01Who we are and what this covers
This Privacy Policy explains how Vigicom Enterprises, a sole proprietorship firm with its principal place of business at 501, Coral Business Center, Solapur, Maharashtra 413101, India(“Vigicom”, “we”, “us” or “our”), collects, uses, discloses and protects personal data.
It applies to:
- Visitors to vigicom.net and any subdomain we operate;
- People who contact us by form, email, telephone or messaging application;
- Prospective, current and former clients, and the individual representatives of those organisations;
- Candidates who apply to work with us, and our vendors and contractors.
It does not apply to personal data we process on behalf of a clientwhile delivering marketing services — for example the customer records inside a client’s advertising or analytics account. In that situation the client is the Data Fiduciary (or Controller) and we act as their Data Processor under a separate written agreement. That client’s own privacy notice governs how those individuals’ data is handled.
Roles. Where we decide why and how personal data is processed, we are a Data Fiduciaryunder India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and a Controllerunder the EU/UK General Data Protection Regulation (“GDPR”).
02Information we collect
Information you give us
- Enquiry details — your name, work email address, telephone number, company name, indicative budget range, the services you are interested in, and whatever you write in the message field.
- Client relationship data — the contact details of your team, billing and GST details, contractual documents, and correspondence with us.
- Recruitment data — your CV, work history and any information you volunteer during a hiring process.
Information collected automatically
- Technical data — IP address, browser type and version, device type, operating system, screen size, referring URL and preferred language.
- Usage data — pages viewed, time on page, scroll depth, links clicked and approximate location derived from IP address at city level.
Usage data is collected only where you have accepted optional analytics cookies. See Cookies and similar technologies.
Information from third parties
- Publicly available business information (for example a company website or a LinkedIn profile) used to research a prospective client before a meeting;
- Referral information where an existing contact introduces you to us.
What we do not collect
We do not knowingly collect financial account numbers, government identifiers such as Aadhaar or PAN of website visitors, biometric data, health data, or any other category of sensitive personal data through this website. Please do not include such information in the enquiry form.
03How we use personal data
We use personal data only for the specified purposes set out below.
| Purpose | Data used |
|---|---|
| Responding to your enquiry and corresponding with you | Name, email, phone, company, message content |
| Preparing proposals, audits and statements of work | Enquiry details, business information you share |
| Delivering contracted services and managing the client relationship | Client contact and account data, correspondence |
| Invoicing, payment collection and statutory tax records | Billing name, address, GSTIN, transaction records |
| Operating, securing and debugging this website | Technical data, server logs |
| Understanding which content is read, in aggregate | Usage data (only with analytics consent) |
| Preventing spam and abuse of our forms | IP address, submission timestamps |
| Complying with legal obligations and defending legal claims | Whichever records are relevant |
We do not sell personal data. We do not share your contact details with other agencies, data brokers or advertising networks for their own marketing, and we do not use your enquiry to build advertising profiles.
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you using automated processing alone.
04Our legal basis for processing
Under the DPDP Act (India). We process personal data on the basis of your consent, given freely, specifically and unambiguously through a clear affirmative action — such as ticking the consent box on our enquiry form — or on the basis of certain legitimate uses recognised by the Act, including where you voluntarily provide data for a specified purpose and have not indicated that you object to its use for that purpose, and where processing is necessary to comply with a legal obligation.
Under the GDPR (EEA/UK). Where the GDPR applies, we rely on:
- Consent (Article 6(1)(a)) — for optional analytics cookies and for marketing email, which you may withdraw at any time;
- Performance of a contract (Article 6(1)(b)) — to deliver services you have engaged us for and to take steps at your request before entering a contract;
- Legal obligation (Article 6(1)(c)) — for tax, accounting and statutory record-keeping;
- Legitimate interests (Article 6(1)(f)) — to secure our website, prevent fraud and spam, and to respond to unsolicited business enquiries. We have assessed these interests against your rights and freedoms and consider them proportionate; you may object at any time (see Rights under the GDPR).
07International transfers
We are based in India and our service providers may store or process personal data outside India, including in the United States and the European Union. Under the DPDP Act, transfer of personal data outside India is permitted except to countries restricted by notification of the Central Government; we monitor and comply with any such restrictions.
Where personal data protected by the GDPR is transferred outside the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with a transfer risk assessment and supplementary technical measures such as encryption in transit and at rest. You may request a copy of the relevant safeguards by contacting us.
08How long we keep it
We keep personal data only for as long as it is needed for the purpose it was collected for, and then erase it — including from routine backups on their normal rotation cycle.
| Category | Retention period |
|---|---|
| Enquiries that do not become clients | 24 months from last contact, then deleted |
| Client relationship records | Duration of the engagement plus 3 years |
| Invoices, tax and statutory accounting records | 8 years, as required under Indian tax and company law |
| Website server logs | Up to 90 days |
| Analytics data (if consented) | Up to 14 months, in aggregated form thereafter |
| Unsuccessful job applications | 12 months, unless you ask us to keep them longer |
09How we protect it
We maintain reasonable security safeguards appropriate to the risk, including:
- TLS encryption for all traffic to and from this website;
- Encryption at rest for data held with our infrastructure providers;
- Multi-factor authentication and a password manager across all business accounts, with access granted on a least-privilege basis;
- Role-based access to client advertising and analytics accounts;
- Confidentiality obligations in every employment and contractor agreement;
- Periodic review of who has access to what, and prompt revocation when people leave.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act, and where the GDPR applies we will notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
10Your rights under the DPDP Act, 2023
If you are a Data Principal whose personal data we process, you have the right to:
- Access — obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom it has been shared;
- Correction and erasure — have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer needed for the purpose it was collected for or where you withdraw consent;
- Grievance redressal — a readily available means of raising a complaint with us about our handling of your data or our response to a request;
- Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
- Withdraw consent — withdraw consent at any time, as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out before it.
You also have duties under Section 15 of the DPDP Act, including not impersonating another person when providing personal data and not raising false or frivolous grievances.
How to exercise these rights
Write to privacy@vigicom.net. We will acknowledge your request promptly and respond substantively within 30 days. We may ask for information sufficient to verify your identity — used only for that verification and then discarded.
Grievance Officer
If you are unsatisfied with how we handle your personal data or a request, you may contact our Grievance Officer, designated under Section 13 of the DPDP Act and the Information Technology Act, 2000:
- Rayan Selvam, Grievance Officer
- Email: privacy@vigicom.net
- Address: 501, Coral Business Center, Solapur, Maharashtra 413101, India
If your grievance remains unresolved, you may escalate it to the Data Protection Board of India in accordance with the DPDP Act.
11Additional rights under the GDPR
If you are in the European Economic Area or the United Kingdom, you additionally have the right to:
- Restrict processing — ask us to pause processing while a dispute about accuracy or lawfulness is resolved;
- Object — object to processing based on our legitimate interests, and object absolutely to direct marketing at any time;
- Data portability — receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Not be subject to automated decision-making producing legal or similarly significant effects — we do not carry out such processing;
- Lodge a complaintwith your local supervisory authority — in the UK, the Information Commissioner’s Office.
We respond to GDPR requests within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. There is no fee unless a request is manifestly unfounded or excessive.
12Notice to residents of California and other US states
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information is collected, used, shared or sold; to delete personal information; to correct inaccurate personal information; to opt out of sale or sharing for cross-context behavioural advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
In the preceding twelve months we have collected the categories of personal information described in Information we collect — identifiers, commercial information and internet activity information — for the business purposes set out in How we use personal data.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We do not knowingly collect or sell the personal information of consumers under 16.
To exercise any of these rights, or to submit a request through an authorised agent, email privacy@vigicom.net. Residents of other US states with comparable privacy legislation may use the same address, and we will honour the rights available to them under their state law.
13Children’s data
This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data of any individual under the age of 18, which is the threshold for a child under the DPDP Act.
We do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us with personal data, contact privacy@vigicom.net and we will delete it promptly.
14Third-party links, changes and contact
Links to other sites
Our website links to third-party websites, including social media profiles. We are not responsible for their content or privacy practices, and this policy does not apply to them. Read their privacy notices before providing personal data.
Changes to this policy
We may update this policy to reflect changes in our practices or in the law. The revision date at the top of the page will always show when it was last changed. Where a change is material — for example a new purpose of processing — we will give prominent notice on the website and, where required, seek fresh consent before the change takes effect.
Contact us
- Privacy enquiries: privacy@vigicom.net
- General enquiries: hello@vigicom.net · +1 929 565 6761
- Post: Vigicom Enterprises, 501, Coral Business Center, Solapur, Maharashtra 413101, India
See also our Terms & Conditions, which govern the use of this website and our services.