← Chronox

Biometric Data Retention & Destruction Policy

Version 1.5 · Effective July 30, 2026 (v1.5: the anti-spoofing (liveness) description is updated for the engine actually in force - the standard liveness verdict is now produced server-side by Luxand, Inc. (USA) on the punch-moment image, which is sent without any name or identifier, is deleted by Luxand within 90 days of upload under its published policy, and is never used for training; the AWS Rekognition Face Liveness browser flow is described as the certified per-company alternative; Chronox-side retention and destruction schedules are unchanged. Prior: v1.4, July 25, 2026 - Photo-mode retention ceiling corrected to 90 days; matching-engine description corrected to cloud AWS Rekognition; v1.3, July 18, 2026 - face-photograph disclosure corrected, Quebec marked not currently offered; v1.1, contact address corrected July 5, 2026) · Chronox is operated by Foundation Digital LLC · This policy is also shown inside the Chronox app before any biometric enrollment, and publication precedes any collection.

1. Scope

This policy governs biometric identifiers and biometric information created by Chronox facial-recognition timekeeping. All face matching in production today runs in the cloud: face-geometry templates and identifiers are held in AWS Rekognition (one collection per customer company, us-west-2, Oregon, USA), and this is the configuration in use for every company. The anti-spoofing (liveness) verdict for each scan and enrollment is produced server-side by Luxand, Inc. (USA): the single punch-moment camera image is forwarded to Luxand without any name or identifier, is used solely for that verdict, and is deleted by Luxand within 90 days of upload under its published policy (Chronox does not grant Luxand's optional training consent). A company may instead be switched to the certified cloud liveness tier, in which short liveness video frames stream from the worker's browser directly to AWS Rekognition Face Liveness. Chronox also ships an optional on-device matching path (Neurotechnology VeriLook offline templates and device template caches). That path is not enabled for any company and no offline templates exist. If it is enabled in the future, the offline templates and device caches it creates are biometric identifiers and are governed by this policy on the same terms. Punch records (timestamps, GPS fixes, match scores) are separate, non-biometric business records governed by the time-record schedule in section 6; at-punch GPS coordinates specifically are retained for up to 6 years and then anonymized, while the punch record itself is kept per that schedule.

Face photographs. Chronox does not retain photographs of faces on its servers, and no face photograph is ever viewable by your employer or by Chronox staff - camera images are converted to non-reversible mathematical templates and discarded. One narrow exception: where offline enrollment is enabled, a single encrypted enrollment image may remain on the enrolling device only until that device next reconnects; it is then transmitted securely to our verification provider to create the face template and is automatically deleted from the device. It is never copied to Chronox servers and is never used for any other purpose. The image forwarded to Luxand for the liveness check is never retained by Chronox; on Luxand's side it is unlinkable (no identifiers accompany it) and ages out under Luxand's published deletion window of no more than 90 days. Timekeeping photos captured in the separate, non-biometric Photo mode (plain selfies with no face recognition) are governed by the Photo-mode policies - retained for a company-configured period that can never exceed 90 days (90 days is both the default and the system-enforced maximum), then automatically deleted with a receipt.

2. Purpose limitation

Biometric identifiers are collected, used, and retained for exactly one purpose: verifying an enrolled employee's identity to record the start and end of work periods and breaks during their employment. They are never used for surveillance, profiling, or marketing, and are never sold, leased, traded, or otherwise profited from.

3. Retention rule

A biometric identifier is retained only while that purpose persists - while the individual remains an enrolled, employed worker of the customer company.

4. Destruction deadlines

Identifiers are permanently destroyed at the first of:

  1. End of employment - an automated purge fires when the employee record is deactivated;
  2. A processed revocation request - an employee may withdraw consent in writing through their employer at any time;
  3. The statutory deadline for the governing jurisdiction: Illinois (BIPA) - no later than 3 years after the individual's last interaction (also Chronox's conservative default everywhere); Colorado - no later than 24 months after last interaction, or 45 days after an annual review concludes storage is no longer necessary; Texas - no later than 1 year after the purpose ends; Quebec - when the purpose is fulfilled (Face ID is not currently offered in Quebec; listed for completeness).

5. Destruction method and proof

Destruction is automated and receipted: AWS DeleteFaces is called for every stored FaceId; offline template rows are deleted; authorized crew devices purge their local caches at next synchronization; and an append-only deletion receipt (what was destroyed, when, and why) is recorded. Failed deletions are retried and surfaced to an integrity audit until resolved. Liveness images held transiently by Luxand carry no identifiers, cannot be mapped to an individual by Luxand, and are deleted by Luxand within 90 days of upload under its published policy - they sit outside the per-individual destruction pipeline precisely because nothing Luxand holds is linked to an individual.

6. Time records are separate

Non-biometric time and payroll records are retained per employment-law schedules (default 7 years) to satisfy wage-hour record-keeping duties. Destroying a face template never alters or deletes any punch or payroll record, and vice versa.

7. Security

Biometric data is protected using a standard of care at least equal to Chronox's other confidential information: TLS in transit; encryption at rest (including keystore-backed AES-256-GCM encryption of offline templates on devices, where the offline path is enabled - it is not enabled today); strict per-company and per-crew access control enforced in the database; written consent required by a database trigger before any enrollment can activate; and append-only consent, event, and audit logs.

8. Incidents

Suspected security incidents involving biometric data follow the Chronox Incident Response Plan. Affected individuals, customers, and regulators are notified as required by applicable law.

9. Contact

Privacy questions, revocation requests, and access requests: privacy@chronoxapp.net. Employee requests are routed through, and verified by, the employer.