Biometric Data Policy
Last updated: June 15, 2026
Introduction
This Biometric Data Policy governs the collection, use, storage, and deletion of biometric data by Bruxus. We are committed to protecting biometric information with the highest level of security and transparency.
Definition
Biometric data refers to personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of an individual, which allows or confirms the unique identification of that individual. This includes facial recognition, fingerprint scans, voice patterns, and iris scans.
Collection of Biometric Data
Bruxus does not actively collect biometric data as part of its core platform services. However, the following scenarios may involve biometric data:
- User-uploaded content: Users may upload images or videos containing biometric data through their projects built on Bruxus.
- Third-party integrations: Integrations with authentication providers that use biometric verification (e.g., Apple Face ID, Windows Hello).
Legal Basis
Where Bruxus processes biometric data, we do so only under the following legal bases:
- Explicit consent obtained from the data subject
- Legal obligation under applicable law
- Substantial public interest as defined by regulation
Data Protection Principles
When processing biometric data, we adhere to:
- Purpose limitation: Biometric data is used only for the specific purpose disclosed at the time of collection
- Data minimization: We collect only the minimum biometric data necessary
- Storage limitation: Biometric data is retained only as long as necessary
- Security: Biometric data is encrypted and stored separately from other personal data
Rights of Data Subjects
Individuals whose biometric data is processed have the right to:
- Be informed about the processing of their biometric data
- Access their biometric data
- Request deletion of their biometric data
- Withdraw consent at any time
- File a complaint with the relevant supervisory authority
Data Retention and Deletion
Biometric data is deleted when:
- The purpose for which it was collected has been fulfilled
- The data subject withdraws consent
- A legal retention period expires
- Upon termination of the relevant service agreement
Security Measures
Biometric data is protected through:
- Encryption at rest using AES-256
- Encryption in transit using TLS 1.3
- Pseudonymization where possible
- Strict access controls with audit logging
- Regular security assessments
Contact
For questions about this Biometric Data Policy, contact privacy@bruxus.com.
