Dieser Inhalt ist auf Englisch verfügbar, während die Übersetzung geprüft wird. · Machine translation preview
LEGAL

Biometric Data Policy

Conditions for any biometric processing, including notice, consent, alternatives, restricted use and destruction.

Last updated: 1. Oktober 2026 · Version 1.0

1. Scope and current website behavior

HireValid is operated by Recordskeeper Inc, a Delaware C-Corp. Our business mailing address is 2261 Market Street STE 86483, San Francisco, CA 94114. The marketing website and its interactive integrity demonstrations do not collect biometric identifiers or activate your camera. This policy sets conditions for any separately enabled assessment feature involving biometric processing; it is not a statement that face recognition is enabled for every assessment.

2. Images and biometric identifiers

Ordinary photographs and video are not necessarily biometric identifiers. Extracting face geometry, a voiceprint or another identifier for recognition may constitute regulated biometric processing. The employer and HireValid must identify the actual processing, applicable law and responsible parties before enabling it.

3. Notice and authorization before collection

Where biometric processing is offered, the person must receive a written explanation of the data collected, specific purpose, intended retention period, recipients and rights before collection. Obtain a written release or other legally required affirmative authorization. A general website privacy notice or acceptance of unrelated terms is not a substitute for the required biometric consent.

4. Purpose and disclosure restrictions

Use biometric information only for the disclosed, authorized purpose. Do not sell, lease, trade or otherwise profit from it, use it for advertising or unrelated model training, or infer health, ethnicity or emotion. Disclosure requires the individual’s authorization or a specific legal exception, such as a valid legal demand. Providers must be bound by equivalent restrictions.

5. Retention and permanent destruction

A specific retention schedule must be disclosed before collection. Destroy biometric identifiers and derived templates permanently when the stated purpose is satisfied or the applicable legal retention limit is reached, whichever is earlier. Where Illinois BIPA applies, destruction is required when the initial purpose is satisfied or within three years of the individual’s last interaction, whichever occurs first, subject to a valid warrant or subpoena. Three years is an outer limit, not a default storage period. Copies and provider-held templates must be included in the destruction process.

6. Safeguards and alternatives

Apply reasonable care and safeguards at least as protective as those used for other confidential sensitive information, including restricted access and secure storage and transmission. Candidates should contact the employer for a non-biometric route or reasonable accommodation where required. Withdrawal requests must be assessed promptly, explaining any lawful consequences for an in-progress verification without coercion.

7. Requests and concerns

Contact [email protected] or use the Privacy topic on our contact form. We may request proportionate information to verify your identity or authority; do not send identity documents unless requested through an appropriate channel. Identify the employer and assessment where possible. We coordinate requests with the responsible employer and investigate collection outside this policy. No Delaware forum clause removes non-waivable biometric privacy rights.