Terms and Conditions
Last updated: July 2026
1. Purpose
DataVigia provides a cloud service for data security auditing, exfiltration and ransomware detection, external domain auditing, on-premises server collector and anti-phishing training, as described on the portal. These terms govern the use of the service by business customers.
2. Definitions
"Service" is the DataVigia platform and its modules; "Customer" is the entity that subscribes to the service; "User" is the person authorised by the customer to gain access; "Customer Data" is the data uploaded or collected on behalf of the customer.
3. Account and access
Customer accounts are created by DataVigia by invitation. The customer is responsible for keeping credentials secure, for enabling two-step verification where available and for all actions carried out in its account.
4. Acceptable use and authorisations
The customer uses the service only in environments for which it is responsible and for which it has authorisation. Audits are read-only. Training simulations may only target the customer's own employees, with authorisation and an internal policy. The on-premises collector is installed with the knowledge of the IT team. The customer warrants that it is entitled to connect the platforms, authorise the audits and carry out the simulations, and that it has informed its employees where required by law.
5. Data protection roles
As regards the data of its employees and of the platforms it connects, the customer is the data controller and DataVigia acts as data processor, under the data processing agreement (DPA) which forms an integral part of these terms.
6. Payment and suspension
The service is billed per active licence and per active on-premises server, by bank transfer, on the agreed terms. Failure to pay may lead to the suspension of access, including of the installed agent, after notice.
7. Availability and changes
We endeavour to ensure the availability of the service, but interruptions may occur for maintenance or for reasons beyond our control. We may improve or change features, without substantially reducing the essential nature of the contracted service.
8. Intellectual property
The platform, the software and the content are the property of DataVigia. Customer data remains the property of the customer. Reverse engineering, copying and unauthorised resale are prohibited.
9. Confidentiality
Each party keeps confidential the non-public information of the other to which it has access and uses it only for the performance of the contract.
10. Warranties and liability
The service helps to identify risks, but does not guarantee the absence of incidents and is provided 'as is'. To the extent permitted by law, DataVigia's total liability is limited to the amount paid by the customer in the twelve months preceding the event and excludes indirect damages. Nothing in these terms excludes liabilities that the law does not allow to be excluded.
11. Force majeure
Neither party is liable for failures caused by events beyond its reasonable control, such as disasters, failures of essential third parties or communications outages.
12. Termination
Either party may terminate the contract on the agreed terms. Following termination, customer data is returned or deleted on request, in accordance with the DPA.
13. Notices and partial invalidity
Relevant communications are made by email to the registered contacts. If any clause is held to be invalid, the remaining clauses stay in force.
14. Governing law and jurisdiction
These terms are governed by Portuguese law. For disputes that cannot be resolved amicably, the courts of DataVigia's registered office have jurisdiction, without prejudice to mandatory rules protecting the customer.