ZKTeco WFM · LEGAL & PRIVACY

U.S. Biometric Privacy Policy

ZK Technology LLC dba ZKTeco WFM

Last Updated: September 1, 2026

1. Purpose and Scope

ZK Technology LLC, doing business as ZKTeco WFM (“ZKTeco WFM,” “we,” “us,” or “our”), provides workforce data-collection hardware, software, and optional hosted middleware services. This U.S. Biometric Privacy Policy (“Policy”) describes ZKTeco WFM’s practices only when ZKTeco WFM receives, possesses, or otherwise processes Biometric Data through an applicable hosted service.

The availability of biometric-capable technology does not mean that ZKTeco WFM collects or possesses Biometric Data. Customers and software partners independently determine whether to enable biometric functionality, which individuals may enroll, the lawful purpose for use, the configuration and deployment model, and the notices, consents, alternatives, and retention periods required by applicable law.

This Policy applies only when both of the following are true:

  • The customer has elected to enable biometric functionality for its employees or other authorized users; and
  • The customer uses an applicable ZKTeco WFM cloud middleware service through which ZKTeco WFM receives, stores, maintains, or otherwise processes a biometric template on the customer's behalf.

When both conditions are present, ZKTeco WFM acts as a service provider or processor to the customer, except to the extent applicable law independently assigns ZKTeco WFM a different role or obligation. ZKTeco WFM processes Biometric Data only for the contracted services, documented customer instructions, security and support functions, and other purposes permitted or required by law.

2. When This Policy Does Not Apply to ZKTeco WFM Processing

ZKTeco WFM does not receive, possess, control, or process Biometric Data solely because a customer or software partner purchases or uses ZKTeco WFM biometric-capable hardware or software.

This Policy does not describe biometric processing that occurs entirely outside ZKTeco WFM’s applicable hosted environment. This includes hardware- or software-only deployments operated through a customer’s or software partner’s infrastructure, use of ZKTeco WFM cloud middleware without biometric functionality, and biometric-enabled deployments in which the resulting data is not received, accessed, possessed, or stored by ZKTeco WFM.

Customers, employers, software partners, and other organizations that independently determine the purposes and means of collecting or using biometric information are responsible for their own biometric practices to the extent required by applicable law, including providing notices, obtaining legally sufficient consent or written releases, offering any required alternative method, responding to individual requests, and complying with laws applicable to their deployment. Nothing in this Policy expands ZKTeco WFM’s responsibility for processing that occurs outside ZKTeco WFM’s systems or contrary to ZKTeco WFM’s documented instructions.

3. Biometric Data Covered by This Policy

For purposes of this Policy, "Biometric Data" includes biometric identifiers, biometric information, biometric data, and similar information protected under applicable U.S. federal, state, or local law.

When this Policy applies, ZKTeco WFM may process a biometric template or other covered representation generated by an enabled biometric system. Depending on the customer-selected product and configuration, the source characteristic may include a fingerprint, facial characteristic, or palm characteristic, or another biometric characteristic expressly supported by the applicable ZKTeco WFM service.

A biometric template is a mathematical or technical representation generated for authentication or identification. Unless expressly stated in product documentation or a customer agreement, ZKTeco WFM’s hosted service is not designed to retain the original fingerprint image, facial image, or palm image used to generate the template. The precise data elements, storage location, and format depend on the selected technology, configuration, and deployment.

4. Purpose of ZKTeco WFM's Processing

ZKTeco WFM receives and maintains the biometric template only as necessary to provide, maintain, support, and administer the biometric functionality selected by the customer and for other purposes expressly authorized by the customer and permitted by applicable law.

Depending on the applicable service and configuration, this may include:

  • maintaining an authorized biometric enrollment or template;
  • supporting the customer's biometric functionality and associated device or system maintenance;
  • synchronizing or restoring authorized biometric templates where required to maintain the customer's deployment;
  • supporting replacement, reconfiguration, or maintenance of authorized devices;
  • diagnosing or troubleshooting the biometric functionality; and
  • maintaining the security, integrity, and availability of the contracted service.

ZKTeco WFM does not use Customer Biometric Data for advertising, targeted marketing, behavioral profiling, data brokerage, model training unrelated to the contracted service, or any other independent commercial purpose.

5. Customer Choice, Notice, and Consent

The customer—not ZKTeco WFM—decides whether biometric functionality will be offered or required, who may enroll, and the employment, access-control, timekeeping, security, or other purpose for which it is used. ZKTeco WFM does not require biometric use merely because a product is biometric-capable or because a customer uses a ZKTeco WFM hosted service. Where required by law or appropriate to the deployment, the customer is responsible for providing a lawful non-biometric alternative.

Before enrolling an individual in biometric functionality or transmitting a biometric template to ZKTeco WFM, the customer must, to the extent required by applicable law, provide all required notices; disclose the purposes, retention period, and any processing by ZKTeco WFM; obtain every required written release, affirmative consent, authorization, acknowledgment, or other permission; provide any required non-biometric alternative; and maintain evidence of compliance.

Use of applicable hosted biometric functionality constitutes the customer’s representation and warranty that it has a valid legal basis for the processing; has provided all required notices; has obtained all required consents, written releases, or authorizations before enrollment or transmission; will retain evidence of compliance; and will not instruct ZKTeco WFM to process Biometric Data in violation of law. Any ZKTeco WFM consent-recording feature is an administrative aid only and does not constitute legal advice or replace the customer’s obligation to determine the legally sufficient notice, consent, and alternative-use process for each jurisdiction.

Customers must establish, maintain, and follow their own written biometric data collection, disclosure, retention, destruction, and storage policies in compliance with all applicable laws, including BIPA where applicable. Unless the customer and ZKTeco WFM are expressly exempt under applicable law, any customer use of ZKTeco WFM products or services to collect, store, disclose, or otherwise process Biometric Data must comply with applicable law.

  • Before collecting or enrolling an individual’s Biometric Data, inform the individual in writing that Biometric Data is being collected, stored, used, and, where applicable, disclosed to or processed by ZKTeco WFM and its authorized service providers;
  • State in writing the specific lawful purpose or purposes for the collection, storage, use, and disclosure of the Biometric Data and the length of time for which it will be collected, stored, used, and retained; and
  • Obtain a legally valid written release, consent, or authorization from the individual or the individual’s legally authorized representative that authorizes the customer and, where required, ZKTeco WFM and its authorized service providers to collect, receive, store, use, and otherwise process the Biometric Data, and authorizes the customer to disclose the Biometric Data to ZKTeco WFM and those service providers. ZKTeco WFM requires authorized service providers to be subject to confidentiality, security, use, retention, and deletion restrictions appropriate to the data and no less protective than ZKTeco WFM’s applicable obligations.

6. ZKTeco WFM's Role

When this Policy applies, ZKTeco WFM processes Biometric Data on the customer’s behalf under the applicable agreement and documented customer instructions. ZKTeco WFM’s legal role may vary by jurisdiction and processing activity, and nothing in this Policy limits any obligation that applicable law independently imposes on ZKTeco WFM. ZKTeco WFM does not determine the customer’s employment practices, enrollment population, or primary business purpose for biometric use.

ZKTeco WFM's responsibilities include, as applicable:

  • processing the biometric template only for authorized purposes;
  • protecting the biometric template using appropriate safeguards;
  • limiting access to authorized personnel, systems, and service providers;
  • restricting unauthorized disclosure or unrelated use;
  • maintaining appropriate retention and destruction practices;
  • supporting the customer's administration and maintenance of the applicable biometric functionality; and
  • complying with legal obligations directly applicable to ZKTeco WFM.

Nothing in this Policy limits or transfers any duty that applicable law independently imposes on ZKTeco WFM. ZKTeco WFM may refuse, suspend, or limit processing instructions that it reasonably believes are unlawful, insecure, outside the contracted services, or inconsistent with this Policy.

7. Cloud Middleware Storage and Processing

When a customer uses biometric functionality together with an applicable ZKTeco WFM cloud middleware service, ZKTeco WFM may receive, store, maintain, transmit, or otherwise process the biometric template on the customer's behalf.

ZKTeco WFM acquires no ownership interest in Customer Biometric Data. As between ZKTeco WFM and the customer, the customer retains all rights it lawfully holds in Customer Biometric Data, subject to ZKTeco WFM’s limited right to process that data to perform the contracted services, protect the services, comply with law, and enforce applicable agreements.

Customer Biometric Data is processed only for customer-authorized purposes and remains subject to applicable contractual and legal requirements.

8. No Sale or Commercialization

ZKTeco WFM does not sell, lease, trade, or otherwise profit from Customer Biometric Data and does not disclose Customer Biometric Data in exchange for monetary or other valuable consideration. Permitted operational disclosures are described in Section 9 and do not authorize any sale, lease, trade, or other prohibited commercialization of Customer Biometric Data.

9. Disclosure and Service Providers

ZKTeco WFM does not disclose or otherwise disseminate Customer Biometric Data except:

  • as directed or authorized by the customer;
  • to authorized service providers that require access to provide, host, secure, maintain, or support the applicable ZKTeco WFM service;
  • with the individual's authorization where required by applicable law;
  • where disclosure is otherwise permitted by applicable law; or
  • when required pursuant to applicable law, regulation, court order, warrant, subpoena, or other valid legal process.

ZKTeco WFM requires service providers with authorized access to process Biometric Data only for specified services and under confidentiality, security, data-protection, retention, and deletion obligations appropriate to the nature of the data and applicable law. ZKTeco WFM remains responsible for selecting and overseeing its service providers as required by applicable law and contract.

10. Retention and Destruction

ZKTeco WFM retains Biometric Data only for the shortest period reasonably necessary to provide the authorized service, satisfy the purpose for which the data was received, comply with documented customer instructions, or meet legal obligations. ZKTeco WFM does not retain Biometric Data indefinitely.

For applicable hosted biometric services, ZKTeco WFM’s standard operational process is designed to delete an individual’s Biometric Data as soon as reasonably practicable and no later than one hundred fifteen (115) days after ZKTeco WFM receives a complete and valid deletion instruction or termination notice from the customer or from the customer’s authorized host application responsible for employee maintenance, unless a shorter period is required by law or contract. Biometric Data will be permanently destroyed by the earliest deadline required by applicable law, including when the initial purpose has been satisfied or an applicable maximum retention period expires.

Customers must immediately notify ZKTeco WFM, through the applicable administrative functionality or support process, when an individual’s employment, authorization, or use of ZKTeco WFM’s biometric products or services terminates or is otherwise discontinued. Customers must promptly deactivate the individual’s biometric enrollment and submit complete and accurate deletion instructions. ZKTeco WFM is not responsible for delay caused by a customer’s failure to provide timely, complete, or accurate notice or instructions.

Deletion is initiated when ZKTeco WFM receives a complete and valid customer instruction, when the applicable service terminates, when the authorized purpose has been satisfied, when the information is no longer reasonably necessary for the service, or when applicable law requires deletion.

Deletion may be deferred only to the extent required by applicable law, valid legal process, a documented preservation obligation, or a necessary security investigation. Residual copies may remain temporarily in encrypted backups until deletion or overwrite occurs under the applicable backup-retention schedule, provided those copies are not restored to active systems or otherwise processed except for disaster recovery, security, or legal compliance. When deletion is required, ZKTeco WFM uses commercially reasonable methods designed to render the data unreadable and incapable of reconstruction.

11. Security of Biometric Data

ZKTeco WFM maintains reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Biometric Data against unauthorized access, acquisition, use, disclosure, alteration, loss, or destruction. ZKTeco WFM applies a standard of care that is at least as protective as the standard used for other confidential and sensitive information that can uniquely identify an individual, taking into account the nature of the data, service architecture, and applicable law.

Depending on the applicable service and architecture, safeguards may include:

  • encryption during transmission;
  • encryption of stored information;
  • access controls and role-based permissions;
  • authentication controls;
  • monitoring and logging;
  • restricted administrative access; and
  • security and incident-response procedures.

Specific safeguards vary by product, service, architecture, deployment model, and contractual commitment. No security measure is infallible, and this Policy does not create a guarantee that unauthorized access or incidents will never occur. ZKTeco WFM will address confirmed incidents involving Biometric Data in accordance with applicable law and contractual obligations.

12. Illinois Biometric Information Privacy Act

For biometric identifiers or biometric information subject to the Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq. (“BIPA”), this Policy serves as ZKTeco WFM’s publicly available written retention and destruction policy to the extent ZKTeco WFM is in possession of such information. ZKTeco WFM will maintain a retention schedule and permanently destroy covered data when the initial purpose for collecting or obtaining it has been satisfied or within three (3) years of the individual’s last interaction with the applicable private entity, whichever occurs first, unless a valid warrant, subpoena, or other applicable legal exception permits or requires different treatment.

Before an Illinois individual is enrolled or any covered data is collected, captured, received, or otherwise obtained, the customer must provide written notice that biometric information is being collected or stored, state the specific purpose and length of term for collection, storage, and use, and obtain a legally valid written release. The customer must ensure that the release covers disclosure to and processing by ZKTeco WFM where required.

ZKTeco WFM will not sell, lease, trade, or otherwise profit from Biometric Data subject to BIPA. ZKTeco WFM will not disclose, redisclose, or otherwise disseminate such data unless the individual or the individual’s legally authorized representative consents; the disclosure completes a financial transaction requested or authorized by the individual; disclosure is required by applicable law or municipal ordinance; or disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. ZKTeco WFM will use at least the reasonable standard of care within its industry and protections at least as protective as those used for other confidential and sensitive information.

Customers must promptly communicate termination, last interaction, or satisfaction of the collection purpose through the applicable administrative or support process so that ZKTeco WFM can apply the required retention schedule. Contractual terms may impose shorter periods and will control where they provide greater protection.

13. Other U.S. State and Local Biometric Privacy Requirements

Biometric privacy requirements vary by jurisdiction and may include biometric-specific statutes, comprehensive privacy laws, employment laws, and local ordinances. Depending on the deployment and the individuals involved, requirements may include advance notice; express, affirmative, or written consent; a public retention policy; use limitations; non-biometric alternatives; security controls; incident response; restrictions on disclosure or sale; and fixed destruction deadlines.

ZKTeco WFM will comply with biometric-processing obligations directly applicable to its role and activities under the laws governing a particular deployment, which may include Illinois BIPA, Texas Business and Commerce Code Chapter 503, Washington Revised Code Chapter 19.375, Colorado Revised Statutes section 6-1-1314, and other applicable state or local requirements. Because definitions, exemptions, consent standards, disclosure restrictions, and retention deadlines differ by jurisdiction, the applicable law controls. Customers remain responsible for determining the laws governing their workforce and deployment and for fulfilling obligations assigned to them.

14. Individual Requests

Individuals should ordinarily direct requests concerning an employer’s or organization’s biometric program to that employer or organization, because the customer determines whether biometric functionality is enabled, controls the underlying relationship and purpose, and can verify the requester’s identity and authority.

When ZKTeco WFM receives a request concerning Biometric Data processed on a customer’s behalf, ZKTeco WFM may request information reasonably necessary to verify identity, locate the applicable customer account, protect the rights of others, prevent fraud, and determine whether ZKTeco WFM or the customer must respond. ZKTeco WFM may refer the request to the customer and will provide reasonable assistance as required by applicable law or contract.

Where ZKTeco WFM is legally required to respond directly, it will do so in accordance with applicable law. Rights may be subject to verification requirements, exceptions, preservation duties, and limitations designed to protect security, confidentiality, and the rights of other persons.

15. Changes to This Policy

ZKTeco WFM may update this U.S. Biometric Privacy Policy from time to time to reflect changes in its products, services, practices, or applicable legal requirements. The current version will be made available on the ZKTeco WFM website and identified by the Last Updated date. Changes become effective when the revised Policy is posted unless applicable law requires a different effective date or additional notice.

16. Additional Terms

This Policy describes ZKTeco WFM’s practices and is intended to satisfy public-policy requirements applicable to ZKTeco WFM. It does not amend any customer agreement, data processing addendum, service description, or security commitment. As between ZKTeco WFM and a customer, the applicable agreement controls if it conflicts with this Policy, except when applicable law requires this Policy or a more protective obligation to control.

Except as provided by applicable law or contract, this Policy does not create additional rights or remedies and does not waive any defense, limitation, privilege, or protection available to ZKTeco WFM. This Policy is not legal advice to customers or individuals. If any provision is found unenforceable, the remaining provisions will continue to apply to the fullest extent permitted by law.

17. Contact Us

Questions about this Policy or ZKTeco WFM’s processing of Biometric Data may be submitted using the contact information below. ZKTeco WFM will review and respond to privacy inquiries in accordance with applicable law and may request information reasonably necessary to identify the applicable customer or service. Please do not send biometric samples or sensitive identification documents by unsecured email.

ZK Technology LLC dba ZKTeco WFM
4515 George Road, Suite 370, Tampa, FL 33634
Privacy Email: privacy@zktecowfm.com