Biometric Information Policy

Last updated: August 25, 2026

1. Purpose and Scope

This Biometric Information Policy describes how Telecom Apps LLC, doing business as Kleos, and its affiliates, where applicable (“Kleos”, “we”, “us”, or “our”), collect, use, retain, disclose, and destroy biometric identifiers and biometric information in connection with identity verification, fraud prevention, security, and compliance activities.

This Policy is intended to serve as Kleos publicly available written biometric retention and destruction policy, including for purposes of the Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq. (“BIPA”), where applicable.

This Policy applies to individuals whose biometric identifiers or biometric information may be collected or processed in connection with identity verification through Kleos Services, including Contractors, Employed Workers, and ultimate beneficial owners, directors, officers, representatives, or other individuals associated with Clients or prospective Clients.

This Biometric Information Policy supplements our Privacy Policy (available at: https://kleos.io/privacy) and applies only to the processing of biometric identifiers and biometric information covered by BIPA in the context described below. If there is any conflict between this Biometric Information Policy and our Privacy Policy regarding biometric identifiers or biometric information subject to BIPA, this Biometric Information Policy governs and controls over any general descriptions of personal data processing in our Privacy Policy.

2. Biometric Information We May Process

In connection with identity verification, fraud prevention, security, and compliance activities, we may collect, capture, receive, access, or otherwise process biometric identifiers or biometric information, including:

  • facial image data
  • photos of face including selfie images and photo or scan of face on the ID document
  • videos or images captured during identity verification
  • liveness verification data
  • face match data
  • facial geometry information
  • biometric templates or similar data generated from facial images, videos, or liveness checks
  • related identity verification results, metadata, and audit records.

Biometric identifiers and biometric information are processed only for the purposes described in this Policy and in our Privacy Policy (available at https://kleos.io/privacy).

3. Purposes of Processing

We may use biometric identifiers and biometric information only for the following purposes:

  • verifying an individual’s identity
  • authenticating identity documents
  • performing liveness and face match checks
  • preventing fraud, impersonation, and unauthorized access
  • conducting compliance, KYC, AML, sanctions, and risk screening activities
  • protecting the security and integrity of our Services
  • complying with applicable legal and regulatory obligations
  • resolving disputes, enforcing agreements, and establishing, exercising, or defending legal claims.

We do not use biometric identifiers or biometric information for advertising, marketing profiling, or to infer characteristics about individuals unrelated to identity verification, fraud prevention, security, or compliance. We do not sell, lease, trade, or otherwise profit from biometric information.

4. Identity Verification Provider

We use third-party identity verification providers to support our identity verification, liveness detection, face match, fraud prevention, security, and compliance activities.

Our current identity verification provider is Sum and Substance Ltd. (Sumsub). For identity verification, fraud prevention, security, and compliance activities conducted for Kleos’s purposes, Kleos determines the purposes and means of processing and acts as the controller of biometric identifiers and biometric information processed for our identity verification, fraud prevention, security, and compliance purposes. Sumsub processes such information on our behalf as our processor under our agreement with Sumsub and applicable data processing terms. Biometric information processed by Sumsub on our behalf is stored on servers located in the European Union (Frankfurt, Germany).

Our identity verification providers may process certain information in accordance with their own privacy notices and applicable legal obligations where they act as independent controllers.

5. Notice and Consent

Where required by applicable law, we provide notice and obtain consent or other required authorization before collecting or processing biometric identifiers or biometric information.

Before any biometric information is collected, you are presented with a consent screen at the beginning of the identity verification flow which, for users in the United States, includes a separate consent specifically addressing the collection and processing of biometric information. Identity verification does not proceed unless you provide this consent, which constitutes a written release where required by applicable law. By completing the identity verification process, you acknowledge that biometric information may be collected and processed for the purposes described in this Biometric Information Policy, subject to any additional consent requirements applicable in your jurisdiction.

For Illinois residents, where BIPA applies, we provide written notice and obtain a written release before collection. The notice explains the purpose for which biometric identifiers or biometric information are collected, stored, and used, and the length of time for which they may be retained.

Notice and consent may be provided as part of the identity verification flow, including through our identity verification provider’s interface.

6. Disclosure and Restrictions on Use

We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.

We do not disclose biometric identifiers or biometric information except where permitted by applicable law, including to our service providers, where necessary to provide the Services, complete identity verification, prevent fraud or security incidents, comply with legal obligations, respond to legal process, protect our rights or the rights of others, or with the individual’s consent.

Service providers that process biometric identifiers or biometric information on our behalf must do so in accordance with our instructions, contractual obligations, and applicable law.

7. Retention

We retain biometric identifiers and biometric information only for as long as reasonably necessary for the purposes for which they were collected, including identity verification, fraud prevention, security, compliance, dispute resolution, legal claims, and legal or regulatory obligations. We apply a uniform retention standard to biometric information designed to satisfy the requirements applicable to our users: biometric identifiers and biometric information are permanently destroyed when the initial purpose for their collection has been satisfied, and in any event no later than the earliest destruction deadline under applicable law.

Where biometric information is stored by Sumsub or another identity verification provider on our behalf, the provider stores and deletes that information in accordance with our instructions, our agreement and data processing terms with the provider, and applicable law.

Where technically available and legally appropriate, we seek to delete or de-identify biometric templates, facial geometry, and liveness verification data when they are no longer needed, while retaining non-biometric verification records where necessary for compliance, audit, fraud prevention, security, dispute resolution, or legal recordkeeping.

For Illinois residents, where BIPA applies, we permanently destroy biometric identifiers and biometric information when the initial purpose for collecting or obtaining them has been satisfied, or within three years of the individual’s last interaction with Kleos, whichever occurs first, unless a valid warrant, subpoena, or other legal requirement permits or requires longer retention.

For Texas residents, where applicable law applies, we destroy biometric identifiers within a reasonable time after the purpose for collecting them expires, and no later than one year after that purpose expires, unless an exception applies.

For Washington residents, where applicable law applies, we retain biometric identifiers no longer than reasonably necessary to comply with law, protect against fraud, criminal activity, security threats, or liability, or provide the Services for which the biometric identifier was collected or enrolled, unless otherwise permitted by law.

For other individuals, we retain biometric identifiers and biometric information for the period reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.

8. Destruction Guidelines

We securely destroy biometric identifiers and biometric information when the applicable retention period expires or when destruction is otherwise required by law.

Where biometric identifiers or biometric information are stored by a service provider on our behalf, we require the provider to delete or destroy such information in accordance with our instructions, contractual obligations, this Policy, and applicable law.

We may retain non-biometric verification records, such as verification status, timestamps, provider reference IDs, audit logs, consent records, compliance records, and risk indicators, for longer where necessary for compliance, fraud prevention, security, legal, audit, dispute resolution, or regulatory purposes.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect biometric identifiers and biometric information against unauthorized access, disclosure, alteration, loss, or destruction.

We require service providers that process biometric identifiers or biometric information on our behalf to implement appropriate security measures and process such information in accordance with applicable contractual obligations and law.

10. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date above reflects the date of the most recent update. Where required by law, we will provide additional notice of material changes.

11. Contact Us

If you have questions about this Policy or Kleos’s biometric data practices, please contact us at:

Telecom Apps LLC d/b/a Kleos

303 Twin Dolphin Drive, Suite 800, Redwood City, CA

United States

Email: support@kleos.io