Owner: Legal
Applies to: Amwins Group, Inc. and all subsidiaries and affiliates worldwide (“Amwins”)
Effective date: March 3, 2026
1. Purpose
Amwins may permit employees to use certain biometric-enabled features:
2. Key Definitions
“Biometric data” in this Policy means biometric identifiers and biometric information.
“Biometric identifier” and “biometric information” includes identifiers or information based on biological characteristics used to identify a person, such as voiceprints/voice signatures and scans of face geometry (and similar concepts).
3. How Amwins Uses Biometrics
A. Microsoft Teams / Teams Rooms (voice isolation; face/voice recognition)
Amwins enables Teams capabilities that allow an employee (if they choose) to enroll a voice profile (voice signature) and a face profile for features such as speaker attribution in transcripts/recaps and improved meeting experiences.
Enrollment is voluntary and optional. Employees can participate in meetings without providing biometric information.
B. Corporate Devices
Employees may choose to enable biometric unlock/authentication on Amwins-owned phones and laptops where supported (e.g., Face ID/Touch ID, Android biometric unlock, and/or biometrics used by Microsoft Authenticator if enabled).
Enabling device biometrics is voluntary and optional. Employees can use a passcode/PIN/password alternative if they do not want to allow this.
4. What Amwins Does Not Do
Amwins will not:
5. Where Biometric Data is Stored and Who Can Access It
A. Microsoft Teams / Teams Rooms
Teams voice and face enrollment and associated biometric data is processed and stored by Microsoft for the feature.
Amwins uses Microsoft as a service provider/processor with confidentiality and data protection language in place.
B. Corporate devices
For device biometric unlock/authentication, biometric data is generally stored locally on the device in protected storage controlled by the device OS and/or relevant application security controls (and is not centrally stored by Amwins).
C. Information security
Amwins will store, transmit, and protect biometric data using a reasonable standard of care and at least as protective as the way Amwins protects other confidential and sensitive information.
6. Retention and Destruction
Amwins will permanently destroy biometric identifiers and biometric information when the initial purpose for collecting/obtaining it has been satisfied, or within three (3) years of the employee’s last interaction with Amwins, whichever occurs first, unless a valid warrant or subpoena requires otherwise.
Operational retention:
7. Notice and Consent
A. Illinois
Employees who are Illinois residents and/or working in Illinois must sign the Illinois Biometric Information Notice & Release (Appendix A) before enrolling in Teams face/voice recognition or using other covered biometric features.
B. UK/EU
For employees in the UK/EU, enrollment is optional and employees may participate in meetings without enrolling.
C. California
Amwins maintains a CPRA workforce Notice at Collection and provides a concise biometrics snippet (Appendix B).
8. Disclosure of Biometric Data
Amwins will not disclose biometric data except:
9. Employee Choices, Requests, and Questions
Teams enrollment / unenrollment: Employees can enroll and unenroll through Teams settings and can choose to stop using these features.
Operational ownership:
10. Regional Implementation and Updates
Where required by local law, Amwins will satisfy any applicable consultation/notification obligations prior to implementing or materially changing biometric processing.
Amwins may update this Policy from time to time. The public-facing version will be posted on Amwins’ website.
For requests and questions, contact privacy@amwins.com.
Appendix A — Illinois Biometric Information Notice & Elective Release
1) What biometric data may be collected/obtained:
2) Purpose of collection/use:
Biometric data will be used for:
3) Length of time biometric data will be collected/stored/used:
Amwins will retain biometric data only as long as necessary for the purposes above and will destroy it when the initial purpose is satisfied or within three (3) years of my last interaction with Amwins, whichever occurs first, unless legally required otherwise.
4) Disclosure
I understand Amwins uses Microsoft as a service provider to provide the Teams features, and my biometric data may be processed by Microsoft for these purposes, subject to Microsoft’s controls and Amwins’ contractual arrangements.
Amwins will not sell, lease, trade, or otherwise profit directly from transacting in biometric data.
By signing below, I acknowledge that:
Amwins has informed me in writing that biometric identifiers/information may be collected or stored;
Amwins has informed me in writing of the purpose and length of term for which biometric identifiers/information are collected, stored, and used; and
I voluntarily provide my written consent and release to Amwins to collect/obtain, store, use, and destroy my biometric identifiers/information for the purposes described above.
Employee Name: __________________________
Signature: __________________________
Date: __________________________
Appendix B — CPRA Workforce Notice
Categories of personal information collected: Biometric information (e.g., voice and face profiles in Microsoft Teams if you choose to enroll; and biometric authentication used on Amwins-owned devices if you choose to enable it).
Purposes:
Retention: Retained only as long as necessary for the purposes above and deleted upon unenrollment and account/device lifecycle events; generally not later than three (3) years after last interaction with Amwins, unless legally required otherwise.
Disclosures: Disclosed to service providers (e.g., Microsoft) to provide the services; not sold or shared for cross-context behavioral advertising.
Your rights: California residents have rights to request disclosure, deletion, correction, and to limit certain uses of sensitive personal information (subject to legal exceptions). To submit a request or ask questions, email privacy@amwins.com.