Data Protection

How we protect and secure your information

How to read this page

Everything below is either something we have tested or something we say plainly that we do not have. There is no third category. If a security property matters to your school, the honest answer is on this page — and where the answer is no, it says no.

What is true today

  • In transit: traffic between a device and the servers we run is encrypted with TLS.
  • Separation between schools: tested exhaustively rather than asserted. Every cross-school read we could construct was refused, at both the database and the application boundary, for every role we could sign in as.
  • Role-based access: what someone sees follows the role their school gave them, and a parent resolves only to their own children.
  • Audit trail: privileged actions are recorded with the actor, the school and the time.
  • Confidential records stay confidential: safeguarding cases are restricted at the database to the people attached to them, not merely hidden in the interface.
  • No sale or secondary use of school, student or parent data. No advertisers.

What we do not claim

  • No encryption of database files at rest. Not implemented.
  • No multi-factor authentication. Not implemented.
  • No automatic logout after inactivity — a session lasts until it is signed out or expires.
  • No certification of any kind — not ISO 27001, not SOC 2, and no assessed compliance with GDPR, FERPA or COPPA.
  • No independent penetration testing. The security work done so far is our own adversarial testing, and it is documented rather than certified.
  • No geographically distributed backups. Backups exist; a multi-region arrangement does not.

If any of these is a requirement for your school or ministry, say so before you commit to anything and we will tell you plainly whether it exists, what it would take, or that the answer is no.

Where your data is

If we host Zafarios for you, your data sits on infrastructure we operate and we will tell you exactly where, in writing, on request. If you run Zafarios yourself — which the licence permits and the software supports — the data never reaches us at all, you are the controller of it, and everything on this page about our hosting is irrelevant to you.

Your Rights

Under applicable data protection laws, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your data (subject to legal retention requirements)
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to certain types of data processing
  • Restriction: Request restriction of processing in certain circumstances

Data retention

There is no published retention schedule yet, and the earlier version of this page invented one. Records stay until the school deletes them or asks us to. Academic and financial records are usually subject to retention periods set by your own regulator rather than by us. When a schedule is agreed with the first hosted schools it will be published here, with the date it took effect.

Data Protection Officer

For data protection inquiries, please contact:

Data Protection Team
Email: dpo@lilit.us