Biometric data retention policy
Version: v1.0
Effective Date: August 22, 2025
Last Updated: August 22, 2025
1. Purpose of This Schedule
This Biometric Retention Schedule explains how Domesta collects, retains, and deletes biometric data used for identity verification, fraud prevention, and trust & safety purposes.
Biometric data includes facial geometry extracted from selfies compared against government-issued IDs during onboarding or verification.
2. Retention Periods
- Raw Biometric Images (ID scans, selfies): Deleted within 90 days after the verification process is completed.
- Verification Outcomes (pass/fail status, fraud flags, audit logs): Retained for up to 7 years, or as long as necessary to:
- Prevent fraudulent activity.
- Resolve disputes or chargebacks.
- Comply with tax, audit, and regulatory obligations.
3. Purpose Limitation
- Biometric data is used only for verification, safety, and compliance purposes.
- Data is never sold, shared for advertising, or reused for unrelated activities.
4. Deletion & Destruction
- Raw biometric images are securely deleted within the retention window stated above.
- Verification outcome records are destroyed once they are no longer needed for fraud prevention, dispute resolution, or compliance.
5. Contact Information
For questions about biometric data retention or to exercise your rights, contact:
Data Protection Officer (DPO): dpo@domesta.com
Support: info@domesta.com