Last updated: 19.06.2026
1. Introduction
This Privacy Policy explains how Trifork A/S processes personal data in connection with the MyConsent platform.
MyConsent is a platform that helps organizations manage media assets, tag people appearing in those assets, request and document consent, and maintain records of consent decisions over time.
This Privacy Policy applies to the personal data we process when operating MyConsent, including account administration, service delivery, support, security, and related platform operations. Where a customer organization uses MyConsent to manage its own media, users, and consent workflows, that customer may be the data controller for those activities, as explained below.
2. Data Controller and Contact
For the operation of the MyConsent platform itself, Trifork A/S is the data controller for the personal data described in this Privacy Policy where we determine the purposes and means of processing.
Trifork A/S
Gdanskgade 2, 2150 Nordhavn
Denmark
CVR: 20921897
Email: privacy@myconsent.dk
You can contact us at privacy@myconsent.dk for questions about privacy, data protection, or this Privacy Policy. This is our privacy contact mailbox. If Trifork A/S has appointed a data protection officer for a specific processing activity, we will provide the relevant DPO contact details where required.
3. Controller and Processor Roles on the Platform
MyConsent is used by companies and organizations that upload assets, invite users, tag people, and send consent requests.
- For platform administration, account management, billing, security, support, service operations, and our own analytics, Trifork A/S acts as data controller.
- For customer-managed content and workflows, such as uploaded media, tagged users, consent requests, consent responses, event consent workflows, and internal team administration, the relevant customer organization will typically act as its own data controller, and Trifork A/S will generally act as a data processor on that organization’s behalf.
If you receive a consent request from an organization using MyConsent, that organization may be separately responsible for its own processing of your personal data. If you contact us about a processing activity where we act as processor, we may refer your request to the relevant customer organization.
4. Personal Data We Process
Depending on how MyConsent is used, we may process the following categories of personal data:
- Account and profile data, such as name, email address, username, role, and profile picture
- Organization and team membership data, such as the company you belong to and your access role
- Consent workflow data, such as consent requests, consent responses, consent history, timestamps, selected purposes, media types, exceptions, and related audit information
- Media-related data, such as uploaded files, file names, folders, projects, tags, thumbnails, previews, and references to people connected to an asset
- Media-processing metadata, such as image dimensions, generated previews, semantic-search metadata, and face-detection counts and bounding boxes where these features are enabled
- Communication data, such as invitation emails, password reset emails, account signup invitations, consent request emails, event invitation emails, and operational email delivery records
- Technical and security data, such as IP address, session information, authentication tokens, timestamps, login and OTP audit events, and system activity logs
- Support and operational data, such as messages sent to us and information needed to troubleshoot service issues
- Analytics data about use of the service, where enabled, such as product events and aggregated usage information
Uploaded assets may contain personal data, including images or videos of identifiable individuals. The customer organization using MyConsent is responsible for ensuring that it has an appropriate legal basis for uploading and using such assets.
5. How We Collect Personal Data
We collect personal data:
- Directly from you when you create an account, respond to a consent request, update your profile, contact support, or otherwise use the platform
- From customer organizations using MyConsent, for example when they invite you to a team, upload media containing you, tag you on an asset, or send you a consent request
- Automatically through the platform when you log in, use authenticated sessions, upload files, or interact with workflows, security features, and product analytics
6. Purposes and Legal Bases
Where Trifork A/S acts as data controller, we process personal data for the purposes and legal bases described below. Where Trifork A/S acts as data processor for a customer organization, the customer organization determines the relevant legal basis and we process the data under that customer’s instructions and applicable data processing agreement.
- To provide and administer the service, including account creation, login, password reset, invitations, organization membership, access management, and service configuration. Legal basis: GDPR Article 6(1)(b) and, where relevant for business customers, Article 6(1)(f).
- To operate customer-managed consent workflows, including sending consent requests, recording responses, documenting history, and showing consent status in relation to media. Where this is customer-managed content, Trifork A/S generally acts as processor and the customer organization determines the legal basis. Where Trifork A/S acts as controller for related service administration, the legal basis may be GDPR Article 6(1)(b), Article 6(1)(c), and/or Article 6(1)(f).
- To host, organize, and process media assets, including storing uploaded files, generating thumbnails and previews, enabling semantic search, and supporting face-detection based workflow prompts where enabled. Where this is customer-managed content, Trifork A/S generally acts as processor. Where Trifork A/S acts as controller for service administration, the legal basis may be GDPR Article 6(1)(b) and/or Article 6(1)(f).
- To maintain security, prevent misuse, investigate incidents, protect accounts, and preserve audit trails. Legal basis: GDPR Article 6(1)(f) and, where applicable, Article 6(1)(c).
- To send service-related communications, including login codes, password reset emails, invitations, consent request notifications, event invitations, support replies, and operational messages. Legal basis: GDPR Article 6(1)(b), Article 6(1)(f), and/or Article 6(1)(c), depending on the context.
- To provide customer support and troubleshoot service issues. Legal basis: GDPR Article 6(1)(b) and Article 6(1)(f).
- To comply with legal obligations, including accounting, tax, security, and regulatory obligations. Legal basis: GDPR Article 6(1)(c).
- To improve service features and understand product usage. Legal basis: GDPR Article 6(1)(f) or consent where consent is required by applicable law.
Uploaded media and consent records may include information that is sensitive or that reveals special categories of personal data. The customer organization is responsible for determining whether such data may be processed and for ensuring that any required legal basis or consent is in place.
7. Consent Records and Audit Trail
MyConsent is designed to document consent decisions and related events over time. Depending on the workflow, records may include:
- Who sent a consent request
- Who received it
- Which asset, event, purpose, or media type the request related to
- Whether the request was approved, declined, revoked, or marked as an exception
- When the action took place
- Related technical metadata needed for accountability, security, or troubleshooting
These records may be retained for as long as necessary to document consent status, comply with legal obligations, resolve disputes, support customer instructions, or protect the security and integrity of the service.
8. Media Processing, Semantic Search, and Face Detection
MyConsent may process uploaded images and videos to provide media-management features. This may include generating thumbnails, resized previews, metadata, and search-related information.
Where semantic search is enabled, MyConsent may create whole-image embeddings for uploaded images. These embeddings are used to support image and text-based search and are associated with the media asset, not with an individual person’s face.
Where face detection is enabled, MyConsent may detect face regions in uploaded images to help customers identify when people in an image may need to be tagged for consent management. Face detection stores face counts and bounding-box metadata, such as the position and size of detected face regions and a detection confidence score.
MyConsent does not use face detection to identify people, verify identity, compare faces against a biometric database, create faceprints, store face-recognition templates, auto-tag people, infer emotions, or infer protected characteristics. The feature is detection-only and is used to support consent workflow quality. It is not used for biometric identification or biometric verification.
9. Sharing of Personal Data and Processors
We do not sell personal data. We may share personal data where necessary with:
- The customer organization using MyConsent, including its authorized users and administrators
- Hosting and infrastructure providers, including Hetzner Cloud and related Hetzner services used to host the platform and supporting services
- Object storage providers, including Hetzner Object Storage where customer media is stored in S3-compatible object storage
- Email delivery providers, including Simply, used to send service-related emails, such as login codes, invitations, consent requests, password resets, and support messages
- Analytics and operational monitoring services, including the analytics service operated at
analytics.laubergs.com where enabled
- Security, support, maintenance, and professional advisers where necessary for operating, protecting, or improving the service
- Authorities, regulators, courts, or other third parties where required by law or necessary to establish, exercise, or defend legal claims
Processors are required to process personal data only under our instructions or the relevant customer organization’s instructions, as applicable, and to apply appropriate confidentiality and security measures.
10. International Transfers
We aim to process and host MyConsent data within the EU/EEA where possible. Where personal data is transferred outside the EU/EEA, appropriate safeguards will be used, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another transfer mechanism permitted by applicable data protection law.
11. Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, to provide the service, to comply with legal obligations, to follow customer instructions where we act as processor, and to protect legitimate business, security, and legal interests.
- Account and organization data is generally retained while the account or customer relationship is active and for a limited period afterwards where needed for administration, security, legal claims, or legal obligations.
- Customer-managed media, tags, consent records, event records, and related workflow data are generally retained according to the customer organization’s use of the platform, customer instructions, contract terms, and applicable legal requirements.
- Face-detection metadata and semantic-search metadata generally follow the retention of the underlying media asset. If the media asset is deleted, related detection and embedding metadata should also be deleted or made inaccessible according to the deletion and backup process.
- Completed email queue records are normally retained for a limited operational period. The platform default for completed queued email records is up to 90 days unless configured otherwise.
- Security logs, login and OTP audit records, admin activity logs, and incident records are retained for limited periods appropriate to security, fraud prevention, accountability, and legal requirements.
- Billing, accounting, and tax records are retained for the period required by applicable law.
- Backups may retain data for a limited period after deletion from the live service, after which they are overwritten or deleted according to backup procedures.
When personal data is no longer needed, we delete, anonymize, or otherwise restrict it in accordance with applicable law, customer instructions, and our operational requirements.
12. Your Rights
Subject to the conditions and limitations in applicable data protection law, you may have the right to:
- Access your personal data
- Correct inaccurate or incomplete data
- Request erasure of personal data
- Restrict processing
- Object to processing based on legitimate interests
- Receive personal data in a portable format where the right to data portability applies
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
Contact us at privacy@myconsent.dk if you wish to exercise your rights in relation to processing for which Trifork A/S is the controller. If your request concerns personal data processed by a customer organization using MyConsent, we may refer you to that organization or assist the organization in responding to your request.
13. Cookies and Similar Technologies
MyConsent uses essential technical mechanisms required for operation, such as authentication cookies, session handling, security controls, and preferences necessary to provide the service.
We may also use privacy-conscious analytics to understand product usage and improve the service. Where analytics or similar technologies require consent under applicable law, we will obtain consent or provide the required choices.
14. Security
We use appropriate technical and organizational security measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. These measures include access controls, authentication, logging, encryption in transit, infrastructure security, and operational procedures appropriate to the nature of the service.
15. Children
MyConsent is not intended for independent use by children. Customer organizations may use MyConsent in contexts where media includes children or young people, but the customer organization is responsible for ensuring that it has the necessary legal basis, permissions, and safeguards for such processing.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, for example when we change the service, add or remove features, change processors, or need to reflect legal or operational requirements. The latest version will be made available on our website and will show the date of the latest update.
17. Contact and Complaints
Trifork A/S
Gdanskgade 2, 2150 Nordhavn
Denmark
CVR: 20921897
Email: privacy@myconsent.dk
If you are located in Denmark, you may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet). More information is available at https://www.datatilsynet.dk/.