Legal

Privacy & Cookie Policy

Last updated: 7 August 2026

This policy explains how we handle personal data collected through the vigiastack.com website (the "Site") — for example when you browse pages, book a walkthrough, or contact us. We take privacy seriously: it is the standard we build our product to, so we hold our own website to it too.

Scope — please read. This policy covers the vigiastack.com marketing website only. The Vigia monitoring service (the application used by observation missions) processes data under separate, mission-specific terms — each deployment carries its own documented purpose, lawful basis, retention period and data-processing agreement. Nothing here governs that product. If you are a client with a question about mission data, contact us and we will point you to the applicable processing terms.

1. Who we are

The data controller for the Site is the operator trading under the registered Spanish trademark OnAir Tools (brand: Vigia) ("we", "us"):

Because we are established in Spain, the lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), and the EU General Data Protection Regulation (GDPR) applies.

2. What we collect and why

We keep website data collection to a minimum. We do not sell personal data, we do not run advertising trackers, and we do not build advertising profiles.

WhatWhyPersonal data?
Aggregate website analytics (Cloudflare Web Analytics) To understand page views, popular pages, referring sources and visitor country — so we can improve the Site. No cookies and no cross-site tracking. Cloudflare processes technical signals to produce anonymised, aggregate statistics. We do not receive data that identifies you individually.
Security & delivery logs (Cloudflare CDN/WAF) To serve the Site quickly and protect it from attacks and abuse. Your IP address and request metadata are processed transiently for security and network delivery.
Product-experience analytics / heatmaps (Microsoft Clarity) — only if you consent Aggregate heatmaps and session insights to see how the Site is used and where it can be clearer. Uses cookies and records usage interactions. Loaded only after you accept analytics cookies (see §4). Disabled by default.
Booking a walkthrough (Microsoft Bookings) To schedule and hold the 20-minute demo you request. Yes — the name and email you enter, and your answers to the booking questions (which election/mission, your role/organisation, mandate). Used only to arrange and follow up on the meeting.
Direct contact (email) To answer you. Yes — your email address and whatever you choose to include in your message.

3. Legal bases (GDPR Art. 6)

4. Cookies and similar technologies

The Site is deliberately light on cookies.

Until the analytics-cookie banner is live on the Site, Microsoft Clarity is not enabled and no analytics cookies are set beyond Cloudflare's cookieless measurement.

5. Service providers (processors)

We use a small set of established providers to run the Site. They act on our instructions under data-processing terms:

We do not share your personal data with third parties for their own marketing.

6. International transfers

Some providers above (Cloudflare, Microsoft) are US-headquartered and may process data outside the European Economic Area. Where that happens, transfers are protected by appropriate safeguards — such as the EU Standard Contractual Clauses and/or the provider's certification under the EU–US Data Privacy Framework. You can ask us for details of the safeguards that apply.

7. How long we keep data

8. Your rights

Under the GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent at any time (without affecting processing already carried out). To exercise any of these, email customercare@vigiastack.com and we will respond within one month.

If you believe we have not handled your data properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or your local EU supervisory authority. We would appreciate the chance to address your concern first.

9. Security

We use reputable providers and reasonable technical and organisational measures to protect data handled through the Site. No method of transmission or storage is completely secure, but we work to protect your information and to review our practices.

10. Children

The Site and the Vigia service are intended for professional and organisational use. They are not directed at children, and we do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top shows the current version. Material changes will be reflected here before they take effect.

12. Contact

Questions, requests, or to exercise your rights: customercare@vigiastack.com.