Copado Biometric Data Retention and Destruction Policy 

Effective Date: September 11, 2026 

1. Purpose and Scope. 

Copado, Inc. ("Copado," "we," "us," or "our") is committed to protecting the privacy and security of  biometric data. We have created this Biometric Data Retention and Destruction Policy ("Policy") to inform  you about how we collect, use, store, and destroy biometric data in connection with our activities, in  compliance with the Illinois Biometric Information Privacy Act, 740 ILCS 14 ("BIPA") and any other  applicable biometric privacy law. 

This Policy applies to Copado, Inc. and its affiliates and subsidiaries and covers all biometric data  collected by or on behalf of Copado, including in connection with experiential installations, events,  products, and services. 

2. What Is Biometric Data. 

For the purposes of this Policy, biometric data means any data generated by automatic measurements of  an individual's biological characteristics, including but not limited to: 

  • Facial geometry and facial scans 
  • Faceprints and face templates 
  • Retina or iris scans 
  • Fingerprints and voiceprints 
  • Hand or face geometry 

Biometric data does not include photographs, video recordings, or physical descriptions such as height,  weight, hair color, or eye color, unless those recordings or descriptions are used to extract a biometric  identifier. 

This definition is consistent with the definition of biometric identifiers and biometric information under  the Illinois Biometric Information Privacy Act, 740 ILCS 14/10. 

3. Current Deployments Involving Biometric Data. 

3.1 Agentia AI Experience — Dreamforce 2026 

Deployment: AI Photo Booth installation at Sentro Filipino, 814 Mission St, San Francisco, CA 94103,  September 15–17, 2026. 

Nature of processing: Copado's technology partner, Yord s.r.o., operates an AI Photo Booth that captures  continuous video of participants. Before any video is transmitted to any external service, Yord's system  applies a digital face masking process using MediaPipe BlazeFace, a pre-trained face detection model  running entirely on Yord's own hardware at the booth. This process transiently detects the location of a  participant's face for the sole purpose of applying a mascot mask. No faceprint, face template, scan of  face geometry, or other biometric identifier is created, stored, or transmitted as part of this masking  process. 

Nature of biometric data involved: Yord's masking system performs transient on-device face detection  solely to apply the mascot mask. No biometric identifier is extracted, stored, or transmitted by Yord's  system. The masked video stream, in which participant faces have been replaced with mascot faces, is  then transmitted to third-party AI vendors for generative processing. In rare edge cases, an unmasked frame may be transmitted to Decart.ai, Inc. as an inherent limitation of real-time face detection  technology. Participants are informed of this limitation and acknowledge it before the experience begins. 

Third-party AI vendors: The masked video stream is transmitted to Decart.ai, Inc. Still images are  transmitted to Google LLC. Google LLC does not use participant data to train, fine-tune, or improve its  models under the paid tier of the Gemini API applicable to this deployment. Decart.ai receives only  masked video in which faces have been replaced with mascot faces. 

Consent: Written consent is obtained from each participant before any video is captured or transmitted.  The consent is specific to this activity and discloses the nature of the processing, the recipients of the  data, the retention period, and the participant's rights. Participants must confirm they are at least 18 years of age before the experience begins. 

4. Retention Schedule. 

Copado retains biometric data only for as long as necessary to fulfil the purpose for which it was  collected, and in no event longer than the periods specified below. 

Data Type Retention Period Deletion Method
Video captured at the installation Held in RAM on the kiosk for the duration of the session only. Never written to kiosk storage. Discarded when the session ends. Automatic discard at session end. Full disk wipe of kiosk hardware at teardown.
Masked video transmitted to Decart.ai, Inc. Retained by Decart only as long as technically necessary to generate and return the output. The face masking safeguard is the primary protection against identifiable face data reaching Decart. Governed by Decart's standard terms. Not within Yord's or Copado's control.
Still images transmitted to Google LLC Retained by Google only as long as technically necessary to generate and return the output. Not used for model training under Gemini API Additional Terms of Service applicable to paid services. Deletion by Google per the applicable Gemini API terms for paid service.
Generated Output stored on content hub Automatically deleted 60 days after creation by an object storage lifecycle rule. Content hub hosted by Cloudflare, Inc. (object storage) and Render Services, Inc. (application backend and database), United States, West US region. Automated lifecycle rule. No manual intervention required.
Generated Output downloaded or published by Copado Retained by Copado for the period stated in the participant's marketing use release, where applicable. Copado's internal data management processes.

In no event will Copado retain biometric data beyond the earlier of:

  • The date on which the specific purpose for which the biometric data was collected has been  satisfied; or 
  • Three (3) years from the individual's last interaction with Copado's systems in connection with the  relevant deployment. 

5. Destruction of Biometric Data. 

Copado uses the following methods to permanently destroy biometric data when the applicable retention  period expires or when the purpose for collection has been satisfied:

  • Kiosk hardware: Full disk wipe before the hardware leaves the venue following each deployment.
  • Content hub: Automated object-storage lifecycle rule permanently deletes session objects 60  days after creation. Storage versioning is disabled and no cross-region replication exists,  ensuring deletion is complete and irreversible. 
  • Third-party vendors: Copado requires its technology partners to delete biometric data within 30  days of expiry or termination of the applicable service term and to provide written confirmation of  deletion. 

6. Prohibition on Sale, Lease, or Profit from Biometric Data. 

Copado does not and will not: 

  • Sell, lease, trade, or otherwise profit from any individual's biometric data. 
  • Disclose or disseminate biometric data to any third party except as necessary to provide the  services described in this Policy and with appropriate contractual protections in place.
  • Use biometric data for any purpose other than the specific purpose for which it was collected and  disclosed to the individual at the time of collection. 
  • Copado does not sell or share biometric data for monetary or other consideration, nor does  Copado share biometric data for cross-context behavioral advertising. 

Notwithstanding the foregoing, Copado may disclose biometric data in the following limited  circumstances: (a) where the subject of the biometric data has consented to the specific disclosure; (b)  where disclosure is required by applicable state or federal law or municipal ordinance; or (c) where  disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. In each  case, Copado will disclose only the minimum biometric data necessary to satisfy the applicable  requirement. 

7. Protection of Biometric Data. 

Copado takes the security of biometric data seriously and has put in place physical, technical, and  administrative safeguards designed to protect biometric data from unauthorized or illegal access,  destruction, use, modification, or disclosure in accordance with applicable laws, including:

  • No persistent storage of video on kiosk hardware. All capture and processing occurs in memory  only. 
  • Server-side encryption at rest (AES-256) on the content hub media store. 
  • TLS 1.2 or higher for all data in transit. 
  • Multi-factor authentication on all administrative accounts with access to participant data.
  • Access limited to a named project team with confidentiality obligations. 
  • No third-party analytics, session replay, or crash reporting capable of capturing media payloads.

Copado stores, transmits, and protects biometric data using a standard of care that is the same as or  more protective than the manner in which Copado stores, transmits, and protects its other confidential  and sensitive information. 

8. Your Rights Under BIPA. 

If you are an Illinois resident, you have the following rights under BIPA: 

  • Right to be informed: You have the right to be informed in writing before Copado collects your  biometric data, including the specific purpose and length of term for which it is being collected,  stored, and used. 
  • Right to written release: Copado will not collect your biometric data without first obtaining a  written release from you. 
  • Right to deletion: You may request deletion of your biometric data at any time by contacting us  using the details in Section 10 below. 
  • Right to no profit: Copado will not sell, lease, trade, or profit from your biometric data.
  • Right to protection: Copado will store, transmit, and protect your biometric data using a  reasonable standard of care consistent with how it protects its own confidential and sensitive  information. 

To exercise any of these rights, please submit a request to privacy@copado.com. We will confirm receipt  of your request within the legally permissible time period. We may require specific information from you  to help us verify your identity and process your request. 

9. Changes to This Policy. 

In the event of changes in the law, our data handling practices, or for other reasons, Copado reserves the  right to update and change this Policy at any time by updating and publishing the revised Policy at  www.copado.com/legal/bipa-policy. 

10. How to Contact Us. 

If you have any questions about this Policy or wish to exercise your rights under BIPA or any other  applicable biometric privacy law, you may send notice by email at privacy@copado.com or if you are in  the United States you may call our toll free telephone number: 1(888) 210-4282. You may also send a  written notice to us at one of the following addresses:  

United States: 
Copado, Inc. 
Attn: Legal Dept. 
200 E Randolph St, Suite 6675 
Chicago, IL 60601 
United States 

European Union:  
Copado Netherlands B.V.  
Attn: Legal Dept.  
Barbara Strozzilaan 201, 1083 HN Amsterdam  
The Netherlands

‍