Security & Compliance
At Quizify, protecting customer data is one of our highest priorities. We implement technical and organizational security measures designed to safeguard your information, maintain data integrity, and help customers meet their security and compliance requirements.
Data Security:
Description: Quizify is designed with multiple layers of security to help protect customer data throughout its lifecycle—from collection and transmission to storage and deletion.
Key Security Measures:
Encryption: All customer data is encrypted both in transit (HTTPS/TLS) and at rest using industry-standard encryption methods to help protect information from unauthorized access.
Secure Infrastructure: Quizify is hosted on secure cloud infrastructure with restricted administrative access, regular system updates, infrastructure monitoring, and industry-standard security practices.
User Authentication: Only authenticated users can access Quizify accounts using valid login credentials.
Role-Based Access Control: Account owners can assign roles and permissions to team members, ensuring users only have access to the information necessary for their responsibilities.
Two-Factor Authentication (2FA): Quizify supports Two-Factor Authentication (2FA) to provide an additional layer of account security and help protect against unauthorized access.
Regular Backups: Automated database backups are performed regularly to help protect against accidental data loss and support disaster recovery when necessary.
Compliance Standards:
Description: Quizify is committed to helping customers meet applicable privacy and security requirements through responsible data handling practices and documented compliance measures.
Standards Supported:
GDPR: Quizify acts as a Data Processor for customer-collected data and provides documentation, including our Data Processing Addendum (DPA), to support customers in meeting their GDPR obligations.
CCPA: Quizify supports customer privacy rights and complies with applicable California Consumer Privacy Act (CCPA) requirements regarding customer data.
Security Best Practices: Quizify follows industry-standard security practices designed to protect customer information and maintain the confidentiality, integrity, and availability of data.
Privacy Policy & Data Handling:
Description: Quizify collects and processes customer data only as necessary to provide the services requested by our customers.
Data Handling Principles:
Data Collection: Quizify only collects data necessary to provide and improve its services.
Data Usage: Customer data is processed solely to provide Quizify functionality and deliver requested services. Quizify does not use customer submission data for its own business purposes.
Data Retention: Submission data remains available until deleted by the customer. Customer account data is retained only as necessary to provide the service and meet legal obligations.
Data Deletion: Customers can permanently delete individual submissions, associated funnel data, or their account data. If a customer deletes their Quizify account, all associated customer data is permanently deleted after a 30-day retention period. Customers may also request deletion of their personal data by contacting our support team at support@quizify.io. Once a valid deletion request is received and verified, it is typically processed within 7 business days, unless a longer retention period is required by applicable law.
Third-Party Integrations
Quizify supports integrations with services such as Webhooks, Zapier, Make, Mailchimp, Klaviyo, ActiveCampaign, HubSpot, Slack, Brevo, and many other third-party platforms.
When a customer enables an integration, Quizify securely transmits the submitted data to the configured third-party service.
Once the data has been successfully delivered, the storage, processing, security, and privacy of that data become the responsibility of the respective third-party provider and are governed by their own terms and privacy policies.
Incident Response:
Description: Quizify maintains procedures to respond promptly to security incidents and minimize their impact.
Response Process:
Incident Identification: Potential security incidents are investigated as soon as they are detected.
Containment: Appropriate measures are taken to limit the impact and prevent unauthorized access where applicable.
Investigation: Our team investigates the nature, scope, and potential impact of the incident.
Customer Notification: Where required by applicable law or contractual obligations, affected customers will be notified without undue delay and provided with relevant information.
Remediation: Corrective actions are implemented to reduce the likelihood of similar incidents in the future.
Best Practices for Customers:
To help keep your Quizify account secure, we recommend:
Use a strong, unique password.
Enable Two-Factor Authentication (2FA).
Grant team member access only where necessary using role-based permissions.
Regularly review connected integrations and remove unused ones.
Keep your devices, browsers, and operating systems updated.
Be cautious of phishing emails and only sign in through the official Quizify website.
Commitment to Security
Security and privacy are ongoing priorities at Quizify. We continuously review and improve our security practices, infrastructure, and compliance documentation to help protect customer data and support organizations across a wide range of industries, including businesses handling sensitive information.