ZOREAL

Privacy · ZOREAL ID app and every ZOREAL biometric check

Biometric Data Privacy Notice

This document is issued by Bynn Intelligence, Inc. and supplements the general Privacy Notice, which continues to apply; where the two differ in respect of the ZOREAL ID app and every ZOREAL biometric check, this document prevails.

Effective date: 10 September 2026

1. Application and controller

1.1 This Biometric Data Privacy Notice (the "Notice") governs the collection, use, storage, disclosure and destruction of Biometric Data by Bynn Intelligence Inc. ("Bynn", the "Company") in connection with the ZOREAL ID application for iOS and Android (the "Application") and every service of the Company in which Biometric Data is processed, including identity enrolment, face comparison, liveness detection, presence attestation and the integrity and identity-assurance measures of ZOREAL Meet (together, the "Services"). The Company is the developer named in the App Store and Google Play listings of the Application.

1.2 This Notice supplements the ZOREAL Privacy Notice, which continues to apply. In respect of Biometric Data, this Notice prevails. The Company is the controller of Biometric Data processed in connection with the Services and may be contacted at privacy@bynn.com.

2. Definitions

2.1 "Biometric Data" means data relating to the physical characteristics of an individual from which the individual can be identified, including facial images, voice recordings, and templates, embeddings or other mathematical representations derived from them, and includes biometric identifiers and biometric information within the meaning of applicable law.

3. Biometric Data collected

3.1 The Company may collect the following Biometric Data: (a) the facial image stored on the chip of a government-issued identity document and read by the Application; (b) images of the identity document captured by the individual; (c) video and still images of the individual's face captured during liveness and presence checks; (d) audio and video of the individual captured during the use of the Services, including in ZOREAL Meet; (e) templates, embeddings and other representations derived from the foregoing; and (f) scores, measurements and other data derived from the foregoing.

3.2 Biometric Data is captured with the individual's participation and after notice within the Application or Service. Authentication performed by the operating system of the individual's device (Face ID, Touch ID and equivalent) is performed by the device, and the Company receives only the result.

4. Purposes and legal bases

4.1 The Company processes Biometric Data for the following purposes: (a) to verify that the individual is the holder of the identity document presented, by comparison of the individual's face with the facial image on the document; (b) to determine that a live individual is present at enrolment, at authentication and during the use of the Services; (c) to issue, maintain, renew and revoke the individual's ZOREAL ID and associated credentials; (d) to detect, prevent and investigate fraud, impersonation, synthetic media and the misuse of the Services, including by comparison against records associated with previous security incidents, and to protect the Company, its users and third parties; (e) to comply with legal obligations and to establish, exercise or defend legal claims; and (f) to research, develop, train, test and evaluate the Company's verification, liveness and fraud-detection technologies, including the measurement of their accuracy and fairness, where the individual has given separate consent to such use.

4.2 The Company may process Biometric Data for purposes compatible with those set out in Section 4.1 to the extent permitted by applicable law. Data derived from Biometric Data that does not identify an individual may be processed for any lawful purpose.

4.3 The Company does not sell, lease, trade or otherwise profit from Biometric Data, does not use Biometric Data for advertising or marketing, and does not disclose Biometric Data to a third-party artificial-intelligence service without the individual's explicit consent.

4.4 Where the General Data Protection Regulation, the UK GDPR or an equivalent law applies, the Company processes Biometric Data on the basis of the individual's explicit consent (Articles 6(1)(a) and 9(2)(a)) and, to the extent permitted, its legitimate interests in the security and integrity of the Services (Article 6(1)(f)) and compliance with legal obligations (Article 6(1)(c)). Consent is obtained separately for the purpose in Section 4.1(f).

5. Consent and withdrawal

5.1 Before the first collection of Biometric Data, the Company informs the individual in writing within the Application that Biometric Data is being collected, of the specific purposes of collection, and of the period for which it will be retained, and obtains the individual's written consent by electronic means. The text, version and time of each consent are recorded.

5.2 Consent may be withdrawn at any time within the Application or by written request to the Company. Withdrawal does not affect the lawfulness of processing before withdrawal. Because the Services cannot be provided without Biometric Data, withdrawal of the consent given under Section 5.1 terminates the individual's ZOREAL ID.

5.3 The Services are not directed to, and Biometric Data is not knowingly collected from, individuals under the age of sixteen.

6. Retention and destruction

6.1 This Section constitutes the Company's written retention schedule and destruction guidelines for Biometric Data. Biometric Data is retained for no longer than is necessary for the purposes for which it was collected and is permanently destroyed upon the earlier of (a) the satisfaction of the initial purpose for which it was collected and (b) three years after the individual's last interaction with the Company, or such shorter period as the law of the individual's jurisdiction requires (Section 11), save where a longer period is required by applicable law or by a legal hold, in which case only the data so required is retained and only for the period required.

6.2 Without limitation to Section 6.1: raw identity-document evidence is destroyed upon completion of verification; liveness video and images are destroyed promptly after the check to which they relate; the facial image and template maintained as the individual's reference for comparison are retained for the life of the individual's ZOREAL ID and destroyed within thirty days of its termination; data processed for the purpose in Section 4.1(d) is retained for a limited period for the investigation of and defence against security incidents; and data retained under the consent in Section 4.1(f) is retained for the duration of that consent and destroyed within thirty days of its withdrawal, except to the extent incorporated in models already trained.

6.3 Destruction means deletion from the Company's active systems and, within their rotation period, from backups, by means that render the data unrecoverable. The Company reviews this schedule at least annually.

7. Security and breach response

7.1 The Company protects Biometric Data using the reasonable standard of care within its industry and in a manner that is the same as or more protective than the manner in which it protects other confidential and sensitive information, including encryption in transit and at rest, access limited to authorised personnel and systems under audited controls, and the retention of signing keys in the secure hardware of the individual's device.

7.2 In the event of unauthorised access to or disclosure of Biometric Data, the Company will contain the incident, assess the data and individuals affected, notify affected individuals and competent authorities within the periods required by applicable law, revoke and re-issue affected credentials as necessary, and document the incident and its response.

8. Disclosure

8.1 The Company may disclose Biometric Data to its affiliates and subsidiaries; to processors engaged under contract to provide infrastructure, storage and services to the Company, including its cloud infrastructure provider; to a successor in the event of a merger, acquisition or reorganisation of the Company or the Services; where required by law, legal process or a governmental request; and as otherwise authorised by the individual. Recipients are bound to protect Biometric Data in a manner consistent with this Notice.

9. Location of processing

9.1 Biometric Data is processed on infrastructure operated by the Company and its processors in the European Union and, for individuals outside the European Economic Area, the United Kingdom and Switzerland, in the United States, and is stored in the regions designated for the relevant Service. Transfers of Biometric Data outside the European Economic Area are made subject to appropriate safeguards under applicable law, including the standard contractual clauses adopted by the European Commission and the United Kingdom addendum.

10. Rights

10.1 Individuals have the rights afforded by applicable law, including the rights to access, rectify and erase Biometric Data, to restrict or object to its processing, to data portability, to withdraw consent, and to lodge a complaint with a supervisory authority. The Company responds to requests within the periods required by applicable law and does not discriminate against an individual for exercising a right. Requests may be made within the Application or to privacy@bynn.com.

11. Jurisdiction-specific provisions

11.1 The following provisions apply in addition to the foregoing to individuals in the jurisdictions indicated.

European Economic Area, United Kingdom and Switzerland

11.2 Biometric Data processed for the purpose of uniquely identifying an individual constitutes a special category of personal data. Consent under Section 5 is given by an affirmative statement, is specific to each purpose for which it is required, and may be withdrawn as easily as it is given. The Company has conducted a data protection impact assessment in respect of the Services and maintains it under review. The Company's data protection officer may be contacted at privacy@bynn.com. The Company's comparison of an individual's face with the individual's own identity document does not constitute remote biometric identification within the meaning of Regulation (EU) 2024/1689.

United States

11.3 Illinois. This Notice constitutes the Company's publicly available written policy establishing a retention schedule and guidelines for the permanent destruction of biometric identifiers and biometric information for the purposes of the Biometric Information Privacy Act, 740 ILCS 14. The notice and written release required by that Act are obtained under Section 5. The Company does not sell, lease, trade or otherwise profit from biometric identifiers or biometric information.

11.4 Texas. The Company informs the individual and obtains the individual's consent before capturing a biometric identifier for a commercial purpose, does not sell, lease or otherwise disclose biometric identifiers except as permitted by Chapter 503 of the Business and Commerce Code, protects them with reasonable care, and destroys them within a reasonable time, and not later than one year, after the purpose for collection has expired.

11.5 Colorado. Sections 6 and 7 constitute the Company's written policy, retention schedule, deletion guidelines and biometric-data-breach protocol for the purposes of C.R.S. § 6-1-1314. Biometric identifiers are deleted upon the earliest of the satisfaction of the purpose for collection, twenty-four months after the individual's last interaction with the Company, and a determination upon annual review that retention is no longer necessary.

11.6 Washington. The Company enrols biometric identifiers only upon notice and consent under Section 5 and does not use or disclose them for a commercial purpose other than those consented to. To the extent biometric data constitutes consumer health data under RCW 19.373, the consent obtained under Section 5 constitutes the individual's affirmative consent.

11.7 California. Biometric information processed to uniquely identify an individual constitutes sensitive personal information. The Company uses it for the purposes set out in Section 4, which include purposes necessary to provide the Services requested and to ensure their security and integrity, and does not sell or share it. Individuals have the rights to know, delete, correct and limit the use of sensitive personal information under the California Consumer Privacy Act.

Canada

11.8 The Company obtains the individual's express consent, stated in plain language, for each purpose in Section 4.1 for which consent is required, and processes Biometric Data for the purpose of verifying that the individual is the holder of the identity document presented.

Brazil

11.9 Biometric Data constitutes sensitive personal data under Law No. 13,709/2018 and is processed on the basis of the individual's specific and highlighted consent for each purpose in Section 4.1 for which consent is required, and on the other legal bases provided by that Law.

Other jurisdictions

11.10 In all other jurisdictions the Company applies this Notice in full and processes Biometric Data in accordance with the law applicable to the individual.

12. Amendments

12.1 The Company may amend this Notice. The effective date of the version in force appears above. An amendment that materially expands the purposes for which Biometric Data is processed will be notified within the Application before taking effect and, where applicable law so requires, will apply to Biometric Data collected under a previous version only with the individual's further consent.