Privacy Policy (GDPR)
Last updated: 22 June 2026
1. Data controller
The controller of the processing activities described below (account, prospecting and browsing data) is:
- Company
- SAS Vigilae, 4 ZA des Grands Prés, 01170 Chevry, France
- Data protection contact
- rgpd@vigilae.org — Alexandre PEREIRA, data protection officer
2. Specific role regarding AML/CFT data (controller / processor)
The following distinction is essential:
- Vigilance file data (identity of the professional's clients, beneficial owners, documents, screening results, suspicious transaction report elements): the regulated professional user is the data controller; Vigilae acts as a processor within the meaning of Article 28 of the GDPR, on the user's documented instructions and under a data processing agreement (DPA).
- Account, billing, prospecting and browsing data: Vigilae is the data controller.
AML/CFT processing rests on a legal obligation incumbent on the professional (French Monetary and Financial Code, art. L.561-1 et seq.); certain retention periods and restrictions on rights follow directly from this.
3. Data processed and purposes
- Account and use of the service
- Professional identity, e-mail, login credentials, technical logs — to provide, secure and improve the service.
- Vigilance data (as processor)
- Data required for AML/CFT due diligence uploaded by the user — to enable extraction, identification of beneficial owners, risk rating, screening and the building of the evidence file, in accordance with the user's instructions.
- Free compliance audit
- Questionnaire responses and contact e-mail — to provide the score, the recommendations and, where appropriate, to contact you again.
- Prospecting and business relationship
- Professional contact details — for commercial communication, on the basis of legitimate interest and/or consent, with the right to object at any time.
- Cookies and audience measurement
- See the "Cookies" section below.
4. Legal bases
- Performance of the contract (provision of the service to the user).
- Legal obligation of the user (AML/CFT framework), for vigilance data processed on their behalf.
- Legitimate interest (security, service improvement, measured B2B prospecting).
- Consent (non-essential cookies, certain communications).
5. Recipients and sub-processors
Data is accessible to the publisher's authorised personnel and, where applicable, to technical sub-processors bound by contract, in particular:
- the hosting provider (Hetzner Online GmbH, Germany — European Union);
- the screening providers (sanctions lists, asset freezes, PEPs) — ComplyAdvantage, when external screening is enabled;
- the AI assistance provider (document extraction, copilot) — Google Cloud (Vertex AI), European Union region, when AI assistance is enabled.
Data is neither sold nor transferred to third parties for commercial purposes.
6. Transfers outside the European Union
Data is hosted and processed within the European Union. The AI assistance (Google Cloud — Vertex AI) and screening services are configured in the EU region; no transfer outside the EU is carried out in the chosen configuration. Should a sub-processor involving a transfer outside the EU be introduced, it would be governed by appropriate safeguards (standard contractual clauses or an adequacy decision) and this policy would be updated.
7. Retention periods
- Account data: for the duration of the contractual relationship, then archived in accordance with applicable legal obligations.
- Vigilance data: retained under the control of the professional acting as data controller. AML/CFT regulations require retention for 5 years from the end of the business relationship or the completion of the transaction (art. L.561-12 of the French Monetary and Financial Code).
- Prospecting data: 3 years from the last contact, unless you object.
- Cookies: duration specified in the dedicated section (at most 13 months for trackers subject to consent).
8. Security
Technical and organisational measures are implemented to protect the data: encryption of sensitive data at rest (AES-256-GCM vault), sealing and timestamping of the register (SHA-256 hash), access control, logging. The confidentiality of the suspicious transaction report is respected by design (art. L.561-18 CMF): its existence and content are not disclosed to the client.
9. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to set instructions regarding the fate of your data after your death.
For vigilance data, the exercise of certain rights (in particular erasure) may be limited by the legal retention and confidentiality obligations specific to AML/CFT, and must be addressed to the professional acting as data controller.
To exercise your rights over the processing for which Vigilae is the controller: rgpd@vigilae.org. You may lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
10. Cookies
The site only stores elements strictly necessary for its operation and your display preferences (light/dark theme, language, remembering your consent choice), stored locally in your browser. It uses cookieless audience measurement (Umami, self-hosted), which is exempt from consent. It also uses Google Analytics 4, a third-party tracker subject to prior consent: nothing is measured through this tool until you have accepted the banner (refusal by default, no advertising cookies). You can withdraw your consent at any time by refusing the banner or clearing the site's data in your browser.
11. Changes
This policy may be updated. The applicable version is the one published on this page on the date you consult it.