Biometric Data Policy
This is the publicly available written retention and destruction schedule required by biometric privacy law, most notably the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.). It is published so that an employee, an auditor or a regulator can read it without asking anyone for it.
1. What this covers
This policy is issued by IT Solutions of LI Inc, which develops and operates the MetricsPro platform and is the party in possession of any biometric data held through it. Each business using the platform is a separate employer, and adopts this schedule as its own written policy for its own staff.
MetricsPro can support face verification at clock-in: comparing a live capture against a stored mathematical representation of a face (a “face descriptor” or template) to confirm that the person clocking in is the person the punch is recorded against.
That is the only biometric identification feature in the platform. It is off by default, and each employing business decides whether to enable it. A non-biometric alternative — a photo at clock-in with no face matching — is always available.
Separately, the mobile app can lock itself behind your phone's own Face ID or fingerprint. That is handled entirely by your device's operating system; that biometric data never leaves your device and never reaches us. It is not covered by this policy because we never receive it.
2. Why a template is collected
The sole purpose is verifying an employee's identity at clock-in, to prevent one employee clocking in for another. A template is not used for surveillance, marketing, analytics, performance evaluation, or any other purpose.
3. Consent
No face descriptor is captured without the employee's prior written consent, which discloses that biometric data is being collected, the specific purpose, and this retention schedule. Consent is recorded per employee with a status and a timestamp.
A declined or withdrawn consent takes precedence over every other setting: an employee who has declined is never face-matched, whatever the business has configured. Where a business turns the feature on after a period with it off, any employee without a consent record on file must be given the disclosure again and make a fresh decision before their template is used.
The employing business is responsible for delivering the notice and obtaining the release. We provide the mechanism; we are not the employer.
4. Retention and destruction schedule
A face descriptor is destroyed at the earliest of the following — “whichever occurs first”, as the statute requires:
| # | Trigger | Timing |
|---|---|---|
| 1 | Purpose satisfied — the person's employment ends | 90 calendar days after their last day of employment. A business may configure a different figure for its own HR process, from a minimum of 1 day up to the ceiling in row 4. It is never silently widened by us. |
| 2 | The employee asks | Immediately on request. |
| 3 | The business turns the feature off, having opted into purge-on-disable | Immediately, for every enrolled template at that business. |
| 4 | Statutory backstop | 1,095 days (3 years) after the person's last interaction with their own template — enrollment, re-enrollment, or a clock-in actually verified by face match. This applies whether or not a termination date is ever recorded. |
Row 4 is an absolute ceiling and cannot be extended by any business using the platform. It is what the law requires when the end of an employment relationship is never formally recorded.
Why 90 days rather than a year
The purpose the template was collected for — verifying a currently employed person at clock-in — is satisfied on that person's last working day. Under a “whichever occurs first” standard that trigger controls as soon as it is reached, regardless of any longer period a business might prefer. Ninety days is short enough to remain clearly purpose-bound while covering the practical realities of a rehire in the same quarter or a late-finalized final punch.
Turning the feature off does not by itself destroy templates
By default, disabling face recognition keeps existing templates so the business can turn it back on without asking everyone to re-enroll. A business that prefers the stronger posture can opt into destroying every template the moment the feature goes off (row 3 above).
5. The right to demand destruction
An employee may ask for their template to be destroyed at any time, through their employer or by writing to us at sales@itsolutionsli.com. It is destroyed immediately on that request, and they revert to the non-biometric clock-in method. Making the request has no effect on their pay or their employment, and the request itself is not a performance record.
6. Never sold, never shared
We do not and will not sell, lease, trade or otherwise profit from a biometric identifier or biometric information. Templates are not shared with any third party, are not used to train any external system, and are not disclosed except with the individual's consent, to complete a transaction they requested, or as expressly required by law or a valid warrant or subpoena.
7. Storage and safeguards
Templates are stored with the same or greater protection than we apply to other confidential information: encrypted transport, restricted access, tenant separation, and audit logging of privileged access. A template is a mathematical representation — it is not a photograph and cannot be used to reconstruct one.
8. Current status
Face recognition is currently disabled across the platform. This policy governs any templates still on file from before that change, and any future re-enablement by a business.
9. Review and contact
This policy is reviewed on any change to the retention schedule, the collection method, or applicable law, and in any event within twelve months. Questions: sales@itsolutionsli.com.