Biometric Data Policy

Last updated: July 24, 2026

Twomagnets LLC d/b/a Clipboard Health (“Clipboard,” “we,” “us”) uses facial-recognition technology to verify the identity of the independent healthcare professionals who use our marketplace. This Policy explains what biometric data we collect, why, how long we keep it, and how we protect and delete it. It is our publicly available written policy under the Illinois Biometric Information Privacy Act (BIPA) and the Colorado Privacy Act, and it supports our compliance with other state biometric and privacy laws.

1. What this Policy covers

This Policy covers “biometric identifiers” and “biometric information” — specifically, scans of facial geometry (“faceprints”) that we create from verification selfies and from government-issued ID photos, identity photos, and other photos that professionals submit to us and through our third-party identity-verification providers, as well as subsequent verification photos (including but not limited to selfies) that may be requested periodically as part of our ongoing identity verification process. It does not cover photographs themselves, or data that is not used to identify an individual.

2. What we collect and why

We collect and use faceprints only to:

  • verify that a professional is who they claim to be (identity verification); and
  • detect and prevent fraud, impersonation, and unauthorized access on the marketplace.

Biometric use is limited to identity verification and fraud prevention. We do not use biometric data to train or develop facial-recognition or other models, and we do not use it to supervise, direct, or evaluate any professional’s work.

We provide a standalone notice and obtain affirmative, opt-in consent from each professional before we collect their faceprint, as required by law. A professional may decline; we explain the consequences for identity verification.

4. Service providers and disclosure

We share biometric data only with third-party technology service providers that help us deliver identity verification and fraud prevention — for example, secure cloud-hosting and facial-recognition technology providers, currently Amazon Web Services (including Amazon Rekognition for facial-recognition processing). These providers process biometric data only to provide the service to us. Where a provider’s standard terms would otherwise permit it to use this data to develop its own technologies, we have opted out of that use; we instruct providers to delete biometric data on our schedule; and they do not sell it.

Clipboard may share the professional’s photos (including of the professional’s face, identification documents, and/or selfie) with healthcare facilities where they have booked shifts, but we will not share the face-geometry template with the facility.

We do not sell, lease, trade, or otherwise profit from biometric data. We do not disclose biometric data except: with the professional’s consent; to complete a transaction the professional requested; to a service provider under the restrictions above; or as required by law (for example, a valid warrant or subpoena).

5. Retention schedule

We retain biometric data only as long as necessary for the purposes in Section 2.

Because identity verification is ongoing for as long as a professional continues to use the marketplace, we may retain a professional’s photos and faceprint while they remain active — including where that is longer than the period below — in order to match future submissions and detect impersonation. We permanently destroy them by the earliest of:

  • 90 days after the professional’s last interaction with the platform;
  • when the purpose for collecting them has been satisfied; or
  • the maximum period permitted by applicable law (under the Illinois BIPA, within three years of the professional’s last interaction with us).

We review retained biometric data at least annually to confirm it is still needed.

6. Destruction

We assign a deletion date to each selfie and to any faceprint or face template created from it. On or after that date, we permanently and irreversibly delete the data — including any face templates or vectors held by our service providers — unless we are legally required to retain it (for example, under a litigation hold, warrant, or subpoena).

7. Data security

We store, transmit, and protect biometric data using the reasonable standard of care in our industry, in a manner at least as protective as how we protect other confidential and sensitive information.

8. Responding to security incidents

We maintain a protocol to respond to any security incident that may compromise biometric data, including investigation, containment, and notification.

9. Your rights

Depending on where you live, you may have rights regarding your biometric data, including to access or delete it, or to limit our use of it. To exercise a right or ask a question, contact us at privacy@clipboardworks.com.

10. Changes to this Policy

We may update this Policy. We will post the updated version here with a new last updated date.