Privacy Policy

    Last updated: 14.04.2026

    Short summary

    MyFaceGuard helps organizations collect, store, review, and track consent in photo-related workflows.

    When an organization uses MyFaceGuard for its photo, consent, or publication process, that organization usually decides why and how personal data is processed. In those situations, MyFaceGuard usually acts as a service provider or processor on the organization's behalf.

    This Privacy policy explains when MyFaceGuard acts as a controller for its own purposes, when it processes data on behalf of organizations, what data is processed, why it is processed, how long it is kept, who it is shared with, whether it is transferred outside the EU/EEA, and what rights data subjects have.

    1. Who we are

    Controller for the processing described in this policy where MyFaceGuard acts in its own name:

    • MyFaceGuard, SIA
    • Registration number: 40203708503
    • Registered address: Rīga, Kaivas iela 31 k-5 - 117, LV-1021, Latvia
    • General email: hello@myfaceguard.com
    • Privacy and compliance email: compliance@myfaceguard.com
    • Contact person responsible for data protection: Eva Luksa

    Pašlaik MyFaceGuard nav iecēlis datu aizsardzības speciālistu. Ja tas mainīsies, attiecīgā kontaktinformācija tiks publicēta šeit.

    2. When this policy applies

    This policy applies to personal data processed by MyFaceGuard:

    • when you visit our website;
    • when you contact us;
    • when you create or use a MyFaceGuard account;
    • when you receive support from us;
    • when you subscribe to product updates or marketing messages;
    • when cookies, analytics, or advertising technologies are used based on your choices;
    • when personal data is processed through the MyFaceGuard platform for or on behalf of an organization.

    If you receive a consent request from an organization through MyFaceGuard, that organization is usually the main controller for the relevant photo workflow and publication decision. In that case, you should also read that organization's privacy information.

    3. Our role: controller or processor

    MyFaceGuard does not always act in the same role.

    MyFaceGuard usually acts as controller for:

    • website operation;
    • account administration;
    • service security;
    • fraud prevention;
    • support and service communications;
    • compliance with legal obligations;
    • product analytics and marketing where permitted.

    MyFaceGuard usually acts as processor or service provider for:

    customer content and consent workflows handled by organizations through the platform, including uploaded photos, consent records, event-related data, workflow history, and similar content.

    The organization using MyFaceGuard usually remains responsible for:

    • choosing the legal basis for processing;
    • deciding whether a photo or other material may be published;
    • ensuring the accuracy, lawfulness, and appropriateness of the information entered in consent requests;
    • deciding how long organization-uploaded content and consent records are kept, where that choice is available in the platform;
    • responding to data subject requests relating to its own workflow, unless MyFaceGuard is required to assist.

    4. What data we process when MyFaceGuard acts as controller

    4.1 Website and contact inquiries

    If you contact us through a form, email, or another contact channel, we may process:

    • name;
    • email address;
    • company name;
    • message content;
    • attachments or other information you choose to share.

    Why we process it: to answer your inquiry, communicate with you, and provide pre-sales, after-sales, or support information.

    Legal basis: pre-contractual steps, contract, or our legitimate interests in handling business inquiries and communications.

    Retention: usually up to 12 months after the matter is resolved, unless a longer period is needed for follow-up, legal reasons, or dispute handling.

    4.2 Account and profile data

    When you create or use an account, we may process:

    • email address;
    • password or authentication credentials, such as sign-in with Google, where available;
    • first name and last name, where collected in the registration or profile flow;
    • account role and organization link;
    • profile settings and preferences;
    • optional profile information, such as phone number, job title, country, city, or profile photo, if you choose to add it.

    Why we process it: to create and manage accounts, authenticate access, provide the service, maintain security, and support account-related functions.

    Legal basis: contract performance and, where relevant, our legitimate interests in service security and administration.

    Retention: while the account is active and for a limited period after closure where needed for security, dispute handling, backups, or legal obligations.

    4.3 Support and service operations

    If you contact support or if we need to investigate a technical issue, we may process:

    • name;
    • email address;
    • organization name;
    • issue description;
    • screenshots;
    • technical logs relevant to the issue;
    • communication history.

    Why we process it: to provide support, diagnose problems, maintain service quality, and prevent abuse.

    Legal basis: contract performance and our legitimate interests in operating and securing the service.

    Retention: usually up to 24 months after the ticket is closed, unless a longer period is needed for security, dispute, or legal reasons.

    4.4 Security, abuse prevention, and logs

    We may process technical and usage data such as:

    • login events;
    • IP-related security data;
    • device and browser information;
    • access and audit logs;
    • error logs and diagnostic records.

    Why we process it: to protect the platform, detect misuse, prevent unauthorized access, maintain system integrity, and document security-related events.

    Legal basis: our legitimate interests in service security and, where applicable, legal obligations.

    Retention: typically 6 to 24 months, depending on the type of log and risk context.

    4.5 Service notices and account-related communications

    We may send service notices that are necessary for account and service operation, such as:

    • email verification messages;
    • security notices;
    • notices about material changes;
    • communications relating to account access or service functionality.

    Important: these communications are not marketing communications. They are part of providing the service.

    Why we process it: to support account operation, service security, and necessary communication with users.

    Legal basis: contract performance and, where needed, our legitimate interests in providing a secure and functioning service.

    Retention: for as long as needed for the specific communication purpose and for a limited period afterwards where needed for evidence, security, or legal reasons.

    4.6 Newsletters and marketing messages

    If you subscribe to newsletters or marketing messages, we may process:

    • email address;
    • name, if provided;
    • subscription preferences;
    • records showing when and how consent to receive such messages was given or withdrawn.

    Why we process it: to send newsletters, product updates, and other marketing communications where permitted.

    Legal basis: consent.

    Retention: until you unsubscribe or withdraw consent. For a limited period, we may keep a minimal record of your opt-out to ensure such messages are not sent to you again by mistake.

    4.7 Cookies, analytics, advertising, and remarketing

    Subject to your cookie choices, we may use:

    • strictly necessary cookies;
    • preference cookies;
    • analytics tools;
    • advertising and remarketing tools.

    This may include tools such as:

    • Cookiebot or an equivalent cookie consent tool;
    • Google Analytics;
    • Google Ads;
    • Meta Ads and remarketing tools.

    Why we process it: to operate the website, remember preferences, understand website usage, improve performance, measure campaigns, and run advertising where permitted.

    Legal basis: strictly necessary cookies are used where necessary for website functionality; non-essential cookies and related tracking are used only based on your consent.

    Retention: according to your cookie choices and the configuration of the relevant provider.

    5. What data may be processed through the platform for customer organizations

    When an organization uses MyFaceGuard, the platform may process personal data such as:

    • uploaded photos;
    • names and contact details of individuals;
    • event details, photo metadata, and related context;
    • consent request messages;
    • consent decisions and status history;
    • records showing when, how, and by whom a decision was made;
    • workflow notes, tags, labels, and internal comments;
    • audit trails and user activity records;
    • communications relating to a consent request;
    • information submitted by a recipient, such as "I am in this photo" or similar responses, where such features are available.

    If an organization plans to publish material in which a person may appear, MyFaceGuard may send a consent request or another workflow-related notice on that organization's behalf to the person's email address or another available communication channel specified by the organization.

    If biometric data is stored in the system and the relevant functionality is enabled, the request may be prepared automatically after the person is recognized. In other cases, the organization may send the request manually using contact information available to it.

    Important: such notices are part of the service functionality and are not considered MyFaceGuard marketing messages.

    In these cases, the organization usually determines the purposes and legal basis for the processing. MyFaceGuard usually processes this data on the organization's behalf in order to provide the service.

    Typical sources of this data may include:

    • the organization using MyFaceGuard;
    • users invited by that organization;
    • recipients responding to requests;
    • data created within the workflow, such as status changes, timestamps, and audit records.

    6. Optional recognition and biometric features

    Some MyFaceGuard features may support optional recognition based on profile data or biometric data, where enabled. If these features are used, the platform may process:

    • face images or technical image derivatives used to set up recognition functionality;
    • reference images selected for comparison;
    • biometric templates or similar technical representations, where such functionality is enabled;
    • recognition results and related workflow data.

    Important: biometric data used to uniquely identify a person may be subject to stricter legal rules under applicable law.

    MyFaceGuard does not treat biometric processing as mandatory. It is an optional feature intended to make use of the service more convenient and automated. Whether biometric processing may lawfully be used in a specific customer workflow depends on the context, the customer's chosen legal basis, and any additional conditions required by law.

    If a user activates face recognition functionality, MyFaceGuard may store a biometric face template necessary for identifying the person and providing the service. These data are retained until the account is deleted, consent is withdrawn, a deletion request is made, or applicable law requires or permits another retention period.

    When an account is deleted or biometric data are removed, the biometric data are also deleted from third-party face recognition services used to provide MyFaceGuard within a reasonable period, where and to the extent they are processed there for that purpose.

    MyFaceGuard applies technical and organizational safeguards designed to protect such data, such as access controls, restricted use, and encryption where appropriate.

    7. Why we process personal data and on what basis

    Mēs apstrādājam personas datus tikai tad, ja tam ir tiesisks pamats. Atkarībā no situācijas mēs paļaujamies uz:

    • līgumu, lai izveidotu kontus, nodrošinātu platformu, autentificētu lietotājus un sniegtu pieprasītās funkcijas;
    • piekrišanu, jaunumu vēstulēm, izvēles mārketingam, neobligātajām sīkdatnēm un noteiktām izvēles funkcijām, ja piekrišana ir atbilstošais pamats;
    • leģitīmajām interesēm, drošībai, ļaunprātīgas izmantošanas novēršanai, atbalstam, pakalpojuma uzlabošanai un biznesa pieprasījumu apstrādei, pēc izvērtējuma, ka mūsu intereses nepārsniedz datu subjektu tiesības un brīvības;
    • juridiskam pienākumam, ja mums jāglabā ieraksti, jāatbild uz likumīgiem pieprasījumiem vai jāizpilda grāmatvedības, nodokļu vai citi juridiski pienākumi.

    Where an organization uses MyFaceGuard for its own workflow, that organization is usually responsible for identifying the correct legal basis for that processing.

    8. Cookies and tracking

    We use a consent management tool to manage cookie choices. This means:

    • non-essential cookies are not activated before consent;
    • cookie categories can be accepted or rejected separately, where applicable;
    • consent choices can be changed later;
    • if a non-essential category is rejected, related tracking is not used for that user.

    Analytics, advertising, and remarketing tools are activated only where appropriate consent has been given.

    9. Who we share personal data with

    We share personal data only when necessary for operating the service, providing requested functionality, or complying with law. Depending on the context, recipients may include:

    • hosting, cloud storage, and infrastructure providers;
    • authentication and security providers;
    • email delivery and communication providers, including Brevo or equivalent providers;
    • messaging providers where another communication channel allowed by the user is used;
    • support and ticketing providers;
    • analytics, advertising, and consent management providers, where permitted by your choices;
    • professional advisers, such as legal, accounting, or audit advisers;
    • public authorities, regulators, courts, or law enforcement, where legally required;
    • customer-selected integrations or subprocessors, where enabled by the organization using the platform;

    We do not sell personal data. We do not use customer-uploaded photos, consent records, or biometric data for our own marketing, publicity, or other purposes unrelated to providing the service, and we do not disclose those materials to third parties for their independent further use.

    10. Transfers outside the EU/EEA

    Photos uploaded to the MyFaceGuard platform and related platform data are stored on servers located in the EU.

    In some cases, certain service providers or integrations may process personal data outside the EU/EEA or provide access to such data from outside the EU/EEA, especially where certain analytics, advertising, or other third-party tools are used.

    Where this happens, we use the safeguards required by applicable law, such as:

    • adequacy decisions, where available;
    • Standard Contractual Clauses;
    • supplementary technical and organizational measures, where needed.

    11. How long we keep data

    We keep personal data only for as long as necessary for the relevant purpose. Typical retention periods may include:

    • contact inquiries: up to 12 months after resolution;
    • account and profile data: while the account is active and for a limited period after closure;
    • support tickets: usually up to 24 months after closure;
    • security and audit logs: usually 6 to 24 months;
    • newsletter data: until unsubscribe or withdrawal of consent, plus a limited minimal record of your opt-out to ensure such messages are not sent again by mistake;
    • analytics and advertising data: according to cookie choices and provider configuration;
    • customer workflow and consent records: according to the customer organization's settings, contract terms, or applicable legal requirements;
    • biometric templates or recognition data: until deletion, account closure, withdrawal of consent, or the applicable retention setting.

    If you submit a response to a consent request, your decision, status history, timestamp, and related audit records may continue to be stored for the organization's consent evidence purposes even after your private account is deleted, where this is necessary for documenting the relevant workflow, for contractual or legal requirements, or as otherwise permitted by applicable law.

    A longer period may apply where required by law, needed for dispute handling, necessary for security, or preserved in backups for a limited cycle.

    12. Your rights

    Depending on the circumstances and applicable law, you may have the right to:

    • access your personal data;
    • request correction of inaccurate or incomplete data;
    • request deletion of your data;
    • request restriction of processing;
    • object to processing based on legitimate interests;
    • withdraw consent at any time, where processing is based on consent;
    • receive your data in a portable format, where applicable;
    • lodge a complaint with a supervisory authority.

    If personal data is processed through MyFaceGuard on behalf of an organization, that organization is usually the first point of contact for rights requests relating to that workflow.

    13. How to exercise your rights

    To exercise your rights, contact us at compliance@myfaceguard.com.

    Please provide enough information for us to identify you and understand your request. We may ask for additional information where necessary to verify your identity or clarify the scope of the request.

    We aim to respond within 1 month, unless a longer period is permitted by law due to the complexity or number of requests.

    To withdraw consent:

    • change your response to photo use in the MyFaceGuard platform, for example from "approved" to "denied", where that functionality is available in the relevant workflow;
    • contact the organization that sent the consent request if you want to withdraw or change your previous response;
    • use the unsubscribe link in marketing emails;
    • change your cookie choices in the consent tool;
    • adjust settings in your account, where available;
    • delete optional biometric or profile data from your account settings, where available.

    14. Automated processing

    MyFaceGuard may use automation to:

    • organize records and workflows;
    • support optional recognition features;
    • log events and status changes;
    • make the service faster and easier to use.

    MyFaceGuard does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

    Any decision about whether a photo or other material may be published remains the responsibility of the organization using the service.

    15. Children

    MyFaceGuard is not designed as a standalone service for children.

    If an organization uses MyFaceGuard in a context involving children or minors, that organization is responsible for ensuring that the processing is lawful, transparent, and appropriate in that context.

    If you believe that a child's data has been submitted without proper authorization or lawful basis, please contact us without delay.

    16. Security

    We use technical and organizational measures designed to protect personal data, including access controls, role-based permissions, logging, encryption where appropriate, and other safeguards relevant to the nature of the data and the service.

    No system can guarantee absolute security, but we work continuously to reduce risk and improve protection.

    17. Complaints

    If you have questions or concerns about privacy, please contact us first at compliance@myfaceguard.com.

    You also have the right to lodge a complaint with the Latvian supervisory authority: Datu valsts inspekcija, Elijas iela 17, Rīga, LV-1050, Email: pasts@dvi.gov.lv, Phone: +371 67223131

    18. Changes to this policy

    We may update this Privacy policy from time to time.

    If the changes are material, we will update the date at the top of this page and, where appropriate, notify users through the website, in-product notice, or email.

    Questions about privacy?

    If you have questions about how we handle your data, please get in touch.

    Contact