1. Who We Are
AISECURE LLP ("AISecure", "we", "us", "our") is the developer and publisher of the VIGIL-X.AI product suite — Vigil-X VMS, Vigil-X AI Sense, Vigil-X Check and Vigil-X Shield — and of the Vigil-X mobile application.
| Legal entity | AISECURE LLP |
|---|---|
| LLPIN | ACO-1664 |
| Registered address | Unit C, 3rd Floor, Spaces and More Business Park at Gachibowli 5, Plot No. 48 and 49, Lumbini Layout, Gachibowli, Serilingampally, K.V. Rangareddy, Hyderabad, Telangana 500032, India |
| Contact | connect@vigil-x.ai |
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the rights available to you. It is issued in accordance with the Digital Personal Data Protection Act, 2023 (India) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and — where applicable to users outside India — the EU/UK General Data Protection Regulation.
2. The Most Important Thing to Understand: Your Video Never Reaches Us
VIGIL-X.AI is deployed on infrastructure owned and controlled by our enterprise customers. Video streams, recorded footage, AI analytics results, detection events and any biometric or face-detection output are stored and processed entirely on the customer's own on-premise servers.
We do not receive, transmit, store, host, access or process customer video footage or analytics data. The Vigil-X mobile application connects directly from your device to your organisation's own Vigil-X server over your organisation's network or VPN. No video passes through any AISecure server.
This creates two distinct roles, and it matters for your rights:
| Context | Data Fiduciary / Controller | Data Processor |
|---|---|---|
| Surveillance footage, detection events, operator activity inside a deployed Vigil-X system | The enterprise customer operating the deployment | AISecure, only when providing support under contract |
| Website visits, demo requests, sales enquiries | AISecure | Our sub-processors (see §7) |
| Mobile app account provisioning | The enterprise customer | AISecure |
| Crash and diagnostic data from the mobile app | AISecure | Our sub-processors (see §7) |
If you are an employee, visitor, patient, student or member of the public recorded by a Vigil-X deployment, your Data Fiduciary is the organisation operating those cameras, not AISecure. Please direct access, correction or erasure requests to that organisation. We will support them in responding, but we cannot action such requests directly because we hold no copy of that data.
3. Personal Data We Collect
3.1 Through the website (www.vigil-x.ai)
| Data | Source | Purpose | Lawful basis |
|---|---|---|---|
| First name, last name | Demo request form | Respond to your enquiry | Consent |
| Company name | Demo request form | Qualify and route the enquiry | Consent |
| Business email address | Demo request form | Respond to your enquiry; send requested material | Consent |
| Phone number | Demo request form | Contact you about your enquiry | Consent |
| Free-text enquiry ("What are you looking to solve?") | Demo request form | Understand your requirement | Consent |
| IP address, browser type, device type, pages visited, referring URL | Server logs | Security, abuse prevention, aggregate site statistics | Legitimate interest |
Demo-request submissions are handled through Zoho Bigin, our customer relationship management platform. See §7.
3.2 Through the Vigil-X mobile application
The Vigil-X app is an enterprise application. Accounts are not self-registered; they are provisioned by your organisation's Vigil-X administrator.
| Data | Purpose | Held by |
|---|---|---|
| Username / login identifier | Authenticate you against your organisation's Vigil-X server | Your organisation's server |
| Authentication token / session credential | Maintain your logged-in session | Your device; your organisation's server |
| Server address or site connection profile | Connect the app to your organisation's deployment | Your device |
| Device model, OS version, app version, app instance identifier | Diagnostics, crash reporting, compatibility | AISecure |
| Crash logs and error diagnostics | Fix defects and improve stability | AISecure |
| Push notification token | Deliver alert notifications to your device | AISecure push service; your organisation's server |
| Incident notes, photographs or annotations you choose to submit | Incident reporting within Vigil-X Shield | Your organisation's server |
| Location coordinates, when you use a location-dependent feature | Geo-tag an incident report; position field responders on the ICCC map | Your organisation's server |
The app does not upload your video, photo library, contacts, call logs, SMS messages, or advertising identifier to AISecure.
4. Device Permissions and Why We Request Them
Each permission is requested only at the point of use and each is refusable. Declining a permission disables the specific feature it supports; it does not prevent you using the app.
Notifications
Used to deliver real-time security alerts, device-health warnings from Vigil-X Check, and incident escalations from Vigil-X Shield. Notification content originates from your organisation's own server. If you decline, you will need to open the app to see alerts.
Camera
Used for two purposes: (a) scanning a QR code to onboard your device to your organisation's Vigil-X server, and (b) capturing a photograph to attach to an incident report you are filing. Images you capture are transmitted to your organisation's server, not to AISecure. The app does not access your camera in the background.
Microphone
Used solely for two-way audio talkback to a compatible camera or intercom device on your organisation's network, and only while you are actively engaging the talk control. The app does not record ambient audio and does not access the microphone in the background.
Location
Used to geo-tag an incident report you file and, in Vigil-X Shield deployments, to display your position on the ICCC situational-awareness map so that dispatch can coordinate field response. Location is accessed only while the app is open and in the foreground. We do not collect background location.
Photos and media
Used to attach an existing image to an incident report, and to save an exported video clip or snapshot to your device when you choose to export one. We access only the specific files you select. We do not scan or index your photo library.
5. What We Do Not Do
- We do not sell personal data.
- We do not share personal data with data brokers.
- We do not use personal data for advertising, ad targeting or ad measurement.
- We do not build advertising or behavioural profiles.
- We do not use customer surveillance footage, images or detection events to train, fine-tune or improve our AI models.
- We do not perform facial recognition, identification or matching against any database held by AISecure. Face detection is a customer-side analytic executing on customer-controlled infrastructure.
6. Biometric and Sensitive Data
Vigil-X AI Sense includes face detection, ANPR and behavioural analytics. Depending on how a customer configures and uses these features, and on the jurisdiction, their output may constitute biometric data or sensitive personal data.
Because these analytics execute exclusively on customer-controlled infrastructure, AISecure holds no biometric data, no facial templates and no vehicle-registration records. Responsibility for the lawful basis, notice, consent, retention limits, impact assessment and access controls governing such processing rests with the deploying organisation as Data Fiduciary. We provide configuration controls, role-based access, audit logging and retention settings to support them in meeting those obligations.
7. Sharing and Sub-Processors
We share personal data only with the following recipients, and only to the extent necessary:
| Sub-processor | Purpose | Data shared | Processing location |
|---|---|---|---|
| Zoho Corporation (Bigin CRM) | Manage sales enquiries and demo requests | Website form submissions | India |
| Google LLC (Firebase Cloud Messaging) | Deliver push notifications | Push token, notification metadata | Global |
| Google LLC (Firebase Crashlytics) | Crash and stability diagnostics | Device model, OS version, stack traces, app instance ID | Global |
| Website hosting provider | Host www.vigil-x.ai | Server logs, IP addresses | India |
We may also disclose personal data where required by law, court order, or lawful request from a government or regulatory authority; to establish or defend legal claims; or in connection with a merger, acquisition or transfer of business assets, in which case affected individuals will be notified.
8. Data Retention
| Data | Retention period |
|---|---|
| Demo request and sales enquiry data | 24 months from last contact, then deleted or anonymised |
| Website server logs | 180 days |
| Crash and diagnostic data | 12 months |
| Mobile app account data | Controlled by your organisation; deleted when your organisation deprovisions your account |
| Push notification tokens | Deleted on logout or uninstall, or after 60 days of inactivity |
| Surveillance footage and analytics events | Determined and controlled entirely by the deploying organisation; AISecure retains none |
Log retention periods reflect the 180-day requirement under the CERT-In Directions of 28 April 2022.
9. Account and Data Deletion
If you are an app user
Your Vigil-X account is issued and controlled by your organisation's Vigil-X administrator. To have your account deleted:
- In-app: open Settings → Account → Request Account Deletion.
- By email: write to connect@vigil-x.ai from your registered address, stating your username and organisation. We will forward the request to your organisation's administrator and confirm completion within 30 days.
- Via your administrator: contact your organisation's Vigil-X administrator directly.
What is deleted: your user account, login credentials, session tokens, push notification token, device registration and app-held connection profiles.
What may be retained, and why: operator audit-trail entries recording actions taken within the surveillance system — who viewed what, who acknowledged which alert — are retained by your organisation for security, audit and legal-compliance purposes, for a minimum of 180 days where the CERT-In Directions apply. These records belong to your organisation, not AISecure. Anonymised, aggregated diagnostic data that cannot identify you may be retained indefinitely.
If you submitted a website enquiry
Email connect@vigil-x.ai requesting erasure of your enquiry record. We will action it within 30 days.
10. Your Rights
Under the Digital Personal Data Protection Act, 2023, where we act as Data Fiduciary you have the right to:
- Access a summary of the personal data we process about you and the processing activities undertaken;
- Correction, completion, updating and erasure of your personal data;
- Nominate another individual to exercise your rights in the event of death or incapacity;
- Grievance redressal through the mechanism at §13, before approaching the Data Protection Board of India;
- Withdraw consent at any time, with the same ease with which it was given. Withdrawal does not affect processing carried out before withdrawal.
If you are in the EU or UK, you additionally have rights of data portability, restriction of processing, objection to processing based on legitimate interest, and the right to lodge a complaint with your national supervisory authority.
To exercise any right, contact connect@vigil-x.ai. We respond within 30 days. We may need to verify your identity before actioning a request.
If your request concerns footage or detection events from a Vigil-X deployment, contact the organisation operating that deployment. We will identify the relevant contact for you where we reasonably can.
11. Security
We implement reasonable security safeguards appropriate to the risk, including:
- Encryption of data in transit using TLS 1.2 or above;
- Role-based access control and least-privilege access for AISecure personnel;
- Multi-factor authentication on internal administrative systems;
- Audit logging of access to systems containing personal data;
- Secure development practices, dependency scanning and periodic security testing;
- Contractual confidentiality and data protection obligations on all personnel and sub-processors.
The security of a deployed Vigil-X system — network segmentation, server hardening, physical security, credential hygiene and patching — is the responsibility of the deploying organisation. We provide hardening guidance and security advisories to support them.
In the event of a personal data breach affecting data for which we are Data Fiduciary, we will notify the Data Protection Board of India and affected individuals as required under the DPDP Act, and will report qualifying cyber incidents to CERT-In within 6 hours of becoming aware of them, as required by the CERT-In Directions of 28 April 2022.
12. Children
The Vigil-X mobile application is an enterprise security tool intended solely for authorised personnel of our customer organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have inadvertently collected such data, we will delete it promptly.
Where a Vigil-X deployment operates in an environment involving children — such as a school or hospital — the deploying organisation is responsible for obtaining any verifiable parental consent required under the DPDP Act and for complying with the restrictions on tracking, behavioural monitoring and targeted advertising directed at children.
13. Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000:
| Grievance Officer | The Grievance Officer, AISECURE LLP |
|---|---|
| connect@vigil-x.ai | |
| Address | Unit C, 3rd Floor, Spaces and More Business Park at Gachibowli 5, Plot No. 48 and 49, Lumbini Layout, Gachibowli, Serilingampally, K.V. Rangareddy, Hyderabad, Telangana 500032, India |
| Response time | Acknowledgement within 24 hours; resolution within 30 days |
14. International Transfers
We are based in India and process data primarily in India. Where a sub-processor listed in §7 processes data outside India, we ensure the transfer is permitted under the DPDP Act and, where the data relates to EU or UK individuals, that it is protected by Standard Contractual Clauses or an equivalent safeguard.
15. Cookies
www.vigil-x.ai uses strictly necessary cookies only — those required for the site to function, for security, and for the operation of the demo request form. We do not use advertising, tracking or profiling cookies. The Vigil-X mobile application does not use cookies or advertising identifiers.
16. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by posting the revised policy at https://www.vigil-x.ai/privacy with an updated "Last Updated" date and, where the change materially affects your rights, by in-app notice or email. Continued use after the effective date constitutes acceptance.
17. Contact
AISECURE LLP
Unit C, 3rd Floor, Spaces and More Business Park at Gachibowli 5, Plot No. 48 and 49, Lumbini Layout, Gachibowli, Serilingampally, K.V. Rangareddy, Hyderabad, Telangana 500032, India
Email: connect@vigil-x.ai
© 2026 AISECURE LLP. All rights reserved.