1. Who We Are

AISECURE LLP ("AISecure", "we", "us", "our") is the developer and publisher of the VIGIL-X.AI product suite — Vigil-X VMS, Vigil-X AI Sense, Vigil-X Check and Vigil-X Shield — and of the Vigil-X mobile application.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the rights available to you. It is issued in accordance with the Digital Personal Data Protection Act, 2023 (India) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and — where applicable to users outside India — the EU/UK General Data Protection Regulation.


2. The Most Important Thing to Understand: Your Video Never Reaches Us

VIGIL-X.AI is deployed on infrastructure owned and controlled by our enterprise customers. Video streams, recorded footage, AI analytics results, detection events and any biometric or face-detection output are stored and processed entirely on the customer's own on-premise servers.

We do not receive, transmit, store, host, access or process customer video footage or analytics data. The Vigil-X mobile application connects directly from your device to your organisation's own Vigil-X server over your organisation's network or VPN. No video passes through any AISecure server.

This creates two distinct roles, and it matters for your rights:

If you are an employee, visitor, patient, student or member of the public recorded by a Vigil-X deployment, your Data Fiduciary is the organisation operating those cameras, not AISecure. Please direct access, correction or erasure requests to that organisation. We will support them in responding, but we cannot action such requests directly because we hold no copy of that data.


3. Personal Data We Collect

3.1 Through the website (www.vigil-x.ai)

Demo-request submissions are handled through Zoho Bigin, our customer relationship management platform. See §7.

3.2 Through the Vigil-X mobile application

The Vigil-X app is an enterprise application. Accounts are not self-registered; they are provisioned by your organisation's Vigil-X administrator.

The app does not upload your video, photo library, contacts, call logs, SMS messages, or advertising identifier to AISecure.


4. Device Permissions and Why We Request Them

Each permission is requested only at the point of use and each is refusable. Declining a permission disables the specific feature it supports; it does not prevent you using the app.

Notifications

Used to deliver real-time security alerts, device-health warnings from Vigil-X Check, and incident escalations from Vigil-X Shield. Notification content originates from your organisation's own server. If you decline, you will need to open the app to see alerts.

Camera

Used for two purposes: (a) scanning a QR code to onboard your device to your organisation's Vigil-X server, and (b) capturing a photograph to attach to an incident report you are filing. Images you capture are transmitted to your organisation's server, not to AISecure. The app does not access your camera in the background.

Microphone

Used solely for two-way audio talkback to a compatible camera or intercom device on your organisation's network, and only while you are actively engaging the talk control. The app does not record ambient audio and does not access the microphone in the background.

Location

Used to geo-tag an incident report you file and, in Vigil-X Shield deployments, to display your position on the ICCC situational-awareness map so that dispatch can coordinate field response. Location is accessed only while the app is open and in the foreground. We do not collect background location.

Photos and media

Used to attach an existing image to an incident report, and to save an exported video clip or snapshot to your device when you choose to export one. We access only the specific files you select. We do not scan or index your photo library.


5. What We Do Not Do


6. Biometric and Sensitive Data

Vigil-X AI Sense includes face detection, ANPR and behavioural analytics. Depending on how a customer configures and uses these features, and on the jurisdiction, their output may constitute biometric data or sensitive personal data.

Because these analytics execute exclusively on customer-controlled infrastructure, AISecure holds no biometric data, no facial templates and no vehicle-registration records. Responsibility for the lawful basis, notice, consent, retention limits, impact assessment and access controls governing such processing rests with the deploying organisation as Data Fiduciary. We provide configuration controls, role-based access, audit logging and retention settings to support them in meeting those obligations.


7. Sharing and Sub-Processors

We share personal data only with the following recipients, and only to the extent necessary:

We may also disclose personal data where required by law, court order, or lawful request from a government or regulatory authority; to establish or defend legal claims; or in connection with a merger, acquisition or transfer of business assets, in which case affected individuals will be notified.


8. Data Retention

Log retention periods reflect the 180-day requirement under the CERT-In Directions of 28 April 2022.


9. Account and Data Deletion

If you are an app user

Your Vigil-X account is issued and controlled by your organisation's Vigil-X administrator. To have your account deleted:

  1. In-app: open Settings → Account → Request Account Deletion.
  2. By email: write to connect@vigil-x.ai from your registered address, stating your username and organisation. We will forward the request to your organisation's administrator and confirm completion within 30 days.
  3. Via your administrator: contact your organisation's Vigil-X administrator directly.

What is deleted: your user account, login credentials, session tokens, push notification token, device registration and app-held connection profiles.

What may be retained, and why: operator audit-trail entries recording actions taken within the surveillance system — who viewed what, who acknowledged which alert — are retained by your organisation for security, audit and legal-compliance purposes, for a minimum of 180 days where the CERT-In Directions apply. These records belong to your organisation, not AISecure. Anonymised, aggregated diagnostic data that cannot identify you may be retained indefinitely.

If you submitted a website enquiry

Email connect@vigil-x.ai requesting erasure of your enquiry record. We will action it within 30 days.


10. Your Rights

Under the Digital Personal Data Protection Act, 2023, where we act as Data Fiduciary you have the right to:

If you are in the EU or UK, you additionally have rights of data portability, restriction of processing, objection to processing based on legitimate interest, and the right to lodge a complaint with your national supervisory authority.

To exercise any right, contact connect@vigil-x.ai. We respond within 30 days. We may need to verify your identity before actioning a request.

If your request concerns footage or detection events from a Vigil-X deployment, contact the organisation operating that deployment. We will identify the relevant contact for you where we reasonably can.


11. Security

We implement reasonable security safeguards appropriate to the risk, including:

The security of a deployed Vigil-X system — network segmentation, server hardening, physical security, credential hygiene and patching — is the responsibility of the deploying organisation. We provide hardening guidance and security advisories to support them.

In the event of a personal data breach affecting data for which we are Data Fiduciary, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act, and will report qualifying cyber incidents to CERT-In within 6 hours of becoming aware of them, as required by the CERT-In Directions of 28 April 2022.


12. Children

The Vigil-X mobile application is an enterprise security tool intended solely for authorised personnel of our customer organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have inadvertently collected such data, we will delete it promptly.

Where a Vigil-X deployment operates in an environment involving children — such as a school or hospital — the deploying organisation is responsible for obtaining any verifiable parental consent required under the DPDP Act and for complying with the restrictions on tracking, behavioural monitoring and targeted advertising directed at children.


13. Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000:


14. International Transfers

We are based in India and process data primarily in India. Where a sub-processor listed in §7 processes data outside India, we ensure the transfer is permitted under the DPDP Act and, where the data relates to EU or UK individuals, that it is protected by Standard Contractual Clauses or an equivalent safeguard.


15. Cookies

www.vigil-x.ai uses strictly necessary cookies only — those required for the site to function, for security, and for the operation of the demo request form. We do not use advertising, tracking or profiling cookies. The Vigil-X mobile application does not use cookies or advertising identifiers.


16. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by posting the revised policy at https://www.vigil-x.ai/privacy with an updated "Last Updated" date and, where the change materially affects your rights, by in-app notice or email. Continued use after the effective date constitutes acceptance.


17. Contact

AISECURE LLP
Unit C, 3rd Floor, Spaces and More Business Park at Gachibowli 5, Plot No. 48 and 49, Lumbini Layout, Gachibowli, Serilingampally, K.V. Rangareddy, Hyderabad, Telangana 500032, India
Email: connect@vigil-x.ai

© 2026 AISECURE LLP. All rights reserved.