An employer asks an employee, a contractor or a customer for something. They agree, or they do not. Both sides need to know what was agreed, when, and whether it still stands.
Nothing here is a checkbox. Every consent is signed against a verified identity.
Every request arrives in one place. You see what is being asked before you answer, and what you have already agreed to.
Ask your workforce or your customers for what you need. Every request and every answer sits in one record — not an email thread, and not somebody’s memory.
An employer needs consent from an employee, a contractor or a customer. So a document goes out, comes back signed, gets copied to both sides, and is filed somewhere.
Then it sits there. Nobody knows what it covers, whether it still applies, or who was supposed to end it.
What replaces it
Each step in the old cycle has its own way of going wrong. None of them survives being digitised properly.
A document drafted, attached and emailed out.
Now: a request, in their accountPrinted, signed, photographed, sent back.
Now: signed with the appOne for them, one for you. They drift apart.
Now: one record, both read itA folder nobody opens, holding their signature.
Now: nothing to storeSomebody has to remember. Nobody does.
Now: it ends when the relationship doesWhy this changed
For years it was a form to be filed. Few organisations did it properly, and the ones that did not were rarely troubled. Then regulators found their teeth — and customers started leaving over it.
Sources: DLA Piper GDPR Fines and Data Breach Survey, January 2026 · CMS GDPR Enforcement Tracker 2025/2026. Spain’s regulator alone has issued several hundred fines against smaller businesses — there is no exemption for company size.
Eight years of enforcement, every regulator in Europe, every company: €7.1 billion. In a single year, 82% of consumers walked away from a brand over how it handled their data. One of those is a penalty. The other is your revenue.
Sources: Thales Digital Trust Index 2025 · Cisco Data Privacy Benchmark Study 2025. Consent that states exactly what it wants, and nothing more, is the cheapest way to stop being the brand somebody leaves.
Two kinds, and you always know which
Every request is one or the other. Neither side can mistake one for the other, because they do not look alike.
It covers what was asked, and nothing else. When it completes, it is over. Both sides keep the record of what was agreed.
A live connection. While it is open, changes you make reach them automatically. Either side can close it, and it closes immediately.
What an ongoing connection is for
Today: you email HR, fill in a form, and wait. You tell the bank separately. The landlord separately. The clinic never finds out.
With a connection open, you change your address in one place and it arrives everywhere you allowed. No form. No email. No delay.
The right to be forgotten
The record
Not an export, not a monthly report. A live record that both sides read and neither side can change.
Where to start
The platform is the same. Your way in depends on whether you are managing your own consent or your organisation’s.
Every company that holds your consent, in one place. Revoke, request deletion, and manage the connections you have open.
Send requests, resolve deletions, hold ongoing connections, and keep an audit trail per person.
Consent
Signed against a verified identity, logged on both sides, revocable from yours.