The clause establishes a hard maximum retention period of two years for biometric facial data, a particularly sensitive category of personal data.
The commitment is to take steps toward destruction rather than guaranteeing destruction, and the timeframe is governed by variable applicable law, meaning retention periods may differ by jurisdiction.
This establishes a binding outer time limit on how long Walgreens may retain biometric data, with an earlier trigger if the collection purpose is fulfilled sooner.
American Airlines has committed to a defined maximum retention period for biometric data, tied to purpose fulfillment or a three-year outer limit, which is consequential given the sensitivity and irreplaceability of biometric identifiers.
This clause places a time-bound destruction obligation on vendors handling biometric data, limiting how long that sensitive category of data may be retained in the identity-verification supply chain.
The clause ties the retention period to a specific, short-duration technical event, minimising how long authentication-purpose Biometric Data is held.
This clause limits Bluesky's own data holdings of sensitive biometric information, meaning Bluesky itself does not build a store of such data from the verification process.
The clause establishes permanent destruction as the default outcome for Biometric Data, with a carve-out only for legal obligations to retain.
Walmart is bound by a specific destruction obligation tied to purpose completion or a fixed time limit, giving biometric data a defined maximum retention period.
Indeed
· Indeed Privacy Policy
For special category data collected by our vendor on our behalf, they will retain this information for the lifetime of the account.
The clause binds both Synthesia and its vendors to a purpose-limited retention standard, preventing indefinite storage of Biometric Data.
BAM will retain biometric data as part of customer identification information for the retention period required by financial laws and regulations.
PayPal
· PayPal Privacy Statement
We retain biometric data for as long as needed or permitted given the purpose for which it was collected and no more than 3 years after your account closes, unless otherwise required by applicable law.
The clause ties the Biometric Data retention period directly to the Avatar's availability, meaning the data persists as long as the Avatar does unless the Customer intervenes.
We will retain your biometric data until it is no longer needed for the purposes in which it was collected, or after 3 years of the termination of our relationship with you, whichever is sooner.
Biometric data collected and processed for our verification purposes is scheduled to be retained until the earlier of when verification is complete or for up to three (3) years following your last interaction with the biometric identity verification provider...
We retain biometric information (as part of our retention of Supplemental Identification Information) for the period required for financial regulatory compliance or otherwise as required by applicable law.
ElevenLabs
· ElevenLabs Privacy Policy (Superseded URL)
The clause places a defined outer limit on how long biometric data—a sensitive category—can be held, protecting users from indefinite retention.
Suno
· Suno Privacy Policy
We will retain this information for no longer than three (3) years following your last interaction with us (at which point, we will erase the informat, except as required otherwise by applicable law.
Suno
· Suno Privacy Policy
A defined maximum retention period for biometric data limits how long this sensitive information is held, giving users a concrete outer boundary for its storage.
Adobe
· Adobe Privacy Policy
Where we process biometric identifiers or biometric information to deliver a feature requested by you, we delete this information once you turn off the feature, unless otherwise specified in the Software or Services.
GOAT
· GOAT Privacy Policy
The timing of biometric data destruction is controlled entirely by GOAT's instruction to Persona, meaning the biometric identifier persists indefinitely until GOAT initiates the destruction order.
This clause establishes a binding destruction schedule for biometric data, which is among the most sensitive categories of personal information and cannot be changed if compromised.
We retain the stored template until the purpose for collecting it is satisfied. For instance, Verizon Wireless retains templates for approximately 90 days, and Total Wireless retains templates for approximately 180 days from the date that you provided it.
Indeed
· Indeed Privacy Policy (Superseded Capture)
For special category data collected by our vendor on our behalf, they will retain this information for the lifetime of the account.
Anthropic
· Anthropic Privacy Policy (Retired Duplicate)
in certain cases we may continue to process and retain data regardless of your request for deletion, objection, blocking or anonymisation, in order to comply with legal, contractual and regulatory obligations
Roblox
· Roblox Privacy Policy
We may continue to process and retain Personal Information regardless of your request to delete, object, block or anonymize it, to comply with legal, contractual and/or regulatory obligations, and to pr...
OpenAI
· OpenAI Enterprise Privacy
The clause defines a deletion window but preserves OpenAI's ability to retain data longer under legal obligation or a reasonably necessary harm-protection determination.
California residents who are Wealthfront Clients are on notice that their deletion rights are generally unavailable due to regulatory obligations, substantially limiting a key California privacy right.
Audio and video from a user's home are actively held on SimpliSafe's systems for a defined 30-day window, meaning sensitive recordings persist beyond any single event.