DataVigiaBack

Privacy Policy

Last updated: July 2026

Who we are and how to contact us

DataVigia operates this data security auditing platform. For any privacy matter or to exercise your rights, please contact privacy@datavigia.com or use the contact form on the website. The controller's full identification and address are available on request.

Controller or processor, depending on the data

In relation to website, account and billing data, DataVigia is the data controller. In relation to data from the platforms that the customer connects (Microsoft 365, Google Workspace, on-premises servers) and to the employee data used in training simulations, the customer is the data controller and DataVigia acts as data processor, under the data processing agreement (DPA).

What data we process

Account data (name, email), billing data, contact form messages, training campaign results (who interacted with the tests) and security metadata from connected platforms (permissions, configurations, access logs, file and folder names). We do NOT access the content of customers' files.

Purposes and legal basis

Provision of the service and account management (performance of the contract, Article 6(1)(b)); billing and compliance with accounting and tax obligations (legal obligation, Article 6(1)(c)); platform security and fraud prevention (legitimate interest, Article 6(1)(f)); responding to commercial enquiries (legitimate interest or consent, which you may withdraw at any time). Data from customer platforms is processed in accordance with the customer's instructions, the customer being responsible for ensuring the relevant legal basis.

Who has access and processors

Internal access is limited to strictly necessary staff, subject to confidentiality. We use processors bound by data processing contracts: Supabase (database and hosting, European Union region, Ireland), Vercel (application hosting and delivery), Anthropic (automated report generation in text), Resend (email delivery) and the Microsoft and Google APIs (accessed with the customer's authorisation). The up-to-date list of processors is available on request.

International transfers

Data is hosted in the European Union (Ireland). Some processors process data outside the European Economic Area, for example in the United States. In such cases, appropriate safeguards apply, in accordance with the transfer mechanism valid at the time: the European Commission's Standard Contractual Clauses and, where the processor is certified, the adequacy decision of the EU-US Data Privacy Framework. Andorra benefits from a European Union adequacy decision, so transfers to Andorra do not require additional safeguards.

Retention periods

Account data is retained for the duration of the contract. Billing data is retained for the applicable statutory periods (as a rule, ten years for tax purposes). Security metadata and audit results are retained during the relationship and deleted or returned at its end, save for any legal obligation. Contact messages are retained for as long as necessary to handle them.

Security

Connector credentials are held in an encrypted vault accessible only to the service; each organisation is isolated from the others (Row Level Security); we apply the principle of least privilege, access control and logging, and data minimisation (we do not collect the content of files).

Automated decisions

Reports are produced with the support of automated processing, but are intended to support human decision-making. We do not take decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals, within the meaning of Article 22 GDPR.

Your rights

You have the right to access your data, rectify it, erase it, restrict or object to the processing, to data portability and to withdraw consent. We respond, as a rule, within one month. Where data is processed on behalf of a customer (the data controller), we forward the request to that customer.

Complaints

You may lodge a complaint with the supervisory authority of your country: in Portugal the CNPD, in Spain the AEPD, in France the CNIL and in Andorra the APDA (Agència Andorrana de Protecció de Dades).

Cookies and minors

We use only essential cookies, described in the Cookie Policy. The service is intended for businesses and is not directed at minors.

Changes to this policy

We may update this policy to reflect legal or service changes. We publish the current version on this page, together with its update date.