HZ360 GENERAL PRIVACY POLICY
How HZ360 collects, uses, shares, retains, and protects personal information
DOCUMENT ID | HZ360-PRIV-GEN-001 |
|---|---|
VERSION | 1.0 (Official) — Effective September 3, 2026 |
STATUS | In effect. |
COORDINATED DOCUMENTS | Children’s Privacy Policy, Direct Notice to Parent, and Parent Consent Instrument |
1. SCOPE AND WHO WE ARE
This General Privacy Policy applies to the websites, applications, HZ360 TrainingOS™, HOTZONE GAME PLAN™, Coach’s Corner™, and related services operated by HOTZONE NCAA SPORTS RECRUITING LLC d/b/a HZ360 (“HZ360,” “we,” “us,” or “our”). HZ360 is located at 1500 John F. Kennedy Blvd, Suite 450, PMB 101, Philadelphia, PA 19102. Contact us at legal@hz360.ai or 888-434-9360.
The HZ360 Children’s Privacy Policy (COPPA), available at https://hz360.ai/privacy/children, controls for children under 13 where COPPA applies. This Policy is published at https://hz360.ai/privacy. A child-friendly or program-specific notice may supplement this Policy. If a supplemental notice provides greater protection, the more protective term applies.
2. AGE GROUPS AND ACCOUNT STRUCTURE
HZ360 TrainingOS™ is available to athletes of all ages. HOTZONE GAME PLAN™ is a mixed-audience recruiting service available to athletes of any age and recommended for athletes U12 and older. HZ360 determines age before collecting personal information beyond what is permitted to identify age or seek parental consent.
- Under 13: a parent or legal guardian creates or authorizes the profile, controls consent and external visibility, and may permit limited age-appropriate child access after verifiable parental consent.
- Ages 13–17: an athlete may have an individual login with age-appropriate safeguards and parental involvement where required by law or program rules.
- Age 18 and older: the athlete controls the account and privacy choices, subject to any organization-sponsored program terms.
- EEA and UK: the applicable national digital-consent age and other child-data requirements also apply.
3. INFORMATION WE COLLECT
- Identity and contact information, such as name, age or birth date, address, email, telephone number, parent or guardian information, and account credentials.
- Athletic and development information, including sport, position, team, graduation year, training plans, attendance, assessments, performance statistics, evaluations, goals, and Coach’s Corner™ notes.
- Academic and recruiting information supplied by the athlete or parent, including school, graduation information, academic preferences, recruiting interests, communications, and college-fit preferences.
- Media, such as photographs, video, audio, and associated metadata when uploaded or recorded with the required authorization.
- Wearable and location information when an optional feature is enabled, including movement, workload, speed, distance, and device-derived performance measures, received by HZ360 from the approved wearable provider through an authorized connection; HZ360 does not send a minor’s personal information to the wearable provider. HZ360 does not treat all wearable data as biometric data; it evaluates the actual technology and data use under applicable law.
- Technical and usage information, including IP address, browser, device, cookies, session identifiers, security logs, feature use, and referral information.
- Support, payment, transaction, survey, and communications information.
4. SOURCES
We collect information directly from athletes, parents, guardians, trainers, facilities, clubs, teams, coaches, schools, approved recruiting or sports-data sources, connected devices, service providers, and ordinary use of the Services. An organization supplying athlete information must have authority to do so and may provide only the minimum permitted pre-consent information for a child under 13.
5. HOW WE USE INFORMATION
- Provide, personalize, secure, troubleshoot, and improve requested Services.
- Create athlete profiles, training plans, performance reports, TacticalDNA™ insights, recruiting intelligence, college-fit indicators, and parent-authorized reports.
- Authenticate users, obtain and record consent, verify age or parental authority, prevent fraud, and protect users and the Services.
- Communicate about accounts, safety, service changes, support, and authorized programs.
- Comply with law, enforce agreements, resolve disputes, and protect legal rights.
- Generate aggregated or de-identified analytics that are not reasonably linkable to an individual.
6. ARTIFICIAL INTELLIGENCE AND AUTOMATED ANALYSIS
HZ360 may use automated analysis to generate reports, recommendations, derived scores, TacticalDNA™ insights, or fit indicators. These outputs are decision-support tools and may be incomplete or inaccurate. HZ360 does not use solely automated processing to make decisions about a child that produce legal or similarly significant effects.
HZ360 will not transmit identifiable minor information to an externally hosted AI model. External AI providers may receive only information processed through HZ360’s approved de-identification controls and contractually restricted from reidentification, secondary use, or model training. The de-identification control is implemented, tested, and documented.
7. COOKIES, ANALYTICS, AND ADVERTISING
HZ360 uses necessary cookies and similar technologies for authentication, security, preferences, session continuity, and service operation. Any nonessential analytics or advertising technology is described and controlled through the applicable consent interface. HZ360 does not sell children’s personal information or use it for targeted or behavioral advertising. Persistent identifiers in a child experience are used only for permitted internal operations unless the required notice and consent are provided.
8. WHEN WE DISCLOSE INFORMATION
- Service providers processing information on HZ360’s documented instructions under confidentiality, security, deletion, and use restrictions. A provider processing a minor’s personal information on HZ360’s behalf may not transmit it to an externally hosted AI model or use it for model training, and must impose the same restriction on its subprocessors.
- Facilities, trainers, clubs, coaches, schools, college programs, or other recipients authorized by the athlete or parent, as applicable.
- Government, law-enforcement, safety, or legal recipients when required by law or reasonably necessary to protect rights and safety.
- A successor in a merger, financing, reorganization, bankruptcy, acquisition, or asset transfer, subject to existing privacy choices and protections.
Athlete profiles are not publicly indexed. Parent-authorized or athlete-authorized share links must be access-controlled, limited in scope, revocable, time-limited, and subject to restrictions against publication, resale, unrelated profiling, and onward disclosure.
9. SENSITIVE, BIOMETRIC, AND LOCATION INFORMATION
Where applicable law treats precise geolocation, biometric identifiers, health information, or other information as sensitive data, HZ360 obtains any required consent and provides any required withdrawal mechanism. Photographs, video, audio, wearable readings, and athletic measurements are not automatically biometric information. HZ360 evaluates whether a technology creates or uses an identifier, template, face or hand geometry scan, voiceprint, or other legally regulated biometric information before deployment.
10. RETENTION AND DELETION
HZ360 retains personal information only as long as reasonably necessary for the disclosed purpose, an active account or program, security, dispute resolution, or a legal obligation. HZ360 maintains a data-specific retention schedule. After deletion from active systems, protected backup copies remain isolated from ordinary use and expire through the backup cycle. If deleted information is restored, HZ360 takes reasonable steps to identify and delete it before using it for a new purpose. Service providers are instructed to delete applicable information.
11. SECURITY
HZ360 uses administrative, technical, and physical safeguards appropriate to the nature of the information, including access controls, encryption in transit and at rest, logging, vendor review, incident response, and periodic risk assessment. No security method is perfect. Users should protect credentials and report suspected unauthorized access promptly.
12. PRIVACY RIGHTS AND REQUESTS
Depending on location and applicable law, an individual may request access, correction, deletion, restriction, portability, or withdrawal of consent, and may object to or opt out of certain processing. Submit a request through the privacy request form at https://hz360.ai/privacy/request, email legal@hz360.ai, call 888-434-9360, or write to 1500 John F. Kennedy Blvd, Suite 450, PMB 101, Philadelphia, PA 19102. HZ360 may verify identity and authority. If HZ360 denies an appealable US state request, the response will explain how to appeal. An individual may also contact the applicable state attorney general or data protection authority.
Privacy rights belong to the individual. A parent or guardian may act for a minor when authorized by the minor or permitted by law, taking account of age and capacity. Parents of children under 13 have the rights described in the HZ360 Children’s Privacy Policy.
13. US STATE PRIVACY RIGHTS
Residents of certain US states may have additional rights under applicable law, including rights to access, correct, delete, or obtain a copy of personal data and to opt out of certain sales, targeted advertising, or profiling. HZ360 does not sell children’s personal information or use it for targeted advertising. When required, HZ360 obtains consent before processing sensitive data and provides a method to withdraw it. These rights apply subject to statutory thresholds, exemptions, and exceptions.
If HZ360 or a provider collects biometric identifiers or biometric information regulated by Illinois law, HZ360 will provide the required written notice, obtain the required written release, follow a public retention and destruction schedule, restrict disclosure and profit, and apply legally required safeguards before collection.
14. EEA AND UK PRIVACY
For individuals in the EEA or UK, HZ360 relies, as applicable, on contract, legal obligation, legitimate interests not overridden by individual rights, or consent. Individuals may exercise GDPR or UK GDPR rights and complain to their local supervisory authority; UK individuals may contact the Information Commissioner’s Office. HZ360 uses a valid transfer mechanism for restricted transfers to the United States, such as the European Commission Standard Contractual Clauses and the applicable UK Addendum or International Data Transfer Agreement, with required assessments and safeguards.
Where consent governs an online service offered directly to a child, the relevant age varies from 13 to 16 in the EEA and is 13 in the UK. Below that age, HZ360 obtains authorization from the holder of parental responsibility and reasonably verifies it. Before EEA or UK launch, HZ360 will complete the required child-focused impact assessment, representative and DPO analysis, transfer documentation, child-friendly notices, and special-category-data assessment.
15. ORGANIZATIONS, THIRD-PARTY LINKS, AND ROLE ALLOCATION
A facility, club, academy, school, or team may be a separate controller, joint controller, or processor depending on the program. HZ360 defines those roles by contract. Third-party websites and services have their own privacy practices; a link does not authorize disclosure of HZ360 data.
16. CHANGES AND CONTACT
HZ360 will post the current Policy and its effective date. If a material change requires new consent, HZ360 will provide notice and obtain that consent before applying the change. Accessibility requests, questions, complaints, and privacy requests may be directed to the contact information in Section 1.