Privacy Policy
Version 1.2 · Effective 21 August 2026
1. Who we are
Vigilis, operated by Abhay Prakash, an Estonian entrepreneur-account holder (“Vigilis”, “we”, “us”). Vigilis is a public-facing business name; it is not a separate legal entity (not an OÜ or FIE). The contracting party is Abhay Prakash. Contact: contact@vigilis.eu. You can verify the entrepreneur account via the official Estonian Tax and Customs Board (MTA) search at apps.emta.ee/saqu/public/entrepreneur/query (IBAN EE62 7700 7710 1338 1168).
2. What data we collect
- Request-for-quotation details: your name, job title, email, phone, company name, registration and VAT number, website, country and address, and the AI-use information you give us so we can prepare a quotation.
- Assessment responses: for a paid assessment, the answers you provide in the questionnaire we send you. The Free AI Act Check stores nothing, it computes a result on screen and discards your answers.
- Document customization details: information you provide to populate generated compliance documents, for example the names, roles, and contact emails of colleagues you designate as your AI compliance owner, human oversight owner, or incident contact. Where this concerns a colleague rather than you, you confirm you are authorised to provide it and, where required, that they have been informed in line with your own organisation’s internal privacy notices.
- Minimal usage signals: e.g. that a free check was completed (risk level only), no answer content and nothing that identifies you.
- Billing details: company name, address and (if any) VAT number, used only to prepare your service agreement and payment request. Payment is by bank transfer, we do not collect or store card details.
3. Why we process your data
- To deliver the compliance assessment and reporting service you purchased (contract, Art. 6(1)(b) GDPR)
- To send transactional emails (order confirmation, report ready) (contract)
- To comply with legal obligations (Art. 6(1)(c) GDPR)
- To improve our platform based on anonymised usage patterns (legitimate interest, Art. 6(1)(f))
4. Who we share data with
We share data only with processors necessary to deliver the service: Supabase (database and file storage, EU region, including generated PDF reports and Word documents), Resend (email), Sentry (error monitoring). Generated reports and documents are stored privately and only ever accessed via short-lived, time-limited download links. We do not sell data to third parties.
5. Data retention
We keep personal data only as long as needed for the purpose it was collected:
- Request-for-quotation enquiries: kept while we prepare and discuss your quotation and for a short period afterwards, then deleted if no engagement follows. You can delete them sooner yourself (Section 7).
- Paid-assessment answers, reports and documents: kept for the duration of the engagement plus a limited support period, then deleted on request or on our retention schedule.
- Payment records and financial documents: retained for the period required by Estonian accounting and tax law (currently 7 years), then deleted.
- The Free AI Act Check stores nothing.
6. International transfers
Supabase stores data in the EU, AWS Europe (Ireland) region (eu-west-1). Other processors (Resend, Sentry) operate under Standard Contractual Clauses where transfers outside the EEA occur.
7. Your rights
Under GDPR you have the right to access, correct, delete, restrict, export (portability), and object. You can see, download, or delete the data we hold about you yourself, at any time, from our Manage your data page, enter your email and we send you a secure link. You can also email contact@vigilis.eu, or lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee). Payment records already created may be retained where accounting law requires, then deleted.
8. Cookies
See our Cookie Policy.