Biometric Retention & Destruction Policy
Effective Date: January 1, 2026 · Last Updated: July 20, 2026
This Biometric Retention & Destruction Policy ("Retention Policy") sets out how long biometric identifiers, biometric information, and identity-verification documents are retained in connection with the Corbivo platform, and how they are destroyed. It is published in satisfaction of BIPA's requirement to maintain a publicly available written retention schedule and destruction guidelines.
1. Scope
This Retention Policy applies to biometric identifiers, biometric information, government ID images, selfies, liveness data, and verification artifacts processed for identity verification. This data is held by our processor, Didit; Corbivo itself stores only verification status, a verification reference identifier, full legal name, and date of birth.
2. Retention Schedule
| Data Category | Custodian | Retention Period |
|---|---|---|
| Government ID images | Didit | Per Didit retention policy / contract; destroyed no later than 3 years after last interaction or when purpose satisfied |
| Selfie images | Didit | Same as above |
| Facial recognition templates | Didit | Same as above |
| Liveness recordings/data | Didit | Same as above |
| Verification artifacts / audit info | Didit | Retained for audit/compliance per contract, then destroyed |
| Verification status | Corbivo | Duration of account plus fraud/legal recordkeeping period |
| Verification reference ID | Corbivo | Same as verification status |
| Full legal name, date of birth | Corbivo | Duration of account plus legal recordkeeping period |
Consistent with BIPA, biometric identifiers and biometric information are destroyed when the initial purpose for collection has been satisfied or within three (3) years of the individual's last interaction with Corbivo, whichever occurs first.
3. Trigger Events for Destruction
- The verification purpose has been satisfied and no ongoing legal basis to retain remains.
- Three (3) years have elapsed since the user's last interaction with Corbivo.
- The user withdraws consent or submits a valid deletion request.
- Account closure, subject to fraud-prevention and legal-hold exceptions.
4. Deletion Schedule and Process
Upon a trigger event, Corbivo submits a deletion instruction to Didit. Didit destroys the applicable biometric and identity-document data using commercially reasonable methods that render it permanently unrecoverable, within the timeframe specified in our contract. Corbivo separately deletes or de-identifies the verification result data it holds. Deletion from active systems occurs promptly; residual copies in backups are overwritten in the ordinary backup-rotation cycle.
5. Legal Hold Exceptions
Destruction may be suspended where retention is required to comply with a legal obligation, respond to a valid warrant or subpoena, preserve evidence for pending or reasonably anticipated litigation, or investigate suspected fraud. When the legal-hold basis ends, the data is destroyed under the ordinary schedule.
6. Vendor Responsibilities
By contract, Didit is required to: (a) retain biometric and identity-verification data only as long as permitted; (b) destroy such data on Corbivo's instruction and in accordance with its published retention policy; (c) maintain appropriate safeguards; (d) restrict use to providing verification services to Corbivo; (e) not sell or profit from the data; and (f) provide records reasonably necessary to demonstrate compliance.
7. Compliance and Review
Corbivo reviews this Retention Policy at least annually and updates it as laws, vendor terms, or business practices change. Questions may be directed to privacy@corbivo.com.