Data Processing Agreement
How Vigil processes personal data on your behalf. The English version governs.
Last updated: {{LAST_UPDATED}} · Version: draft
Parties & roles
This DPA is between {{LEGAL_ENTITY}} ("Processor", "Vigil") and you, the customer ("Controller"). It forms part of the Terms of Service. It governs Vigil's processing of personal data on your behalf.
Subject-matter & duration
Vigil processes personal data captured by your cameras — images of people, and, if you enable it, biometric face data — on your own premises, for the term of your subscription.
Nature & purpose
Processing consists of on-premises person detection, alerting, evidence storage, and optional AI narration, carried out on your documented instructions. You determine which cameras are watched and to what end.
Categories of data & data subjects
Personal data: images of persons on your premises; optionally, biometric face templates (a special category of data). Data subjects: staff, visitors and passers-by captured by your cameras.
Processor obligations
We process personal data only on your documented instructions; keep it confidential; and apply the security measures below. We assist you, so far as we reasonably can, with data-subject requests and with your breach and impact-assessment duties.
Sub-processors
If you enable AI scene descriptions, we use Groq to generate the description from a single still image per incident. We use {{HOSTING_PROVIDER}} only if you use our hosted demo or control services. The Telegram bot that delivers your alerts is created and controlled by you and is not our sub-processor. Our staff access your console only through an impersonation tool that is recorded in an audit log. We will inform you of intended changes to sub-processors.
International transfers
Where a sub-processor (for example, our AI provider) processes data outside {{YOUR_REGION}}, we rely on {{TRANSFER_MECHANISM}}.
Special-category (biometric) data
Face recognition is off by default and is enabled per business only after consent is recorded in the product. You are responsible for the lawful basis and any consent required from data subjects. Face data is stored on your premises; there is no central identity database.
Data-subject requests & breach
Because the data is on your premises, most requests can be met by you directly. We will assist within {{RESPONSE_WINDOW}} and notify you without undue delay after becoming aware of a personal-data breach affecting data we process for you.
Deletion & return
Evidence images are deleted automatically on your plan's retention schedule. On termination the guard stops; the data on your box remains with you to export or destroy. We are not able to return data we never held.
Security measures
PIN hashing at rest; per-business tenant isolation; secure http-only session cookies; per-business evidence storage; scheduled retention. We provide reasonable assistance with audits of these measures.
Governing text
This Data Processing Agreement is provided in English; the English version governs. Governing law: {{GOVERNING_LAW}}.