Sonavera Biometric Retention and Destruction Policy

Version: 2026-08-11 revision 5

North Star Software Inc. operates the Sonavera hosted biometric service. In this policy, “Sonavera,” “we,” “us,” and “our” refer to North Star Software Inc. as operator of the Sonavera service.

7. Retention and deletion

This section is Sonavera’s public biometric retention and destruction policy. The current-flow consent screen summarizes the applicable boundary in plain language; this policy supplies the complete retention, deletion, backup, and compliance-record terms.

Raw audio and video

Sonavera processes live camera and microphone streams during the session but does not save them as raw recordings in its application systems.

Service providers may process audio or visual content as described in Section 8. Their retention may differ from Sonavera-held application records.

Liveness, enrollment, and verification

When consent is requested, the screen shows the artifact-retention limit. Limits range from 30 minutes to 360 days; the Sonavera Public Demo uses 30 minutes.

Each session’s deadline stays within that limit. Reuse never extends it.

Enrollment may store both protected face and voice templates. Both are governed by the enrollment-retention boundary disclosed in the consent modal. Verification does not create a new durable enrollment template. Liveness does not create an enrollment template.

Uniqueness

Uniqueness face and voice templates or impressions, comparison records, transcripts, session evidence, continuity signals, and related diagnostic records are retained until the exact uniqueness-scope deadline shown in the consent modal. A uniqueness scope may not last more than 24 hours after it is created.

Expiry and asynchronous deletion

At the applicable deadline, expired uniqueness matching records are excluded from new matching or scoring.

Other expired Sonavera-held data enters an automatic deletion process. Deletion from active systems is asynchronous. If a session remains active at its deadline, physical deletion from active systems may wait until the active session ends.

Encrypted backups

Encrypted automated database backups may retain a recoverable copy of a deleted database record for up to seven additional days. Backups are used only for disaster recovery and are not used for ordinary biometric processing.

A completed participant deletion removes protected face and voice templates from active systems, subject to the encrypted-backup and limited compliance-record rules below.

A consent record contains no raw audio, raw video, transcript, face template, voice template, or reusable browser credential. A consent may become inactive and unavailable for reuse before every compliance record concerning that consent is deleted.

Absent a completed participant deletion request, Sonavera retains the full consent record while the consent may be reused and for five years after it becomes inactive. The record is then deleted or irreversibly de-identified unless a documented legal hold applies.

After a completed participant deletion request, the full consent record may be deleted once Sonavera has preserved the limited sanitized consent proof needed for the data-rights record.

Sonavera retains data-rights request records, including that sanitized consent proof, for five years after the final response or appeal resolution. Those records contain request and response information and limited sanitized consent and version evidence, but not the deleted biometric content or raw tenant subject identifier. They are then deleted or irreversibly de-identified unless a documented legal hold applies.

Limited security, reliability, delivery, fraud-prevention, and operational records may be retained separately as reasonably necessary for those purposes or to meet legal obligations. Those records must not contain raw media or reusable biometric templates.