Biometric Data Policy
Biometric Data Policy and Notice
Original Date:
1. Purpose
GetReal Security ("Company") has adopted this Biometric Data Policy and Notice (this "Biometric Policy") to govern the collection, use, and treatment of the Biometric Data of (a) the Company’s employees and prospective employees, (b) the employees and prospective employees of Company’s clients, (c) any persons who consent, and (d) any participant in a virtual meeting (collectively, “Participants”). Protecting the confidentiality and integrity of Biometric Data is a critical responsibility that must always be taken seriously. Compliance with this Policy is mandatory.
2. Scope
This Policy applies to all Participants and the Company’s agents, representatives, including any contractor or third-party service provider to the Company, namely Amazon Rekognition ("Third-Party Service Provider"), who have access to Biometric Data on behalf of the Company. This Policy applies to all Biometric Data collected, maintained, transmitted, stored, retained, or otherwise used by the Company, regardless of the media on which that information is stored and whether relating to Participants.
3. Definitions
"Biometric Data" means collectively all Biometric Identifiers and Biometric Information.
"Biometric Identifiers" means:
- Retina or iris scans.
- Fingerprints.
- Voiceprints.
- Scans of hand or face geometry.
- Any other unique biological pattern or characteristic used to identify a specific individual
Biometric Identifiers do not include:
- Writing samples and written signatures.
- Photographs.
- Human biological samples used for valid scientific testing or screening.
- Demographic data.
- Tattoo descriptions.
- Physical descriptions, such as:
- height;
- weight;
- hair color; or
- eye color.
- Information captured from a patient in a healthcare setting.
- Information collected, used, or stored for healthcare treatment, payment, or operations under the Health Insurance Portability and Accountability Act (HIPAA).
- Donated organs, tissues, or parts as defined by the Illinois Anatomical Gift Act or blood or serum stored in connection with organ transplants.
- Biological materials regulated under the federal Genetic Information Privacy Act.
"Biometric Information" means information, regardless of how it is captured, converted, stored, or shared, that is based on a Biometric Identifier. Biometric Data does not include information derived from items or procedures excluded under the definition of Biometric Identifiers.
4. Retention Schedule
In circumstances where the Company directly retains Biometric Data, or uses the services of Amazon Rekognition, the Company will permanently destroy, or direct Amazon Rekognition to destroy, an individual's Biometric Data within three (3) years of collection or the initial purpose for collecting or obtaining such identifiers or information has been satisfied.
Initial purposes for collection end when:
- The individual last interacts with the technology using Biometric Data.
- The individual's employment is terminated.
- GetReal’s contract with the Client is terminated.
5. Biometric Data Collection
The Company collects, stores, and uses Biometric Data for the purpose of verifying an Employee's identity (including, without limitation, identification and authentication) (“Purposes”). Before collecting Biometric Data from any individual, the Company will obtain the individual's written consent to the collection. The Company may also provide for withdrawal of consent and deletion of Biometric Data after the Purpose has been met. Company shares Biometric Data with Amazon Rekognition solely for these Purposes. Amazon Rekognition’s policy can be found here. You acknowledge and agree that it is your responsibility to review this policy.
6. Biometric Data Security
The Company and Amazon Rekognition shall use a reasonable standard of care (such as encryption in transit and at rest) to store, transmit, and protect from disclosure any paper or electronic Biometric Data collected.
7. Biometric Data Disclosures
The Company may disclose an individual's Biometric Data to additional third-party vendors and/or licensors to facilitate the provision of its Purposes. The Company prohibits any further disclosure or re-disclosure of Biometric Data unless:
- The individual or the individual's legally authorized representative consents to the disclosure;
- The disclosure is required by applicable law or regulation; or
- The disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
The Company does not sell, lease, or trade Biometric Data.
Please click here for our Privacy Policy. You acknowledge and agree that it is your responsibility to review this policy.
PARTICIPANT’S CONSENT TO BIOMETRIC INFORMATION COLLECTION, STORAGE, AND USE
I have read GetReal’s Biometric Data Policy and Notice and Privacy Policy, and I consent to its terms. I understand that by being present in this meeting, my biometric information (e.g., voice print, face, and facial geometry) may be collected, and that my information will be stored, collected, used, disclosed, and destroyed pursuant to these policies. By signing, I acknowledge that I have been properly notified of the collection of my biometric information, and I consent to GetReal’s use, disclosure, and/or dissemination of my biometric information and identifiers for the purposes outlined in the policies, including, without limitation, to Amazon Rekognition.