Privacy Policy
Version 0.9
This policy explains what personal data Vigil handles, why, who else processes it, and your rights under India's Digital Personal Data Protection Act, 2023. For the workspace content your organisation puts into Vigil, your organisation decides what is processed and we process it on its instructions; for account and usage data, we decide.
What we collect
| Data | Examples | Where it comes from |
|---|---|---|
| Account data | name, email, role, company name, sign-in times, two-factor settings | you and your administrator |
| Workspace content | projects, programmes, tasks, documents, notes | you and your team |
| Connected email | messages in the inbox, sent and spam folders, attachments, sender and recipient addresses, calendar free/busy times | the mailboxes you connect |
| Connected WhatsApp | messages, sender names and numbers, photos, documents and media in the groups you link | the WhatsApp account you connect |
| Usage and technical data | pages viewed and for how long, errors, request timings, browser type, IP address at sign-in | your use of Vigil, recorded by Vigil itself |
Connected email and WhatsApp include personal data of people who are not Vigil users, such as clients and contractors. Your organisation is responsible for having a lawful basis to connect them.
Why we use it
- To provide Vigil: file messages and documents to projects, read and summarise them, propose schedule changes and draft replies.
- To secure Vigil: sign-in, two-factor checks, detecting misuse, and a record of what our staff do.
- To support you and fix problems, using error and performance records.
- To bill you, when you are on a paid plan.
- To improve Vigil, using only counts and measurements that identify no person or customer.
We do not sell personal data, use it for advertising, or let our AI provider train on it.
Who else processes it
| Provider | What it does for Vigil | Data it handles | Location |
|---|---|---|---|
| Microsoft Azure | runs Vigil's servers and stores files; sends system email (invites, password resets) | all of the above | India (servers in South India, files in Central India) |
| MongoDB Atlas | Vigil's database | all of the above except file contents | India (Mumbai, on Amazon Web Services) |
| Vercel | serves Vigil's website | pages requested, IP address | global network |
| Anthropic | the AI that reads, summarises, classifies and drafts | the content Vigil sends for each task: message text, attachments, project context | United States |
| Google, Microsoft | your own mailbox and calendar, which you connect | what Vigil reads from your mailbox | per your account |
| WhatsApp (Meta) | your own WhatsApp account, which you connect | what Vigil reads from linked groups | per your account |
| OpenStreetMap | finding a project's location on a map | the address or place you search for | Europe |
Some of this processing happens outside India. We use providers bound by contract to protect the data and to use it only to serve Vigil.
How long we keep it
- Workspace content and connected messages: while your organisation uses Vigil, then deleted within 30 days of the agreement ending, and removed from backups within 35 days.
- Account data: while the account exists, and up to 90 days after it is removed.
- Error and usage records: up to 12 months.
- AI requests: our AI provider keeps them only for the limited period its commercial terms allow, for safety and abuse monitoring, and does not train on them.
- Records of which version of these terms each person accepted, with the time, IP address and browser: kept permanently, including after an account is deleted, as evidence of the agreement.
- The record of what our staff did in our operator tools: kept permanently for security.
Your rights
You can ask to see the personal data we hold about you, correct it, have it erased, or nominate someone to act for you, and you can withdraw consent to optional processing. For data inside a customer's workspace, we will pass your request to that organisation and help it respond. You can raise a grievance with our Grievance Officer, and if you are not satisfied, with the Data Protection Board of India.
Security
Data is encrypted in transit; files are served through short-lived signed links; staff access is limited, protected by two-factor sign-in and passkeys, and recorded. If a breach affects your personal data, we will notify you and the authorities as the law requires.
Children
Vigil is for business use and not for anyone under 18.
Contact
Grievance Officer, Beans-n-Beams: vigil@beansnbeams.com. We respond within 7 days and aim to resolve within 30 days.