Skip to content
Vigile AI

Legal

Privacy Policy

How we handle personal data: what we collect on this website, what the platform reads from a connected Microsoft environment, what we do with file contents, who else processes it, and how to exercise your rights.

Effective 7 October 2026. Last updated 7 October 2026.

1. Overview

This Privacy Policy explains how Vigile AI, Inc. (Vigile AI, we, us or our) collects, uses, shares, stores and protects personal data when you visit our website, when you contact us, and when your organization uses the Vigile AI Enterprise platform (the Service).

Two roles matter here. When we run our own website and handle our own sales and marketing contacts, we are the controller of that personal data. When we process data that originates in our customer's Microsoft environment, the customer is the controller and we are the processor, acting only on the customer's documented instructions. Our processing as a processor is governed by our data processing addendum.

2. Scope of this policy

This policy covers our website, our sales and support communications, and the Service. It does not cover the Microsoft 365 and Microsoft Entra ID environments that our customers connect, which are governed by Microsoft's own terms and privacy documentation. It also does not cover third party websites we link to.

3. Personal data we collect

We collect the following categories of personal data:

  • Contact details you give us: your name, work email address, company, role, country and phone number, together with anything you write in a message or a form on our website.
  • Account and usage data for the Service: user identifiers, role and status, sign-in records for the platform itself, and an activity log of actions taken inside the platform.
  • Connection and configuration data: the tenant identifier and the scopes granted when an organization connects its Microsoft environment.
  • Technical data from our website: IP address, browser and device type, pages viewed, referring page, and timestamps, collected in server logs and in privacy-respecting analytics where enabled.
  • Communications: the content of emails, support requests, security questionnaires and meeting notes.

We do not ask for special category data, and we ask that you do not send it to us through our website forms.

4. Data we read from a connected Microsoft environment

When an organization connects its Microsoft environment, the Service reads the following, through a read-only integration:

  • Directory and organization information: users, employees, groups and their status and role attributes.
  • Identity and authentication data: sign-in history, failed sign-in attempts and, where the licence tier provides it, risk detections, risk levels and risk states.
  • Application data: registered and enabled applications, their publishers, their permissions, and application sign-in activity.
  • File metadata from OneDrive and SharePoint: file names, paths, owners, sharing state and permissions.
  • File contents, processed in memory only, to detect categories of sensitive data such as credentials, secrets and personal identifiers.

Two commitments apply to the last item and matter more than the rest. File contents are not stored and are not displayed in the Service. What a user sees is the finding category, a count and a confidence indicator. Private files are excluded from content detection by default, and an administrator must deliberately extend the scan policy for them to be included.

Only an organization owner can connect or disconnect the integration. The connection is read-only, it can be revoked at any time from the Microsoft admin portal, and revoking it stops further collection.

5. How we use personal data and our legal bases

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract: to provide the Service, to set up the connection, to deliver reports and notifications, and to support the organization that bought it.
  • Legitimate interests: to secure and improve the Service, to prevent abuse, to understand how our website is used, and to conduct business-to-business sales and marketing where your rights do not override those interests.
  • Consent: to send marketing email where consent is required, and for non-essential cookies where we ask for it. You can withdraw consent at any time.
  • Legal obligation: to keep records, to respond to lawful requests, and to meet accounting and tax requirements.

Where the CCPA or CPRA applies, we process personal information for the business purposes described in this policy. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

6. Cookies and similar technologies

Our website and the Service use a small number of storage mechanisms. The theme preference on this site is stored locally in your browser and is never sent to us. Where we use analytics, it is configured to avoid advertising profiles and to respect browser signals where we are able to honour them. The Service uses strictly necessary cookies to keep a signed-in session working.

You can clear or block cookies in your browser settings. Blocking strictly necessary cookies will prevent you from signing in to the Service.

7. How we share personal data

We share personal data only as follows:

  • With service providers and sub-processors who host, secure, monitor or support the Service, and who act on our instructions under written terms.
  • With service providers who run our website and handle inbound enquiries, including our email, form and scheduling providers.
  • With professional advisers such as lawyers and auditors, where necessary.
  • With authorities or other parties where the law requires it, or where it is necessary to establish, exercise or defend legal claims.
  • With a successor entity in the event of a merger, acquisition or sale of assets, subject to this policy.

A current list of sub-processors is available on request from support@vigile.ai, and is attached to our data processing addendum. We give customers notice of a new sub-processor before it starts processing, so there is an opportunity to object.

8. International transfers

We are based in the United States and our service providers may process personal data in other countries. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on a lawful transfer mechanism, such as the European Commission's standard contractual clauses or an equivalent approved mechanism, together with additional safeguards where appropriate.

9. How we protect personal data

We use administrative, technical and organizational measures designed to protect personal data. These include a read-only Microsoft integration, encryption in transit, least-privilege access for our personnel, role-based access inside the Service, activity logging, and a policy of not storing the file contents that the platform inspects.

No method of transmission or storage is completely secure. If we become aware of a breach of personal data that affects your organization, we will notify your organization without undue delay and provide the information it needs to meet its own notification duties.

10. How long we keep personal data

We keep personal data only for as long as we need it for the purposes in this policy, and then delete or de-identify it. In practice:

  • Workspace data from a connected environment is retained while the subscription is active, and is deleted or de-identified after termination, subject to the export window described in the Terms.
  • Platform sign-in records and the activity log are retained for the period needed for security and audit purposes.
  • Website server logs are retained for a short operational period.
  • Sales and marketing contact records are kept for as long as there is a relevant business relationship, and are removed on request.
  • Records we must keep for tax, accounting or legal reasons are kept for the period the law requires.

11. Your rights

Depending on where you live, you may have the right to access your personal data, to correct it, to delete it, to restrict or object to processing, to receive it in a portable format, and to withdraw consent. If you are in the United States, you may also have rights to know, to delete, and to correct personal information, and to be free from discrimination for exercising those rights.

Where your organization is our customer, most of the data in the Service belongs to that organization and we act as its processor. Send requests about that data to your organization first. We will assist it in responding. For requests about our own website, marketing or contract records, contact us directly.

We will respond within the time the applicable law allows, normally thirty (30) days, and we may need to verify your identity first. You also have the right to complain to your local data protection authority.

12. Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under sixteen (16) years of age. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Automated processing

The Service uses automated analysis to classify risk, detect sensitive content categories and prioritise findings. That analysis supports decisions made by people. It does not produce legal effects or similarly significant effects on an individual, and it is not used to make employment decisions about any person.

Our website does not respond differently when a browser sends a Do Not Track signal, because there is no industry consensus on how to interpret one.

14. Changes to this policy

We may update this policy. We will change the date at the top of this page, and for a material change we will give notice inside the Service or by email before it takes effect. If a change affects how we process data on behalf of a customer, we will give that customer notice as required by our data processing addendum.

15. How to contact us

For any question about this policy, or to exercise a right, contact us using the details below.

  • Privacy and data protection enquiries: support@vigile.ai
  • Pricing, procurement and security questionnaires: sales@vigile.ai
  • Postal address: Vigile AI, Inc., 1600 Bryant St #411447, San Francisco, CA 94141, United States

If your organization has a data processing addendum with us, please use the contact named in that document for matters it covers.

Need this in writing for a review?

Security questionnaires, sub-processor lists and a data processing addendum are routine for us. Ask, and we will send them before you need to chase.

Next step