 General Sharing Practices
We do not sell Personal Information to third parties. We limit the Personal Information we share with any third party to what is necessary and impose confidentiality and security requirements on recipients.
We may share de-identified or aggregated information to promote and improve the Services, subject to the de-identification standards described in Section 3.3.
6. PROHIBITED USES OF STUDENT DATA
With respect to Personal Information from or about students, including education records as defined under the Family Educational Rights and Privacy Act ("Education Records") (collectively, "Student Data"), and Personal Information from or about children, Apptegy will not:
(a) use Student Data or child Personal Information for targeted advertising, whether on the Services or any other website, service, or application;
(b) use information acquired through a student's or child's use of the Services to target advertising on any other website, service, or application;
(c) use Student Data to create advertising profiles;
(d) sell Student Data, except in connection with a transaction described in Section 9 (Change of Control) where the successor is bound by the same restrictions;
(e) use Student Data to create a profile about a student except in furtherance of K-12 school purposes;
(f) disclose Student Data except as necessary to provide the Services, as directed by the Client, or as otherwise described in this Policy; or
(g) use tracking technologies from third parties to serve behavioral advertising to End Users who are children or students.
Any disclosure of Student Data to Subprocessors is subject to contractual obligations requiring the Subprocessor to: (1) use the data only for providing the contracted service, (2) not further disclose the data, and (3) implement and maintain reasonable security measures.
7. STUDENT DATA PRIVACY
7.1 Certifications
We maintain our policies and practices in alignment with the following iKeepSafe certification programs:
(a) iKeepSafe COPPA Safe Harbor Program
(b) iKeepSafe FERPA Certification Program
(c) California Student Privacy Certification Program
For more information, visit https://ikeepsafe.org/certifications/ or email privacy@ikeepsafe.org.
7.2 COPPA Compliance
We receive Personal Information about children under 13 only from Clients or End Users acting under a Client's direction, and only in connection with providing the Services.
When a School adds children to the Services, the School consents on behalf of parents and guardians for Apptegy's collection, use, and storage of children's Personal Information, provided that the data is for the use and benefit of the School and not for commercial purposes. Schools are responsible for obtaining and maintaining all required parental or guardian consents for any children under their account.
Schools receive notice of our children's data practices through this Policy, our Terms of Use, and the services agreement provided as part of the contractual relationship.
Parents and guardians may review, request deletion of, or refuse further collection of their child's information by contacting their School. Schools may contact us to facilitate these requests.
If we learn that we have received Personal Information from a child outside of this framework, we will delete it promptly.
7.3 FERPA Compliance
When a School provides Education Records, Apptegy acts as a "school official" under FERPA with a legitimate educational interest. We use Education Records only to provide the Services and do not disclose Education Records except as permitted by FERPA or as directed by the School.
Schools may inspect, review, and request amendments to Student Data by contacting us. We will respond within timeframes required by applicable law.
7.4 California Student Privacy (AB 1584 and SOPIPA)
For California school districts, county offices of education, and charter schools (collectively, "local educational agencies" as defined under California Education Code § 49073.1), the following applies:
(a) Student records obtained from a School continue to be the property of and under the control of the School.
(b) End Users may retain possession and control of their own student-generated content. Schools may contact us to facilitate the transfer of student-generated content to a personal account.
(c) Apptegy will not use any information in a student record for any purpose other than those required or specifically permitted by our Terms of Use and this Policy.
(d) Parents, legal guardians, or eligible students may review personally identifiable information in student records and correct erroneous information by contacting their School. End Users may also access, correct, update, or delete Personal Information in their profile by signing into their account.
(e) Apptegy is committed to maintaining the security and confidentiality of student records. We: (1) limit employee access to Student Data to those with a need to know; (2) conduct background checks on employees with access to Student Data; (3) conduct regular employee privacy and data security training; and (4) protect Personal Information with technical, contractual, administrative, and physical safeguards.
(f) In the event of an unauthorized disclosure of a student's records, Apptegy will promptly notify the School unless directed not to by law enforcement. Notification will identify: (1) the date and nature of the unauthorized disclosure; (2) the data involved; (3) a general description of what occurred; (4) steps Apptegy has taken or will take to mitigate the impact; (5) corrective actions taken or planned; and (6) an Apptegy contact. Apptegy will keep the School informed until the incident is resolved.
(g) Apptegy will delete or de-identify Personal Information when it is no longer needed, upon expiration or termination of the agreement with the School, completed according to the terms of the agreement or at the School's direction.
(h) Apptegy agrees to work with Schools to ensure compliance with FERPA by providing parents, legal guardians, or eligible students with the ability to inspect and review student records and to correct inaccuracies as described in item (d) above.
(i) Apptegy prohibits using personally identifiable information in student records to engage in targeted advertising.
8. AI FEATURES
The Services may include artificial intelligence features ("AI Features"). AI Features are provided on an opt-in basis.
When enabled, AI Features process data only to generate outputs for the Client's use within the Services. The Services may also use automated tools to categorize and process user-submitted content, such as messages and attached files, to support product functionality (for example, classifying absence reasons). These tools process content only as necessary to deliver the applicable Service. Apptegy does not use Personal Information to train, tune, or improve general-purpose AI models. We use commercially reasonable efforts to ensure that third-party AI model providers do not use Personal Information processed through the Services to train their general-purpose AI models.
Outputs generated by AI Features may contain errors or inaccuracies and should be reviewed before use. Clients are responsible for ensuring that End Users are aware when they are interacting with AI Features and for obtaining any notices or consents required by applicable law.
9. CHANGE OF CONTROL
In the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, or in connection with bankruptcy, liquidation, or similar proceeding, Personal Information may be transferred to the successor entity.
Any successor entity will be bound by privacy and data protection commitments that are substantially similar to those in this Policy with respect to Personal Information collected prior to the transaction. We will notify affected Clients within a reasonable time after the closing of any such transaction.
If the successor entity intends to use Personal Information in a manner materially different from this Policy, the successor will provide advance notice and, where required by applicable law, obtain consent before doing so. Until such notice is provided and any required consent is obtained, the successor must continue to handle Personal Information in accordance with this Policy.
10. DATA RETENTION AND DELETION
We retain Personal Information only for as long as reasonably necessary to fulfill the purposes for which it was collected, provide the Services, and comply with applicable law.
10.1 Clients
We retain and delete Personal Information associated with a Client account according to the Client's instructions, the applicable services agreement and data processing addendum, and applicable law. Upon termination or expiration of the services agreement, the Client may request an export of its data within thirty (30) days. After that period (or earlier at the Client's request), we will delete or de-identify Personal Information in our possession or control, except as required for legal or compliance purposes or as otherwise set forth in the applicable data processing addendum.
10.2 End Users
We retain and delete Personal Information about End Users according to the instructions of the Client that manages the End User's account and applicable law. If you are an End User and have questions about retention or deletion of your Personal Information, please contact the Client that manages your account.
10.3 Visitors
We retain Personal Information collected from Visitors for as long as permitted under applicable law and our internal data retention policies.
10.4 Children's Personal Information
We receive Personal Information about students and children only from Clients or End Users acting under a Client's direction, and only as necessary to provide the Services. We retain this information for the duration of the Client's services agreement unless the Client requests deletion earlier. Upon termination or expiration of the services agreement, we delete or de-identify this information in accordance with Section 10.1. We also delete or de-identify children's Personal Information when it is no longer needed for the purposes for which it was collected, even if the services agreement remains in effect..
11. SECURITY
We maintain administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, use, or disclosure. These safeguards are appropriate to the sensitivity of the information and the nature and scope of our operations.
11.1 Our Practices
(a) We use industry-accepted encryption to protect Personal Information in transit and at rest.
(b) We conduct periodic system evaluations, maintain security certifications, and perform regular backups.
(c) We maintain a written information security plan with a designated program coordinator, annual risk assessments, and periodic program reviews.
(d) Employees and contractors receive privacy and security training and are bound by our data protection policies.
(e) We conduct background checks on employees with access to Student Data.
(f) We enforce role-based access controls. Access is revoked promptly when an employee or contractor no longer requires it.
(g) We conduct security audits no less than annually. Schools may request access to audit results or, with approval, conduct their own audit of our practices related to their data.
11.2 Data Breach Notification
If we become aware of an unauthorized access to or disclosure of Personal Information that compromises its security or confidentiality, we will:
(a) Notify affected Clients within seventy-two (72) hours of confirmation of the incident, unless notification within that time would disrupt a law enforcement investigation, in which case notification will be made within a reasonable time.
(b) Include in the notification: (1) the date and nature of the incident; (2) the categories of data involved; (3) a general description of what occurred; (4) steps taken or planned to mitigate the impact; (5) corrective actions taken or planned; and (6) an Apptegy contact for further information.
(c) For End Users, provide notification according to the instructions of the Client that manages the account and applicable law.
(d) For Visitors, provide notification in accordance with applicable law.
(e) Cooperate with the affected Client to investigate and respond to the incident.
For more information about our security practices, visit https://trust.apptegy.com.
12. YOUR RIGHTS BY JURISDICTION
12.1 California Privacy Notice (CCPA/CPRA)
This section applies to individual residents of California where Apptegy acts as a "business" with or for that individual (for example, Visitors). This section does not apply to End Users under School-Created User Accounts. If you use the Services under a School-Created User Account, the privacy policies of the Client that manages your account govern your Personal Information and your rights. Contact the Client that manages your account with any questions.
For information about the categories of Personal Information we collect, see Section 3. For how we use personal information, see Section 4. For how we share Personal Information, see Section 5.
Under the CCPA, certain uses of tracking technologies for analytics or promotional purposes may be considered "sales" or "sharing" of Personal Information. To the extent any of our activities fall within those definitions, they apply only to Visitors and not to End Users or School-Created User Accounts. We do not sell or share Personal Information of minors for commercial marketing or targeted advertising.
If you are a qualifying California resident, you have the following rights:
(a) Right to know. You may request the specific pieces and categories of Personal Information we have collected about you, the sources, our purposes for collecting or sharing it, and the categories of third parties with whom we have shared it.
(b) Right to delete. You may request that we delete Personal Information we have collected about you, subject to certain exceptions.
(c) Right to opt out of sales and sharing. You may direct us not to sell or share your Personal Information for cross-context behavioral advertising. Submit a request at www.apptegy.com/donotsellmypersonalinformation. If you are not logged into an account, your request will apply only to that browser. Opting out does not prevent you from seeing ads about Apptegy; they will not be tailored to you.
(d) Right to correct. You may request that we correct inaccurate Personal Information.
(e) Sensitive Personal Information. Certain Services may allow Users to voluntarily submit information that could be considered sensitive Personal Information under the CCPA, such as health-related information provided in connection with absence reporting. We use such information only as necessary to provide the Services as directed by the applicable Client and do not use it for any purpose other than performing the Services.
(f) Right to non-discrimination. We will not refuse the Services, change pricing, or provide a different quality of Services because you exercised your CCPA rights. Exercising certain rights may limit our ability to provide some features that require Personal Information to function.
We may need to verify your identity before processing a request, which may require additional information from you. We reserve the right to decline requests where we are unable to verify your identity, or as otherwise permitted by applicable law. You may designate an authorized agent to make requests on your behalf with proof of authorization.
We do not provide financial incentives related to the collection, use, or disclosure of Personal Information.
We will comply with valid requests from California residents under California's "Shine the Light" law.
To exercise any of these rights, contact us at privacy@apptegy.com, 1-888-501-0024, or Apptegy, Inc., c/o Data Protection Officer, 2201 Brookwood Drive, Suite 115, Little Rock, AR 72202.
12.2 European Union and United Kingdom Privacy Notice (GDPR/UK GDPR)
If you are located in the European Union or United Kingdom, you may have the following rights under the GDPR or UK GDPR: access to your Personal Information, correction of inaccurate data, deletion, restriction of processing, data portability, and objection to processing. You may also have the right to lodge a complaint with your local data protection authority.
If you use the Services under a Client account, contact the Client that manages your account about your Personal Information and your rights.
To exercise any of these rights as an individual user, contact our Data Protection Officer at privacy@apptegy.com.
Personal Information will be transferred to and processed in the United States or Canada. We maintain safeguards appropriate to the sensitivity of the information for all international transfers.
12.3 Canadian Residents
If you are located in Canada, the following applies:
(a) Consent. By using the Services, you consent to the collection, use, and disclosure of your Personal Information in accordance with this Policy. You may withdraw consent at any time by contacting us at privacy@apptegy.com. Withdrawing consent may limit our ability to provide certain Services.
(b) Access and correction. You may request access to and correction of your Personal Information by contacting us at privacy@apptegy.com.
(c) Interest-based advertising. To opt out of interest-based advertising, visit AdChoices (https://youradchoices.ca).
(d) CASL. We send commercial electronic messages only where we have express or implied consent. You may unsubscribe at any time by following the instructions in the message. This applies only to messages sent by Apptegy on its own behalf, not messages sent by Clients using the Services.
13. ADVERTISING AND MARKETING; TRACKING
If you are a School or a teacher, administrator, or staff member under a School-Created User Account, we may contact you about other Apptegy services, resources, and events. We will not contact parents, guardians, or students for this purpose.
Marketing communications include instructions for opting out. You may also contact us at privacy@apptegy.com to manage your preferences at any time.
We use cookies and similar tracking technologies to operate and improve the Services. We use third-party analytics tools to understand how Users interact with the Services. Information about the analytics tools we use and links to their privacy policies is available at https://trust.apptegy.com.
We do not use tracking technologies to serve behavioral advertising to End Users, children, or students.
End User accounts are controlled by the Client. Some preference changes may require contacting the Client that manages your account.
14. DATA TRANSFERS
Apptegy is based in the United States. Personal Information will be accessed, transferred, processed, and stored in the United States or Canada. We also have personnel in locations outside of the United States. In some circumstances, Personal Information may be processed outside of the United States when reasonably necessary to provide, operate, or maintain the Services.
We maintain administrative, technical, and physical safeguards for the protection of Personal Information in all locations where we do business. By using the Services, you consent to the transfer and processing of your Personal Information in the United States and other locations where we operate.
15. THIRD-PARTY LINKS
The Services may contain links to websites or services operated by third parties. We are not responsible for the privacy practices or content of any third-party website or service. We encourage you to review the privacy policies of any third-party website or service before providing Personal Information.
16. CHANGES TO THIS POLICY
We may update this Policy from time to time. The most current version will always be available at https://www.apptegy.com/privacy. Changes are effective upon posting.
If we make changes that materially reduce the protections for Personal Information described in this Policy, we will provide advance notice on the Services and, if required by applicable law, request consent. For affected Clients, we will also provide notice via the contact information on file.
For non-material changes, continued use of the Services after changes are posted constitutes acceptance of the revised Policy.
17. CONTACT US
If you have questions about this Policy, please contact us:
Email: privacy@apptegy.com
Phone: 1-888-501-0024
Mail: Apptegy, Inc., c/o Data Protection Officer, 2201 Brookwood Drive, Suite 115, Little Rock, AR 72202
If you are an End User whose account was created by a School, please direct questions about your Personal Information to your School first. Your School may then contact us as needed to address your request.