Privacy Policy

Updated on: May 20, 2026

1. Who We Are

Limitls AI operates the Vigil platform at vigil-intel.com. We are committed to protecting your personal data and processing it in accordance with the UAE Personal Data Protection Law (UAE PDPL Federal Decree-Law No. 45 of 2021) and, where applicable, the EU General Data Protection Regulation (GDPR). This Privacy Policy explains what data we collect, how we use it, and your rights.

2. Data We Collect

Account Information

Name, work email address, password (hashed), and authentication provider (Google OAuth or email/password). This is required to operate your account.

Subscription and Billing Data

Subscription tier, billing interval, and payment status. Card and payment instrument data is handled exclusively by our PCI-compliant payment processor; we never store card numbers or CVVs.

Usage Data

Brief generation history (country selections, role, sectors, time window, generated content), watchlist preferences (per your subscription tier limits), brief quality ratings, and feature interaction logs (pages visited, filters applied). Basic tier brief history is retained to enforce the one-lifetime sample-brief limit.

User-Provided Context

Any free-text context you optionally provide when generating a brief (e.g., portfolio exposure, areas of concern). This is passed to the Vigil AI Engine to generate your brief.

Technical Data

IP address (for fraud prevention), browser type, and session tokens. We use a privacy-first analytics provider that does not use cookies and does not track individuals across sessions.

3. How We Use Your Data

  • Service delivery: To authenticate you, process subscriptions, generate AI briefs, and enforce tier limits
  • Product improvement: To analyze aggregate usage patterns, improve AI prompt quality, and prioritize features, all at a population level, not individually
  • Transactional emails: Subscription confirmations, invoice receipts, watchlist alerts, and service notices via our transactional email provider
  • Legal compliance: To comply with applicable laws, respond to lawful requests, and enforce our Terms of Service

We do not use your data for advertising, profiling, or selling to third parties.

4. Data Sharing and Sub-Processors

We share the minimum necessary data with trusted third-party service providers to enable core platform functions, including payment processing, email delivery, and hosting. All sub-processors are bound by data processing agreements and are prohibited from using your data for any purpose other than providing their specific service to us.

5. Data Retention

Account and subscription data is retained for the lifetime of your account plus 3 years for financial record compliance. Brief generation history is retained for the lifetime of your account. You may request deletion at any time (see Section 6). Anonymized, aggregated usage data may be retained indefinitely for product analytics.

6. Your Rights

Under the UAE PDPL and GDPR (where applicable), you have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your account and associated data
  • Restriction of processing: Request that we limit how we use your data in certain circumstances
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests

To exercise any right, email privacy@vigil-intel.com. We will respond within 30 days. We may require identity verification before fulfilling requests.

7. GDPR and UAE PDPL Compliance

Our legal bases for processing under GDPR are: (a) contract performance (service delivery, subscription management); (b) legitimate interests (product improvement, fraud prevention, security); (c) legal obligation (financial record keeping); and (d) consent (marketing communications, where applicable).

Under the UAE PDPL, we process personal data only to the extent necessary for the purposes described in this policy and maintain appropriate technical and organizational safeguards. Data transfers outside the UAE are governed by standard contractual clauses or equivalent transfer mechanisms.

8. Security

We implement technical and organizational measures including database row-level security (RLS), externally managed payment processing (we never store card data), encrypted connections (TLS), industry-standard password hashing, and access controls limited to essential personnel. In the event of a data breach affecting your personal data, we will notify you in accordance with applicable legal requirements.

9. Cookies

We use session cookies strictly necessary for authentication. We do not use advertising or tracking cookies. Our analytics provider is cookieless. You may delete session cookies via your browser settings, which will log you out of the platform.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. Continued use of the platform after notification constitutes acceptance of the updated policy.

11. Contact

Privacy inquiries and data rights requests: privacy@vigil-intel.com
General: vigil-intel@limitls.ai

© 2026 Vigil by Limitls AI. All rights reserved.