Privacy policy
Last updated: September 2026
This translation is provided for convenience. Only the French version is legally binding.
Vigicap processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the French loi Informatique et Libertés. This page describes which data is processed, why, and what your rights are.
Who is responsible for what
Vigicap acts in two different capacities, and the distinction determines who you send a request to:
- For the data of your own account (controller): name, e-mail address, hashed password, role, sign-in logs of your users. Vigicap decides on this processing and answers for it.
- For the data of your SME clients (processor, art. 28 GDPR): client records, assessments, action plans, evidence, registers. It is you, the IT service provider, who decides which data to collect and why; Vigicap processes it solely on your instructions and on your behalf. A data subject employed by a client SME therefore exercises their rights with their service provider, not with Vigicap — whom we assist where needed. The respective obligations in that context are set out in the data processing agreement.
Contact for any question relating to data: contact@vigicap.fr. No data protection officer (DPO) has been appointed at this stage, appointment not being mandatory within the meaning of article 37 GDPR for the current activity.
Publisher of the service: Vigicap is published by NEXTLAB. Its full registration particulars appear in the legal notice.
Data processed
- MSP account: name, e-mail address, password (hashed), role, organisation.
- Business data entered by the MSP: records of its SME clients, assessments, actions, quotes, NIS2 registers.
- Connector credentials: instance URL and API tokens of the client's tools, encrypted at rest (AES-256-GCM).
- Technical data: audit logs (action, timestamp, IP address) necessary for security and traceability.
- Public self-assessment: the email address entered on the self-assessment page to receive the report, the reading language, the declared sector and headcount, and the computed score. The individual answers are not kept.
Purposes and lawful basis
- Provision of the service and performance of the contract (art. 6.1.b GDPR).
- Security, fraud prevention and traceability — legitimate interest (art. 6.1.f).
- Compliance with legal and accounting obligations (art. 6.1.c).
- Sending the self-assessment report you requested and following up on that request — consent (art. 6.1.a), collected through a box that is not pre-ticked and withdrawable at any time (art. 7.3).
Recipients and sub-processors
The data is neither sold nor assigned. The actual sub-processors are as follows:
- Scaleway — hosting of the application and of the data, in France.
- Brevo (Sendinblue, France) — sending of transactional e-mails. Processing within the EU.
- Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Dublin, Ireland) — collection of the MSP's subscription: identity and billing address, VAT number, payment history and payment method. Card details are entered in a form hosted by Stripe and never pass through Vigicap's servers. This processing concerns the data of the MSP's account, never that of its SME clients.
Consultation of the Sirene register (INSEE): when you search for a company while creating a client record, the name or the SIRET entered is sent to INSEE (France) to query the official business register. Only that query is transmitted — no data from your agency, no assessment content — and the information returned is public. A point that matters: for a sole trader, the business name is the name of a natural person, so the search may relate to a person's name. That is data already published in the register, but we prefer to write it down rather than claim that no personal data is ever involved. INSEE is on that basis a public data source, not a processor within the meaning of article 28 — it processes no data on our behalf. Results are held in cache for up to 30 days to limit the number of calls.
Sign in with Google (optional). If you choose "Sign in with Google" instead of a password, your browser takes you to Google Ireland Limited to authenticate there, and Google returns four things to us and not one more: a stable account identifier, your email address, whether Google considers it verified, and the display name on your Google account. We request no other access — not your mail, not your contacts, not your calendar — and we never receive your Google password. You trigger that sharing yourself by choosing this sign-in method: nothing is sent to Google if you use a password, and you can go back to a password at any time. Google acts here as a controller for the authentication it performs, under its own privacy policy, not as a Vigicap sub-processor. No data belonging to your SME clients is transmitted to it.
Use of artificial intelligence
Vigicap uses no artificial intelligence model: no data is transmitted to an AI provider. The platform's proposals result from deterministic rules and document templates, subject to your validation; no automated decision within the meaning of article 22 GDPR is taken.
Retention period
- Account data and business data: retained for the entire duration of the contractual relationship, then deleted on request (see “Your rights”).
- Connector credentials: deleted immediately when the connector is disconnected.
- Address confirmation and password reset tokens: single-use, expiring after 24 hours and 30 minutes respectively.
- Audit logs: retained for the duration of the contractual relationship. No automatic purge is in place to date; their deletion happens with that of the account. We state it rather than announce a period the service does not yet apply.
- Audience measurement: 13 months, the maximum the CNIL recommends, chosen because it is what allows a month to be compared with the same month a year earlier — the only analytical reason to hold this data that long. A purge runs nightly against the Umami database and removes events, sessions and their attached data beyond that period. These measurements contain no IP address: Umami's schema stores none, and the tracker sets no cookie.
- Technical error reports: 3 months. Error traces collected by our self-hosted GlitchTip instance, reachable only from our private network, are deleted automatically after that period. They exist for diagnosis and correction, never to track a user.
- Public self-assessment: 3 years from your last contact, each new self-assessment restarting that period. It is the period the CNIL recommends for prospect data (référentiel « gestion des activités commerciales ») and we apply it as a ceiling: it is a recommendation, not a legal obligation. An automatic purge runs every night and deletes the records of addresses that have not reappeared within that period.
Transfers outside the European Union
The service aims for hosting within the European Union. Any transfer outside the EU would be governed by appropriate safeguards (the European Commission's standard contractual clauses). The actual hosting region is stated in the legal notice.
Security
Encryption of tokens at rest, hashed passwords (argon2), revocable sessions, multi-tenant separation per MSP and an audit log. The publisher implements technical and organisational measures appropriate to the risk.
Your rights
You have a right of access, rectification, erasure, restriction, objection and portability. These rights are exercised with contact@vigicap.fr, with a response within one month (art. 12.3 GDPR). Export of your data in a structured format is also available immediately from Audit log → GDPR export in the application. For the data of your SME clients, Vigicap acting as processor, please address your service provider. You may lodge a complaint with the CNIL (cnil.fr).
Cookies
Vigicap uses only cookies strictly necessary for operation (session, security). No audience-measurement or advertising cookie is placed without your consent.
This document describes Vigicap's commitments and does not constitute legal advice. For the application of these rules to your own situation, please consult your legal adviser.