Privacy Policy
This Policy explains how ActivityLock may collect, use, store, disclose, transfer, and protect personal information, educational records, exam content, monitoring signals, and analytics.
Who we are and how to contact us
ActivityLock is operated by MYZ LLC, a limited liability company registered in the United States, serving schools primarily in the United Arab Emirates.
- Operator / data controller: MYZ LLC
- State of registration: Wyoming
- Registered address: MYZ LLC is registered in the State of Wyoming, United States. Our full registered address is available on request from activitylock@madrasatna.com.
- Privacy & data protection contact: activitylock@madrasatna.com
- Data deletion requests: activitylock@madrasatna.com — see Retention and deletion
Write to us at the address above about anything in this policy: access to your data, correction, deletion, objection, or a complaint. We aim to respond within 30 days.
1. Roles and responsibilities
For many educational deployments, the school, teacher, institution, ministry, or organization is the controller or educational authority that decides why ActivityLock is used. ActivityLock acts as a service provider or processor for platform operation, subject to applicable agreements and laws.
Where an individual teacher creates an account independently, that teacher is responsible for providing required notices and obtaining required consents from students, parents, guardians, or institutions before using monitoring or assessment features.
2. Information we may process
- Account information: name, email, role, school or institution details, subject, plan, billing status, support messages, and settings.
- Educational content: exams, activity questions, answer keys, uploaded PDFs, annotations, student submissions, marks, notes, rubrics, exports, and feedback.
- Monitoring data: timestamps, session identifiers, browser focus changes, fullscreen status, device and browser information, screen size, permission status, connection state, activity logs, and violation signals.
- Media or evidence where enabled: screenshots, screen sharing signals, webcam or microphone permission events, or other proctoring evidence depending on teacher or institution settings.
- AI data: writing answers, prompts, marks, feedback, cognitive level labels, similarity flags, confidence scores, analytics, and teacher-provided AI marking instructions.
- Technical data: IP address, user agent, cookies, local storage identifiers, crash logs, security logs, and usage metrics.
- Payment data: plan, subscription, checkout references, invoices, and payment status. Full card details are handled by payment processors and are not stored by ActivityLock.
3. Why we process information
We process information to provide accounts, run exams and activities, enable monitoring selected by teachers or institutions, save submissions, grade activities, provide AI marking and analytics, maintain security, prevent abuse, process payments, provide support, comply with legal obligations, and improve reliability.
ActivityLock uses Google Analytics for limited page-usage and reliability measurement. Analytics receives a sanitized ActivityLock route without query parameters, activity codes, email addresses, student names, exam identifiers, or document titles. Advertising personalization and Google advertising signals are disabled.
Depending on jurisdiction, legal bases may include contract performance, legitimate interests, consent, school authorization, public interest or educational task, compliance with law, or processor instructions from an institution.
4. Children, students, COPPA, FERPA, and school authorization
ActivityLock may be used with students, including minors. Institutions and teachers are responsible for determining whether parental consent, school consent, student consent, or another legal basis is required. For children under 13 in the United States, schools may provide consent for educational technology used for school-authorized educational purposes where permitted by COPPA guidance.
For FERPA-covered institutions, ActivityLock may process education records as a school official or service provider when configured by the institution, subject to institutional control, legitimate educational interest, and applicable contractual or policy safeguards.
5. AI and automated analysis
AI-generated marks, feedback, analytics, similarity indicators, cognitive level labels, and review warnings are not final decisions. Teachers and institutions must review AI output before using it for grades, discipline, eligibility, progression, or significant educational decisions.
AI processing may involve third-party AI infrastructure. We aim to send only the information needed to perform the requested feature, such as the question, answer, max marks, marking settings, and relevant context.
6. Storage, third-party integrations, and international transfers
ActivityLock may use Firebase, Google Cloud, Google Drive, Microsoft OneDrive, Stripe, AI providers, email providers, and other service providers. Information may be processed in countries different from where users are located. We use contractual, technical, and organizational measures intended to protect transferred data where required.
When a teacher connects Google Drive or Microsoft OneDrive, new uploaded files are routed to that teacher-owned cloud account. This includes activity PDFs, logos, activity images, student-uploaded images, submissions, exports, and related generated files. ActivityLock processes the content and stores file identifiers and operational metadata needed to display and manage it. Disconnecting or deleting content from that account may prevent ActivityLock from accessing those files.
7. Retention and deletion
Monitoring evidence is deleted automatically. Camera images, screen captures, and attempt working data captured during a monitored activity are automatically and permanently deleted 49 hours after the attempt. This is enforced by an automated job, not by manual review.
Other data is kept as follows:
- ActivityLock-hosted files after plan expiry or downgrade - paid-plan expiry starts a seven-day migration or renewal grace period, after which ActivityLock-hosted uploaded files are permanently deleted. A downgrade that leaves usage over the new limit also starts a seven-day period, after which excess files are deleted oldest first. Files in a connected user-owned Drive are not part of this cleanup.
- Activities, student attempts, answers and marks — kept while the teacher's account is active, so results remain available to the school. Deleted when the teacher deletes the activity or their account.
- Account and profile data — kept while the account exists; removed on deletion (see below).
- Payment records — retained where required for tax, accounting and dispute resolution.
- Security, audit and legal-acceptance records — retained for accountability and abuse prevention. These do not contain student work.
How to delete your data
Teachers: you can delete your own account and all data you created at any time, without contacting us. In the app, open your account settings and choose Delete my account and data, then confirm. This permanently removes your profile, every activity you created, and all student attempts, submissions, files and results belonging to those activities. It cannot be undone.
Students, parents and guardians: student data in ActivityLock belongs to the school or teacher who created the activity. The fastest route is to ask that school or teacher directly, because they can remove a student's attempt immediately. You may also contact us at activitylock@madrasatna.com and we will action or forward your request. Please include the activity name or code and the student name used to join, so the record can be located.
Institutions: an institution administrator can remove members and their data from Institution Management, or contact us at the address above.
We aim to respond to deletion and access requests within 30 days. Deletion may be limited only where records must be retained for legal compliance, tax/accounting, dispute resolution, security, or backup recovery — in which case we will tell you what was retained and why.
8. Disclosure
We may disclose information to authorized teachers, institution administrators, students where appropriate, service providers, payment processors, cloud providers, support personnel, legal authorities when required, and parties involved in security, abuse, billing, or legal enforcement.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object, export, or complain about personal data processing. Students should usually contact their teacher or institution first because the school or institution often controls educational records.
10. Security
We use technical and organizational safeguards designed to protect data. However, no online service is completely secure. Users must protect passwords, devices, browser sessions, connected cloud accounts, and institution access controls.
11. Policy updates
We may update this Policy. Material changes may require renewed acceptance or notice. Acceptance records may include version, timestamp, IP address, user agent, and device information for audit readiness.