Vigilante · Legal
DATA PROCESSING AGREEMENT
GDPR-aligned data processing terms for business customers.
Last updated June 15, 2026 · Version 1.0
1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between Vigilant Intelligence, Inc. ("Processor") and the customer entity ("Controller") using the VIGILANTE Service where Processor processes Personal Data on Controller's behalf.
This DPA applies when Controller is subject to GDPR, UK GDPR, or similar data protection laws and Personal Data is processed through the Service.
2. Definitions
"Personal Data," "Processing," "Controller," "Processor," "Sub-processor," and "Data Subject" have the meanings in applicable data protection law.
"Customer Personal Data" means Personal Data submitted to or generated within the Service by or on behalf of Controller, excluding data Processor processes as a controller (e.g., billing contact for Controller's account with Processor).
3. Roles and instructions
Controller determines purposes and means of Processing Customer Personal Data. Processor Processes Customer Personal Data only on documented instructions from Controller, including as configured through the Service and as necessary to provide, secure, and support the Service.
Controller instructs Processor to Process Customer Personal Data to deliver target-intelligence monitoring, authentication, storage, notifications, and related features described in the Terms of Service.
4. Processor obligations
Processor will:
- Process Customer Personal Data only as instructed and for the duration of the agreement.
- Ensure personnel with access are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures.
- Assist Controller with Data Subject requests where feasible, using available tools or support channels.
- Notify Controller without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data.
- Delete or return Customer Personal Data upon termination, subject to legal retention requirements.
- Make available information necessary to demonstrate compliance and allow audits upon reasonable notice, no more than once per year unless required by a supervisory authority.
5. Sub-processors
Controller authorizes Processor to engage Sub-processors listed in our Subprocessor List. Processor will impose data protection obligations on Sub-processors substantially similar to this DPA.
Processor will notify Controller of new Sub-processors and provide opportunity to object on reasonable grounds relating to data protection.
6. International transfers
Where Customer Personal Data is transferred outside the EEA/UK, Processor will implement appropriate safeguards, including Standard Contractual Clauses where required.
Upon request, Processor will provide applicable transfer mechanisms.
7. Controller obligations
Controller represents it has lawful basis to Process Customer Personal Data and to instruct Processor. Controller is responsible for Target configuration, notices to Data Subjects where required, and accuracy of instructions.
8. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA limits either party's liability where prohibited by law.
9. Precedence
If there is a conflict between this DPA and the Terms of Service regarding Processing of Customer Personal Data, this DPA controls.
10. Contact
Data protection inquiries: privacy@vigilant.app
Vigilant Intelligence, Inc.
251 Little Falls Drive, Wilmington, DE 19808, United States