Skip to main content

General terms of use

Last updated: September 2026

This translation is provided for convenience. Only the French version is legally binding.

These terms govern access to and use of the Vigicap service. By creating an account, the user accepts them without reservation.

1. Purpose

Vigicap is a white-label platform for managed service providers (MSP) to steer the cyber compliance of their SME clients: ANSSI ReCyF assessment, action plan, quotes, reports and automated verification connectors.

2. Access to the service

Access requires the creation of an MSP account. The provider may offer free, trial or paid plans, whose pricing terms are set out in the general terms of sale. The provider endeavours to ensure continuous availability but does not guarantee the complete absence of interruption (maintenance, incidents, third-party constraints).

3. Account and security

The user is responsible for the confidentiality of their credentials and for all activity carried out from their account. The user undertakes to report any unauthorised use without delay. Multi-factor authentication and a strong password policy are recommended.

4. Acceptable use

The user undertakes not to:

  • divert the service from its purpose or impair its integrity, security or availability;
  • configure connectors or access credentials for which they hold no legitimate authorisation;
  • upload unlawful content or content infringing third-party rights.

5. Third-party connectors

Connectors read the state of third-party tools from the access credentials supplied by the user, under the user's responsibility and for the user's own clients. Credentials are encrypted at rest. The results produced are proposals to be validated by the consultant and do not bind the provider.

6. End-client mandate and indemnity

The connectors and delegated access configured in the platform give the provider the ability to read directory, asset and security information at the SME client. That access is opened by the user; it is never granted by the SME directly to the provider. This article draws the consequences.

The user represents and warrants, for each connector they configure and throughout the duration of the connection:

  • that they hold a mandate or written contractual authorisation from their client allowing them to access the tools concerned and to entrust the reading of those tools to a third-party provider for the purposes of cyber governance;
  • that this access is exercised in compliance with the terms of the vendor of the connected tool, including, where applicable, the delegated administration terms applicable to partners;
  • that they have informed their client, under articles 13 and 14 of the GDPR, of the use of the platform, and that they have obtained, where their own contract so requires, authorisation to engage the provider as a sub-processor;
  • that they configure access according to the principle of least privilege, read-only where the connected tool allows it;
  • that they disconnect without delay any connector whose corresponding mandate has ended, has been revoked or never existed.

These representations are a determining condition of the provider's consent: having no contractual relationship with the SME client, the provider is not in a position to verify the existence of the mandate and performs the readings on the sole faith of the configuration carried out by the user, which constitutes documented instructions within the meaning of the data processing agreement.

Indemnity. The user indemnifies the provider against any claim, action or proceeding brought by an SME client, a data subject, the vendor of a connected tool or any third party, arising from the absence, insufficiency, expiry or revocation of the mandate referred to in this article. This indemnity covers reasonable defence costs and civil awards made on that basis. It does not cover administrative fines, the burden of which cannot be transferred by contract.

The provider may suspend a connector, after informing the user where possible, if it has serious grounds to believe that the corresponding mandate is lacking.

This article governs the relationship between the parties. It alters neither the qualification adopted under the GDPR — the user remains the controller and the provider the processor — nor the responsibilities the regulation places on each of them towards data subjects.

7. Intellectual property

The provider grants a personal, non-exclusive and non-transferable right to use the service. Data entered by the user remains the user's property. The trade mark and the MSPs' white-label brands remain the property of their respective holders.

8. Personal data

The processing of personal data is described in the privacy policy, which forms an integral part of these terms.

Where the user is an IT service provider (MSP) entering their own clients' data into the platform, the user acts as controller and Vigicap as processor. The processing clauses within the meaning of article 28 of the GDPR then apply and likewise form an integral part of these terms.

9. Responsibility

Vigicap is a decision-support tool: it does not replace the responsibility of the company's management, nor an audit or advice provided by a qualified professional. The provider cannot be held liable for decisions taken on the basis of the analyses produced, nor for indirect damage.

10. Limitation of liability

The service is supplied to professionals, at a price that takes account of the cap stipulated below. This cap constitutes an allocation of risk agreed between professionals and a determining condition of the price level granted: its consideration is the provider's undertaking to maintain a complete and self-service export of the data, available at any time and without the provider's involvement.

Cap. The provider's liability, all causes and all heads of loss combined for any one contractual year, is limited to the total amount actually paid by the user under their subscription during the twelve (12) months preceding the event giving rise to the damage. Where the contractual relationship has lasted less than twelve months at that date, the cap cannot be lower than three (3) monthly instalments of the plan subscribed to.

Excluded heads of loss. The provider is not liable for indirect damage, nor for the following heads of loss:

  • loss of turnover, of profit, of clientele, of anticipated savings or of commercial opportunity;
  • harm to the image, the reputation or the relationship of the user with their own clients;
  • loss, alteration or corruption of data, the user having a complete export available at all times and it being for the user to keep a copy of it;
  • the cost of a replacement or reconstitution service, beyond the foregoing cap.

What the cap does not cover. The foregoing provisions do not apply and cannot be invoked by the provider in the event of:

  • wilful misconduct or gross negligence by the provider (art. 1231-3 du code civil);
  • personal injury or harm to a person's life or physical integrity;
  • breach of an obligation the violation of which would deprive the contract of its substance, this article being inapplicable to the extent that it would have that effect (art. 1170 du code civil);
  • obligations which the law prohibits from being adjusted by contract, in particular the provider's liability towards data subjects under article 82 of the GDPR, which this article does not affect.

Nor does the cap apply to sums owed by the user under their subscription.

11. Termination

The user may stop using the service at any time. The provider may suspend or terminate an account in the event of a breach of these terms, after notice where possible.

12. Amendments

These terms may be updated. Users are informed of substantial changes; continued use constitutes acceptance.

13. Governing law and jurisdiction

These terms are governed by French law, excluding its conflict-of-laws rules. The parties endeavour to settle any dispute amicably, by prior written exchange addressed to contact@vigicap.fr, before any court action.

Failing an amicable settlement, any dispute relating to the formation, interpretation, performance or termination of these terms is subject to the exclusive jurisdiction of the competent courts of Paris (France), including in interim proceedings, where there are several defendants or where a third party is joined.

This choice of jurisdiction is agreed between persons both contracting in the capacity of merchant (commerçant), within the meaning of article 48 du code de procédure civile, the service being open only to registered professionals acting for the purposes of their business. If the user does not contract in that capacity, this clause is unenforceable against them and jurisdiction is determined by the ordinary rules of law, without this affecting the validity of the other provisions.

This document sets out Vigicap's commitments and does not constitute legal advice. For how these rules apply to your situation, please consult your own legal adviser.