AidKit may collect, receive, or process biometric identifiers or biometric information when necessary to support identity verification, fraud prevention, account security, program administration, legal compliance, or audit requirements.
The AidKit Biometric Information Retention and Destruction Policy “Biometric Policy” explains how AidKit handles biometric identifiers and biometric information, including how long such information is retained and when it is destroyed. Individuals will be provided notice prior to collection of biometric information, and written consent will be obtained where required by applicable law.
Scope
The Biometric Policy applies to biometric identifiers and biometric information collected, received, or processed by AidKit or by service providers acting on AidKit’s behalf.
For purposes of the Biometric Policy, biometric identifiers and biometric information may include, where applicable:
- Face geometry or face templates created from a selfie, photo, or video;
- Liveness detection results;
- Voiceprints;
- Fingerprints;
- Retina or iris scans;
- Hand geometry; or
- Other biometric data used to identify or verify an individual.
AidKit does not always collect biometric identifiers or biometric information. When biometric verification is used, it is used only for the limited purposes described in the Biometric Policy.
Purpose for Collection and Use
AidKit uses biometric identifiers and biometric information only as needed to:
- Verify an applicant’s identity;
- Prevent fraud, duplicate applications, unauthorized access, or misuse of program funds;
- Protect applicant, program, and platform security;
- Support eligibility review and program administration;
- Comply with legal, contractual, audit, or government program requirements; and
- Investigate or respond to suspected fraud, security incidents, or legal claims.
Disclosure and Sharing
AidKit does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information nor use biometric identifiers or biometric information for advertising, marketing, or unrelated profiling.
AidKit may disclose or share biometric identifiers or biometric information only:
- With service providers that support identity verification, fraud prevention, security, or program administration;
- With program administrators, government entities, auditors, or oversight bodies when required or permitted by contract, law, audit, or program requirements;
- To complete a transaction or service requested or authorized by the individual;
- In response to valid legal process, such as a subpoena, warrant, court order, or other legal requirement; or
- As otherwise required or permitted by applicable law.
Service providers that process biometric identifiers or biometric information on AidKit’s behalf are required to protect the information and use it only for the services they provide to AidKit or the applicable program.
Retention and Destruction
AidKit retains biometric identifiers and biometric information only for as long as needed for the purpose for which it was collected or obtained. When no longer needed, AidKit permanently deletes or de-identifies the information, subject to applicable law and any retention obligations that require a longer period, such as a legal hold, investigation, audit, or government program requirement.
In practice, AidKit typically retains biometric identifiers and biometric information for the duration of the applicable program and up to two years after its termination, or longer if required by contract, law, or program requirements. State-specific periods may apply. See Section 9 for details.
Destruction Guidelines
When biometric identifiers or biometric information are no longer required under the Biometric Policy, AidKit will permanently destroy the information using secure deletion methods appropriate to the format and storage location of the information.
Destruction may include:
- Secure deletion from AidKit systems;
- Deletion or destruction by AidKit service providers;
- Removal from active systems and scheduled deletion from backups according to applicable backup retention processes;
- Vendor certification, confirmation, or contractual assurance of deletion where applicable; and
- Documentation of deletion where required for audit, legal, contractual, or compliance purposes.
Security Safeguards
AidKit protects biometric identifiers and biometric information using reasonable administrative, technical, and physical safeguards designed to protect against unauthorized access, disclosure, alteration, or destruction. Safeguards used will be at least as protective as those AidKit applies to other confidential and sensitive personal information.
These safeguards may include access controls, encryption, vendor security requirements, retention controls, and incident response procedures.
Individual Questions and Requests
Individuals may contact AidKit with questions about the Biometric Policy by emailing:
privacy@aidkit.cloud
Depending on applicable law and program requirements, individuals may be able to request access, correction, deletion, or additional information about biometric information associated with them.
Biometric Policy Updates
AidKit may update the Biometric Policy from time to time to reflect changes in law, technology, program requirements, or business practices. The “Last Updated” date will show when the Biometric Policy was most recently revised.
State specific Biomtric Requirements
The following state-specific requirements apply in addition to the general practices described in the Biometric Policy. Where state law requires a stricter standard, that standard controls.
Illinois
Prior to collecting biometric identifiers or biometric information from Illinois residents, AidKit will: (1) inform the individual in writing that biometric data is being collected or stored; (2) inform the individual in writing of the specific purpose and length of time for which the data will be collected, stored, and used; (3) identify with whom the biometric identifiers or biometric information may be shared; and (4) obtain a written release or electronic signature from the individual before collection.
AidKit will not retain biometric identifiers or biometric information of Illinois residents longer than the earlier of: the date the initial purpose has been satisfied, or three years after the individual's last interaction with AidKit.
Texas
Prior to collecting biometric identifiers from Texas residents, AidKit will provide notice that biometric data is being collected and obtain the individual's consent. AidKit will delete biometric identifiers no later than one year after the purpose for collection has been satisfied, unless a statutory exception applies.
Colorado
Prior to collecting biometric identifiers from Colorado residents, AidKit will provide notice and obtain consent as required by applicable Colorado law. Colorado residents may have the right to request information about the source of their biometric data, the purpose for which it was collected, and any third parties with whom it has been shared.
AidKit will delete biometric identifiers and biometric data of Colorado residents by the earliest applicable deadline, which may include: when the purpose has been satisfied; 24 months after the individual's last interaction with AidKit; or no later than 45 days after AidKit determines the data is no longer necessary, adequate, or relevant to the processing purpose.
Other States
For residents of other states with applicable biometric or privacy laws, AidKit will comply with those requirements, including applicable notice, consent, and deletion obligations.