Effective Date: September 11, 2026
Copado, Inc. ("Copado," "we," "us," or "our") is committed to protecting the privacy and security of biometric data. We have created this Biometric Data Retention and Destruction Policy ("Policy") to inform you about how we collect, use, store, and destroy biometric data in connection with our activities, in compliance with the Illinois Biometric Information Privacy Act, 740 ILCS 14 ("BIPA") and any other applicable biometric privacy law.
This Policy applies to Copado, Inc. and its affiliates and subsidiaries and covers all biometric data collected by or on behalf of Copado, including in connection with experiential installations, events, products, and services.
For the purposes of this Policy, biometric data means any data generated by automatic measurements of an individual's biological characteristics, including but not limited to:
Biometric data does not include photographs, video recordings, or physical descriptions such as height, weight, hair color, or eye color, unless those recordings or descriptions are used to extract a biometric identifier.
This definition is consistent with the definition of biometric identifiers and biometric information under the Illinois Biometric Information Privacy Act, 740 ILCS 14/10.
3.1 Agentia AI Experience — Dreamforce 2026
Deployment: AI Photo Booth installation at Sentro Filipino, 814 Mission St, San Francisco, CA 94103, September 15–17, 2026.
Nature of processing: Copado's technology partner, Yord s.r.o., operates an AI Photo Booth that captures continuous video of participants. Before any video is transmitted to any external service, Yord's system applies a digital face masking process using MediaPipe BlazeFace, a pre-trained face detection model running entirely on Yord's own hardware at the booth. This process transiently detects the location of a participant's face for the sole purpose of applying a mascot mask. No faceprint, face template, scan of face geometry, or other biometric identifier is created, stored, or transmitted as part of this masking process.
Nature of biometric data involved: Yord's masking system performs transient on-device face detection solely to apply the mascot mask. No biometric identifier is extracted, stored, or transmitted by Yord's system. The masked video stream, in which participant faces have been replaced with mascot faces, is then transmitted to third-party AI vendors for generative processing. In rare edge cases, an unmasked frame may be transmitted to Decart.ai, Inc. as an inherent limitation of real-time face detection technology. Participants are informed of this limitation and acknowledge it before the experience begins.
Third-party AI vendors: The masked video stream is transmitted to Decart.ai, Inc. Still images are transmitted to Google LLC. Google LLC does not use participant data to train, fine-tune, or improve its models under the paid tier of the Gemini API applicable to this deployment. Decart.ai receives only masked video in which faces have been replaced with mascot faces.
Consent: Written consent is obtained from each participant before any video is captured or transmitted. The consent is specific to this activity and discloses the nature of the processing, the recipients of the data, the retention period, and the participant's rights. Participants must confirm they are at least 18 years of age before the experience begins.
Copado retains biometric data only for as long as necessary to fulfil the purpose for which it was collected, and in no event longer than the periods specified below.
In no event will Copado retain biometric data beyond the earlier of:
Copado uses the following methods to permanently destroy biometric data when the applicable retention period expires or when the purpose for collection has been satisfied:
Copado does not and will not:
Notwithstanding the foregoing, Copado may disclose biometric data in the following limited circumstances: (a) where the subject of the biometric data has consented to the specific disclosure; (b) where disclosure is required by applicable state or federal law or municipal ordinance; or (c) where disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. In each case, Copado will disclose only the minimum biometric data necessary to satisfy the applicable requirement.
Copado takes the security of biometric data seriously and has put in place physical, technical, and administrative safeguards designed to protect biometric data from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with applicable laws, including:
Copado stores, transmits, and protects biometric data using a standard of care that is the same as or more protective than the manner in which Copado stores, transmits, and protects its other confidential and sensitive information.
If you are an Illinois resident, you have the following rights under BIPA:
To exercise any of these rights, please submit a request to privacy@copado.com. We will confirm receipt of your request within the legally permissible time period. We may require specific information from you to help us verify your identity and process your request.
In the event of changes in the law, our data handling practices, or for other reasons, Copado reserves the right to update and change this Policy at any time by updating and publishing the revised Policy at www.copado.com/legal/bipa-policy.
If you have any questions about this Policy or wish to exercise your rights under BIPA or any other applicable biometric privacy law, you may send notice by email at privacy@copado.com or if you are in the United States you may call our toll free telephone number: 1(888) 210-4282. You may also send a written notice to us at one of the following addresses:
United States:
Copado, Inc.
Attn: Legal Dept.
200 E Randolph St, Suite 6675
Chicago, IL 60601
United States
European Union:
Copado Netherlands B.V.
Attn: Legal Dept.
Barbara Strozzilaan 201, 1083 HN Amsterdam
The Netherlands