Privacy at Vigil
This page describes how Vigil Health processes personal data, including special-category health data under Article 9 of the UK GDPR. The wording here is operational; final legal copy will be issued before public launch.
What we hold
- Account: email, date of birth, sex at birth.
- Blood test data you enter or upload: marker values, units, reference ranges, date taken, lab name.
- Interpretations generated for you: the exact text shown, the model version, the prompt version, the de-identified payload sent to the model.
- An audit trail of consent, exports, deletions, and interpretations rendered.
Lawful basis
- Article 6(1)(b) — performance of contract — for service delivery.
- Article 9(2)(a) — explicit consent — for health data. You give this on signup and can withdraw it from your account page.
Where it lives
All your data is stored in the European Union. Interpretation is run on AWS Bedrock in Frankfurt (eu-central-1). Your name, email, and date of birth are never sent to the language model — interpretation receives only an age band, sex, and the marker values.
Sub-processors
| Provider | Purpose |
|---|---|
| Supabase (EU) | database and authentication. |
| Amazon Web Services (eu-central-1) | Bedrock inference; Textract OCR when added. |
| Vercel (Frankfurt) | application hosting. |
| Cloudflare | DNS and edge routing. No health data passes through Cloudflare beyond TLS termination. |
| Resend / Loops | transactional and marketing email. Health values are never included in email bodies. |
Your rights
- Access (Article 15): download a JSON export of everything Vigil holds about you from your account page.
- Erasure (Article 17): delete your account from your account page. All panels, observations, and interpretations are removed.
- Rectification (Article 16): edit values on each panel from the panel view.
- Restriction, portability, complaint to the ICO: contact us at privacy@vigilhealth.co.uk.
Retention
Your data is kept as long as your account is active. Deletion is honoured immediately. The audit log retains event timestamps for seven years (without your identity) to meet legal-defence requirements.