Legal

Privacy Policy

Last updated: June 2026  ·  Effective date: June 2026

VIGIL is committed to protecting your financial data and personal information. This policy explains what we collect, why we collect it, how we use it, and your rights. If you have questions, email us at support@vigilgl.com.

1. Who We Are

VIGIL ("we", "us", "our") provides AI-powered general ledger intelligence software. Our service is operated by VIGIL Technologies, LLC ("the Company"). References to "you" mean the individual or organisation using our service.

Our contact address for privacy matters: support@vigilgl.com

2. Data We Collect

Account data

When you create an account we collect your username, email address, and a hashed version of your password. We never store your password in plain text.

Financial data

To provide GL analysis, VIGIL processes general ledger data you provide — either by connecting QuickBooks Online via OAuth 2.0 or by uploading a CSV/XLSX export. This data includes journal entries, account names, transaction amounts, and dates.

Usage data

We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate and improve the service. This data is retained for up to 90 days.

Payment data

Payments are processed by Paddle. We do not store your card details. We receive a customer ID and subscription ID from Paddle to manage your account status.

Free health check data

If you use the free GL health check without creating an account, your GL data is processed in memory and results are held for 24 hours only, after which they are deleted. A privacy-safe hash of your IP address is retained for 30 days solely to enforce the one-check-per-30-days rate limit.

3. How We Use Your Data

We do not use your financial data to train general AI models. GL data is processed solely to produce findings for your workspace.

We may send you product update and feature announcement emails. You can opt out of non-transactional emails at any time by clicking the unsubscribe link in any such email or by emailing support@vigilgl.com. We will continue to send essential transactional emails (account verification, billing receipts, security notices) regardless of marketing preferences.

4. Lawful Basis for Processing (GDPR)

For users in the UK and EU, our lawful bases are:

5. Data Sharing and Sub-processors

We share data only with the third parties necessary to operate the service:

We do not sell your data to third parties. We do not share your financial data with advertisers.

6. Data Retention

We retain your account data and GL findings for as long as your subscription is active. Upon cancellation, your data is retained for 30 days to allow for re-activation or export, then permanently deleted. You may request earlier deletion at any time by emailing support@vigilgl.com.

7. Data Security

We implement industry-standard security measures including:

Breach notification

In the event of a personal data breach that is likely to result in a risk to your rights or freedoms, we will notify you and relevant supervisory authorities within the timeframes required by applicable law (within 72 hours under GDPR where feasible). Our notification will describe the nature of the breach, the categories of data affected, likely consequences, and the steps taken or proposed to address it.

8. International Transfers

VIGIL is hosted on AWS infrastructure. If you are located in the UK or EU, your data may be processed in the United States. Where this occurs, we rely on Standard Contractual Clauses (SCCs) as the legal mechanism for the transfer.

9. Your Rights

Depending on your location, you may have the following rights:

To exercise any of these rights, email support@vigilgl.com. We will respond within 30 days.

If you are in the UK or EU and believe we have not handled your data correctly, you have the right to lodge a complaint with your local supervisory authority (e.g. the ICO in the UK).

10. Cookies

VIGIL uses a single httpOnly cookie to maintain your authenticated session (the refresh token). We do not use tracking, advertising, or analytics cookies. No third-party cookies are set by our service.

11. Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal. VIGIL does not currently respond to DNT signals because no industry-wide standard has been established. We do not track users across third-party websites and do not use cross-site behavioural advertising.

12. California Residents (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise these rights, email support@vigilgl.com with "California Privacy Request" in the subject line. We will verify your identity and respond within 45 days, with a possible 45-day extension where permitted by law.

13. Children's Privacy

VIGIL is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

14. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by email and by updating the "Last updated" date above. Continued use of the service after changes are posted constitutes your acceptance of the updated policy.

15. Contact

For any privacy-related questions or to exercise your rights, contact us at: support@vigilgl.com