1. Summary
Ayonix Zoomer verifies the identity of people attending training delivered over Zoom, so that an organisation can evidence who actually attended. Doing that requires processing biometric data — a mathematical representation of a face. We treat that as the most sensitive category of data we hold, and this policy says plainly what we do with it.
We do not record meetings. We do not store meeting video or audio. Video frames are analysed and discarded.
Roles
The organisation that runs the training (our customer) is the data controller. Ayonix is the data processor, acting on that customer's instructions. If you are a trainee and want your data removed, contact the organisation running your course; if you cannot reach them, contact us and we will route your request.
2. What we process, and why
| Data | Purpose | Retention |
|---|---|---|
| Face template — a numeric vector derived from an enrolment photograph. Not an image, and the original photograph is not kept. | Verify that the person attending is the person enrolled. | Until the trainee record is deleted, or on request. |
| Trainee record — name, trainee ID, department, email. | Identify who a course result belongs to. | Controlled by the customer. |
| Monitoring events — timestamped observations such as "face not visible", "camera off", "identity not confirmed". | Attendance evidence and host alerting. | Configurable; 90 days by default. |
| Analysis samples — per-sample results of face analysis. | Produce the attendance report. | Configurable; 14 days by default. |
| Evidence snapshots — a still image captured when a rule triggers. | Let a human check an automated detection before acting on it. | Disabled by default. 7 days when enabled. |
| Zoom meeting and participant data — meeting ID, topic, schedule, display name, email, join/leave times. | Link a Zoom meeting to a training session and match attendees to trainees. | Controlled by the customer. |
| Zoom OAuth tokens. | Call the Zoom API on the customer's behalf. | Deleted immediately on disconnect or uninstall. |
| Administrator accounts — name, email, password hash. | Authenticate staff using the console. | Until the account is removed. |
| Audit log — who did what, and when. | Accountability. Deliberately excludes face templates, image keys and tokens. | Controlled by the customer. |
Meeting video and audio are never recorded or stored. Frames are analysed in memory and discarded. Ayonix Zoomer does not access Zoom chat, files or cloud recordings.
3. Legal basis and consent
Face data is biometric personal information. Under Japan's Act on the Protection of Personal Information it is 個人識別符号 (a personal identification code); under the GDPR it is a special category of data under Article 9.
- Enrolment requires the trainee's explicit, recorded consent, captured in the product with the version of the consent text the person actually saw.
- Consent is revocable. Withdrawing it stops further processing and triggers deletion of the template.
- Customers are responsible for notifying participants that identity verification is in use before a session begins.
4. How the data is protected
- Face templates, OAuth tokens and evidence images are encrypted at rest with AES-256-GCM.
- Templates are never sent to a browser. Comparison happens server-side, so a tampered client cannot assert a match.
- Evidence images are reachable only through HMAC-signed links that expire after 60 seconds, and every access is written to the audit log.
- All traffic uses TLS 1.2 or higher; TLS 1.0 and 1.1 are refused.
- Each customer is a separate tenant. Every record carries an organisation identifier and every query is filtered by it.
- Access is role-based. Viewing an evidence image and exporting evidence in bulk are deliberately separate permissions.
Further detail, including known limitations, is in our Security Policy.
5. Automated decisions
Ayonix Zoomer does not make automated decisions with legal or similarly significant effect. Detections are signals for a human to review. The product will not mark a trainee as having failed a course on its own, and it reports only observable facts — whether a face is visible, whether the camera is on, whether an identity was confirmed. It does not infer attention, comprehension, emotion or any other mental state.
6. Sharing and sub-processors
We do not sell personal data and do not use it for advertising or for training machine-learning models.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database (D1), object storage (R2), CDN and WAF. | Asia-Pacific region |
| Zoom Communications, Inc. | Only where the customer has connected Zoom: meeting and participant metadata is read from Zoom. No personal data from Ayonix Zoomer is written back to Zoom. | Per the customer's Zoom agreement |
We disclose data to a public authority only where legally compelled, and will notify the customer unless prohibited from doing so.
7. Where data is stored
Data is stored in Cloudflare's Asia-Pacific region (D1 and R2). Customers with a strict domestic-residency requirement should confirm this with us before deployment.
8. Your rights
Depending on where you live you may have rights of access, correction, deletion, restriction, objection and portability. Because Ayonix acts as a processor, please direct requests to the organisation running your training. If that is not possible, email privacy@ayonix.com and we will help.
We respond to rights requests within 30 days. Verifying who is making the request may take longer where the request concerns biometric data.
9. Deletion
- Withdrawing consent deletes the face template.
- Deleting a trainee deletes their template, events and evidence.
- Disconnecting Zoom deletes the stored Zoom tokens immediately.
- Data past its retention window is deleted automatically by a scheduled job, and the deletion is itself recorded in the audit log.
- To delete an entire account, email support@ayonix.com from the administrator's address. We confirm deletion in writing.
10. Cookies
Ayonix Zoomer sets one strictly necessary cookie, zoomer_session, which keeps an
administrator signed in. It is HttpOnly, Secure and SameSite=Lax,
and expires after 12 hours. We use no advertising or cross-site tracking cookies.
11. Changes and contact
Material changes will be notified to customer administrators before they take effect. The version and effective date at the top of this page always reflect the current text.
- Privacy: privacy@ayonix.com
- Support: support@ayonix.com
- Security reports: security@ayonix.com
日本語要約
Ayonix Zoomer は、Zoomで実施する研修の受講者本人確認を行うため、顔特徴量(個人識別符号) を取り扱います。会議の録画は行わず、映像・音声は保存しません。解析後のフレームは破棄されます。
- 顔の原画像は保存せず、暗号化した特徴量のみを保存します(AES-256-GCM)。
- 特徴量をブラウザへ送信することはありません。照合はサーバー側で実行します。
- 証跡画像の保存は既定で無効です。有効化した場合も、60秒で失効する署名URL経由でのみ閲覧でき、閲覧はすべて監査ログに記録されます。
- 顔情報の登録には本人の明示的な同意が必要で、同意はいつでも撤回できます。撤回により特徴量は削除されます。
- 自動判定のみで受講可否を決定することはありません。理解度・集中度・感情などの心理状態は判定しません。
- 通信はすべて TLS 1.2 以上です。データはCloudflareのAPACリージョンに保存されます。
受講者ご本人からの削除・開示のご請求は、まず研修を実施する組織へご連絡ください。 難しい場合は privacy@ayonix.com までご連絡ください。