Biometric Information Retention Policy — Connexy
Legal · Biometric

Biometric Information Retention Policy

How long Connexy keeps any information collected through the Connexy Miroir that some U.S. state laws may treat as biometric, and how that information is destroyed. Applied out of an abundance of caution, in parallel with our broader Confidentiality Policy.

Last updated: May 24, 2026
In short

The shortest possible retention.

The original photograph is deleted within 24 hours. The simulated preview is deleted within 30 days. The consent audit record is retained indefinitely for legal purposes but never contains the image or the preview after they are destroyed. We never sell, lease, or share this information with the third-party image-processing service that generates the preview.

Photograph
24 hours
Original photo deleted from Connexy's systems within 24 hours of preview generation. Third-party image host also auto-deletes within 1 hour.
Preview
30 days
Simulated preview retained for up to 30 days so the dental clinic can follow up with the patient, then automatically deleted.
Our commitments

What we never do with this information.

  • Create or store biometric templates. The photograph is processed only to generate a cosmetic preview. We do not produce, retain, or maintain any biometric identifier, facial-geometry record, faceprint, or template that could be used to identify a person.
  • Perform facial recognition. We do not match the photograph against any database of faces, and we do not maintain or operate any system capable of doing so.
  • Train machine-learning models on patient photographs. Images are used solely to generate that patient's own preview. They are not retained, reused, or repurposed for model training, model improvement, or model evaluation.
  • Share patient names, emails, or contact information with the third-party image-processing service. That service receives only the anonymized image URL and the rendering instructions required to produce the preview. It never receives identifying information about the patient.
  • Sell, lease, or otherwise profit from this information. Photographs and previews are never sold, leased, traded, or monetized.
  • Use photographs or previews for advertising or third-party marketing.
01

Who we are

Connexy Inc. ("we," "us," "our") is a Canadian company headquartered in Montreal, Quebec, providing a smile-preview iPad system to dental clinics in the United States under the brand name Connexy Miroir. The Miroir is operated by clinic staff during in-chair patient consultations to generate a simulated visual preview of potential dental treatment outcomes.

Back to top
02

What this policy covers

This policy applies, out of an abundance of caution, to information collected through the Connexy Miroir that one or more U.S. state biometric-information statutes might treat as biometric — even if Connexy's view is that the information falls outside those statutes' definitions of "biometric identifier." Specifically:

  • Photographs of a patient's smile taken via the iPad's built-in camera, and
  • Simulated previews generated from those photographs.

This policy does not cover non-biometric information such as the patient's name, email address, treatment preferences, or appointment details. That information is governed by the dental clinic's own privacy practices and by Connexy's general Confidentiality Policy at connexy.ca/confidentialitypolicy.

Back to top
03

Purpose of collection

We collect and process the patient's smile photograph for the sole purpose of generating a simulated visual preview of potential dental treatment outcomes. The preview is delivered to the patient by email and made available to the participating clinic to support informed consent and treatment-planning conversations.

The defensive denials in the "What we never do" block above apply to every photograph and preview collected under this policy.

Back to top
04

With whom we share this information

We share the smile photograph and the simulated preview only with the following parties, and only to the extent strictly necessary to deliver the Connexy Miroir service:

  • The participating dental clinic that operated the Miroir during the consultation. The clinic uses the preview to support the patient's treatment consultation and follow-up.
  • Connexy personnel who require access to operate the service, provide support, or investigate technical issues.
  • Third-party service providers that Connexy uses to operate the system, including hosting, image processing, and email delivery. These providers are bound by confidentiality, process information only as instructed by Connexy, and receive only the data strictly required for their function.

The third-party image-processing service that generates the preview receives only the anonymized image URL and rendering instructions. It never receives the patient's name or contact information.

We do not sell, lease, trade, or otherwise profit from any information covered by this policy. We do not disclose information covered by this policy to anyone outside the participating clinic and Connexy, except where required by law (for example, a valid court order or regulatory request).

Back to top
05

Retention period

We apply a split retention schedule that minimizes how long sensitive information exists on our systems.

Original photograph

Deleted from Connexy's systems within twenty-four (24) hours of the preview being generated. The original photograph's only purpose is to feed the preview generation. Once the preview exists, the original serves no further purpose, and we delete it.

In addition, Connexy applies a one-hour expiration parameter on its image-upload calls so that the original photograph is removed from the third-party image-hosting service within one (1) hour of upload — a defense-in-depth measure on top of the 24-hour ceiling.

Simulated preview

Retained for up to thirty (30) days from the date of generation, then automatically and permanently deleted. The preview is retained for this period solely to support the patient's follow-up conversation with the participating clinic.

Consent audit record

Retained indefinitely as required for legal and audit purposes. The audit record contains only the timestamp, consent version, and cryptographic hash of the consent text shown — not the photograph or the preview, both of which are destroyed on the schedule above.

We may delete either the photograph or the preview sooner if (a) the patient requests deletion, (b) the patient withdraws consent, or (c) the immediate purpose has been fulfilled and continued retention serves no legitimate purpose.

Back to top
06

Destruction process

The 24-hour photograph deletion and the 30-day preview deletion are both executed by automated scheduled jobs from all primary and backup storage systems that Connexy controls. The third-party image-hosting service's transient copy of the photograph is removed on its own automated schedule, which does not exceed twenty-four (24) hours and is further constrained by Connexy's 1-hour expiration parameter described in Section 5.

Deletion is final and not reversible. Once an item is deleted under this policy, it cannot be restored from any Connexy system.

Back to top
07

Cross-border processing

Connexy is a Canadian company headquartered in Montreal, Quebec. Patient data submitted through the Connexy Miroir is processed in the United States and in Canada. We use commercially reasonable safeguards — including encryption in transit, access controls, and contractual data-processing agreements with sub-processors — to protect the data regardless of which country it transits through.

Back to top
08

Patient rights

If you are a patient who has used the Connexy Miroir at a participating clinic, you have the following rights regarding the information covered by this policy:

  • Access: request a copy of the information we currently hold about you under this policy.
  • Deletion: request deletion of your smile photograph and preview at any time, including before the automated 24-hour and 30-day deletion windows.
  • Withdrawal of consent: withdraw your consent for any future use of your information.
  • Amendment: request correction of inaccurate information we hold about you.
  • Restriction: request that we limit how your information is used.
  • Accounting of disclosures: request a record of how, when, and to whom your information has been disclosed.
  • Confirmation: receive confirmation of the date your information was destroyed.

To exercise any of these rights, email [email protected] with your full name and the name of the clinic where you used the Miroir. We will respond within thirty (30) days. If your dental clinic also holds your name and email in its own records, the clinic's privacy practices govern that data; you may need to contact the clinic separately for those records.

Back to top
09

Minors

We do not knowingly collect personal information from children under thirteen (13). Dental clinics must obtain verifiable parental or legal-guardian consent before using the Connexy Miroir with any patient who is under eighteen (18), or refrain from using the Miroir with that patient. The on-iPad consent flow requires the patient or guardian to confirm this before any photograph is captured.

Back to top
10

Security and breach notification

We use industry-standard security measures to protect the information covered by this policy while it is in our possession, including:

  • Encryption in transit (HTTPS / TLS 1.3) on all web and iPad endpoints.
  • Access controls limiting who within Connexy can read or copy the data.
  • Per-iPad credentials so that data captured at one clinic cannot be accessed by another clinic's iPad.
  • Contractual data-processing agreements with each third-party service provider.
  • Regular review of our data-handling practices.

No method of transmission over the internet or electronic storage is one hundred percent secure. If a security incident occurs that affects information covered by this policy, we will investigate, take reasonable steps to mitigate harm, and notify the affected clinic within seventy-two (72) hours of discovery. We will assist the clinic with any further patient notification it is required to perform, document the incident and the steps taken to remediate it, and report to applicable regulatory authorities where required by law (including the U.S. Department of Health and Human Services for breaches affecting five hundred (500) or more individuals).

Back to top
11

Business Associate Agreements

When a covered dental practice uses the Connexy Miroir in a manner that involves Protected Health Information under HIPAA, Connexy acts as a Business Associate of that practice.

BAA available on request. Connexy will execute a Business Associate Agreement with a covered practice upon written request to [email protected]. Under the BAA, Connexy processes Protected Health Information solely to provide the Connexy Miroir service and applies safeguards appropriate to the nature of the data.

Back to top
12

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced on this page at connexy.ca/biometric-policy at least thirty (30) days before they take effect.

Back to top
13

Related policies

This policy is intentionally narrow: it addresses only the photograph, the preview, and the destruction schedule applied to them. Connexy's broader handling of personal information — including how we collect clinic-owner contact data, how we advertise, how we share data with third-party platforms, and our HIPAA posture — is documented in our Confidentiality Policy.

Confidentiality Policy
How Connexy handles personal information for dental clinics that use the Miroir, and for the patients of those clinics whose data flows through the platform. Read alongside this policy.
Read the policy
Back to top
14

Contact

If you have any questions about this policy, want to exercise one of the patient rights described in Section 8, or wish to request a Business Associate Agreement, please reach out. We acknowledge requests within five (5) business days and respond in full within thirty (30) days.

Get in touch

Connexy Inc.

Address 365 Rue Sainte-Catherine E UNIT #400, Montreal, Quebec, Canada
The address above is our Canadian business address. Patient data inquiries can be sent by email and we will respond from the same domain.