Biometric Data Retention and Destruction Policy
This policy explains what biometric information Byte Federal, LLC ("Byte Federal," "we," "us," or "our") collects, why we collect it, how long we keep it, and how we destroy it. It is published in accordance with the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) and comparable state biometric privacy laws, and applies to everyone whose biometric information we handle, wherever they live.
1. What we mean by biometric information
When you complete an identity verification with us, our verification technology takes a short video of your face and derives from it a mathematical representation of your facial geometry. That representation is a biometric identifier. Information derived from it and used to identify you is biometric information. This policy covers both, and refers to them together as "biometric data."
Biometric data is treated as biometric data regardless of the form it takes. A facial template that has been hashed, encrypted, or otherwise transformed is still biometric data for the purposes of this policy, because it can still be used to recognise a person.
Photographs of your identity document, and the images captured during a face scan, are not in themselves biometric identifiers, but they are handled under the same retention and destruction rules set out below.
2. Why we collect it
We collect biometric data for identity verification, and for no other purpose. Specifically, to confirm that:
- a live person is present, rather than a photograph, mask, recording, or synthetic image;
- the person present matches the photograph on the identity document they have presented; and
- where the law requires it of us, that we know who our customer is.
We do not use biometric data for advertising, profiling, behavioural analysis, or training machine-learning models. We do not use it to identify you in any context other than the verification you began, and we do not search your face against a database of other people.
3. Consent
We do not collect biometric data without your consent. Before any face scan begins, we tell you in writing that biometric data will be collected, what it will be used for, and how long it will be kept, and we ask you to agree. You may decline. If you decline, the verification simply does not happen.
Consent is specific to the verification you are completing. We do not treat consent given for one verification as consent for a different purpose or a later one.
4. Retention schedule
How long we keep biometric data depends on why it was collected. There are two cases, and they are very different.
(a) Verifications you complete for a third party (Byte Verify). Where another party has asked us to confirm that you are a real person and that you are who your identity document says you are, we keep no biometric data at all once the verification ends.
Your face scan, the biometric template derived from it, the images of your identity document, and the records our verification provider holds are destroyed as soon as the verification reaches its result, and in no event later than 24 hours afterwards. This applies whether the verification succeeds, fails, or expires without being completed.
What remains is a record that a verification took place, when it happened, who asked for it, and whether the answer was yes or no. That record contains no name, no date of birth, no images, and no biometric data.
(b) Verifications you complete to open or use a Byte Federal account. Where you are verifying your own identity in order to use our products, we retain biometric data no longer than is necessary, and in any event destroy it when the initial purpose for collecting it has been satisfied, or within three years of your last interaction with us, whichever occurs first.
Financial-services recordkeeping law separately requires us to retain certain customer identification records, such as your name, date of birth, address, and identity document number, for a defined period. Those records are not biometric data, and retaining them does not extend the destruction deadline for your biometric data. The two are held separately and destroyed on their own schedules.
5. How we destroy it
Destruction is permanent. We do not archive biometric data, move it to cold storage, or retain a copy for analysis.
- Our own systems. Biometric data and the images it was derived from are deleted from our systems as part of the transaction that records the verification's result, so no successful verification leaves them behind.
- Our verification provider. We instruct our provider to destroy its copy as well. That instruction is issued automatically, is retried until it succeeds, and raises an alert to our staff if it does not, so that a failed destruction is found and acted on rather than going unnoticed.
- Backups. Where biometric data may persist briefly in system backups, those backups are encrypted, access-controlled, and expire on a fixed cycle, after which no copy remains.
Destruction happens on the schedule above whether or not you ask for it. You do not have to make a request for your biometric data to be destroyed.
6. Disclosure
We do not sell, lease, trade, or otherwise profit from your biometric data. We never have and this policy prohibits it.
We disclose biometric data only to the technology provider that performs the verification on our behalf, which is contractually bound to use it solely for that purpose, to protect it to at least the standard we apply ourselves, and to destroy it on our instruction.
We do not disclose biometric data to the party that requested a verification. A requesting party receives only the result: yes or no. They do not receive your face scan, your images, your biometric template, or the contents of your identity document.
We would disclose biometric data otherwise only where required by a valid subpoena, warrant, or court order, or where you have separately consented in writing.
7. How we protect it
We store and transmit biometric data using the reasonable standard of care applicable to our industry, and in the same manner as, or a manner more protective than, the way we store other confidential and sensitive information.
In practice that means biometric data is encrypted in transit and at rest, is accessible only to the systems that need it to complete a verification, is never written to application logs, and is destroyed on the schedule set out above. The single most effective protection we apply is not keeping it: for third-party verifications, there is no stored biometric data to breach.
8. Your rights
Depending on where you live, you may have the right to know what biometric data we hold about you, to obtain a copy, to have it deleted, and to withdraw consent. Because of the retention schedule above, in most cases we will already hold nothing.
Illinois residents have rights under the Biometric Information Privacy Act. Texas residents have rights under the Capture or Use of Biometric Identifier Act. Washington residents have rights under RCW 19.375. We honour these rights for all users regardless of residence.
To exercise any of them, contact us using the details below. We will not discriminate against you for doing so.
9. Changes to this policy
If we change this policy we will update the date shown at the top of this page. A change that shortens a retention period takes effect immediately. A change that would extend one applies only to biometric data collected after the change, and only with fresh consent.
10. Contact
Questions about this policy, or requests relating to your biometric data, should be directed to our Privacy Officer:
Byte Federal, LLC
Attn: Privacy Officer
795 Commerce Dr. Ste 5
Venice, FL 34292
Email: privacy@bytefederal.com