Privacy Policy
Last updated: April 2026
Tandem Lens Cybersecurity ("we", "us", "our") operates Vigil ("the Service"). This policy explains how we collect, use, and protect your information.
1. Information We Collect
Information you provide:
• Account information: name, email address, password
• Company information: company name, industry, size
• Security assessment data: answers to onboarding questions, scores, gaps, and roadmap items
• Communication content: notes, policies, reports you create within the Service
Information collected automatically:
• Usage data: pages visited, features used, time spent in the Service
• Technical data: IP address, browser type, device type, operating system
• Cookies: session management and preferences
Information we do NOT collect:
• Payment card numbers (processed by Stripe)
• Government ID numbers
• Biometric data
• Sensitive health information beyond what you voluntarily enter for security assessment purposes
2. How We Use Your Information
We use your information to:
• Provide and improve the Service
• Send you transactional emails (account, digests)
• Respond to your support requests
• Ensure the security of the Service
• Comply with legal obligations
We do NOT use your information to:
• Sell to third parties
• Train AI or machine learning models
• Display advertising
• Profile you for marketing without consent
3. Data Storage and Security
Your data is stored using Supabase (PostgreSQL), hosted on AWS infrastructure. Data is encrypted at rest and in transit using industry-standard encryption (AES-256, TLS 1.2+).
We implement row-level security to ensure your data is only accessible to authorized users within your organization.
5. Your Rights
Depending on your location, you may have the right to:
• Access: request a copy of your data
• Correction: update inaccurate information
• Deletion: request deletion of your account and data
• Portability: export your data in standard formats
• Objection: opt out of certain processing activities
To exercise these rights, use the Admin > Data Export section in the app, or contact support@tandemlens.net. We will respond to requests within 30 days.
6. GDPR (European Union Users)
If you are located in the European Economic Area, you have additional rights under the GDPR.
Legal basis for processing:
• Contract performance: to provide the Service
• Legitimate interests: to improve and secure the Service
• Consent: for optional communications
Our data processors are listed in Section 4. Data transfers outside the EEA use standard contractual clauses where required.
To exercise your GDPR rights, contact: support@tandemlens.net
7. CCPA (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act:
• Right to know what personal information we collect
• Right to delete personal information
• Right to opt-out of sale (we do not sell data)
• Right to non-discrimination for exercising rights
To exercise these rights, contact: support@tandemlens.net
9. Data Retention
We retain your data for as long as your account is active. When you delete your account:
• Your data is immediately inaccessible to others
• Data is permanently deleted within 30 days
• Backup copies are purged within 90 days
Some data may be retained longer if required by applicable law.
10. Children
The Service is not directed to children under 16. We do not knowingly collect information from children. If you believe we have collected information from a child, contact us immediately.
11. Changes to This Policy
We will notify you of material changes by email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent changes.
12. Contact
Privacy questions and data requests:
Email: support@tandemlens.net
Website: vigil.tandemlens.net
Tandem Lens Cybersecurity