COPPA Direct Notice to Schools

Updated on: September 29, 2026

1. About This Notice

Apptegy, Inc. (“Apptegy”), located at 2201 Brookwood Drive, Suite 115, Little Rock, AR 72202, provides this COPPA Direct Notice (this “Notice”) to Schools that use the Services. Apptegy provides communication and engagement tools for schools and their communities. This Notice covers all Services, including www.apptegy.com, www.thrillshare.com, and www.edurooms.com, the Apptegy platform, and the websites and mobile applications Apptegy provides to Schools. It does not cover third-party services that a School or End User chooses to connect to, which are governed by their own terms and privacy policies. “Personal Information” means information that identifies, relates to, or could reasonably be used to identify an individual. Other capitalized terms used but not defined in this Notice have the meanings given in Apptegy’s Privacy Policy (https://www.apptegy.com/privacy-policy/).

2. Why Apptegy Provides This Notice

The Children’s Online Privacy Protection Act (“COPPA”) allows schools to consent on behalf of parents to the collection of personal information from children under 13, but only for school-authorized educational purposes. To rely on that consent, Apptegy must give the School the direct notice it would otherwise give parents. This Notice is that direct notice and describes how Apptegy collects, uses, and discloses children’s Personal Information through the Services. A School provides this authorization through its Services Agreement with Apptegy or other written authorization.

3. Highlights

Apptegy’s key commitments regarding Student Data:

●      Apptegy does not sell Personal Information.

●      The School controls Student Data and is the data controller. Apptegy is the data processor and processes Student Data only as directed by the School.

●      Apptegy does not use Personal Information to train general-purpose AI models.

●      Apptegy does not build advertising profiles from Student Data and does not use behavioral tracking to serve ads to students, children, or parents.

4. Information Apptegy Collects

Apptegy receives Personal Information from the School and End Users and collects certain information automatically through use of the Services. Not all categories apply to every individual. Categories include:

●      Contact details (name, phone number, email address), user ID, school ID, profile information, login credentials, and communication preferences

●      Demographic data: gender and language

●      Education records: school year, classes, groups, activities, clubs, assignments, assessment data, achievements, attendance, consents and forms, dietary requirements, transportation preferences, parent/student associations, and absence reasons and supporting documentation submitted by parents or guardians

●      Other information uploaded by the School or End User

●      Automatically collected data: IP addresses, web browsers, operating systems, device identifiers, general geographic location (not precise geolocation), time zone, language, pages viewed, features used, interaction data, and analytics and usage data from third-party tools used to measure and improve the Services

Apptegy does NOT collect or scrape Personal Information from users’ computers, contacts, email accounts, or other personal sources.

5. How Apptegy Uses Information

Apptegy uses Student Data only for the following purposes:

(a)            To provide, operate, and maintain the Services, including transmitting communications and servicing accounts, as directed by the School.

(b)            To carry out End User requests within the scope authorized by the School.

(c)            To maintain the security, integrity, and availability of the Services, comply with applicable law, detect and prevent fraud, protect safety and rights, and enforce agreements.

(d)            To measure and improve engagement using third-party analytics tools (information available at https://trust.apptegy.com).

Apptegy will NOT contact parents, guardians, or students about other Apptegy services, resources, or events.

6. Disclosure to Third Parties

Apptegy uses third-party service providers (“Subprocessors”) to help deliver the Services. Subprocessors act on Apptegy’s behalf and under its direction. Before sharing Personal Information with a Subprocessor, Apptegy assesses its privacy and security practices. Apptegy maintains a written agreement with each Subprocessor requiring confidentiality, integrity, and security of Personal Information. Apptegy remains responsible for a Subprocessor’s handling of Personal Information to the same extent Apptegy would be liable if performing the services directly. When a Subprocessor handles Student Data, Apptegy informs it that the Services may be used by children and provides applicable privacy and security requirements.

Any disclosure of Student Data to a Subprocessor requires the Subprocessor to:

(a)            Use the data only for providing the contracted service;

(b)            Not further disclose the data; and

(c)            Implement and maintain reasonable security measures.

A current list of Subprocessors is available at: https://trust.apptegy.com/subprocessors.

7. No Commercial Use Unrelated to the Services

Apptegy will not use or share Student Data for commercial purposes unrelated to the provision of the Services. Specifically, Apptegy will not:

(a)            Use Student Data for targeted advertising or to create advertising profiles.

(b)            Use information acquired through a student’s or child’s use of the Services to target advertising on any other website, service, or application.

(c)            Sell Student Data, except in connection with a change of control where the successor entity is bound by the same restrictions.

(d)            Use Student Data to create a profile about a student except in furtherance of K-12 school purposes.

8. Reviewing Children’s Personal Information

Schools control Student Data. Schools may contact Apptegy at any time to review, inspect, or request amendments to Student Data that Apptegy maintains on the School’s behalf.

Parents and guardians who wish to review their child’s Personal Information, request deletion of that information, or refuse further collection or use of their child’s information should contact their School directly. The School may then contact Apptegy at privacy@apptegy.com or 1-888-501-0024 to facilitate those requests.

9. Retention and Deletion

Apptegy retains children's Personal Information only to provide the Services to the School and does not retain it indefinitely. During the services agreement, the School decides what information remains in the Services and may delete information through the Services or direct Apptegy to delete it at any time. After the services agreement ends, Apptegy deletes or de-identifies children's Personal Information as described below and removes it from backup systems pursuant to Apptegy's backup schedule.

Upon termination or expiration of the services agreement, the School may request an export of its data within 30 days. After that period (or earlier at the School’s request), Apptegy will delete or de-identify Personal Information, except as required for legal or compliance purposes or as set forth in the School’s data processing addendum.

If Apptegy learns it has received Personal Information from a child outside of the school consent framework, it will delete that information promptly.

10. Security

Apptegy maintains administrative, technical, and physical safeguards designed to protect children’s Personal Information. These measures include:

●      Industry-accepted encryption of data in transit and at rest.

●      Periodic system evaluations, security certifications, regular backups, and security audits conducted at least annually, with summary security documentation available through the Trust Center (https://trust.apptegy.com) or under NDA.

●      A written information security plan with a designated program coordinator, annual risk assessments, and periodic program reviews.

●      Privacy and security training for all employees and contractors, who are bound by data protection policies, and background checks on employees with access to Student Data.

●      Role-based access controls; access is revoked promptly when no longer required.

11. AI Features

The Services may include artificial intelligence features (“AI Features”). AI Features are disabled by default and may be enabled only by the School. When enabled, AI Features process data solely to generate outputs for the School’s use within the Services.

The Services may also use automated tools to categorize and process user-submitted content in support of product functionality (for example, classifying absence reasons from parent or guardian submissions).

Apptegy does not use Personal Information to train, tune, or improve general-purpose AI models. Apptegy uses commercially reasonable efforts to prevent third-party AI model providers from using Personal Information to train their general-purpose AI models.

12. Sharing This Notice With Parents

COPPA generally does not require Schools to share this Notice with parents. Apptegy recommends sharing it so families can see what information is collected, how it is used, and how it is protected.

13. Resources and Contact

Resources

●      Privacy Policy: https://www.apptegy.com/privacy

●      Terms of Use: https://www.apptegy.com/terms-of-use/

●      Trust Center: https://trust.apptegy.com

Apptegy participates in the iKeepSafe COPPA Safe Harbor Program and holds iKeepSafe FERPA Certification, California Student Privacy Certification, and iKeepSafe ATLIS Certification. Apptegy's certification profile is available at https://ikeepsafe.org/product/thrillshare/.

Contact

●      Email: privacy@apptegy.com

●      Mail: Apptegy, Inc., c/o Data Protection Officer, 2201 Brookwood Drive, Suite 115, Little Rock, AR 72202

●      Phone: 1-888-501-0024

14. Disclaimer

This Notice does not constitute legal advice. Apptegy recommends that Schools consult their designated legal counsel if they have any concerns or inquiries regarding compliance with COPPA or any other applicable law.