Privacy & Data Retention¶
Biometrid processes temporarily stores personal data to provide identity verification services. All data handling follows strict security and privacy guidelines to protect user information.
Data Security¶
All data processed through Biometrid is protected through multiple layers of security:
Encryption in Transit¶
- All API communications are encrypted using HTTPS/TLS 1.2+
- No data is transmitted over unencrypted channels
- Certificate pinning ensures secure connections
Encryption at Rest¶
- All sensitive data is encrypted in our database using AES encryption with digital certificates
- Digital certificates ensure data integrity and authenticity
- Access to encrypted data requires proper authentication and authorization
- Encryption keys and certificates are managed separately from encrypted data
Access Controls¶
- Multi-factor authentication required for all administrative access
- Role-based permissions limit data access to authorized personnel only
- All data access is logged and monitored for security compliance
Data Retention Policy¶
By default, Biometrid retains sensitive information for a limited period:
Sensitive Data Retention¶
- Images and documents: Retained for 30 days after process completion
- Biometric templates: Retained for 30 days after process completion
- Personal information: Retained for 30 days after process completion
- Process metadata: Retained for compliance and audit purposes
Automatic Process Cleanup¶
- Idle processes: Automatically cancelled after 7 days of inactivity
- Cancelled processes: Data immediately queued for deletion
- Completed processes: Data retained according to retention policy
Configurable Retention¶
All retention periods are configurable based on your specific requirements:
- Custom retention periods: Available upon request
- Immediate deletion: Can be configured for specific data types
- Extended retention: Available for compliance requirements
- Data residency: Region-specific storage options available
Privacy Principles¶
Data Controller Responsibility¶
- All personal data processed is under the control of the data controller (you or your client)
- Biometrid acts as a data processor following your instructions
- You maintain full control over data processing purposes and legal basis
Data Minimization¶
- Only necessary data is collected for identity verification purposes
- Unused data is automatically purged according to retention policies
- No unnecessary data tracking or profiling occurs
Transparency¶
- Clear documentation of all data processing activities
- Regular security audits and compliance assessments
- Open communication about data handling practices