Skip to main content

    Biometric Retention & Destruction Policy

    Effective Date: January 1, 2026 · Last Updated: July 20, 2026

    This Biometric Retention & Destruction Policy ("Retention Policy") sets out how long biometric identifiers, biometric information, and identity-verification documents are retained in connection with the Corbivo platform, and how they are destroyed. It is published in satisfaction of BIPA's requirement to maintain a publicly available written retention schedule and destruction guidelines.

    1. Scope

    This Retention Policy applies to biometric identifiers, biometric information, government ID images, selfies, liveness data, and verification artifacts processed for identity verification. This data is held by our processor, Didit; Corbivo itself stores only verification status, a verification reference identifier, full legal name, and date of birth.

    2. Retention Schedule

    Data Category Custodian Retention Period
    Government ID images Didit Per Didit retention policy / contract; destroyed no later than 3 years after last interaction or when purpose satisfied
    Selfie images Didit Same as above
    Facial recognition templates Didit Same as above
    Liveness recordings/data Didit Same as above
    Verification artifacts / audit info Didit Retained for audit/compliance per contract, then destroyed
    Verification status Corbivo Duration of account plus fraud/legal recordkeeping period
    Verification reference ID Corbivo Same as verification status
    Full legal name, date of birth Corbivo Duration of account plus legal recordkeeping period

    Consistent with BIPA, biometric identifiers and biometric information are destroyed when the initial purpose for collection has been satisfied or within three (3) years of the individual's last interaction with Corbivo, whichever occurs first.

    3. Trigger Events for Destruction

    • The verification purpose has been satisfied and no ongoing legal basis to retain remains.
    • Three (3) years have elapsed since the user's last interaction with Corbivo.
    • The user withdraws consent or submits a valid deletion request.
    • Account closure, subject to fraud-prevention and legal-hold exceptions.

    4. Deletion Schedule and Process

    Upon a trigger event, Corbivo submits a deletion instruction to Didit. Didit destroys the applicable biometric and identity-document data using commercially reasonable methods that render it permanently unrecoverable, within the timeframe specified in our contract. Corbivo separately deletes or de-identifies the verification result data it holds. Deletion from active systems occurs promptly; residual copies in backups are overwritten in the ordinary backup-rotation cycle.

    5. Legal Hold Exceptions

    Destruction may be suspended where retention is required to comply with a legal obligation, respond to a valid warrant or subpoena, preserve evidence for pending or reasonably anticipated litigation, or investigate suspected fraud. When the legal-hold basis ends, the data is destroyed under the ordinary schedule.

    6. Vendor Responsibilities

    By contract, Didit is required to: (a) retain biometric and identity-verification data only as long as permitted; (b) destroy such data on Corbivo's instruction and in accordance with its published retention policy; (c) maintain appropriate safeguards; (d) restrict use to providing verification services to Corbivo; (e) not sell or profit from the data; and (f) provide records reasonably necessary to demonstrate compliance.

    7. Compliance and Review

    Corbivo reviews this Retention Policy at least annually and updates it as laws, vendor terms, or business practices change. Questions may be directed to privacy@corbivo.com.

    We use cookies and similar technologies to improve your experience. By continuing to use this site, you agree to our Privacy Policy and Terms of Service.