A
AYONIX
ZOOMER

Privacy Policy

Version 1.0 · Effective 25 September 2026 · Ayonix Corporation

1. Summary

Ayonix Zoomer verifies the identity of people attending training delivered over Zoom, so that an organisation can evidence who actually attended. Doing that requires processing biometric data — a mathematical representation of a face. We treat that as the most sensitive category of data we hold, and this policy says plainly what we do with it.

We do not record meetings. We do not store meeting video or audio. Video frames are analysed and discarded.

Roles

The organisation that runs the training (our customer) is the data controller. Ayonix is the data processor, acting on that customer's instructions. If you are a trainee and want your data removed, contact the organisation running your course; if you cannot reach them, contact us and we will route your request.

2. What we process, and why

DataPurposeRetention
Face template — a numeric vector derived from an enrolment photograph. Not an image, and the original photograph is not kept.Verify that the person attending is the person enrolled.Until the trainee record is deleted, or on request.
Trainee record — name, trainee ID, department, email.Identify who a course result belongs to.Controlled by the customer.
Monitoring events — timestamped observations such as "face not visible", "camera off", "identity not confirmed".Attendance evidence and host alerting.Configurable; 90 days by default.
Analysis samples — per-sample results of face analysis.Produce the attendance report.Configurable; 14 days by default.
Evidence snapshots — a still image captured when a rule triggers.Let a human check an automated detection before acting on it.Disabled by default. 7 days when enabled.
Zoom meeting and participant data — meeting ID, topic, schedule, display name, email, join/leave times.Link a Zoom meeting to a training session and match attendees to trainees.Controlled by the customer.
Zoom OAuth tokens.Call the Zoom API on the customer's behalf.Deleted immediately on disconnect or uninstall.
Administrator accounts — name, email, password hash.Authenticate staff using the console.Until the account is removed.
Audit log — who did what, and when.Accountability. Deliberately excludes face templates, image keys and tokens.Controlled by the customer.

Meeting video and audio are never recorded or stored. Frames are analysed in memory and discarded. Ayonix Zoomer does not access Zoom chat, files or cloud recordings.

3. Legal basis and consent

Face data is biometric personal information. Under Japan's Act on the Protection of Personal Information it is 個人識別符号 (a personal identification code); under the GDPR it is a special category of data under Article 9.

4. How the data is protected

Further detail, including known limitations, is in our Security Policy.

5. Automated decisions

Ayonix Zoomer does not make automated decisions with legal or similarly significant effect. Detections are signals for a human to review. The product will not mark a trainee as having failed a course on its own, and it reports only observable facts — whether a face is visible, whether the camera is on, whether an identity was confirmed. It does not infer attention, comprehension, emotion or any other mental state.

6. Sharing and sub-processors

We do not sell personal data and do not use it for advertising or for training machine-learning models.

Sub-processorPurposeLocation
Cloudflare, Inc.Application hosting, database (D1), object storage (R2), CDN and WAF.Asia-Pacific region
Zoom Communications, Inc.Only where the customer has connected Zoom: meeting and participant metadata is read from Zoom. No personal data from Ayonix Zoomer is written back to Zoom.Per the customer's Zoom agreement

We disclose data to a public authority only where legally compelled, and will notify the customer unless prohibited from doing so.

7. Where data is stored

Data is stored in Cloudflare's Asia-Pacific region (D1 and R2). Customers with a strict domestic-residency requirement should confirm this with us before deployment.

8. Your rights

Depending on where you live you may have rights of access, correction, deletion, restriction, objection and portability. Because Ayonix acts as a processor, please direct requests to the organisation running your training. If that is not possible, email privacy@ayonix.com and we will help.

We respond to rights requests within 30 days. Verifying who is making the request may take longer where the request concerns biometric data.

9. Deletion

10. Cookies

Ayonix Zoomer sets one strictly necessary cookie, zoomer_session, which keeps an administrator signed in. It is HttpOnly, Secure and SameSite=Lax, and expires after 12 hours. We use no advertising or cross-site tracking cookies.

11. Changes and contact

Material changes will be notified to customer administrators before they take effect. The version and effective date at the top of this page always reflect the current text.

日本語要約

Ayonix Zoomer は、Zoomで実施する研修の受講者本人確認を行うため、顔特徴量(個人識別符号) を取り扱います。会議の録画は行わず、映像・音声は保存しません。解析後のフレームは破棄されます。

受講者ご本人からの削除・開示のご請求は、まず研修を実施する組織へご連絡ください。 難しい場合は privacy@ayonix.com までご連絡ください。