Privacy Policy (GDPR)
Last updated: 21 August 2026
1. Data controller
The controller of the processing activities described below (account, prospecting and browsing data) is:
- Company
- VIGILAE, simplified joint-stock company with a sole shareholder (SASU), 4 ZA Les Grands Prés, 01170 Chevry, France — R.C.S. Bourg-en-Bresse, SIREN 108 950 528
- Data protection contact
- rgpd@vigilae.org — Alexandre PEREIRA, data protection officer
2. Specific role regarding AML/CFT data (controller / processor)
The following distinction is essential:
- Vigilance file data (identity of the professional's clients, beneficial owners, documents, screening results, suspicious transaction report elements): the regulated professional user is the data controller; Vigilae acts as a processor within the meaning of Article 28 of the GDPR, on the user's documented instructions and under a data processing agreement (DPA).
- Account, billing, prospecting and browsing data: Vigilae is the data controller.
AML/CFT processing rests on a legal obligation incumbent on the professional (French Monetary and Financial Code, art. L.561-1 et seq.); certain retention periods and restrictions on rights follow directly from this.
3. Data processed and purposes
- Account and use of the service
- Professional identity, e-mail, login credentials, technical logs — to provide, secure and improve the service.
- Vigilance data (as processor)
- Data required for AML/CFT due diligence uploaded by the user — to enable extraction, identification of beneficial owners, risk rating, screening and the building of the evidence file, in accordance with the user's instructions.
- Free compliance audit
- Questionnaire responses and contact e-mail — to provide the score, the recommendations and, where appropriate, to contact you again.
- Prospecting and business relationship
- Professional contact details — for commercial communication, on the basis of legitimate interest and/or consent, with the right to object at any time.
- Cookies and audience measurement
- See the "Cookies" section below.
4. Legal bases
- Performance of the contract (provision of the service to the user).
- Legal obligation of the user (AML/CFT framework), for vigilance data processed on their behalf.
- Legitimate interest (security, service improvement, measured B2B prospecting).
- Consent (non-essential cookies, certain communications).
5. Recipients and sub-processors
Data is accessible to the publisher's authorised personnel and, where applicable, to technical sub-processors bound by contract, in particular:
- the hosting provider (OVH SAS : hosting, France — European Union; Hetzner Online GmbH : backups, Germany — European Union);
- the customer relationship management tool (HubSpot Ireland Ltd — data hosted in the European Union), to record and follow up on requests sent through the public forms of the site (online audit, demonstration) — never client file data;
- the payment provider (Stripe Payments Europe, Ltd. — Ireland — European Union), for collecting subscription payments and managing payment methods ;
- the AI assistance provider (Google Cloud — Vertex AI, Anthropic's Claude model — European Union), for assisted extraction of documents and the documentary copilot ;
- the email delivery provider (Brevo — Sendinblue SAS, France — European Union), to send transactional messages: request for documents addressed to a firm's client, audit report, digest and reminders. It receives the recipient's address and name, the subject and content of the message, as well as the attachments;
- no screening provider: the official lists (European Union, United Nations, the French Direction générale du Trésor) are downloaded onto our servers and the comparison is carried out locally. No client name is transmitted to a third party for screening;
- AI assistance (document extraction, copilot): it is not currently enabled — no data is transmitted to a model provider, and AI perception remains inert. Screening, risk rating and the register work without it, on deterministic engines. Should this assistance be brought into service, the provider chosen and its region would appear here and in the list of sub-processors before any processing.
Data is neither sold nor transferred to third parties for commercial purposes.
6. Transfers outside the European Union
Data is hosted and processed within the European Union. No transfer outside the EU is carried out in the chosen configuration. Should a sub-processor involving a transfer outside the EU be introduced, it would be governed by appropriate safeguards (standard contractual clauses or an adequacy decision) and this policy would be updated.
7. Retention periods
- Account data: for the duration of the contractual relationship, then archived in accordance with applicable legal obligations.
- Vigilance data: retained under the control of the professional acting as data controller. AML/CFT regulations require retention for 5 years from the end of the business relationship or the completion of the transaction (art. L.561-12 of the French Monetary and Financial Code).
- Prospecting data: 3 years from the last contact, unless you object.
- Cookies: duration specified in the dedicated section (at most 13 months for trackers subject to consent).
8. Security
Technical and organisational measures are implemented to protect the data: encryption of sensitive data at rest (AES-256-GCM vault), sealing and timestamping of the register (SHA-256 hash), access control, logging. The confidentiality of the suspicious transaction report is respected by design (art. L.561-18 CMF): its existence and content are not disclosed to the client.
9. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to set instructions regarding the fate of your data after your death.
For vigilance data, the exercise of certain rights (in particular erasure) may be limited by the legal retention and confidentiality obligations specific to AML/CFT, and must be addressed to the professional acting as data controller.
To exercise your rights over the processing for which Vigilae is the controller: rgpd@vigilae.org. You may lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
10. Cookies
The site only stores elements strictly necessary for its operation and your display preferences (light/dark theme, language, remembering your consent choice), stored locally in your browser. It uses cookieless audience measurement (Umami, self-hosted), which is exempt from consent. It also uses Google Analytics 4, a third-party tracker subject to prior consent: nothing is measured through this tool until you have accepted the banner (refusal by default, no advertising cookies). You can withdraw your consent at any time by refusing the banner or clearing the site's data in your browser.
11. Changes
This policy may be updated. The applicable version is the one published on this page on the date you consult it.