> For the complete documentation index, see [llms.txt](https://devcenter.unico.io/privacy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://devcenter.unico.io/privacy/usa/policies/unico-biometric-data-policy.md).

# Unico Biometric Data Policy

Effective Date: August 15, 2026

#### 1. Our Commitment

Unico ("we," "us") provides identity verification services that may involve biometric data. This policy explains how we collect, use, and protect this information globally.

We may process data as a data processor (on behalf of a Customer) or a data controller (where we determine the purpose). If we act as a processor, the Customer is responsible for your notice and consent.

#### 2. What is Biometric Data?

For purposes of this policy:

1. Biometric Identifier: A scan of facial geometry.

2. Biometric Data: Information derived from an identifier used to identify you, such as facial data from a selfie or video.

This policy is intended to reflect the general principles found across applicable biometric and data privacy laws worldwide, including notice, consent, purpose limitation, retention limits, and destruction obligations. It does not enumerate every jurisdiction's specific requirements; where a law grants rights beyond what is described here, that law governs.

#### 3. Why We Collect Data

We collect biometric data to:

1. Conduct a facial scan to support our customers’ identity verification and fraud prevention processes.&#x20;
2. Perform liveness detection to ensure the selfie represents a real person.

Unico does not sell, lease, or trade Biometric Data, and does not use it for advertising or marketing.

#### 4. Data Sharing

We only share biometric data when:

1. You or your representative provides consent.
2. It is required to complete a transaction you initiated.
3. Required by law, valid court order, or subpoena

Any vendor or service provider that processes Biometric Data on Unico's behalf does so under a contract requiring it to protect the data and use it solely to deliver the contracted service.

#### 5. How Long We Keep Data

We delete data as soon as:

1. The initial purpose for collection is fulfilled.
2. The maximum retention period of 1 year, designed to comply with or exceed applicable state laws, including:
3. Illinois (BIPA): Within 1 year of your last interaction with Unico, or when the initial purpose for collection is satisfied, whichever occurs first.
4. Texas (CUBI): No later than 1 year after the purpose for collection expires or 1 year after the data is no longer required to be maintained by law.
5. Colorado (CPA): The earliest of (i) fulfillment of the collection purpose, (ii) 1 year from your last interaction with Unico, or (iii) within 45 days of an annual review determining storage is no longer necessary.
6. Washington (RCW 19.375): Up to 1 year, or as long as reasonably necessary to provide the services, protect against fraud or security threats, or satisfy legal obligations.
7. You request deletion (if we are the controller) or we receive a deletion instruction from a Customer (if we are the processor).

Once retention is no longer required, Biometric Data is securely and permanently destroyed, unless further retention is required by law.

#### 6. Security Standards

Unico has taken reasonable measures designed to secure biometric information, during collection, use, and storage, from unauthorized acquisition. Unico’s data security practices are appropriate based on the volume, scope, and the nature of the biometric information it processes and nature of our business.&#x20;

#### 7. Your Privacy Rights

Depending on your location, you may have the right to access, correct, or delete your data. To exercise these rights, contact the business that directed you to us, or reach out to our team below. Additional information is included in our [Privacy Notice](https://devcenter.unico.io/privacy/usa/policies/privacy-policy).

#### 8. Changes to This Policy

Unico may update this policy from time to time. Material changes will be posted here, together with the effective date above.

#### 9. Contact Us

Privacy Team&#x20;

[privacy.us@unico.io](mailto:privacy@unico.io)

\ <br>
