Article 28 GDPR

Data processing agreement.

You are the controller of your client data; Vigilae acts as processor. Here, clause by clause, is what we undertake. This document is annexed to the subscription contract and is provided to you signed on request.

Score out of 100 in 2 minutes · No credit card · No commitment

The film

Vigilae, in 55 seconds.

From a scattered file to a sealed registry: the AI perceives, the engine classifies, you decide, the evidence is sealed.

55 seconds · French voiceover · subtitles available · sound on

Article 1

Subject matter, nature and duration.

What we process, why, and for how long.

  • Subject matter. Provision of an anti-money-laundering and counter-terrorist-financing compliance service: building and retaining due diligence files, screening against the official lists, preparing suspicious transaction reports.
  • Nature of the operations. Collection, recording, structuring, storage, consultation, extraction, encryption, erasure.
  • Categories of data subjects. The firm's clients and prospects, their beneficial owners, their counterparties, and the members of the firm using the service.
  • Categories of data. Identification data, supporting documents, risk assessment elements, and — where a report exists — its content, the confidentiality of which is protected by article L.561-18 of the French Monetary and Financial Code.
  • Duration. That of the subscription, extended by the statutory retention periods you configure, in particular the five years of article L.561-12.
Article 2

Our obligations.

  • Documented instructions. We process your data only on your instructions, as expressed by your use of the service and by this agreement. If an instruction appears to us to infringe the Regulation, we tell you so.
  • Confidentiality. The persons authorised to access the data are bound by a confidentiality undertaking. Access to suspicious transaction reports is further restricted, within the service, to the persons you designate for that purpose.
  • Assistance. We assist you in answering requests to exercise data subject rights, in your impact assessments, and in the event of a data breach — which we notify to you without undue delay.
  • Record. We keep the record of the categories of processing carried out on your behalf, required by article 30(2).
Article 3

Sub-processors.

You authorise the use of the processors listed below. Any addition is notified to you before it goes into service, which leaves you free to object.

ProviderPurposeLocation
OVH SASHosting of the application servers and of the database.France
Hetzner Online GmbHRetention of an encrypted backup copy in a country other than the one where the service is operated, in order to allow restoration after an outage, accidental destruction or a cyberattack.Germany
Google Cloud (Vertex AI) — modèle Claude d'AnthropicAssisted extraction of supporting documents and documentary copilot, where the firm has enabled the function.European Union
Stripe Payments Europe, Ltd.Collection of subscription payments and management of payment methods.Ireland
HubSpot Ireland LtdRecording and follow-up of requests sent through the site's public forms (online audit, demo).Ireland
Brevo (Sendinblue SAS)Delivery of transactional e-mails: request for documents from the client, audit report, digest and reminders.France
OVH SAS — stockage objetRetention of the supporting documents in the due diligence files for the statutory period of five years.France
Google Ireland Ltd (Google Analytics 4)Audience measurement of the public pages of the marketing site, after the visitor's explicit consent.Ireland

The up-to-date list, with the data concerned and the applicable safeguards, appears on the page processors.

Article 4

Security.

The measures below are the ones actually in place, not a list of intentions.

  • Encryption of data at rest (AES-256-GCM) and in transit (TLS).
  • Segregation of data by firm, enforced at database level and not by the application code alone.
  • Access logging and a chained integrity registry on every file, verifiable independently of the service.
  • Second authentication factor available for every account, and enforceable across an entire firm.
  • Encrypted backups and tested restoration.
Article 5

The fate of the data at the end of the contract.

At the end of the service, you choose between return and erasure. Return is made in a usable format, together with the evidence needed to check its integrity. Erasure covers the copies, backups included, within a period we state to you.

One reservation, and it is an important one: data you are required to keep under a legal obligation — in particular the five years of article L.561-12 — is not erased for as long as that obligation runs. It is your compliance framework that governs, not the end of the subscription.

Article 6

Audit.

You may ask us to demonstrate compliance with these obligations. We make the technical documentation of the service available and answer verification questionnaires. An on-site audit may be agreed, at your expense, on reasonable notice and without compromising the confidentiality of other firms' data.

Move to clear due diligence

Need this document signed?

Ask for it: we send it back signed, with no prior negotiation.

No credit card · No commitment · Guided onboarding

Vigilae assists the professional with their AML/CFT obligations. The tool perceives, structures, screens and documents; the professional remains the sole decision-maker and the sole party reporting to the FIU.