Last updated: 29 September 2026
VigiWorks takes the privacy of visitors, prospective clients, clients and Partner Program participants seriously. This Privacy Policy explains what personal data we process, why we process it, and what choices and rights you have.
This Privacy Policy covers the personal data VigiWorks processes through vigiworks.com, its contact form, and its Partner Program. It describes what we actually do, based on how our systems are built, rather than a general description of what a website could do.
This policy does not cover cookies and similar browser technologies in detail. That is covered separately in our Cookie Policy, which this policy refers to where relevant.
This policy also does not describe the personal data practices of an individual client website or webshop that VigiWorks builds or maintains. Those are addressed separately in section 13 and in the relevant client's own project agreement.
This policy applies to:
Where we work with a client on their own website or webshop, that client's own visitors and customers are usually the client's responsibility, not ours. Section 13 explains this in more detail.
The personal data we process depends on how you interact with us.
If you contact us through our contact form, we process the name, email address and message you submit.
If you use our Partner Program as a partner, we process the name we hold for your partner account and a security token used to identify your unique referral link. We do not ask partners for further personal details to participate.
If you are referred to us by a Partner Program participant, we process whatever the referring partner submits about you, which may include a company name, a contact person's name, contact details such as an email address or phone number, a website address, and any notes the partner has added about the opportunity.
If you visit our website, and only if you give consent, we process analytics information such as pages viewed and general technical and browser information. This is described in full in our Cookie Policy, not repeated here.
If you become a client, we process the information needed to deliver, invoice and support your project. Much of this happens through direct communication (for example email) rather than through this website, so this policy describes the general principles that apply rather than an automated data flow.
We also process limited technical information, such as timestamps and submission status, alongside the categories above, to operate our systems securely and reliably.
We do not ask for or knowingly process special categories of personal data (such as health, religious or political information) through this website.
We collect personal data in the following ways.
We use personal data for the following purposes.
We do not use personal data submitted through this website for advertising or for sale to third parties.
Where the General Data Protection Regulation (GDPR) applies, we rely on the following legal bases, depending on the specific purpose.
Responding to your enquiry is based on our legitimate interest in communicating with people who contact us, and where your enquiry concerns a possible project, on the steps you have asked us to take before entering into a contract.
Providing, invoicing and supporting an agreed project is based on the performance of the contract with our client.
Administering Partner Program referrals and commission is based on the performance of our agreement with the partner, and on our legitimate interest in evaluating and following up on a referred business opportunity.
Security measures, such as limiting submissions from the same source, are based on our legitimate interest in protecting our website and systems from misuse.
Website analytics is based on your consent, which you can withdraw at any time through Cookie preferences.
Meeting legal and accounting obligations is based on the legal obligations that apply to us.
We use a small number of service providers to operate our own website and business systems. We do not sell personal data, and we only share it where necessary for the purposes described in this policy.
The providers described below process personal data for VigiWorks' own website and business systems specifically. A client's own website or webshop may be built using different providers chosen for that project, for example its own payment provider. Those providers are not covered by this policy and are addressed in the relevant project agreement and, where applicable, a separate data processing agreement.
Google provides the infrastructure our website and internal systems run on, including website hosting, the server-side functions that handle our contact form and Partner Program, and our database. Where you have given analytics consent, Google Analytics also processes technical and usage information as described in our Cookie Policy.
Formspree is an email delivery service. If you submit our contact form, your name, email address and message are sent from our own server to Formspree so that the message can reach us by email. Formspree does not run in your browser and does not set any cookie through this website.
Google Sheets is used internally to record approved Partner Program referrals, so that we can administer partner commission. Only referrals that an administrator has approved are recorded there.
Our footer also links to our own Instagram, TikTok and LinkedIn profiles. These are ordinary outbound links. No data is sent to those platforms unless and until you actively click through to them, and once you do, that platform's own privacy policy applies.
The server-side systems we operate ourselves, including the functions that handle our contact form and Partner Program, run on infrastructure located in the European Union.
Some of the service providers described in section 7, including Google and Formspree, are global companies that may process data in countries outside the European Economic Area as part of their own infrastructure. Where this happens, such providers are generally required to have appropriate safeguards in place.
We aim to keep personal data only for as long as it is needed for the purpose it was collected for.
Contact form messages are forwarded to us by email and are not separately stored in our own systems beyond that. How long the resulting email itself is kept follows our normal business email practices.
Partner Program referral information is kept while a referral is awaiting review, and for a limited period afterwards to allow for commission administration and record-keeping. Once a referral is approved, a durable record is also kept in the Google Sheet used to administer commission, separately from our database.
Partner account details are kept for as long as the partner relationship is active, and can be deactivated or permanently removed on request.
Where we temporarily hold account credentials or other sensitive setup information for a client's project, this is kept only for as long as reasonably necessary to complete that setup or handover, as described in section 13.
We use reasonable technical and organisational measures to protect personal data, including transmitting data over encrypted connections, restricting direct access to our database so that it can only be reached through our own controlled server-side systems, and requiring administrator authentication for access to Partner Program and referral data.
Security tokens used to identify a partner's referral link are stored in a form that cannot be reversed back into the original token.
No method of storing or transmitting information over the internet is completely secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security.
Where the GDPR applies to you, you have the right to:
To exercise any of these rights, email info@vigiworks.com. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Our use of cookies, local storage and analytics, including exactly what is used, why, and how to change your choice, is covered in full in our Cookie Policy. Please refer to that page for details and to manage your preferences.
When we build or maintain a website or webshop for a client, that client generally decides what personal data is collected through their own website and why, for example their own customers' order or contact details. In that relationship, the client is usually the party responsible for deciding the purposes and means of that processing.
Where we process personal data on a client's behalf as part of delivering or supporting their website, for example by hosting it or handling data that flows through it, we may act as a data processor for that client rather than as the party responsible for that data. Our exact role depends on the specific project and what has been agreed.
Where this applies, a separate written data processing agreement may be needed between VigiWorks and the client, setting out the scope of that processing and each party's responsibilities.
Setting up a project can also require VigiWorks to temporarily handle account credentials, billing details or other sensitive setup information belonging to a client, for example to configure a third-party service the project depends on. Where practical, we ask clients to provide highly sensitive information, such as payment card details, directly to the relevant provider rather than to us, and we do not seek to hold full payment card information ourselves. Where we do temporarily receive credentials or sensitive setup information because this is genuinely needed to configure a service, we keep it only for as long as reasonably necessary for that purpose, and take reasonable steps to remove it from our own records once a project or handover is complete and we no longer need it, subject to any legal or accounting obligation to keep specific records for longer.
This section describes the general relationship. It does not by itself describe every project, since the personal data involved and the responsibilities that follow depend on what has actually been agreed for that project.
We may update this Privacy Policy from time to time, for example if our website, services or use of personal data changes. The most recent version will always be published on this page.
If you have questions about this Privacy Policy or how we handle personal data, email info@vigiworks.com.