Written Information Security Policy (WISP) | Zigazoo
Written Information Security Policy
Our commitment to protecting the confidentiality, integrity, and availability of information.
Effective Date: March 23, 2026 · Last Updated: April 17, 2026
1. Purpose
Zigazoo, Inc. ("Zigazoo," "we," "our," or "the Company") is committed to protecting the confidentiality, integrity, and availability of the information we collect, process, and store—particularly data related to children, families, educators, and partners.
This Written Information Security Policy ("WISP") establishes administrative, technical, and physical safeguards designed to protect sensitive information and support compliance with applicable laws and regulations.
We maintain a written information security program that contains safeguards that are appropriate to the sensitivity of the personal information collected from children and Zigazoo's size, complexity, and nature and scope of activities.
2. Scope
This policy applies to:
- All Zigazoo employees, contractors, and consultants
- All systems, networks, and devices owned, operated, or managed by Zigazoo
- All data collected, processed, or stored by Zigazoo, including personal data, student and child data, customer and partner data, and internal business information
3. Definitions
Sensitive Information Non-public data that could cause harm if disclosed, including personal data, student records, login credentials, and financial information.
Personal Data Information that identifies or reasonably relates to an individual.
Child Data Personal data collected from users under 13, subject to applicable laws such as COPPA.
Authorized User An individual granted access to systems or data for legitimate business purposes.
4. Information Security Governance
The primary contacts responsible for the coordination of our safety and information security protocols are the Chief of Staff and the Lead Engineer. Together, they oversee and maintain this WISP. Responsibilities include:
- Policy implementation and enforcement
- Risk assessment and mitigation
- Incident response coordination
- Vendor and third-party security oversight
- Ongoing security program improvement
5. Data Classification
Zigazoo classifies data into the following categories:
- Public Approved for public disclosure.
- Internal Non-public, low sensitivity.
- Confidential Sensitive business or user data.
- Restricted Highly sensitive data (e.g., child data, authentication credentials).
Handling Requirements:
- Confidential and Restricted data must be encrypted in transit and at rest where appropriate
- Access must be limited based on role and business necessity
- Storage and sharing must follow approved security controls
6. Access Controls
Zigazoo enforces access controls based on the principle of least privilege. All authorized users must:
- Use unique credentials
- Follow strong password requirements
- Use multi-factor authentication (MFA) where supported
Access is reviewed periodically and revoked promptly upon termination or role change.
7. Data Protection & Security Measures
Zigazoo implements administrative, technical, and physical safeguards consistent with industry standards.
Technical Safeguards:
- Encryption of data in transit and at rest where appropriate
- Secure cloud infrastructure and hardened environments
- Network security controls (e.g., firewalls, intrusion detection/prevention systems)
- Logging, monitoring, and alerting for suspicious activity
Organizational Safeguards:
- Privacy-by-design product development
- Secure coding and development practices
- Regular security reviews, testing, and updates
8. Employee Training & Responsibilities
All personnel must complete security and privacy training upon hire and periodically thereafter. Personnel are responsible for:
- Protecting credentials and access devices
- Recognizing phishing and suspicious activity
- Promptly reporting potential security incidents
Violations of this policy may result in disciplinary action, up to and including termination.
9. Incident Response
Zigazoo maintains an incident response process to detect, respond to, and recover from security incidents. Incidents must be reported promptly to the Security Lead or designated contact. Zigazoo will:
- Investigate and contain the incident
- Mitigate potential impact
- Notify affected parties and authorities as required by applicable law
10. Vendor & Third-Party Security
Zigazoo evaluates vendors and service providers prior to granting access to sensitive data. Vendors must:
- Agree to contractual data protection obligations
- Implement appropriate security safeguards
- Access only the data necessary to perform contracted services
11. Compliance & Regulatory Alignment
Zigazoo is committed to complying with applicable data protection laws and frameworks, including:
- COPPA (Children's Online Privacy Protection Act)
- FERPA (Family Educational Rights and Privacy Act), where applicable
- CCPA/CPRA (California Consumer Privacy laws)
- Other applicable U.S. and international data protection regulations
12. Monitoring & Enforcement
Zigazoo monitors systems and networks for unauthorized access, misuse, or anomalies. Violations of this policy will be investigated and may result in disciplinary or legal action.
13. Policy Review & Updates
This WISP is reviewed at least annually and updated as needed to reflect changes in business practices, technology, or legal requirements. Updates are approved by Zigazoo leadership.
14. Contact Information
For questions regarding this policy or to report a security concern:
Zigazoo, Inc.