Biometric Data Retention and Destruction Policy
Inovantics, LLC. publishes this policy as required by state biometric privacy laws, including the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) and comparable laws in other states.
Inovantics, LLC. publishes this policy as required by state biometric privacy laws, including the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) and comparable laws in other states. It explains what biometric data we collect, how long we keep it, and how we permanently destroy it.
Who This Applies To
This policy applies to drivers who enroll in face verification on the Inovantics platform.
Inovantics does not collect biometric data from students. We do not collect, capture, purchase, receive, or store any face scan, fingerprint, voiceprint, or other biometric identifier from any student, including students under 13. No student face template exists in our platform.
If we ever add a feature that captures student images, including in-vehicle cameras, we will not enable it until this policy is updated and republished, separate parental consent covering biometric collection is obtained, and a separate retention and destruction standard for student biometric data is published.
What We Collect
A scan of face geometry is a biometric identifier. The mathematical template created from it is biometric information. Both are covered by this policy. We do not treat template-only storage as removing data from the scope of this policy or of the law.
We collect and store the following:
- Enrollment photograph — one photograph of the driver's face, taken when they enroll.
- Face template — a mathematical representation of the driver's facial geometry, created from the enrollment photograph.
- Verification photograph — a photograph taken each time a driver begins a shift, compared against their face template.
- Verification records — the result, date, and time of each check.
- Driver's license image — supplied by the driver's transportation operator and used once at enrollment to confirm identity.
Why We Collect It
For one purpose: to verify that an authorized driver is the person beginning a transportation shift, and to maintain a record of that verification for the transportation operator and the school district.
We do not use biometric data for marketing, profiling, behavioral analysis, productivity monitoring, attendance, or any purpose other than driver identity verification and the compliance record it produces.
Our Destruction Standard
Inovantics permanently destroys each biometric identifier and item of biometric information when the initial purpose for collecting it has been satisfied, or within three years of the individual's last interaction with Inovantics, whichever occurs first.
Three years is an outer limit, not a target. Where the purpose ends sooner — when a driver separates from their transportation operator, or withdraws consent — destruction occurs at that earlier point.
Retention Schedule
- Enrollment photograph — destroyed 90 days after the enrollment decision is made, by an automated nightly process.
- Verification photograph — destroyed 90 days after capture, by an automated nightly process. No copy is retained on the driver's device.
- Face template — destroyed when the driver separates from their transportation operator or withdraws consent, and in no case later than three years after the driver's last use of the platform.
- Verification records — retained for three years. Biometric-derived values, including match confidence scores, are removed at the time the record is written. The retained record shows only that a verification occurred, its result, and when.
- Driver's license image — retained while the driver is active, and destroyed three years after the driver separates or withdraws consent.
- Backup copies — backups are retained for seven days. Destroyed data is removed from backup systems within that window.
How We Destroy It
Destruction is permanent. We do not mark records inactive in place of deleting them.
When a retention period ends, or when a driver withdraws consent, we:
- Delete the data from all production databases
- Remove it from all active indexes and caches
- Purge it from backup systems within the seven-day backup window
- Record the destruction in a log that cannot be altered, including the data type, the trigger, the date, and confirmation the deletion succeeded
Destruction following a withdrawal request is completed within 30 days, and we confirm it to the driver in writing.
How We Store and Protect It
Biometric data is transmitted over encrypted connections and stored in access-restricted cloud storage. Access is limited to personnel with a specific operational need, and access events are logged.
We protect biometric data using the reasonable standard of care for our industry, and in a manner at least as protective as the manner in which we store and protect other confidential and sensitive information.
We Do Not Sell or Profit From Biometric Data
Inovantics does not sell, lease, trade, or otherwise profit from any biometric identifier or biometric information.
We do not disclose or disseminate biometric data except as necessary to provide the verification service described in the driver consent agreement, or where required by valid legal process.
We Do Not Use an Outside Face Recognition Service
Face processing runs on servers controlled by Inovantics using publicly available, commercially licensed software components. Biometric data is not sent to any third-party facial recognition provider.
Driver biometric data is never used to train, tune, or improve any model.
Consent Is Required Before Collection
We obtain a written release from each driver before any biometric data is collected. The consent form is presented on its own, separately from any terms of service, privacy policy, or employment agreement.
Drivers may withdraw consent at any time in writing. Withdrawal triggers destruction as described above.
Enrollment Is Voluntary
Inovantics does not employ drivers. Transportation operators do. Our agreements with transportation operators require that they not condition employment, continued employment, compensation, or route assignment on a driver's enrollment in biometric verification. A driver who declines is verified through the operator's standard manual process.
A failed biometric match does not, by itself, prevent a driver from beginning a shift. A failed match is escalated to the transportation operator for manual verification by a person, and the escalation is recorded.
Changes to This Policy
We may update this policy. Material changes to our retention or destruction practices will be posted here with a revised effective date, and drivers will be notified where required by law. Prior versions are archived and available on request.
