Biometric Data Retention & Destruction Policy

Saconde & Saconde, LLC — Biometric Data Retention and Destruction Policy — Effective Date: July 11, 2026

Saconde & Saconde, LLC
Effective Date: July 11, 2026
Company Name: Saconde & Saconde, LLC
Principal Place of Business: New York, New York, United States
Website: www.saconde.com
Mobile Applications: Saconde mobile applications, including applications made available for iOS, Android, or other supported platforms
Retail/Showroom Location: 521 W 26th St, Floor 5, New York, NY 10001
Contact: hello@saconde.com

1. PURPOSE

Saconde & Saconde, LLC, doing business as Saconde (“Saconde,” “Company,” “we,” “us,” or “our”), adopts this Biometric Data Retention and Destruction Policy (“Policy”) to establish:

This Policy is intended to satisfy or exceed the requirements of applicable law, including laws that require a publicly available written biometric retention and destruction policy.

2. SCOPE

This Policy applies to Biometric Data collected, captured, received, generated, converted, stored, possessed, controlled, used, disclosed, or otherwise processed by or on behalf of Saconde in connection with:

This Policy applies to:

3. DEFINITIONS

3.1 Biometric Identifier

“Biometric Identifier” means a biological, physiological, or behavioral characteristic, or data generated through automated measurement of such a characteristic, used or intended to identify or authenticate a particular individual.

Examples may include:

3.2 Biometric Information

“Biometric Information” means information based on, derived from, or generated from a Biometric Identifier and used or intended to identify or authenticate an individual.

3.3 Biometric Data

“Biometric Data” means Biometric Identifiers and Biometric Information, subject to applicable statutory definitions and exclusions.

3.4 Authentication Metadata

“Authentication Metadata” means non-biometric records associated with an authentication event, such as:

Authentication Metadata is not treated as Biometric Data unless it contains, is derived from, or is reasonably capable of being used as covered biometric information under applicable law.

3.5 Permanent Destruction

“Permanent Destruction” means deletion, erasure, cryptographic destruction, secure overwriting, physical destruction, or another process reasonably designed to render information permanently unreadable, unrecoverable, and incapable of reconstruction in the ordinary course of business.

4. POLICY PRINCIPLES

Saconde will follow these principles:

  1. Purpose limitation: Collect and use Biometric Data only for specific, disclosed, legitimate, and lawful purposes.
  2. Data minimization: Collect only the minimum information reasonably necessary and proportionate to the purpose.
  3. Consent: Obtain advance notice and affirmative consent when required.
  4. Alternative access: Provide a reasonable non-biometric alternative when required or reasonably practicable.
  5. No sale: Never sell, lease, trade, or otherwise profit from Biometric Data.
  6. Limited disclosure: Disclose Biometric Data only as authorized by law and this Policy.
  7. Security: Protect Biometric Data using safeguards appropriate to its sensitivity.
  8. Limited retention: Retain Biometric Data only for as long as reasonably necessary and legally permitted.
  9. Permanent destruction: Permanently destroy Biometric Data when the applicable retention period expires.
  10. Accountability: Document collection, access, disclosure, retention, and destruction where reasonably practicable.
  11. Privacy by design: Evaluate privacy and security risks before introducing a new biometric technology.
  12. No repurposing: Do not materially change the purpose without additional notice and consent where required.

5. DEVICE-NATIVE BIOMETRIC LOGIN

Saconde’s preferred biometric-login architecture is device-native authentication.

For device-native authentication:

Where Saconde does not possess the underlying Biometric Data, this Policy does not require Saconde to destroy information it never received or controlled. Users must manage biometric enrollment stored by their device through the device’s settings.

Authentication Metadata will be retained under Saconde’s general security-log schedule rather than as raw Biometric Data, unless applicable law requires different treatment.

6. APPROVED PURPOSES

Saconde may process Biometric Data only for an approved purpose, including:

The following uses are prohibited unless expressly authorized by law and approved through enhanced legal review:

7. APPROVAL OF NEW BIOMETRIC TECHNOLOGY

Before implementing or materially changing biometric technology, Saconde must complete a documented review addressing:

No business unit, employee, contractor, or service provider may independently deploy biometric technology on Saconde’s behalf without written authorization.

8. NOTICE AND CONSENT REQUIREMENTS

Before directly collecting or obtaining Biometric Data, Saconde must provide a clear notice that identifies:

Where required, Saconde must obtain a written release or affirmative consent before collection.

Consent must be:

Silence, inactivity, or use of a service without an affirmative action will not constitute consent where affirmative consent is required.

Saconde will not use dark patterns to obtain consent.

9. RETENTION SCHEDULE

9.1 General Rule

Saconde will retain Biometric Data only until the earliest of:

  1. satisfaction of the initial purpose for collection;
  2. expiration of the applicable period listed below;
  3. withdrawal of consent, where no other lawful basis permits continued retention;
  4. completion of a verified deletion request;
  5. termination of the relationship that justified collection;
  6. expiration of a legally required retention period;
  7. or another date required by applicable law.

9.2 Device-Native Biometric Login

Data retained by Saconde: Saconde generally retains no raw biometric identifier or template.

Authentication Metadata: Ordinarily retained for up to 24 months after the authentication event for security, fraud prevention, auditing, and troubleshooting, unless:

Biometric-login preference: Retained until:

9.3 Directly Collected Biometric Login Templates

Saconde should not ordinarily collect or retain a central biometric-login template.

If Saconde later implements such a system, the template must be destroyed by the earliest of:

9.4 Identity-Verification Selfies, Videos, and Derived Face Data

Unless a supplemental notice specifies a shorter period:

A raw image may be retained longer only when:

When an exception ends, the data must be promptly destroyed.

9.5 Account Recovery

Biometric Data collected solely for account recovery must be destroyed:

A non-biometric record confirming that account recovery occurred may be retained under the applicable security-log schedule.

9.6 Fraud and Security Investigations

Biometric Data associated with a documented fraud or security investigation may be retained until:

Access must be restricted, and the reason for extended retention must be documented.

9.7 Employees and Contractors

Biometric Data collected from an employee or contractor must be destroyed by the earliest of:

Saconde should avoid retaining employee biometric templates centrally when device-native or card-based alternatives are reasonably available.

9.8 Applicants

Applicant Biometric Data must be destroyed when:

9.9 Physical Retail Locations

Biometric Data collected at a physical retail location must be retained only as long as necessary for the disclosed purpose.

Saconde may not implement customer facial-recognition or biometric-identification technology in a New York City retail location without first completing a legal review and implementing all legally required signage, notices, restrictions, and consent mechanisms.

9.10 Backups

Where Biometric Data exists in backups:

If technical limitations prevent immediate deletion from an immutable backup, Saconde must isolate the information from active processing and delete it when technically feasible.

9.11 Legal Holds

A legal hold temporarily suspends destruction only for information relevant to:

The legal hold must:

10. STRICTEST-APPLICABLE RETENTION RULE

When multiple laws apply, Saconde will use the shortest legally applicable retention period unless:

As a nationwide operational baseline:

11. DESTRUCTION PROCEDURES

When destruction is required, Saconde will use methods reasonably designed to prevent reconstruction or future use.

Depending on the storage medium, methods may include:

Deletion must include:

12. DESTRUCTION DOCUMENTATION

Saconde should maintain records sufficient to demonstrate compliance, including:

A destruction log must not itself contain unnecessary Biometric Data.

13. SERVICE-PROVIDER REQUIREMENTS

Before a service provider may process Biometric Data, Saconde must conduct reasonable due diligence concerning:

Contracts should require the provider to:

  1. process Biometric Data only on documented instructions;
  2. use the information only for specified purposes;
  3. maintain confidentiality;
  4. implement appropriate security;
  5. limit access;
  6. prohibit sale and advertising use;
  7. prohibit independent profiling;
  8. avoid combining the data with unrelated information except as authorized;
  9. notify Saconde of a security incident without unreasonable delay;
  10. assist with privacy requests;
  11. maintain accurate records;
  12. delete or return Biometric Data at the end of services;
  13. require equivalent protections from subprocessors;
  14. permit reasonable compliance review or audit;
  15. comply with applicable retention deadlines;
  16. provide written deletion certification upon request;
  17. and notify Saconde before making a legally compelled disclosure unless prohibited by law.

14. DISCLOSURE RESTRICTIONS

Saconde will not disclose or disseminate Biometric Data except:

Before disclosing Biometric Data, Saconde should document:

15. PROHIBITION ON SALE AND MONETIZATION

Saconde will not:

Biometric Data will not be used as consideration in an advertising, analytics, data-broker, or commercial-data arrangement.

16. INFORMATION SECURITY

Saconde will maintain safeguards proportionate to the sensitivity of Biometric Data, including, where appropriate:

Biometric Data may not be stored:

17. ACCESS CONTROLS

Access to Biometric Data must be limited to personnel who require it for an authorized purpose.

Saconde should:

Employees and contractors may not copy, export, share, or use Biometric Data for an unauthorized purpose.

18. DEVELOPMENT AND TESTING

Saconde will not use identifiable production Biometric Data in development, quality-assurance, demonstration, or testing environments unless:

Synthetic, anonymized, or non-identifiable test data should be used whenever possible.

19. DATA-PROTECTION ASSESSMENTS

Saconde will conduct and document a data-protection assessment before engaging in biometric processing that presents a heightened risk of harm or where an assessment is required by law.

The assessment should evaluate:

20. INDIVIDUAL RIGHTS REQUESTS

Saconde will maintain procedures for receiving and responding to requests to:

Requests may be submitted to [INSERT PRIVACY EMAIL] or through [INSERT PRIVACY REQUEST URL].

Saconde will:

21. MINORS

Saconde will not knowingly process a minor’s Biometric Data without legally required authorization.

Before collecting a minor’s Biometric Data, Saconde must determine whether:

Biometric Data of minors must not be used for advertising, unrelated profiling, or commercial surveillance.

22. INCIDENT-RESPONSE PROCEDURES

A suspected loss, unauthorized access, acquisition, disclosure, alteration, or destruction of Biometric Data must be reported immediately to Saconde’s designated privacy and security personnel.

Saconde’s response will include, as appropriate:

  1. containment;
  2. preservation of relevant evidence;
  3. identification of affected systems and individuals;
  4. assessment of the type of Biometric Data involved;
  5. determination of whether the information was encrypted or otherwise protected;
  6. investigation of the cause and scope;
  7. engagement of service providers or forensic specialists;
  8. legal analysis of notification duties;
  9. notification to individuals, regulators, law enforcement, insurers, or business partners where required;
  10. remediation;
  11. documentation;
  12. review of retention and access controls;
  13. and corrective action.

Because biometric characteristics generally cannot be reissued in the same manner as a password, incidents involving Biometric Data will be treated as high priority.

23. STATE-SPECIFIC REQUIREMENTS

23.1 Illinois

Saconde will:

23.2 Texas

Saconde will:

23.3 Washington

Saconde will:

23.4 Colorado

Saconde will:

23.5 California

Where California law applies, Saconde will:

23.6 New York City

At covered New York City retail locations, Saconde will:

23.7 Comprehensive State Privacy Laws

Where biometric data is defined as sensitive data under an applicable state privacy law, Saconde will:

24. COMPLIANCE AUDITS

Saconde will periodically review its biometric practices to determine:

Material findings must be documented and remediated.

25. TRAINING

Personnel who access, manage, develop, procure, or oversee biometric technology must receive appropriate training concerning:

26. ENFORCEMENT

Violations of this Policy may result in:

Employees and contractors must promptly report suspected noncompliance.

27. POLICY OWNERSHIP

Saconde’s designated privacy officer, legal function, or other authorized executive is responsible for:

Saconde should designate, in writing:

28. ANNUAL REVIEW

This Policy will be reviewed:

29. CHANGES TO THIS POLICY

Saconde may amend this Policy to reflect changes in law, technology, services, or business practices.

A material change that expands the collection or use of Biometric Data will not be applied to previously collected information without additional notice and consent where required.

The “Last Updated” date identifies the most recent revision.

30. CONTACT

Questions, concerns, or requests regarding this Policy may be submitted to:

Saconde, LLC
Attn: Biometric Privacy
521 W 26th St, Floor 5
New York, NY 10001
United States

Email: hello@saconde.com
Website: www.saconde.com