Skip to content

Security & compliance

We handle minors' data, payment information, and school records. This page explains how, in plain language, and lists the documentation we can send your procurement office.

Last reviewed August 2026

Student data

zFairs and ISEF Forms are used by programs that serve K-12 students. That means we hold names, school affiliations, project information, and sometimes contact details for minors. We use that data to run the program you hired us to run. We do not sell student data, and we do not use it to train advertising models.

Your data is yours. Programs can export it, and we return or delete it at the end of an engagement on request.

FERPA and COPPA apply to much of this work. We treat both as obligations, not badges. If your district needs a data processing agreement, a completed security questionnaire, or specific contract language, ask — we will send what we have and tell you honestly if something is still being prepared.

Payments

When a program sells tickets or collects fees, card payments are processed by a payment processor. Card numbers are not stored on our servers. PCI is a real obligation in that flow; the exact SAQ and processor name are in the documentation we send procurement offices, so the claim you take to a board is checkable rather than decorative.

We do not claim HIPAA coverage on this site. Student competition software is not a medical record system. If a specific engagement requires a BAA, that is a contract conversation, not a homepage badge.

Encryption, hosting, and availability

Data is encrypted in transit using TLS. Data at rest is encrypted. Hosting, backup frequency, retention, and the last twelve months of uptime are listed in the packet we send on request, because those figures change and a static marketing page is a bad place to freeze them.

The more important sentence is operational: during competition season we treat the platform as event infrastructure. There is a named person on the other end of the phone. A support ticket queued for next week is not a plan when registration closes on Friday.

Access and accounts

Access to customer data inside our company is limited to staff who need it to support you. Inside an event, accounts use roles — organizer, judge, volunteer, participant — so a judge sees the entries assigned to them and nothing else.

Accessibility

We design to WCAG 2.2 Level AA. This website has not yet had an independent audit, and we are still inventorying remaining gaps. The careful version is in the accessibility statement.

Read our accessibility statement

Who else touches your data

We use a small number of subprocessors to host the service, send email, process payments, and keep the site running. The current list is part of the documentation packet. We will notify you before adding a subprocessor that handles customer data.

If something goes wrong

If customer data is affected by a security incident, we will notify affected customers without undue delay and within any timeframe your contract or applicable law requires, and we will tell you what happened, what data was involved, and what we are doing about it.

Found a vulnerability? Email support@zfairs.com with the subject line "Security". We will acknowledge within two business days.

What we can send your procurement office

  • Data processing agreement, where one is in place for your program
  • Completed security questionnaire
  • Certificate of liability insurance
  • W-9
  • Subprocessor list
  • Accessibility statement
  • Sample contract

Ask and we will send them. You should not have to chase a vendor for these.