Privacy Policy
Onflo is committed to protecting the personal information of our clients, users, and visitors. This privacy policy explains how your personal information is collected, used, and disclosed by Onflo in connection with our website and online services.
Onflo, LLC (“Onflo” “us” or “we”) is committed to protecting the personal information of our Clients, users, and visitors. This Privacy Policy explains how your personal information is collected, used, and disclosed by Onflo in connection with our website and online services available at www.onflo.com, or any other website or mobile application linked to this Privacy Policy (collectively, the “Sites”). This Privacy Policy also describes how we collect Data through the online software platform and technology services solutions used by our Clients to engage with their customers, end users, students, parents, school community members, and other individuals (the “Client Solutions”). The Site and Client Solutions together are collectively referred to as our “Service.” “You” or “your” means a visitor or a user (whether signed in or not) of our Service.
This Privacy Policy describes Onflo’s use of information collected through the Service. This Privacy Policy does not govern the data practices of any third parties, such as our Clients who may use your personal information collected through the Service for their own purposes in accordance with their own privacy policy.
By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use and disclosure of personal information as described in this Privacy Policy.
1. OUR SOLUTION, SOFTWARE AND SERVICES
Onflo software solutions are provided in an Application Service Provider (“ASP”) model and accessed using industry-standard web browsers via the web, or a mobile device, or using a mobile app on a mobile device. Many of our Clients use our software solutions on a Self-Service basis, whereby the Client or its authorized staff are solely responsible for the data they input to our system and the data our systems collect from their stakeholders. Such use of our solution is referred to in this document as “Self-Service”. In some instances, we may manage a project on behalf of our Clients, which we refer to as our “Consulting Service”. In either scenario, we process Client Data (defined below) on our Client’s behalf.
2. HOW WE COLLECT INFORMATION AND DATA
We collect personal information in a variety of ways through our Sites and Solutions.
When registering for our Services or submitting a request on our Sites, we generally request the following information: including, but not limited to, name and contact information, company name, name of business representative, title of business representatives, company address, telephone number, email address, username and password, and billing information which may include credit card numbers. Clients also provide us with information regarding the services they have ordered. We may also collect information if you complete a survey or provide content or commentary through the provision of feedback, reviews, or customer service requests, or otherwise communicate with us.
In providing the Client Solutions, we collect information and content input to the Solution by Clients or their users as well as information generated by Onflo relating to the Client’s use of the Solution (all of which we call “Data”). Depending on how the Client chooses to use (or, in case of Consulting Services, direct Onflo staff to use) the Client Solutions, Data may include personal information relating to our Client’s employees, visitors, users and others. For example, when used by a School Client, Data could include first and last name, student ID number, grade level, ethnicity, address, phone number, and email, or any combination of the same, and Let’s Talk! dialogue information, which contains questions, comments, concerns, suggestions, compliments, and similar communications by any stakeholder in a school system.
We automatically collect certain types of device and usage information when you visit or use our Sites or Solutions deployed on Client websites through tracking technologies such as cookies, web beacons, pixels, and similar technologies. We collect information about your device and its software (such as your IP address, device type/model/manufacturer, and unique identifier), information about the way you access and use the Service (such as visited pages, surveys, landing pages of our Clients and interest areas, referring URLs), information about your location (depending on your device settings, this could include GPS or other location data, or we may infer your location through other data such as an IP address), and analytics information. We may use third party partners to collect this information. For example, we use Google Analytics to help us measure traffic and usage trends for the Service and to understand more about the demographics of our users. You can learn more about Google’s practices at http://www.google.com/policies/privacy/partners and view its opt-out options at https://tools.google.com/dlpage/gaoptout. Unfortunately, we are unable to respond to Do Not Track signals set by your browser at this time. We and our third-party partners may also use cookies and tracking technologies for advertising purposes. For more information about tracking technologies, please see Section 7 “third-party tracking and online advertising” below.
3. HOW WE USE INFORMATION
We use the information we collect, including personal information, to operate, maintain, and provide the features and functionality of the Service, to process billing and payments, to improve, market and promote our solutions and services, to inform our marketing and advertising activities; to detect and protect against fraud or misuse, and for other similar purposes. We also use information to communicate directly with you, such as to send you email messages and push notifications and permit you to communicate with others. We may send you Service-related emails or messages (e.g., account verification, change or updates to features of the Service, technical and security notices).
We use information collected through tracking technologies to remember information so that a user will not have to re-enter it during subsequent visits; provide custom, personalized content and information; to provide and monitor the effectiveness of our Service; monitor aggregate metrics such as total number of visitors, traffic, and usage on our website and our Service; diagnose or fix technology problems; help users efficiently access information after signing in, and otherwise to plan for and enhance our Service.
4. HOW WE USE CLIENT DATA
Onflo collects and processes Data solely on behalf of our Clients, and in accordance with our agreements with our Clients, in order to provide our Solutions and Service. All Data is owned and controlled by the Client and we regard Data as highly confidential. We do not use or disclose Data except as authorized and required by our Clients and as provided for in our agreements with our Clients.
We maintain a database of our Clients’ information that is used only for internal business functions, such as technical support, marketing activities, billing, and to notify Clients of changes or enhancements to the services. We may use Data to improve the performance of our website and services by analyzing user behavior, including frequency of use, troubleshooting technical problems, resolving disputes and to address complaints, and to verify compliance with our Terms of Service. We may also anonymize and aggregate the Data and use such anonymized and aggregated data for our own business purposes and benchmarks.
Onflo, its staff, and authorized consultants, all of whom follow this Privacy Policy and are bound to protect Client Data in the manner indicated here, may access Data solely to provide customer support or Services requested by Client. Other than to provide technical support upon request or to process Data as part of a Consulting Service, Onflo employees and consultants do not actively access and view Data.
5. INFORMATION SHARING AND DISCLOSURE
We may share information that we collect with:
• Agents, vendors, or contractors that Onflo uses to support the operations of our business and that perform services on our behalf, which may include serving targeted advertisements, sending emails, processing payments, providing web hosting and analytic services, subject to reasonable confidentiality terms.
• Third parties as required by law or subpoena or if we reasonably believe that such action is necessary to (a) comply with the law and the reasonable requests of law enforcement; (b) to enforce our Terms of Use or other agreements or to protect the security or integrity of the Onflo Service, including to prevent harm or financial loss, or in connection with preventing fraud or illegal activity; and/or (c) to exercise or protect the rights, property, or personal safety of Onflo, our Clients, users or others.
• With other companies and brands owned or controlled by Onflo, or under common ownership and control as Onflo. These companies will use your personal information in the same way as we can under this Privacy Policy.
• Other parties in connection with a company transaction, such as a merger, sale of company assets or shares, reorganization, financing, change of control or acquisition of all or a portion of our business by another company or third party, or in the event of a bankruptcy or related or similar proceedings. If we sell, divest or transfer our business, we will require the new owner to continue to honor the terms provided in this Privacy Policy or we will provide the Client with notice and an opportunity to opt-out of the transfer of Data before the transfer occurs.
In addition, Data collected from or on behalf of a Client is shared with that Client and its authorized users. Depending on the Client’s use and settings, some Data input to the Solutions may be publicly available to other Client users or to the public. We also share Data with third parties as instructed by, or at the direction of, the Client or its users. Our Client’s use of such Data collected through the Service is governed by the Client’s own privacy policies.
We may also share information or Data with others in an aggregated or otherwise anonymized form that does not reasonably identify you directly as an individual. For example, we may use and share aggregate or anonymized data to study and improve our Service, user functionality and product offerings.
We may share information or Data to the extent necessary to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Terms of Service, or as otherwise required by law. However, electronic communications made through the Let’s Talk! ™ Service may be deemed an “electronic communication” by Onflo. As such, Onflo reserves the right to protect Information that it believes is protected from compelled disclosure pursuant to the Electronic Communications Privacy Act, 18 U.S.C. § 2510, et seq., (“ECPA”) and the Stored Communications Act, 18 U.S.C. § 2701, et seq., (“SCA”), in addition to protections afforded by state law. The protections provided under the SCA and ECPA enable Onflo to prevent governmental authorities from seeking compelled disclosure of certain electronic communications
6. YOUR DATA RIGHTS AND CHOICES
Modifying your information. Clients’ information may be viewed and modified in our active database in real-time, at any time. The changed information may remain in archives and records for some period of time. Once survey responses have been submitted, the survey participant will not be able to access his or her participant information. If you use the Service offered by a Onflo Client, please contact the Client to request modification to your information.
Remaining anonymous. Onflo has built software features that may allow for anonymity, though these features may depend on the Client’s configuration of the Service. For example, the Client may elect to either hide or make available to survey participants certain client contact information in connection with a survey. Similarly, users may be able to send communications through the Service without sharing personal information with the recipient. Please note, the identity of a user may be revealed upon reasonable belief that identification is reasonably necessary to protect the life, health or safety of Onflo, our users, or any other individual, or as may be required by law or in response to a legal request.
Control email communications. You can opt-out of receiving promotional emails from Onflo by clicking the “unsubscribe” feature at the bottom of each email. Unfortunately, you cannot unsubscribe from Service-related messaging.
Communications sent by Clients. Clients may send email or SMS/text messages to recipients through the Client Solutions and Onflo does not control those communications. Our Clients are solely responsible for all communications sent through the Service and for compliance with all applicable laws relating to such communications. To opt-out of receiving communications from a Client through the Solutions, please contact the Client directly.
7. THIRD-PARTY TRACKING AND ONLINE ADVERTISING
Onflo does not display any targeted ads on the Client Solutions.
Please note that although we may permit third party advertising partners to collect information from visitors to our website for the purpose of displaying advertisements on other websites or online services on our behalf, we take many steps to prevent such collection from users of our Client Solutions. We may display non-targeted advertisements to users on our website, while using our Services or on other sites or services.
When you visit our website, we work with third-party online advertising networks which use technology to recognize your browser or device and to collect information about your visit to our Service to provide customized content, advertising and commercial messages to you on other websites or services, or on other devices you may use. We (through the third-party advertising networks) use this information to direct our online advertisements to those people who may find them relevant to their interests. Typically, though not always, the information is collected through cookies or similar tracking technologies. You may be able to set your browser to reject cookies or other tracking technology by actively managing the settings on your browser or mobile device. To learn more about cookies, clear gifs/web beacons and online advertising technologies and how you may opt-out of some of this advertising, you may wish to visit the Digital Advertising Alliance’s resources at www.aboutads.info/choices and/or the Network Advertising Initiative’s online resources, at www.networkadvertising.org.
8. INFORMATION RETENTION AND DELETION
We will retain personal information for as long as needed to provide the Service and for our internal business purposes, which may extend beyond the termination of your subscription or user account. For example, we may retain certain data as necessary to prevent fraud or future abuse, for recordkeeping or other legitimate business purposes, or if required by law. We may also retain and use information which has been de-identified or aggregated such that it can no longer reasonably identify a particular individual. All retained personal information will remain subject to the terms of this Privacy Policy. To request deletion of your information, please email us at privacy@onflo.com.
Data. Unless otherwise specified in writing, Onflo shall delete or de-identify Data within ninety (90) days after termination of this Agreement, in accordance with Onflo’s standard data deletion and destruction practices, unless the Client provides Onflo with a written request to delete such data prior to the ninety (90) days or to follow a different deletion practice. The Client may also delete, download, or retrieve the Data at any time during the Term and for up to thirty (30) days thereafter. The Client is responsible for requesting deletion of any Data which is no longer needed for the Client’s purpose.
If you use the Service offered by a Onflo Client, you may request deletion of your information by contacting the Client directly. We will cooperate with the Client to respond to this request.
We may not be able to immediately or completely delete all data in all instances, such as information retained in technical support records, customer service records, backups, and other similar business records. Similarly, we may not be able to permit information that was previously shared with others through the Services, such as the content of messages and other communications. We will not be required to delete any information which has been de-identified or disassociated with personal identifiers such that the remaining information cannot reasonably be used to identify a particular individual.
9. HOW WE STORE AND PROTECT INFORMATION
Storage and processing: Your information collected through our Service may be stored and processed in the United States or any other country in which Onflo or our affiliates or service providers maintain facilities. If you are located in the European Union or other regions with laws governing data collection and use that may differ from U.S. law, please note that we may transfer information, including personal information, to a country and jurisdiction that does not have the same data protection laws as your jurisdiction.
Keeping information safe: We care about the security of your information and employ physical, administrative, and technological safeguards designed to preserve the integrity and security of all information collected and maintained by our Service. Unique usernames and passwords must be entered each time a person logs on. Our websites are hosted in a secure server environment that uses a firewall and other technology to prevent access from outside intruders, in line with prevailing industry standards. Internally, we use security-logs, train our employees, and limit access to Onflo personnel who need to know in order to perform their job functions. Other security safeguards include, but are not limited to, data encryption and physical and technological access controls. All of our technology and processes are not, however, guarantees of absolute security. In the event that any information under our control is compromised as a result of a breach of security, we will take reasonable steps to investigate the situation and, where appropriate, notify our Client or individual users whose information may have been compromised and take other steps, in accordance with any applicable laws and regulations and our agreements with our Clients. Clients must actively protect their information by maintaining the confidentiality of all usernames and passwords and by adequately installing the appropriate anti-virus programs and security measures on their own systems. You must immediately notify Onflo if any information security breach is suspected.
10. HOW WE PROTECT STUDENT DATA AND COMPLY WITH LAWS
When the Service is used by Clients that are providers of educational services, such as schools, school districts, or teachers (collectively referred to as “School Clients”), we may collect or have access to Data that includes personal information of students, which may be provided by the School Client or by a student, parent, guardian or other user (“Student Data”). While we consider all Client Data to be confidential and in general do not use such data for any purpose other than improving and providing our Services to our Clients, we exercise special caution to protect Student Data.
Student Data privacy principles. We are committed to the following principles to protect Student Data:
• We collect, maintain, use, and share Student Data only to provide and support the Service as described in our Privacy Policy, to maintain, develop, support or improve our websites, services and applications, and as otherwise permitted by our agreements or with the consent of the parent, guardian, student or School Client.
• We do not use or disclose Student Data for targeted advertising purposes. While we do permit third-party advertising partners to operate on our website for the purpose of retargeting, analytics, and attribution services, we do not engage third party advertising partners to collect information through our Solution Services.
• We do not build a personal profile of a student other than in furtherance of the School Client’s use of the Service, or as authorized by a student or parent.
• We maintain a comprehensive data security program designed to protect the types of Student Data maintained by the Service.
• We will clearly and transparently disclose our data policies and practices to our users.
• We will never sell Student Data unless the sale is part of a corporate transaction, such as a merger, acquisition, bankruptcy, or other sale of assets, in which case we will require the new owner to continue to honor the terms provided in this Privacy Policy or we will provide the School Client with notice and an opportunity to opt-out of the transfer of Student Data by deleting the Student Data before the transfer occurs.
• We will not make any material changes to our Privacy Policy or contractual agreements that relate to the collection or use of Student Data without first giving notice to the School Client and providing a choice before the Student Data are used in a materially different manner than was disclosed when the information was collected.
How we use and disclose Student Data. We use and disclose Student Data as described in our Privacy Policy under Section 4 “How We Use Client Data” and Section 5 “Information Sharing and Disclosure.”
How we retain and delete Student Data. We do not knowingly retain Student Data beyond the time period required to support the School Client’s purpose, unless authorized by a School Client, student, or parent. Unless otherwise directed by a School Client, we will delete or de-identify Student Data after the termination of our agreement with the School Client, in accordance with the terms of any applicable written agreement with the School Client, written requests from authorized School Client administrators, and our standard data retention schedule.
School Clients can request account or data deletion at any time by contacting us at privacy@k12insight.com. We may not be able to immediately or completely delete all data in all instances, such as information retained in technical support records, customer service records, backups, and other similar business records. Similarly, we may not be able to delete information that was previously shared with others through the Services, such as the content of messages and other communications. We will not be required to delete any information which has been de-identified or disassociated with personal identifiers such that the remaining information cannot reasonably be used to identify a particular individual.
Compliance with laws. We do not use Student Data for any purpose other than to provide the Services, in accordance with contractual agreements with our School Clients. Onflo does not own or control Student Data, which belongs to the individual student and/or the School Client. As specified in our agreements with School Clients, the Onflo Service is designed to provide protections for Student Data as required by various applicable privacy laws. For example:
• The Family Educational Rights and Privacy Act (“FERPA”). This Privacy Policy and our Service are designed to meet our responsibilities to protect personal information from the students’ educational records under FERPA. We agree to work with our School Clients to jointly ensure compliance with the FERPA regulations.
• Children’s Online Privacy Protection Act (“COPPA”). Onflo is not directed to children under 13 and does not knowingly collect any information from children under the age of 13. To the extent a School Client uses the Service to collect personal information from children under the age of 13 or sends communications through the Service to children under the age of 13, the School Client provides the requisite consent for Onflo to collect and use such personal information from students under 13 for the purpose of providing the Service and as otherwise described in this Agreement, as permitted by COPPA.
• Students Online Personal Information Protection Act (“SOPIPA”). This Privacy Policy and ourService are designed to comply with SOPIPA. We do not use Student Data for targeted advertising purposes. We do not use collected information to amass a profile of a K-12 student except in furtherance of providing the features and functionality of the Service. We never sell Student Data unless the sale is part of a corporate transaction, such as a merger, acquisition, bankruptcy, or other sale of assets, in which case we make efforts to ensure the successor entity honors the privacy commitments made in this policy and/or we will notify the School Client and provide an opportunity to opt-out by deleting student accounts before the data transfer occurs.
• California Assembly Bill 1584 (“AB 1584”). This Privacy Policy and our Service are designed to comply with AB 1584. Pupil records obtained by Onflo from a local educational agency (“LEA”) continue to be the property of and under the control of the LEA. Parents, legal guardians, or eligible pupils may review personally identifiable information in the pupil’s recordsand correct erroneous information by contacting their LEA directly. In the event of an unauthorized disclosure of a pupil’s records, Onflo will notify the LEA and will provide the LEA with information to be shared with the affected parent(s), legal guardians(s) or eligible pupil(s). Pupil records will be deleted and/or de-identified in accordance with our agreements with each School Client and as described in this Privacy Policy.
If you have any questions about our practices with regard to Student Data, please contact us at privacy@onflo.com.
11. CHANGES TO OUR PRIVACY POLICY.
As we are constantly improving the Services and expanding our business, Onflo reserves the right to modify this Privacy Policy from time to time to reflect such improvements. In the event we make such changes, we will announce the changes and post the new policy at https://www.onflo.com/privacy-policy/. We will also use our best efforts to provide advance notice of any material changes to this Privacy Policy, to permit you a reasonable chance to review before such changes go into effect. If you object to any changes, you may close your account and/or discontinue your use of the Service. Continuing to use our Service after we publish changes to this Privacy Policy means that you are consenting to the changes.
Onflo shall not make any material change to the Privacy Policy or our practices that involve the collection or use of Student Data without first giving thirty (30) days’ notice to School Client and providing a choice before the Student Data is used in a materially different manner than was disclosed when the information was collected.
Last Updated: December 15, 2019
Effective Date: January 1, 2020
K12 Insight, LLC d/b/a Onflo (“Onflo”, “our”, “us”, or “we”) is committed to protecting the personal information of our Clients, Users, and Visitors. This Privacy Policy explains how your personal information is collected, used, and disclosed by Onflo in connection with our website and online services available at www.onflo.com, or any other website or mobile application linked to this Privacy Policy (collectively, the “Sites”). This Privacy Policy also describes how we collect personal information through the online software platform and technology services solutions used by our Clients to engage with their customers, end users, students, parents, school community members, and other individuals (the “Onflo Client Solutions”). The Site and Onflo Client Solutions together are collectively referred to as our “Service.”
In this Privacy Policy:
- “Client” means a company, organization, school district, or other legal entity that subscribes to or licenses Onflo’s services.
- “User” means an individual who uses the services subscribed to by Client, including Authorized Users as defined in the Cloud Services MSA. Where the context requires, “User” or “Users” may also include Clients as defined in the Cloud Services MSA.
- “Visitor” means all visitors to our Sites, whether they are Client, Users, or any other visitor to the Site.
- Clients, Users, and Visitors are referred to as “you” or “your”, as may be applicable depending upon the context in which it is used.
Onflo provides its software and consulting services to Clients on a subscription and licensing basis. A Client subscribes to or licenses our Services. Upon subscribing, the Client administers those Services using its own employees and also provides access to its own customers and community members, who thereby become Users of our Services. In the context of school districts (our “School Clients”), those Users may include parents, district citizens, teachers, students, and staff.
This means that when you interact with our Service, you are most likely doing so through a Client that has subscribed to Onflo. Your personal information may be collected both by Onflo (as the service provider) and by the Client (as the party that directs the use of the Service). Onflo processes Data on behalf of and at the direction of the Client; the Client retains ownership and control of the Data it inputs or generates through the Service. Any use of your personal information by the Client itself is governed by the Client’s own privacy policy, not this one.
This Privacy Policy is subject to Onflo’s Cloud Services Master Subscription Agreement, available at https://www.onflo.com/cloud-services-msa/ (“Cloud Services MSA”), as updated from time to time. If any capitalized word or phrase has been defined within the Cloud Services MSA but has not been defined within this Privacy Policy, that word or phrase shall have the same meaning that has been assigned to it under the Cloud Services MSA.
By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use and disclosure of personal information as described in this Privacy Policy.
Onflo’s websites and online services are not directed to children under 13. Onflo does not knowingly collect personal information directly from children under 13. For information about our practices regarding children under 13, see Section 10.3.2 of this Privacy Policy.
1. OUR SOLUTION, SOFTWARE AND SERVICES.
Onflo software solutions are provided in a Software-as-a-Service Provider (“SaaS”) model and accessed using industry-standard web browsers via the web, or a mobile device, or using a mobile app on a mobile device. Many of our Clients use our software solutions on a Self-Service basis, whereby the Client or its authorized staff are solely responsible for the data they input to our system and the data our systems collect from their stakeholders. Such use of our solution is referred to in this document as “Self-Service”. In some instances, we may manage a project on behalf of our Clients, which we refer to as our “Consulting Service”. In either scenario, we process Data (defined below) on our Client’s behalf.
2. INFORMATION AND DATA COLLECTION.
We collect personal information in a variety of ways through our Sites and Onflo Client Solutions. We limit our data collection to only the data that is necessary for the purpose for which it is being collected.
2.1. Information You Provide. When you register, submit a request, or otherwise interact with us, we may collect: name, contact information, company or entity name, representative details, username and password, billing information, and any feedback, ratings, reviews, or service requests you provide. Clients also provide information about the Services they have ordered.
2.2. Visitor Personal Information. When a Visitor visits the Site, Onflo collects personal information as per Section 2.7 of this Privacy Policy. We may also collect personal information that is provided by you at your discretion, such as when you contact us.
2.3. Collection of Onflo Client Solutions Data. In providing the Onflo Client Solutions, we collect information and content input to the Onflo Client Solutions by Clients or their users as well as information generated by Onflo relating to the Client’s use of the Onflo Client Solutions (all of which we call “Data”). Depending on how the Client chooses to use (or, in the case of Consulting Services, direct Onflo staff to use) the Onflo Client Solutions, Data may include personal information relating to our Client’s employees, visitors, users and others. For example, when used by a School Client (as defined below), Data could include first and last name, student ID number, grade level, ethnicity, address, phone number, and email, or any combination of the same, and Onflo dialogue information, which contains questions, comments, concerns, suggestions, compliments, and similar communications by any stakeholder in a school system. Additionally, at a Client’s direction, Onflo may collect Data through integrations with mutually agreed third-party systems, such as a Student Information System (SIS), learning management system, or similar platforms. The specific systems and data elements involved in any such integration are set forth in the applicable agreement between Onflo and the Client.
2.4. Manually Provided Device and Software Information. Clients of Onflo’s IT Asset Management and IT Service Management services may provide device and software related information to Onflo for the purpose of the services provided by Onflo to the Client. Such information may include, but is not limited to: (a) hardware identifiers, such as MAC addresses, serial numbers, or other identifying information about hardware; (b) information related to software licenses; (c) date of purchase or licensing; amounts paid and/or due; and/or (d) subscription related information such as subscription term, renewal date, and amounts payable.
2.5. Automatic Collection of Device and Usage Information. We automatically collect certain types of device and usage information when you visit or use our Sites or Solutions deployed on Client websites through tracking technologies such as cookies, web beacons, pixels, and similar technologies. We collect information about your device and its software (such as your IP address, device type/model/manufacturer, and unique identifier), information about the way you access and use the Service (such as visited pages, landing pages of our Clients and interest areas, referring URLs), information about your location (depending on your device settings, this could include GPS or other location data, or we may infer your location through other data such as an IP address), and analytics information. We may use third-party partners to collect this information. For example, we use Google Analytics to help us measure traffic and usage trends for the Service and to understand more about the demographics of our users. You can learn more about Google’s practices at https://www.google.com/policies/privacy/partners and view its opt-out options at https://tools.google.com/dlpage/gaoptout. We do not respond to Do Not Track signals, as there is no industry-standard definition for how DNT should be interpreted. However, where required by applicable U.S. state law, we recognize and honor Universal Opt-Out Mechanisms (UOOMs), including the Global Privacy Control (GPC) signal, as described in Section 6.11 of this Privacy Policy. We and our third-party partners may also use cookies and tracking technologies for advertising purposes. For more information about tracking technologies, please see Section 7 (Third-party Tracking and Online Advertising) below.
2.6. Voice Data Collection. When you or your users interact with our AI Agent Services, you are communicating with an automated system. Your spoken words will be recorded and processed. The AI Agent uses automated speech recognition and natural language processing to transcribe and respond to Communications. The AI Agent’s responses are generated algorithmically and may not always be accurate. We collect and process Voice Data, which includes: recordings of spoken Communications; transcriptions of spoken Communications; voice characteristics and patterns necessary to process Communications; and metadata associated with voice Communications (e.g., time, duration, device information). Voice Data is processed using automated speech recognition and natural language processing technologies for the purpose of providing the AI Agent Service, and, where permitted by applicable law, improving the AI Agent’s functionality. Voice Data may be shared with third-party artificial intelligence providers that support the AI Agent Service; however, we contractually require such providers to use Voice Data solely for the purpose of providing the Service, to refrain from using Voice Data to train, improve, or develop their own models or algorithms, and to maintain the confidentiality of Voice Data in accordance with applicable law. For contractual terms governing AI Agent Services and Voice Data, see our AI Addendum, Section 3. We retain Voice Data in accordance with our data retention practices and agreements with Clients, including the Student Data retention and deletion provisions described in Section 10 of this Privacy Policy.
2.7. Biometric Data. Where voice characteristics collected through the AI Agent constitute “biometric identifiers” or “biometric information” under applicable law, such data is subject to the protections described in Section 10.6 of this Privacy Policy.
3. HOW WE USE PERSONAL INFORMATION.
We use the information we collect, including personal information, to operate, maintain, and provide the Services or features and functionality of the Services, to process billing and payments, to contact you regarding technical support, improve our solutions and services, to market and promote our solutions and services, to inform our marketing and advertising activities, to detect and protect against fraud or misuse, to protect our legal rights, to improve the performance, features and security of the Site and Services, and for other similar purposes. We also use information to communicate directly with you, such as to send you email messages and push notifications and permit you to communicate with others. We may send you Service-related emails or messages (e.g., account verification, change or updates to features of the Service, technical and security notices).
We use information collected through tracking technologies to remember information so that a user will not have to re-enter it during subsequent visits; provide custom, personalized content and information; to provide and monitor the effectiveness of our Service; monitor aggregate metrics such as total number of visitors, traffic, and usage on our Site and our Service; diagnose or fix technology problems; help users efficiently access information after signing in, and otherwise to plan for and enhance our Service.
We do not make decisions that produce legal or similarly significant effects based solely on automated processing of your personal information. The AI Agent may use automated processing to route Communications and generate responses, but such processing does not produce decisions with legal or similarly significant effects.
4. HOW WE USE CLIENT DATA.
Onflo collects and processes Data solely on behalf of our Clients, and in accordance with our agreements with our Clients, in order to provide our Solutions and Service. All Data is owned and controlled by the Client and we regard Data as highly confidential. We do not use or disclose Data except as authorized and required by our Clients and as provided for in our agreements with our Clients. We may use de-identified or anonymized data derived from Data to operate, analyze, or improve the Service, provided such use complies with applicable law and does not involve re-identification. Onflo may use de-identified or anonymized Student Data for marketing the Service only to the extent that such data has been de-identified and/or anonymized in accordance with the standards set forth below and such uses are not prohibited by applicable state student data privacy laws. For the contractual authorization permitting this use, see our Cloud Services MSA, Section 7.4. De-identification and anonymization are performed in accordance with the standards set forth in FERPA’s de-identification guidance, which requires that reasonable determination be made that a student’s identity is not personally identifiable, either through the removal of all personally identifiable information or by applying statistical methods to ensure that there is a reasonable basis for concluding that the information is not personally identifiable.
We maintain a database of our Clients’ information that is used only for internal business functions, such as technical support, marketing activities, billing, and to notify Clients of changes or enhancements to the services. We may use Data to improve the performance, features, and security of our Sites and Services by analyzing user behavior, including frequency of use, troubleshooting technical problems, resolving disputes, addressing complaints, and verifying compliance with our Cloud Services MSA. We may also use and share de-identified or anonymized data derived from Data for purposes including: operating, analyzing, or improving the Service; marketing the Service; developing new products or services; conducting research; and other lawful business purposes.
Onflo, its staff, and authorized consultants, all of whom follow this Privacy Policy and are bound to protect Client Data in the manner indicated here, may access Data solely to provide customer support or Services requested by Client. Other than to provide technical support upon request or to process Data as part of a Consulting Service, Onflo employees and consultants do not actively access and view Data.
5. INFORMATION SHARING AND DISCLOSURE.
We do not sell personal information. We may share information that we collect with:
5.1. Agents, Vendors, or Contractors. We may share information with agents, vendors, or contractors that Onflo uses to support the operations of our business and that perform services on our behalf, which may include serving targeted advertisements, sending emails, processing payments, providing web hosting and analytic services, and providing artificial intelligence capabilities, subject to confidentiality terms consistent with this Privacy Policy and our applicable agreements. With respect to Student Data and Voice Data shared with third-party artificial intelligence providers, we contractually require such providers to: (i) use such data solely for the purpose of providing the Service; (ii) refrain from using such data to train, improve, or develop their own models or algorithms; and (iii) maintain the confidentiality of such data in accordance with applicable law. A current list of subprocessors with access to Student Data is available to School Clients upon request to privacy@onflo.com.
5.2. Legal Compliance. We may share personal information or Data as required by law, subpoena, or legal process, or when we reasonably believe disclosure is necessary to: (a) comply with applicable law or law enforcement requests; (b) to enforce our Cloud Services MSA or other agreements, or to protect the security or integrity of the Service, including to prevent harm or financial loss, or in connection with preventing fraud or illegal activity; and/or (c) to exercise or protect the rights, property, or safety of Onflo, our Clients, users, or others. Onflo reserves the right to resist compelled disclosure of electronic communications to the extent protected by applicable law, including the Electronic Communications Privacy Act (18 U.S.C. § 2510 et seq.) and the Stored Communications Act (18 U.S.C. § 2701 et seq.).
5.3. Affiliated Companies. We may share information with other companies and brands owned or controlled by Onflo, or under common ownership and control as Onflo, subject to the same restrictions on use and disclosure described in this Privacy Policy. Our affiliated companies use shared personal information only for the purposes described in this Privacy Policy and do not use it for cross-context behavioral advertising.
5.4. Business Changes. Other parties in connection with a company transaction, such as a merger, sale of company assets or shares, reorganization, financing, change of control or acquisition of all or a portion of our business by another company or third party, or in the event of a bankruptcy or related or similar proceedings. If we sell, divest or transfer our business, we will require the new owner to continue to honor the terms provided in this Privacy Policy or we will provide the Client with notice and an opportunity to opt-out of the transfer of Data before the transfer occurs. For Student Data—specific protections in the event of a corporate transaction, see our Cloud Services MSA, Section 7.5.
5.5. Client and Authorized Users. In addition, Data collected from or on behalf of a Client is shared with that Client and its authorized users. Depending on the Client’s use and settings, some Data input to the Solutions may be publicly available to other Client users or to the public. We also share Data with third parties as instructed by, or at the direction of, the Client or its users. Our Client’s use of such Data collected through the Service is governed by the Client’s own privacy policies.
5.6. Disclosing Aggregate or Anonymized Data. We may also share information or Data with others in an aggregated or otherwise anonymized form that does not reasonably identify you directly as an individual. For example, we may use and share aggregate or anonymized data to study and improve our Service, user functionality and product offerings.
6. YOUR DATA RIGHTS AND CHOICES.
6.1. Right to Access and Correction. Client and its Authorized Users may view and modify Clients’ information in our active database in real-time, at any time. If you are an individual User of a Client’s Service, please contact the Client to request modification of your information. The changed information may remain in archives and records for a reasonable period of time. If you use the Service offered by an Onflo Client, please contact the Client to request modification to your information. If you are a Visitor or a past Client, please contact us to request a copy of your personal information or to modify your personal information.
6.2. Right to Data Portability. Onflo provides Clients the ability to export information in multiple formats. Clients may exercise the right to data portability by exporting information in a standard machine-readable format.
6.3. Right to Erasure. Onflo deletes personal information as specified in Section 8 (Personal Information Retention and Deletion) of this Privacy Policy. Clients may delete personal information from their own accounts at any time during the term of their subscription and for up to thirty (30) days after termination, as further described in Section 8. Deleted information may continue to exist in our backups for disaster recovery purposes for a reasonable duration. To the extent not prohibited by applicable law, we may refuse to grant the request for erasure if we consider the retention of your information is necessary for us to protect our contractual or legal rights or to enforce your contractual or legal obligations, for law enforcement purposes, for compliance with a court order, or for detection or prevention of fraud or misuse of the Service.
6.4. Right to Opt-Out of Sale/Sharing. You may opt-out of sale of your personal information by contacting us as provided in this privacy policy. Where required by applicable law, such as if you are located in California, you may also opt-out of the sharing of your personal information for the purpose of cross-contextual behavioral advertising by contacting us or visiting the page linked above.
6.5. Right to Designate an Agent. Where required under applicable law, you may designate an agent to exercise your rights under this privacy policy on your behalf by contacting us as provided in this privacy policy.
6.6. Remaining Anonymous. Onflo has built software features that may allow for anonymity, though these features may depend on the Client’s configuration of the Service. For example, users may be able to send communications through the Service without sharing personal information with the recipient. Please note, the identity of a user may be revealed upon reasonable belief that identification is necessary to protect the life, health or safety of any individual, or as may be required by law or in response to a valid legal request.
6.7. Control Email Communications. You may opt-out of receiving promotional emails from Onflo by clicking the “unsubscribe” feature at the bottom of each email. You cannot unsubscribe from Service-related messaging.
6.8. Communications Sent by Clients. Clients may send email or SMS/text messages to recipients through the Onflo Client Solutions and Onflo does not control those communications. Our Clients are solely responsible for all communications sent through the Service and for compliance with all applicable laws relating to such communications. To opt-out of receiving communications from a Client through the Onflo Client Solutions, please contact the Client directly.
6.9. Onflo’s Responses. If you contact Onflo to exercise any of your rights under this privacy policy, Onflo will respond to you within the period of time specified under applicable law, but in no event later than forty-five (45) days of receipt of a verifiable request. Where a shorter timeframe is required by applicable state law, Onflo will comply with the shorter timeframe. For California residents, Onflo will confirm receipt of your verifiable request within ten (10) business days. Where permitted by applicable law and reasonably necessary, the response period may be extended by an additional forty-five (45) days (or such other period as required by applicable state law), provided that Onflo notifies you of the extension and the reason for the delay within the original response period.
6.10. Right to Appeal. If we fail to take any action on the request made by you, you have a right to file an appeal at privacy@onflo.com. Within 60 days of your appeal (unless a shorter duration is required under the applicable law), Onflo will review your appeal and provide a written decision with an explanation of any action taken or not taken. If you are dissatisfied with our response under appeal, you may have a right to contact your state’s Attorney General.
6.11. Universal Opt-Out Mechanisms. Where required under applicable U.S. state laws, Onflo recognizes and honors Universal Opt-Out Mechanisms (UOOMs), including browser settings and technologies such as the Global Privacy Control (GPC) signal. When we detect a valid opt-out preference signal from your browser or device, we will treat this as a request to opt out of the sale and sharing of your personal information, as well as the use of your information for cross-context targeted advertising. This means that we will not sell or share your personal data or use it for targeted advertising across different websites or services when you have enabled such a universal opt-out preference. Onflo will honor such opt-out signals automatically and without requiring additional verification steps, except where the applicable state law requires a different approach for any particular processing activity.
6.12. Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights.
7. THIRD-PARTY TRACKING AND ONLINE ADVERTISING.
Onflo does not display any targeted ads on Onflo Client Solutions or use Student Data for targeted advertising (See Section 10).
Please note that although we may permit third-party advertising partners to collect information from Visitors to our Site for the purpose of displaying advertisements on other websites or online services on our behalf, we take many steps to prevent such collection from Users of our Onflo Client Solutions. We may display non-targeted advertisements to Users on our Site, while using our Services or on other sites or services.
When you visit our Site, we work with third-party online advertising networks that use technology to recognize your browser or device and to collect information about your visit to our Service to provide customized content, advertising and commercial messages to you on other websites or services, or on other devices you may use. We (through the third-party advertising networks) use this information to direct our online advertisements to those people who may find them relevant to their interests. Typically, though not always, the information is collected through cookies or similar tracking technologies. You may be able to set your browser to reject cookies or other tracking technology by actively managing the settings on your browser or mobile device. To learn more about cookies, clear gifs/web beacons and online advertising technologies and how you may opt-out of some of this advertising, you may wish to visit the Digital Advertising Alliance’s resources at www.aboutads.info/choices and/or the Network Advertising Initiative’s online resources, at www.networkadvertising.org.
In addition to the above, the Site, Service, or Onflo Client Solutions, may include links to, or offer integrations with, third-party websites, applications, services, or software. Onflo is not responsible for the practices employed by third-party websites, applications, services, or software. We recommend that you review the security and privacy related practices and policies of third-party websites, applications, services, or software, before using any such third-party website, application, service or software, and/or before authorizing a third party to access any of your data through the Service such as by enabling a third-party integration.
8. PERSONAL INFORMATION RETENTION AND DELETION.
8.1. Data Retention. We will retain personal information only for as long as necessary to fulfill the purposes for which it was collected, to provide the Service, to comply with legal obligations, to resolve disputes, and to enforce our agreements. The following retention periods apply as a general guideline: (a) Client account information: retained for the duration of the subscription and three (3) years thereafter for account reactivations / resubscriptions; (b) Student Data: retained as directed by the School Client; deleted or de-identified within ninety (90) days of agreement termination (see Section 8.2 for full deletion terms); (c) Voice Data: retained in accordance with Section 10.6 of this Privacy Policy; (d) Site visitor data: retained for up to two (2) years from collection, unless a shorter period is required by applicable law; (e) billing and transaction records: retained for seven (7) years as required for tax and accounting compliance. We may retain and use personal information which has been de-identified or aggregated indefinitely. All retained personal information will remain subject to the terms of this Privacy Policy. General deletion limitations described in Section 8.3 also apply to Student Data.
8.2. Data Deletion. Unless otherwise specified in writing, Onflo will delete or de-identify Data within ninety (90) days after termination of this Agreement, in accordance with Onflo’s standard data deletion and destruction practices, unless the Client provides Onflo with a written request to delete such data prior to the ninety (90) days or to follow a different deletion practice. The Client may also delete, download, or retrieve the Data at any time during the term of an ongoing subscription and for up to thirty (30) days thereafter. The Client is responsible for requesting deletion of any Data that is no longer needed for the Client’s purpose. To request deletion of your information, please email us at privacy@onflo.com. If you use the Service offered by a Client, you may request deletion of your information by contacting the Client directly. We will cooperate with the Client to respond to this request.
8.3. Deletion Limitations. We may not be able to immediately or completely delete all data in all instances, such as information retained in technical support records, customer service records, backups, and other similar business records. Similarly, we may not be able to permit deletion of information that was previously shared with others through the Services, such as the content of messages and other communications. We will not be required to delete any information which has been de-identified or disassociated with personal identifiers such that the remaining information cannot reasonably be used to identify a particular individual.
9. HOW WE STORE AND PROTECT INFORMATION.
To prevent unwanted and unauthorized access to the personal information, Onflo uses the following methods, techniques, and technologies:
9.1. Storage and Processing. Your personal information collected through our Service may be stored and processed in the United States or any other country in which Onflo or our Affiliates or service providers maintain facilities. If you are located in other regions with laws governing data collection and use that may differ from U.S. law, please note that we may transfer information, including personal information, to a country and jurisdiction that does not have the same data protection laws as your jurisdiction.
9.2. Keeping Information Safe. We care about the security of your information and employ physical, administrative, and technological safeguards designed to preserve the integrity and security of all information collected and maintained by our Service, including: (a) encryption of Data in transit and at rest; (b) unique usernames and passwords for access; (c) role-based access controls limiting access to personnel who need to know; (d) security logging and monitoring; and (e) regular employee security training. Our Sites are hosted in a secure server environment that uses a firewall and other technology to prevent access from outside intruders, in line with prevailing industry standards. Internally, we use security logs, train our employees, and limit access to Onflo personnel who need to know in order to perform their job functions. All of our technology and processes are not, however, guarantees of absolute security. Clients are responsible for maintaining the security of their own systems and credentials. Clients must promptly notify Onflo of any suspected information security breach affecting Data processed through the Service by contacting privacy@onflo.com.
9.3. Data Breach Notification. In the event of a security breach (as described in the Cloud Services MSA as a “Security Incident”) involving unauthorized access, acquisition, disclosure, or use of personal information under our control, we will: (a) take reasonable steps to investigate the breach and contain its effects; (b) notify affected Clients within the time period required by applicable law; (c) cooperate with School Clients to support their notification of affected students, parents, and eligible students as required by applicable state law; (d) provide the information required by applicable state breach notification law in our notifications, which may include, depending on the jurisdiction: the categories of personal information affected, the date(s) of the breach, steps taken to contain the breach, and steps individuals may take to protect themselves; and (e) comply with any additional breach notification obligations set forth in our agreements with affected Clients. For contractual obligations regarding breach notification costs and indemnification for Student Data, see our Cloud Services MSA, Section 7.9. To report a suspected security incident or breach, please contact Onflo at privacy@onflo.com.
10. HOW WE PROTECT STUDENT DATA AND COMPLY WITH LAWS.
When the Service is used by Clients that are providers of educational services, such as schools, school districts, or teachers (collectively referred to as “School Clients”), we may collect or have access to Data that includes personal information of students, which may be provided by the School Client or by a student, parent, guardian or other user (“Student Data”). While we consider all Client Data to be confidential and in general do not use such data for any purpose other than improving and providing our Services to our Clients, we exercise special care to protect Student Data.
10.1. Student Data Privacy Principles. We are committed to the following principles to protect Student Data:
10.1.1. Purpose-limited collection, use, and sharing. We collect, maintain, use, and share Student Data only to provide and support the Service, to maintain, develop, support, or improve our Sites, services, and applications, and as otherwise permitted by our agreements or with the consent of the parent, guardian, student, or School Client.
10.1.2. No targeted advertising or profiling. We do not use Student Data for targeted advertising or to build a personal profile of a student, except as authorized by the School Client, student, or parent to support the School Client’s use of the Service. For our full contractual commitments regarding advertising restrictions, see our Cloud Services MSA, Section 7.6.
10.1.3. No sale of Student Data. We do not sell, share for consideration, or rent Student Data. In the event of a corporate transaction (merger, acquisition, bankruptcy, or sale of assets), we will either require the successor to honor these commitments or notify the School Client and provide an opportunity to delete Student Data before transfer. For our full contractual commitments regarding restrictions on the use and disclosure of Student Data, see our Cloud Services MSA, Section 7.5.
10.1.4. Data security. We maintain a comprehensive data security program designed to protect Student Data.
10.1.5. Transparency. We clearly and transparently disclose our data policies and practices.
10.1.6. Policy stability. We will not make material changes to our Privacy Policy or contractual agreements regarding Student Data without first providing notice and choice to the School Client before any materially different use occurs. For specific notice requirements, see our Cloud Services MSA, Section 7.10, and Section 11 of this Privacy Policy.
10.2. How We Use and Disclose Student Data. We use and disclose Student Data as described in Section 4 (How We Use Client Data) and Section 5 (Information Sharing and Disclosure).
10.3. Consent and Confidentiality for Special Categories.
10.3.1. Family Educational Rights and Privacy Act (FERPA, 34 C.F.R. Part 99). When Onflo processes Student Data that constitutes “education records” under FERPA, it does so as a “school official” under the direction and control of the School Client, as described in our agreements with School Clients. Onflo: (i) performs a service or function that the School Client would otherwise use its own employees to perform; (ii) is subject to the School Client’s direct control regarding the use and maintenance of Student Data; and (iii) uses Student Data only for the authorized purposes for which it was disclosed. Parents and eligible students who wish to inspect, review, seek amendment of, or request a hearing regarding Student Data that constitutes education records should contact the School Client directly, as the School Client is the educational agency or institution responsible for responding to such requests under FERPA. Onflo does not re-disclose personally identifiable information from education records except: (i) as directed by the School Client; (ii) to its service providers and sub-processors who perform functions on Onflo’s behalf in providing the Service, and who are subject to the same restrictions on use and re-disclosure as Onflo under this subsection; or (iii) as otherwise permitted by FERPA. For the contractual commitments regarding Onflo’s status as a school official, see our Cloud Services MSA, Section 7.2.
10.3.2. Children under 13 (COPPA, 16 C.F.R. Part 312). We do not knowingly collect personal information directly from children under 13. Where School Clients direct us to collect such information for educational purposes, we rely on the School Client, acting as the parent’s agent under COPPA, to obtain verifiable parental consent. This Privacy Policy serves as the notice to School Clients regarding the types of information collected from children under 13, how it is used, and whether it is disclosed to third parties, as required by 16 C.F.R. § 312.5(c). Parents and guardians seeking to review or delete information collected from their child should contact the School Client, which will coordinate with us. We collect, use, and disclose information from children under 13 only for educational purposes and as permitted by COPPA, and we do not condition participation on disclosing more information than reasonably necessary. If we learn that we have collected information from a child under 13 without appropriate consent, we will delete it promptly. Where the AI Agent may interact with children under 13, School Clients must ensure appropriate notice and consent are in place beforehand. School Clients represent and warrant that they have the authority to provide the requisite consent for Onflo to collect and use such personal information, as set forth in our Cloud Services MSA, Section 7.3.
10.3.3. Students with disabilities (IDEA, 20 U.S.C. § 1400 et seq.; 34 C.F.R. Part 300, Subpart E). Where Student Data includes personally identifiable information related to students with disabilities, we maintain its confidentiality and use it only for purposes authorized by the School Client and permitted under IDEA. School Clients are responsible for ensuring that disclosure of disability-related information to us complies with IDEA’s consent and notice requirements.
10.3.4. Surveys and evaluations (PPRA, 20 U.S.C. § 1232h). PPRA compliance obligations rest with the School Client. School Clients are solely responsible for obtaining prior written parental consent where required. Onflo does not use such data beyond the educational purpose specified by the School Client and is not responsible for content administered by School Clients.
10.4. SOPIPA and AB 1584. Our Service is designed to comply with the Students Online Personal Information Protection Act and California Assembly Bill 1584. Under these laws: (a) we do not use Student Data for targeted advertising, profiling, or sale; (b) we do not amass a profile of a K-12 student except to support the Service’s features; (c) we implement reasonable security practices to protect Student Data; (d) we limit collection, use, and retention of Student Data to what is reasonably necessary; (e) pupil records obtained from an LEA remain the property of and under the control of the LEA; (f) parents, guardians, or eligible pupils may review and correct personally identifiable information by contacting their LEA; and (g) in the event of unauthorized disclosure of pupil records, we will notify the LEA and provide information for the LEA to share with affected individuals.
10.5. Retention and Deletion of Student Data. For Student Data retention periods and deletion practices, see Section 8.1(b) and Section 8.2 of this Privacy Policy, and our Cloud Services MSA, Section 7.8.
10.6. Voice Data and Biometric Information. Certain jurisdictions may classify voice recordings, voiceprints, or voice characteristics as “biometric identifiers” or “biometric information” under applicable law. To the extent Voice Data constitutes biometric information under applicable law: (a) we collect Voice Data only with appropriate consent (collected and managed by the School Client) as required by law; (b) we do not sell, lease, trade, or otherwise profit from Voice Data; (c) we retain Voice Data only as long as necessary to provide the Service or as required by our agreements with our Clients, and in no event longer than three (3) years from the last interaction unless a longer period is required by law or contract; however, our AI Agent service provider may retain Voice Data for up to thirty (30) days for the purpose of compliance with its acceptable use policy; and (d) we protect Voice Data using reasonable security measures. School Clients are responsible for obtaining any consent required under applicable laws before directing individuals to the AI Agent.
Clients are responsible for providing any legally required notices and obtaining any legally required consents before permitting their users to interact with our Services, including but not limited to the AI Agent.
If you have any questions about our practices with regard to Student Data, please contact us at privacy@onflo.com.
11. CHANGES TO OUR PRIVACY POLICY.
As we are constantly improving the Services and expanding our business, Onflo reserves the right to modify this Privacy Policy from time to time to reflect such improvements. In the event we make such changes, we will announce the changes and post the new policy at https://www.onflo.com/privacy-policy. We will also use our best efforts to provide advance notice of any material changes to this Privacy Policy, to permit you a reasonable chance to review before such changes go into effect. If you object to any changes, you may close your account and/or discontinue your use of the Service. Continuing to use our Service after we publish changes to this Privacy Policy means that you are consenting to the changes.
Onflo shall not make any material change to the Privacy Policy or our practices that involve the collection or use of Student Data without first giving at least thirty (30) days’ notice to School Client and providing a choice before the Student Data is used in a materially different manner than was disclosed when the information was collected. For specific contractual notice requirements regarding Student Data, see our Cloud Services MSA, Section 7.10.
12. CONTACT US.
To exercise your rights under this privacy policy, please contact us through any of the following methods:
Email: privacy@onflo.com
Toll Free Phone: (703) 542-9600
Last Updated: June 30, 2026
Effective Date: July 01, 2026