Privacy Policy
Last updated: April 24, 2026
This Privacy Policy describes how Vigil Assurance ("Vigil Assurance," "we," "us," or "our") collects, uses, and discloses information about you when you visit our website at www.vigilassurance.com (the "Site"), contact us, or engage our professional services. Your privacy matters to us, and we are committed to handling your information responsibly and in accordance with applicable law.
By using the Site or engaging our services, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree with our practices, please do not use the Site or provide information to us.
Scope of This Policy
This Privacy Policy applies solely to information collected through our Site, through direct communications with our team (such as email, phone, or video calls), and in the course of delivering our professional services. It does not apply to information collected through any third-party platform or service that is not owned or controlled by Vigil Assurance, even if it is linked from our Site.
Information We Collect
We collect information that you voluntarily provide to us, information collected automatically when you interact with the Site, and information we receive from third parties in limited circumstances.
Information You Provide Directly
- •Contact details such as your name, business email address, phone number, and company name submitted through forms on our Site, by email, or during consultations.
- •Business information you share to help us understand your audit scope, compliance objectives, systems, vendors, and personnel.
- •Evidence, documents, and communications you share with us during an engagement, which may include technical and operational information about your environment and, in limited cases, personal information about your personnel.
- •Payment and billing information such as your company name, billing contact, address, and invoice references. We do not store full payment card numbers; card processing is handled by third-party payment processors.
- •Any other information you choose to provide, including feedback, survey responses, or inquiries about our services.
Information Collected Automatically
- •Device and usage data such as IP address, browser type, operating system, referring URLs, pages viewed, and timestamps.
- •Cookies and similar technologies used to operate the Site, remember your preferences, and understand how visitors engage with our content. See the Cookies and Tracking Technologies section below for details.
Information From Third Parties
- •Referral information from trusted partners, including auditor marketplaces, compliance platforms, and referral sources who introduce prospective clients to us.
- •Publicly available information from professional networks, company websites, or regulatory filings that we use to assess fit for potential engagements.
How We Use Your Information
- •To respond to inquiries, scope potential engagements, and provide quotes.
- •To deliver our professional services, including SOC examinations, ISO assessments, gap analyses, and related consulting.
- •To communicate with you about your engagement, including status updates, evidence requests, and deliverables.
- •To issue invoices, process payments, and maintain financial records.
- •To send administrative messages, service updates, and, where permitted, information about new services, events, or resources that may be of interest to you.
- •To operate, maintain, secure, and improve the Site.
- •To comply with legal, regulatory, and professional obligations, including AICPA, state board of accountancy, and applicable tax and records retention requirements.
- •To establish, exercise, or defend legal claims, and to protect the rights, property, and safety of Vigil Assurance, our clients, and others.
How We Share Your Information
We do not sell or rent your personal information. We share information only as described below:
- •Service providers and subprocessors who support our business, such as cloud hosting providers, secure file sharing platforms, billing and payment processors, email providers, and professional advisors. These parties are bound by contractual obligations to protect your information and use it only for the purposes we authorize.
- •Referral partners and channel partners, but only to the extent necessary to administer a referral or joint engagement and only with information you have agreed may be shared.
- •Regulators, peer reviewers, courts, or other authorities when required by law, subpoena, or professional standards, including AICPA peer review obligations.
- •Successors in interest in connection with a merger, acquisition, reorganization, or sale of all or part of our business, subject to confidentiality protections.
- •With your consent, or at your direction, for any other purpose disclosed at the time of collection.
Your Rights and Choices
You have choices regarding your information. Depending on your location, you may have the right to:
- •Request access to the personal information we hold about you.
- •Request correction of information that is inaccurate or incomplete.
- •Request deletion of your information, subject to legal and professional retention obligations.
- •Opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us directly.
- •Object to or request restriction of certain processing activities.
- •Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the details in the Contact Us section below. We will respond within the timeframe required by applicable law. We may need to verify your identity before acting on your request.
Data Security
We maintain administrative, technical, and physical safeguards designed to protect your information against unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption of sensitive data in transit and at rest, access controls based on role and need to know, multi-factor authentication for systems storing client data, secure file sharing platforms for evidence exchange, logging and monitoring, vendor due diligence, and regular review of our security practices.
No method of transmission over the internet or method of electronic storage is perfectly secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any credentials you use to access our platforms and for promptly notifying us of any suspected unauthorized use.
Data Retention
We retain personal and client information for as long as necessary to fulfill the purposes described in this Policy, to deliver our services, and to meet our legal, regulatory, and professional retention obligations. Audit workpapers and engagement records are retained in accordance with AICPA professional standards and applicable state board of accountancy requirements. When information is no longer required, we securely delete or anonymize it.
Cookies and Tracking Technologies
Our Site uses cookies and similar technologies to operate effectively, remember your preferences, and analyze traffic. Cookies are small text files stored on your device. We use the following categories:
- •Strictly necessary cookies that enable core functionality of the Site.
- •Performance and analytics cookies that help us understand how visitors use the Site so we can improve it.
- •Functional cookies that remember your choices and preferences.
- •Advertising cookies, where applicable, that may be used to understand your interests and present relevant content on other sites. The techniques used do not collect personally identifying information such as your name, email address, mailing address, or phone number.
You can control cookies through your browser settings and, where applicable, through the cookie banner presented on our Site. You can also opt out of advertising cookies by emailing us at contact@vigilassurance.com. Please note that disabling certain cookies may affect how the Site functions.
Third Party Links
Our Site may contain links to third-party websites, tools, or resources that are not operated by Vigil Assurance. We are not responsible for the content, privacy practices, or security of those third parties. We encourage you to review the privacy policies of any third-party site before providing any information.
Children's Privacy
Our Site and services are directed to businesses and their representatives. We do not knowingly collect personal information from children under the age of 16. If you believe that a child has provided us with personal information, please contact us and we will take steps to delete it.
International Users
Vigil Assurance operates in the United States. If you access the Site or engage our services from outside the United States, you understand that your information may be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your jurisdiction. Where required by law, we implement appropriate safeguards for such transfers.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this Policy and, where appropriate, provide additional notice (such as by posting a notice on the Site or sending an email). Your continued use of the Site or our services after the effective date of the revised Policy constitutes your acceptance of the changes.
Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our privacy practices, please contact us at:
Vigil Assurance
Email: contact@vigilassurance.com