Biometric Data Policy

Effective: August 22, 2026 · Last updated: August 22, 2026

This is the publicly available written retention and destruction schedule required by biometric privacy law, most notably the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.). It is published so that an employee, an auditor or a regulator can read it without asking anyone for it.

1. What this covers

This policy is issued by IT Solutions of LI Inc, which develops and operates the MetricsPro platform and is the party in possession of any biometric data held through it. Each business using the platform is a separate employer, and adopts this schedule as its own written policy for its own staff.

MetricsPro can support face verification at clock-in: comparing a live capture against a stored mathematical representation of a face (a “face descriptor” or template) to confirm that the person clocking in is the person the punch is recorded against.

That is the only biometric identification feature in the platform. It is off by default, and each employing business decides whether to enable it. A non-biometric alternative — a photo at clock-in with no face matching — is always available.

Separately, the mobile app can lock itself behind your phone's own Face ID or fingerprint. That is handled entirely by your device's operating system; that biometric data never leaves your device and never reaches us. It is not covered by this policy because we never receive it.

2. Why a template is collected

The sole purpose is verifying an employee's identity at clock-in, to prevent one employee clocking in for another. A template is not used for surveillance, marketing, analytics, performance evaluation, or any other purpose.

3. Consent

No face descriptor is captured without the employee's prior written consent, which discloses that biometric data is being collected, the specific purpose, and this retention schedule. Consent is recorded per employee with a status and a timestamp.

A declined or withdrawn consent takes precedence over every other setting: an employee who has declined is never face-matched, whatever the business has configured. Where a business turns the feature on after a period with it off, any employee without a consent record on file must be given the disclosure again and make a fresh decision before their template is used.

The employing business is responsible for delivering the notice and obtaining the release. We provide the mechanism; we are not the employer.

4. Retention and destruction schedule

A face descriptor is destroyed at the earliest of the following — “whichever occurs first”, as the statute requires:

#TriggerTiming
1Purpose satisfied — the person's employment ends90 calendar days after their last day of employment. A business may configure a different figure for its own HR process, from a minimum of 1 day up to the ceiling in row 4. It is never silently widened by us.
2The employee asksImmediately on request.
3The business turns the feature off, having opted into purge-on-disableImmediately, for every enrolled template at that business.
4Statutory backstop1,095 days (3 years) after the person's last interaction with their own template — enrollment, re-enrollment, or a clock-in actually verified by face match. This applies whether or not a termination date is ever recorded.

Row 4 is an absolute ceiling and cannot be extended by any business using the platform. It is what the law requires when the end of an employment relationship is never formally recorded.

Why 90 days rather than a year

The purpose the template was collected for — verifying a currently employed person at clock-in — is satisfied on that person's last working day. Under a “whichever occurs first” standard that trigger controls as soon as it is reached, regardless of any longer period a business might prefer. Ninety days is short enough to remain clearly purpose-bound while covering the practical realities of a rehire in the same quarter or a late-finalized final punch.

Turning the feature off does not by itself destroy templates

By default, disabling face recognition keeps existing templates so the business can turn it back on without asking everyone to re-enroll. A business that prefers the stronger posture can opt into destroying every template the moment the feature goes off (row 3 above).

5. The right to demand destruction

An employee may ask for their template to be destroyed at any time, through their employer or by writing to us at sales@itsolutionsli.com. It is destroyed immediately on that request, and they revert to the non-biometric clock-in method. Making the request has no effect on their pay or their employment, and the request itself is not a performance record.

6. Never sold, never shared

We do not and will not sell, lease, trade or otherwise profit from a biometric identifier or biometric information. Templates are not shared with any third party, are not used to train any external system, and are not disclosed except with the individual's consent, to complete a transaction they requested, or as expressly required by law or a valid warrant or subpoena.

7. Storage and safeguards

Templates are stored with the same or greater protection than we apply to other confidential information: encrypted transport, restricted access, tenant separation, and audit logging of privileged access. A template is a mathematical representation — it is not a photograph and cannot be used to reconstruct one.

8. Current status

Face recognition is currently disabled across the platform. This policy governs any templates still on file from before that change, and any future re-enablement by a business.

9. Review and contact

This policy is reviewed on any change to the retention schedule, the collection method, or applicable law, and in any event within twelve months. Questions: sales@itsolutionsli.com.