Privacy Policy

Effective Date: July 7, 2026

Last Updated: July 7, 2026

Nexveris LLC ("Company," "we," "us," or "our") operates the KeaCircle mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Please read this policy carefully. By using the App, you consent to the practices described in this Privacy Policy.

This Privacy Policy applies to all users of the App on iOS and Android platforms.

1. Information We Collect

1.1 Personal Information (Collected Directly from You)

When you use the App, we may collect the following personal information that you provide directly:

  • Account Information: Email address, password, and associated organization/agency details.
  • Client/Resident Information: First name, middle name, last name, date of birth, phone number, email address, member ID, admission ID, and other identification numbers.
  • Care Information: Location, branch, care level, disciplines, coordinator details, and Managed Care Organization (MCO) information.

1.2 Biometric Data

Our App collects biometric data for the purpose of identity verification and check-in/check-out services:

  • Facial Photographs: We capture multiple face photographs (from different angles) during the client onboarding process. These images are transmitted to and processed by Amazon Web Services (AWS) Rekognition, a third-party facial recognition service provided by Amazon, to generate facial identifiers used for secure, contactless check-in and check-out at care facilities.
  • Signatures: We capture digital signatures during the onboarding process and for manual check-in verification. Signatures may be treated as biometric identifiers when used for identity verification.

Important: Biometric data is collected only after obtaining explicit consent from the individual (or their authorized representative). We do not sell, lease, trade, or otherwise profit from biometric data. Biometric data is used solely for identity verification within the App.

1.3 Automatically Collected Information

  • Device Information: Device type, operating system, and device identifiers.
  • IP Address: Recorded when signatures are captured for audit and security purposes.
  • Usage Data: Check-in/check-out timestamps, activity selections, and interaction logs.

1.4 Camera Data

The App requires access to your device's camera to capture face photographs for biometric onboarding and facial recognition during kiosk check-in. Camera data is processed in real-time for face detection. Images captured by the camera are used only for the purposes described in this Privacy Policy and are not stored beyond what is necessary for the service.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Identity Verification: To verify the identity of clients/residents during check-in and check-out using facial recognition technology powered by AWS Rekognition.
  • Client Onboarding: To register and manage client profiles within care facilities.
  • Authentication: To verify user credentials and maintain secure access to the App.
  • Service Delivery: To facilitate care facility operations, including attendance tracking and activity management.
  • Security: To prevent unauthorized access, fraud, and to maintain the integrity of our services.
  • Compliance: To comply with legal obligations, including record-keeping requirements for care facilities.

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • With Your Organization: Information is shared with the agency or care facility organization that manages your account, as the App operates on a multi-tenant basis.
  • Amazon Web Services (AWS): Facial photographs are securely transmitted to AWS Rekognition, a third-party AI-powered facial recognition service, for the purpose of generating facial identifiers and performing identity verification. AWS processes this data on its cloud infrastructure in accordance with its own privacy and security policies. We ensure that AWS provides equivalent data protection through contractual obligations.
  • Other Service Providers: We may share information with third-party service providers who assist us in operating the App, such as cloud hosting and data storage providers. These providers are contractually obligated to protect your data.
  • Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request.
  • Safety: We may disclose information when we believe it is necessary to protect the safety, rights, or property of our users, the public, or our company.

4. Third-Party AI Service Disclosure

The App uses AWS Rekognition, a third-party artificial intelligence (AI) service provided by Amazon Web Services, to process facial photographs for identity verification. Specifically:

  • What data is sent: Facial photographs captured during onboarding and check-in are transmitted to AWS Rekognition.
  • Why: To generate facial identifiers (face vectors) and to compare faces during check-in/check-out for identity verification.
  • Consent: Explicit consent is obtained from the individual (or their authorized representative) before any facial data is transmitted to AWS Rekognition.
  • Opt-out: Users may decline facial recognition. In such cases, a manual check-in process using digital signatures is available as an alternative.

5. Biometric Data Policy

We take the collection and protection of biometric data seriously. This section provides additional detail on our biometric data practices in compliance with applicable biometric privacy laws, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and the California Consumer Privacy Act (CCPA).

  • Types of Biometric Data Collected: Facial photographs, facial geometry/identifiers (generated by AWS Rekognition), and digital signatures.
  • Purpose: Biometric data is collected and used solely for identity verification and attendance check-in/check-out at care facilities.
  • Consent: We obtain written or digital consent before collecting biometric data. Users are informed of the purpose of collection before any data is captured.
  • Retention: Biometric data is retained for the duration of the client's active enrollment with the care facility. Upon termination of the client relationship, biometric data is permanently deleted within 90 days, unless a longer retention period is required by law.
  • Destruction: When biometric data is no longer needed or upon a valid deletion request, it is permanently and irreversibly deleted from all systems, including AWS Rekognition indexes.
  • No Sale: We will never sell, lease, trade, or otherwise profit from any individual's biometric data.
  • No Advertising/Profiling: Biometric data is never used for marketing, advertising, profiling, or surveillance purposes.
  • Third-Party Processing: Biometric data is processed by AWS Rekognition as described in Section 4. No other third party has access to biometric data.

6. Data Storage and Security

We implement industry-standard security measures to protect your information:

  • All data transmissions are encrypted using HTTPS/TLS protocols (encryption in transit).
  • Data stored on our servers and AWS infrastructure is encrypted at rest.
  • Authentication tokens are securely stored on the device using encrypted local storage.
  • The App includes screenshot and screen recording protection to prevent unauthorized capture of sensitive information.
  • Access to the App is controlled through role-based authentication.
  • Biometric data is stored on secure servers with restricted access, limited to authorized personnel only.
  • AWS infrastructure complies with industry security standards including SOC 2 and ISO 27001.

While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

7. Data Retention

We retain different categories of data for different periods:

Data CategoryRetention Period
Account InformationDuration of active account, deleted within 30 days of account closure
Client Personal InformationDuration of active enrollment with the care facility
Biometric Data (Face Images, Facial Identifiers)Duration of active enrollment, permanently deleted within 90 days of termination
Digital SignaturesDuration of active enrollment, or as required by law for record-keeping
Check-in/Check-out RecordsAs required by applicable care facility regulations
Device and Usage Data12 months from date of collection

Data may be retained longer if required by applicable law, regulation, or legal process.

8. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, including biometric data. We will process deletion requests within 30 days.
  • Withdraw Consent: Withdraw your consent for data processing at any time. Note that withdrawing consent for biometric data may affect your ability to use facial recognition check-in features.
  • Data Portability: Request a copy of your data in a structured, commonly used format.
  • Opt-Out of Sale: We do not sell personal data. If this changes, we will provide a clear opt-out mechanism.

To exercise any of these rights, please contact us at privacy@nexveris.com. We will respond to your request within 30 days.

9. Kiosk Mode and Shared Devices

The App may operate in a kiosk configuration on shared devices at care facilities. When using kiosk mode:

  • The device captures facial images in real-time for identity verification during check-in/check-out.
  • Multiple individuals may use the same device for check-in/check-out during a single session.
  • Facial images captured during kiosk check-in are used only for real-time verification and are not retained on the device after verification is complete.
  • Session data from one individual is not accessible to other individuals using the device.

10. Children's Privacy

The App is designed for use by authorized staff members (18 years or older) of care facilities only. The App is not intended for use by children under 18, and we do not knowingly collect personal information directly from children under 18. If you believe that we have inadvertently collected information from a child, please contact us immediately at privacy@nexveris.com so that we can take appropriate steps to delete such information.

11. Third-Party Services

The App uses the following third-party services:

  • Amazon Web Services (AWS): Cloud infrastructure, data storage, and facial recognition services (AWS Rekognition). Facial photographs are securely transmitted to and processed by AWS Rekognition for identity verification.

The App may also contain links to other third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Effective Date" and "Last Updated" date at the top of this page and, where appropriate, through in-app notifications. Your continued use of the App after any changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or to exercise your data rights, please contact us at:

Nexveris LLC
Email: privacy@nexveris.com