Legal
Privacy policy
How we process the personal data you provide to us through the site and the product · Updated: 2026-05-17.
Translation for information only. This page is a translation of the Spanish original. In case of any discrepancy, the Spanish version prevails.
Provisional document This document describes our practices during the PRIVATE BETA phase. Before general release, it will be reviewed by a specialist law firm. For specific questions, write to us at info@vigilatum.es.
1 · Data controller
Vigilatum (company in formation), with the contact email info@vigilatum.es, is the controller of the personal data collected through this site and through the operational platform.
2 · Data we collect
We distinguish between data from the public website and data from the Vigilatum service.
2.1 · Website (vigilatum.es)
- Data submitted through the contact form: name, email address, company, optional telephone number, free-text message, browsing language.
- Technical metadata: IP address (stored for up to 24 hours for rate-limit control), browser and referrer.
- Visit statistics, using a tool of our own hosted on our server (Umami, at
metrics.vigilatum.es): the page visited, the page the visitor came from, the browser language and the screen size. It helps us know which pages are read and which are not. - The site does not install any cookies, does not create any identifier that follows you between visits and does not use external analytics services (Google Analytics, Meta, etc.): those statistics remain on our server and are not shared with anyone.
2.2 · Vigilatum platform (customers)
- Customer account data: company name, technical contacts, subscribed plan.
- Network metrics generated by the probes: latency, packet loss, DNS, HTTP, LAN inventory, PCAP captures in the event of an incident.
- Data from the monitored endpoints: hostname, local IP, operating system, health metrics. We do not access application content, files or end-user communications.
3 · Purpose and legal basis
- Sales contact: responding to the request and, where applicable, maintaining communication during the negotiation. Legal basis: consent and legitimate interest in commercial management.
- Provision of the service: monitoring the customer’s network and generating alerts, recommendations and evidence. Legal basis: performance of the contract.
- Service security: rate limiting, anti-spam, abuse detection. Legal basis: legitimate interest.
4 · Retention
- Form messages: up to 24 months from the last contact, unless the sender becomes a customer.
- Customer operational data: for the duration of the contractual relationship + 1 year for audit purposes.
- Technical logs: up to 90 days by default.
5 · Disclosures and service providers
We do not sell or share personal data with third parties for commercial purposes. We use the following data processors:
- Hetzner Online GmbH (Germany): hosting of the infrastructure. Data hosted in a European data centre.
- IONOS (Germany): hosting of the public website vigilatum.es and email delivery.
We do not carry out international transfers of data outside the European Economic Area.
6 · User rights
You may exercise the rights of access, rectification, erasure, objection, restriction and portability by writing to info@vigilatum.es. We will reply within one month at the latest. If you consider that your request has not been properly dealt with, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).
7 · Security
We apply reasonable measures proportionate to the risk: encryption in transit (TLS 1.3), authentication of each probe with its own credential on every message it sends, logical separation per customer (multi-tenant), access control to the backend, and encrypted backups. The implementation is described in the technical documentation available to customers.