PRIVACY AND DATA HANDLING POLICY

Effective Date: August 10, 2026
Version: 1.0

1. Purpose and Scope

Midwest Identity Services (“MIS,” “we,” “us,” or “our”) provides fingerprint capture, live scan, FBI channeling, background screening, notarial, and related identity services to individuals, employers, licensing bodies, and educational institutions.

This Policy describes how MIS collects, uses, safeguards, retains, and disposes of biometric data and personal information obtained in the course of providing those services. It applies to all services delivered at our Kansas City office, at client sites during mobile or on-site sessions, and through any electronic submission we perform on an individual’s behalf. It applies to all MIS owners, employees, technicians, and contracted personnel.

2. Definitions

  • Biometric Data. Fingerprint images and any associated minutiae or template data captured by ink card or live scan device.
  • Personal Information. Information that identifies or can reasonably be used to identify an individual, including name, date of birth, place of birth, address, physical descriptors, government identification numbers, and contact information.
  • Data Subject. The individual whose fingerprints and personal information are captured, referred to throughout this Policy as the “individual.”
  • Requesting Institution. An employer, school, agency, or organization that arranges for MIS to provide services to a group of individuals.
  • Channeler. An entity approved by the Federal Bureau of Investigation to submit fingerprint-based requests electronically to the FBI and receive the corresponding response on behalf of the individual.

3. Information We Collect

MIS collects only the information necessary to complete the specific service the individual has requested. Depending on the service and the receiving agency’s requirements, this may include:

  • Fingerprint images captured by live scan device or ink card
  • Full legal name, and any alias or maiden name required by the receiving agency
  • Date of birth, place of birth, and citizenship where required
  • Sex, race, height, weight, hair color, and eye color, where required by the applicable fingerprint card format
  • Social Security number, where required by the receiving agency
  • Mailing address, email address, and telephone number for delivery of results or receipts
  • The type of government-issued photographic identification presented for identity verification

We do not collect or retain payment information. Payments are handled separately through a third-party payment processor, and no payment record forms part of the service information described in this Policy.

We do not photograph, photocopy, or retain images of the identification documents presented for verification. Identification is inspected visually and returned to the individual immediately.

4. Purpose of Collection and Consent

Biometric data and personal information are collected for one purpose only: to complete the fingerprint-based service the individual has requested or that the individual is completing in connection with employment, licensure, enrollment, or a background check requirement.

Before any capture takes place, each individual is informed of the purpose of the collection, the agency to which the submission is directed, and how results will be delivered. No fingerprints are captured without the individual’s knowing participation. An individual may decline or discontinue service at any point prior to submission.

MIS does not use biometric data or personal information for marketing, profiling, research, product development, artificial intelligence or algorithm training, or any purpose unrelated to the requested service.

5. Use and Disclosure

MIS discloses biometric data and personal information only as follows:

  • To the receiving agency. Fingerprints and the accompanying required data elements are transmitted to the Federal Bureau of Investigation, a state identification bureau, or another agency designated by the individual’s requirement, either directly or through an FBI-approved channeling partner.
  • To the individual. Completed fingerprint cards, receipts, and, where applicable, results are provided to the individual.
  • As required by law. MIS may disclose information where compelled by subpoena, court order, or other legally binding process, or where required by an agency with lawful authority over the submission.

MIS does not sell, lease, trade, or otherwise profit from biometric data or personal information, and does not share it with data brokers, advertisers, or any party for commercial purposes.

6. Handling of Background Check Results

Where MIS submits a request on an individual’s behalf, results are returned to the individual through a secure retrieval process using credentials issued at the time of service. MIS personnel do not review, copy, print, store, or discuss the contents of an individual’s results.

Where a Requesting Institution has arranged an on-site session but has specified that it is not to receive results, MIS will not transmit results, outcomes, or any indication of an individual’s record status to that institution. In such engagements, the institution’s only involvement is scheduling and facility access.

Where an institution or employer is a lawful recipient of results, MIS will release them only pursuant to the individual’s written authorization and in accordance with the Fair Credit Reporting Act and any other applicable law governing that disclosure.

7. Retention and Destruction

MIS retains biometric data and personal information for the shortest period necessary to complete the requested service and to satisfy applicable audit obligations.

  • Fingerprint images. Retained on the live scan workstation for no more than thirty (30) days following transmission, solely to permit resubmission at no additional cost to the individual in the event the receiving agency rejects the submission for image quality. Images are automatically deleted at the end of that period. They are not archived, backed up to external storage, or retained for future submissions. An individual returning for a later service is fingerprinted again.
  • Printed cards. Delivered to the individual or transmitted to the receiving agency. MIS does not keep copies.
  • Spoiled or rejected materials. Cards that are misprinted or otherwise not usable are marked “VOID” and handed back to the individual along with their completed card. Because the fingerprints belong to the individual, disposition of voided cards rests with them. MIS does not retain, file, or take custody of voided cards under any circumstances.
  • Transaction records. A minimal service log (name, date of service, service type, and transaction control number) is retained for up to twelve months for audit, dispute resolution, and reprint requests, then destroyed. This log does not contain fingerprint images, payment information, or background check results.

8. Safeguards

Physical

  • Live scan equipment is under the direct control of an MIS technician at all times during a session and is never left unattended
  • Blank and completed cards are kept in the technician’s possession and transported in a secured container
  • Office records are stored in a locked facility with controlled access

Technical

  • Live scan workstations are password protected and encrypted, with automatic screen lock
  • Transmissions to the FBI or a channeling partner are encrypted in transit
  • Session data is cleared from the capture device after each transmission
  • No biometric data is stored on mobile phones, personal devices, removable media, or consumer cloud storage services

Administrative

  • Access to systems containing personal information is limited to personnel who require it to perform their duties
  • All personnel are trained on the handling of personally identifiable information and on the confidentiality obligations of this Policy prior to performing services
  • All personnel, including contracted technicians, execute a written confidentiality agreement
  • Contracted technicians are subject to the same requirements as employees, and MIS remains responsible for their compliance

9. On-Site and Mobile Sessions

When MIS provides service at a client location, the following practices apply:

  • Sessions are conducted in a space that allows information to be given out of earshot and out of view of other participants
  • Screens are positioned so that entered information is not visible to those waiting
  • Rosters, sign-in sheets, and any working notes are collected by the technician, transported in a secured container, and destroyed by cross-cut shredding at our office
  • No materials containing personal information are left at the client site

10. Incident Response and Breach Notification

MIS maintains procedures for identifying, containing, and remediating any suspected loss, theft, or unauthorized access to or disclosure of biometric data or personal information.

In the event of a confirmed incident, MIS will notify each affected individual without unreasonable delay, and in any event within seventy-two hours of confirmation. Where the incident arises in connection with services arranged by a Requesting Institution, MIS will notify that institution’s designated contact within the same period.

Notification will describe the nature of the incident, the categories of information involved, the steps taken in response, and the measures available to the individual. MIS will additionally notify any agency or regulator where required by law.

11. Individual Rights

Any individual serviced by MIS may:

  • Request confirmation of what information MIS holds about them and for how long
  • Request correction of inaccurate personal information in a pending submission
  • Request destruction of any retained transaction record, subject to any legal or agency retention obligation
  • Decline service at any point prior to submission
  • Submit a complaint regarding the handling of their information

Requests may be directed to the contact listed in Section 14 and will be acknowledged within five business days.

12. Compliance

MIS provides services in a manner consistent with applicable federal and state requirements governing fingerprint-based record checks, including the requirements imposed by the Federal Bureau of Investigation and its approved channelers, the Fair Credit Reporting Act where MIS acts in connection with a consumer report, and applicable state law governing the collection and handling of biometric identifiers in the jurisdictions in which we operate.

Where a Requesting Institution is subject to additional obligations, including the Family Educational Rights and Privacy Act, MIS will cooperate in meeting those obligations and will execute such further agreements as the institution reasonably requires.

13. Subcontractors and Service Providers

Where MIS engages a third party in the delivery of services, including FBI-approved channeling partners, payment processors, and contracted fingerprint technicians, that party is provided only the information necessary to perform its function and is bound by confidentiality and data protection obligations no less protective than those in this Policy.

MIS does not authorize any subcontractor to use information for its own purposes.

14. Policy Administration and Contact

This Policy is reviewed at least annually and upon any material change to our services, systems, or legal obligations.

Questions, requests, and complaints concerning this Policy or the handling of personal information should be directed to:

Alhussain Yusuf, Owner
Midwest Identity Services
8101 E. Bannister Rd., Kansas City, MO 64134
Telephone: (816) 442-0295
Email: moservices.midwest@gmail.com