Legal

Privacy Policy

Last updated 2026. This policy explains how VigilDocs collects, uses and protects your personal and project data.

Data Controller

The data controller for VigilDocs is VigilDocs, operating under the laws of Scotland. If you have any questions about this policy or how we handle your data, please contact us through the details provided in your account settings.

Information We Collect

We collect only the information necessary to provide and improve the VigilDocs service:

  • Account information: your name, email address, job title and company details.
  • Project and company data: project descriptions, task inputs, site locations, team roles, risk assessments, method statements, construction phase plans, and inspection records.
  • Media and evidence: site location photos, inspection walkaround images, fleet registration photographs, signatures, and company logos uploaded for document branding.
  • Technical data: IP address, browser type, and usage analytics used for security and service reliability.

How Data is Used

We use the information we collect to:

  • Generate site health & safety documentation, including RAMS, Construction Phase Plans, Method Statements and Toolbox Talks.
  • Manage team permissions, project access, and stakeholder distribution lists.
  • Dispatch completed compliance packs and reminders to project stakeholders via email.
  • Maintain accurate asset and fleet compliance records, including due-date reminders and inspection logs.
  • Provide customer support, security monitoring, and service improvements.

Data Storage & Security

All data is encrypted in transit using TLS/HTTPS and at rest via Supabase, which is hosted on AWS infrastructure with industry-standard encryption and access controls.

VigilDocs is built on strict multi-tenant Row Level Security (RLS). This means your organizational data is structurally isolated at the database layer, so one company or team cannot access another company's data unless explicitly invited.

We do not sell your personal data. Access is restricted to authenticated users within your team and, where necessary, approved platform administrators for support or security purposes.

AI Data Processing

Document generation processes data through enterprise AI APIs under terms that strictly prohibit using customer inputs to train public foundational AI models. Your project inputs are used solely to generate your requested documents and are not retained or reused by the AI provider for model improvement.

Payment Processing

All payment and credit card information is processed directly by Stripe, which is PCI-DSS Level 1 compliant. VigilDocs never sees, stores, or processes your card details. Stripe provides us only with the subscription status, invoice history and payment confirmation required to manage your account.

Email Services

Document dispatch, compliance reminders, and stakeholder notifications are sent using the Resend transactional email API. Resend processes recipient email addresses and message metadata on our behalf but does not use that data for any other purpose.

Your Rights

Under UK GDPR and applicable data protection law, you have the following rights in relation to your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate or incomplete data.
  • Erasure: request deletion of your personal data in certain circumstances.
  • Data portability: receive your data in a structured, machine-readable format.
  • Restriction of processing: ask us to limit how we use your data.
  • Objection: object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, please contact us through your account settings or by emailing the address provided on your invoice. We will respond within one month.

Governing Law & Jurisdiction

This privacy agreement and any dispute arising from it are governed by the laws of Scotland, and the Scottish courts have exclusive jurisdiction, save where mandatory local law provides otherwise.