vigilhealth

Privacy at Vigil

This page describes how Vigil Health processes personal data, including special-category health data under Article 9 of the UK GDPR. The wording here is operational; final legal copy will be issued before public launch.

What we hold
Lawful basis
Where it lives

All your data is stored in the European Union. Interpretation is run on AWS Bedrock in Frankfurt (eu-central-1). Your name, email, and date of birth are never sent to the language model — interpretation receives only an age band, sex, and the marker values.

Sub-processors
ProviderPurpose
Supabase (EU)database and authentication.
Amazon Web Services (eu-central-1)Bedrock inference; Textract OCR when added.
Vercel (Frankfurt)application hosting.
CloudflareDNS and edge routing. No health data passes through Cloudflare beyond TLS termination.
Resend / Loopstransactional and marketing email. Health values are never included in email bodies.
Your rights
Retention

Your data is kept as long as your account is active. Deletion is honoured immediately. The audit log retains event timestamps for seven years (without your identity) to meet legal-defence requirements.