Updated: 16.09.2026.
This version takes effect on the day it is published.
MyFaceGuard helps organisations and other clients manage photo-use requests and people’s responses. The client determines the purposes and legal basis for processing its photos. MyFaceGuard provides the platform and processes data on the client’s behalf in line with its documented instructions.
Managing your individual account, identity verification, optional biometric search and the decision about photo use are separate actions. Creating an account, signing in or recognising yourself in a photo is not, in itself, permission to publish the photo.
You can write to compliance@myfaceguard.com about your data and your rights even if you have no account or no longer have access to one.
The platform is provided by MyFaceGuard, SIA, registration No. 40203708503, registered address: Kaivas iela 31 k-5 - 117, Riga, LV-1021, Latvia.
General enquiries: hello@myfaceguard.com. Technical support: support@myfaceguard.com. Privacy and data protection matters: compliance@myfaceguard.com.
This policy applies to website visitors, users, client representatives, recipients of photo-use requests and other people whose data is processed on the platform. It explains how data is processed; reading the policy is not a general consent to all processing purposes.
MyFaceGuard is the controller for processing whose purposes and essential means we determine ourselves: administering individual accounts, the identity verification we provide, managing the biometric template of an individual profile, website operation, security, communication, marketing and compliance with our own legal obligations.
The client is the controller to the extent it determines the purposes and means of processing its albums, contacts, photo-use requests and responses. MyFaceGuard stores and manages that data on the client’s behalf as a processor, under a data processing agreement and the client’s documented instructions. The role in any specific processing is determined by the actual circumstances.
The client is responsible for the lawfulness of uploading photos, granting access and any further use, for informing the people concerned and for an appropriate retention period. This policy does not replace the privacy information provided by the client. If a client acts on behalf of another controller, it must have the corresponding authorisation and contractual arrangements in place.
The client’s administrators and editors act on the client’s behalf within their access rights. These roles do not give the right to access another person’s individual account or to make decisions about the use of that person’s photos.
From you we receive registration and profile information, contact details, settings, responses to requests, support correspondence and, if you choose biometric search, the face photos you submit for it.
From the client or its authorised users we receive album photos, contacts including imported contact lists, event information, request purposes, channels, deadlines and the access rights granted. Receiving a request does not mean that you are a registered user or that you are necessarily shown in the photo.
From authentication and identity verification services we receive the information needed to carry out the particular sign-in or verification.
Technical data and an activity history arise on the platform: sign-in and security events, IP address, device and browser information, the time of requests and responses, statuses, changes and withdrawals. During biometric search, a face template and possible match results are generated.
If your contact details were submitted by a client, that client provides the information about their origin and the basis for the specific request. MyFaceGuard helps you find out which client sent the request.
To create an account, authenticate you, store settings and provide the core functions you request, we process account and access data in order to perform the contract with the user — Article 6(1)(b) of the General Data Protection Regulation (GDPR). The mandatory fields in registration are necessary to create the account; without them we cannot provide the relevant function. Additional profile fields are voluntary.
We respond to your pre-contractual enquiry on the basis of Article 6(1)(b) GDPR. For general business communication and communication with client representatives we rely on our legitimate interest in maintaining and administering client relationships — point (f). A contract with a legal entity is not, in itself, a basis under point (b) for processing the data of all its employees.
To provide support we use your correspondence and the technical data needed to resolve the issue: to perform the contract or on our legitimate interest in keeping the service running. We process security events and logs on our legitimate interest in preventing unauthorised access, fraud and incidents, assessing the impact on your rights.
Data needed to comply with legal obligations, such as accounting requirements and data subject requests, is processed under Article 6(1)(c) GDPR. We may keep the limited information required to establish or defend specific legal claims on the basis of legitimate interests.
We send newsletters and optional marketing messages with your consent — point (a). You can opt out through the unsubscribe link in each message. Opting out does not affect your account or the necessary service notifications.
Biometric search requires separate, explicit consent — Article 6(1)(a) and Article 9(2)(a) GDPR. Its conditions are described in section 7.
Signing in with an email address or an available external account, such as Google or Microsoft, gives access to the account. Such a sign-in is not, in itself, equivalent to verifying a person’s identity with an electronic identification means.
For identity verification we use eID Easy and the electronic identification service you choose. Depending on the method and the scope of the check, identity attributes are processed, such as first name, surname, personal identifier, as well as the verification result, time and transaction reference. The exact amount of data is determined by the chosen method and by what the verification requires.
The purpose of this processing is to link platform activity to a verified person. The basis is the performance of the identity verification service provided to the user; for fraud prevention measures it is our legitimate interest in providing a trustworthy service. If a required verification is not completed, the function that depends on it may be unavailable. This does not remove your right to contact the controller and exercise your data protection rights.
The retention period of the identity service is not the retention period of the verification record kept by MyFaceGuard. We keep the necessary verification evidence for the traceability of the account and its activity in accordance with section 10.
The client determines which photos it wants to use, for what purpose, in which channels and for how long. The platform records the request, your response and the history of changes to it.
Confirming “This is me” concerns whether the person in the photo is you. Permission to use the photo is a separate decision. Not responding, creating an account or consenting to face recognition is not permission to use a photo.
If the use is based on consent, you can withdraw it on the platform or by contacting the client. Withdrawal does not affect processing carried out lawfully beforehand. The client must stop any further use based on the withdrawn consent and assess the deletion steps required.
If the client relies on another legal basis, such as legitimate interests, it informs you of that basis and assesses your objection in line with the applicable requirements. The response status on the platform does not, in itself, determine the lawfulness of the processing.
MyFaceGuard records your decision; changing it does not, in itself, delete photos on the client’s website, on social networks, in printed materials or in other systems. The relevant controller is responsible for the follow-up actions.
The client’s authorised users can see the request, the response linked to the person, the status and the necessary history of changes in line with their access rights. Other album users may be able to see photos according to the album access settings, including where several people appear in them.
If a client asks its own employee for consent, it must ensure a genuinely free choice. Refusing or withdrawing consent must not lead to detriment in the employment relationship; the validity of consent has to be assessed in the light of the employer–employee relationship.
Biometric search helps find photos in which you may appear. It is an optional feature. Without it you can still use the functions available to you that do not require biometric data.
The face photos submitted for this feature are used to create a face template — a mathematical representation of facial features. The template is compared with the face data technically derived from the photos in the relevant album. The result is a prediction of a possible match, not an infallible proof of identity. You can review the result and indicate that the person in the photo is not you.
Separate, explicit consent is required before biometric data is processed. Accepting the terms of use does not replace it. Consent covers the stated search purpose and scope; it does not allow a client to use your biometric data for other purposes. Where permission is requested for a search in a specific client’s albums, you manage that separately from storing the face template.
The original photos submitted to create the biometric template are deleted after processing. This does not apply to photos uploaded to a client’s album. The stored biometric template is protected with encryption and access restrictions; it is not anonymous information.
You can withdraw biometric consent and request deletion of the template in your profile settings or by writing to compliance@myfaceguard.com. Withdrawal stops any further search based on that consent. Deletion of the template must also be ensured at the biometric processing service provider involved. A minimal record of the fact of consent and withdrawal may be kept as evidence, without keeping the template itself for that purpose.
Withdrawing biometric consent does not, in itself, change your responses about photo use; those are managed separately. Likewise, withdrawing permission to use a photo is not, in itself, deletion of the face template.
One person’s consent does not cover the processing of the biometric data of other people appearing in an album. Processing for album searches must have an appropriate legal basis in respect of every person whose data is processed. Transient technical processing is also processing.
MyFaceGuard does not use client photos, responses or biometric templates for its own marketing or for purposes unrelated to providing the requested service.
Data is received, to the extent necessary, by the client’s authorised users, our authorised staff and service providers: cloud infrastructure and storage providers, including AWS; the biometric search provider AWS Rekognition; the identity verification provider eID Easy and the provider of the chosen identification means; authentication, email delivery, including Brevo, and technical support providers.
Depending on your choices, data may be shared with cookie management, analytics and advertising services. Where necessary, data is received by legal and accounting advisers or by competent authorities on the basis of a lawful request.
We apply data protection and confidentiality terms to processors. Some identity, sign-in or other service providers may act as independent controllers for their own purposes; their privacy information applies to that processing.
We do not sell personal data. You can request information about the recipients involved in a specific processing activity at compliance@myfaceguard.com.
Platform photos and related platform data are stored in the European Union. AWS infrastructure in Europe is used to provide biometric processing.
Storage in Europe does not, in itself, rule out access by a recipient or its support staff from a country outside the European Economic Area (EEA). Some authentication, communication, analytics or advertising services may involve international transfers.
A transfer outside the EEA requires an applicable legal mechanism, such as a European Commission adequacy decision or standard contractual clauses with the necessary supplementary safeguards. Information about the specific mechanism and a copy of the applicable safeguards can be requested at compliance@myfaceguard.com.
We set retention periods according to the purpose of the data and what is necessary:
Account deletion is permanent. Signing in again does not restore a deleted account, and no 12-month account recovery period applies.
Deleting an individual account does not, in itself, mean deleting all photos and decision history held by a client. A client may keep the necessary evidence of a decision and its withdrawal only where it has a separately justified need, a legal basis and a limited period. Keeping evidence does not give permission to continue using a photo after consent has been withdrawn.
Data may remain in backups until the end of the relevant backup rotation cycle, with restricted access. Backups are not intended for day-to-day use of a deleted account or for continuing a biometric search that has been withdrawn. We inform you in our reply to a request about the deletion applicable to it and any retention exceptions.
Closing a client account and deleting an individual account are different actions. Save the information you need before you lose access.
Subject to the conditions of the specific processing, you can request access to your data and a copy of it, rectification, erasure, restriction of processing and data portability. Portability applies to data you have provided that is processed by automated means, where the basis is consent or a contract.
You can withdraw consent at any time. You can object to processing based on legitimate interests, stating the grounds relating to your particular situation. You can object to direct marketing at any time without giving reasons.
Write to compliance@myfaceguard.com. If a request concerns data controlled by a client, we will help direct it to that client and provide the necessary support. Creating an account is not a condition for exercising your rights.
We reply without undue delay and no later than one month after receiving the request. Because of complexity or the number of requests, the period may be extended by a further two months; we notify you of that and of the reasons within the first month.
We ask for additional identity information only where there are reasonable doubts about the requester’s identity, and to a proportionate extent. Requests are generally free of charge. A refusal or a fee may be justified only on the conditions provided for in applicable law.
Automation helps shortlist possible photo matches, manage requests and record statuses. Face comparison can be wrong. A technical match is not, in itself, a decision to publish.
MyFaceGuard does not take decisions based solely on automated processing that have legal or similarly significant effects on a person. The client is responsible for its photo-use decisions.
Under the terms of use, individual accounts are intended for people aged 18 and over. This does not mean that minors cannot appear in a client’s photos. The client must ensure the lawfulness of processing their data and the necessary representation; an adult user’s account does not automatically give the right to decide on behalf of another person. Report any possible unauthorised processing of a child’s data to compliance@myfaceguard.com.
We use technical and organisational safeguards appropriate to the risk of the processing, including access control, separation of roles, encryption and activity logs. Access to data is granted only to the extent necessary. A service provider’s certification does not, in itself, mean that MyFaceGuard is certified against the same standards.
If you suspect unauthorised access to an account or a personal data breach, contact support@myfaceguard.com or compliance@myfaceguard.com.
You can contact us about any data protection matter. You have the right to lodge a complaint with the Latvian Data State Inspectorate (www.dvi.gov.lv) or another competent EEA supervisory authority, including in the country of your habitual residence, place of work or the place of the alleged infringement. Contacting us first is not a precondition for a complaint.
The current version and the date it was updated are available on this page. We inform you of material changes in an appropriate way before the relevant new processing starts. Updating the policy does not, in itself, extend the scope of consent given earlier; where new processing requires consent, we ask for it separately.