Biometric Information Privacy Policy
Effective Date: 4 August 2022
1. Introduction
This Biometric Information Privacy Policy (the “Policy”) is applicable to users residing in the United States of America. This Policy supplements our Privacy Policy. Daon has instituted this Policy as it specifically relates to any biometric data that Daon possesses as a result of a users use of the Services or of Daon’s customers’ and their clients use of the Services. Daon’s customers are responsible for (a) providing you (as a user and data subject) with notice and obtaining your consent to use of your biometric data and biometric information; and (b) developing and complying with their own biometric data retention and destruction policies as may be required under applicable law.
1.1 Biometric Data Defined
As used in this Policy, biometric data means any biological characteristics of a person, or information based upon such a characteristic, including characteristics such as those defined as “biometric identifiers” and “biometric information” under the Illinois Biometric Information Privacy Act, 740 ILCS 14/1, et seq. “Biometric identifier” means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. “Biometric information” means any information, regardless of how it is captured, converted, stored, or shared, based on an individual’s biometric identifier used to identify an individual.
1.2 Collection, Storage, Use, and Transmission of Biometric Data
Our customers are responsible for compliance with applicable law governing any collection, storage, use, and/or transmission of biometric data they collect or facilitate collection of through the use of our Services. To the extent required by law, our customers will obtain written authorisation from each data subject to collect, store, use, and/or transmit biometric data prior to the collection of such data. Neither Daon nor its vendors will sell, lease or trade any biometric data that it receives from its customers’ as a result of their use of Daon services.
We may process, use and/or transmit biometric data in connection with providing certain products or services to our customers. With respect to such biometric data processed by Daon, to the extent required by law, Daon’s customers’ will obtain written authorization from each data subject for the benefit of Daon to process such biometric data prior to the processing of such data.
1.3 Authorisation
If you use our Services, you authorise Daon to process, capture, or otherwise obtain your biometric data in connection with the Services provided to you.
1.4 Disclosure
Daon will not disclose, disseminate and/or transmit any customer biometric data to any person or entity other than the customer and Daon’s authorized licensors or vendors without/unless:
- First having the customers’ written consent;
- The disclosed information completes a financial transaction authorised by the customer;
- Disclosure is required by state or federal law; or
- Disclosure is required pursuant to a valid warrant or subpoena.
1.5 Retention Schedule
Daon will only retain biometric data for the relevant retention period specified in Records Retention and Protection Policy. For the purposes of this Policy, Daon shall retain any customers biometric data in Daon’s possession only until the following occurs:
- Daon receives written notice from its customer that the initial purpose for obtaining such biometric data has been satisfied; or
- Within 1 years of Daon receiving written notice of the customers (and its users) last interaction with the customer, (Whichever is shorter).
1.6 Biometric Data Storage
Daon and/or its vendors shall use a reasonable standard of care to store, transmit and protect from disclosure any paper or electronic biometric data collected, and shall store, transmit, and protect from disclosure all biometric data in a manner that is the same as or more protective than the manner in which Daon stores, transmits, and protects other personal information that can be used to uniquely identify an individual or an individual’s account or property, such as account numbers, driver’s license numbers, and social security numbers.
1.7 Security.
Daon has implemented and agrees to maintain the security measures indicated in the Daon Data Security Standard Policy. The security measures are subject to technical progress and further developments. Daon shall be permitted in principle to implement alternative security measures. The level of security may not thereby fall below the level existing prior to the implementation of such alternative security measures. Any substantial change to security measures shall be documented and notified to Customer by Daon.
Daon is responsible for assessing its requirements with respect to appropriate technical and organizational measures to ensure compliance with Data Protection Law, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, making an independent determination and satisfying itself that the security measures specified in the Daon Data Security Standard Policy meet its requirements.