Vigía ES

Privacy policy

What data Vigía sees, what it stores, for how long, and who answers for it.

The essentials in four sentences. Vigía only reads: it cannot change any setting in your Google Workspace because it does not request any write permission. It never asks for access to the content of Gmail, of Drive or of any file. The e-mail addresses of the people in your organisation that appear in a report are deleted automatically after 24 hours. When you disconnect, everything is deleted and access is revoked at Google.

Who the data controller is

The data controller is Diego Fariña, in a personal capacity, as the developer and operator of Vigía. Contact for any question about data or to exercise your rights: diego@diegofarina.com.

Vigía does not belong to any company and does not act on behalf of any organisation other than yours.

Vigía's two roles

The distinction matters because it determines who decides about each piece of data:

Legal basis

ProcessingBasis (GDPR)
Reading your Workspace configuration in order to generate the report Your explicit consent, given on Google's screen (art. 6(1)(a)). It can be withdrawn at any time, and withdrawing it stops the processing.
Storing the score and the state of each control to show you how they change over time Performance of the service you requested (art. 6(1)(b)).
Minimal technical logs so the service works and is secure Legitimate interest (art. 6(1)(f)), limited to what is indispensable.

The permissions requested, and what each one is for

All of them are read-only and none belongs to Google's 'restricted' category, which is precisely the one that would give access to the content of messages and files. This is the complete list, the same one you will see on the consent screen:

PermissionWhat for
openid The identifier of the Google session that authorises the connection.
email Which administrator address connected, so it can be shown in the interface and the authorisation tied to your organisation.
admin.directory.user.readonly List the accounts and their security metadata: 2-Step Verification enrolment, administrator role, last sign-in, suspension state, creation date, recovery details and organizational unit.
admin.directory.domain.readonly List your verified domains, so SPF, DKIM, DMARC and MTA-STS can be checked for each one through public DNS.
admin.reports.audit.readonly Read the audit log: which third-party applications have been authorised, recent administrative changes, and sign-in events.
cloud-identity.policies.readonly Read the settings configured in your Admin console (Drive sharing, Gmail forwarding, password policy, session length, Marketplace and Groups) so they are checked automatically instead of by hand.

profile is not requested: Vigía does not read your name or your photo.

What is stored, and for how long

DataWhat forHow long
A vigia_theme cookie holding the value light or dark, and nothing else Remembering whether you chose the light or the dark theme, so these pages do not change the background on you when you leave the dashboard. It contains no identifier, it cannot be used to recognise you, and it only exists if you press the toggle: by default your operating system's preference is respected and nothing is stored One year, or until you set it back to your system's theme
Your primary domain and your verified domains Identifying your organisation and knowing what to check Until you disconnect
The address of the administrator who connects Showing you which authorisation is active and sending you the alerts Until you disconnect
An OAuth refresh token, encrypted at rest (Fernet, AES-128 in CBC mode with HMAC) Repeating the scheduled scan without asking you for consent again Until you disconnect
The score, the counts and the result of each control (identifier and state) Showing you the progress, the improvements and the regressions Until you disconnect
E-mail addresses of the people in your organisation who appear as affected by a finding So that you can tell who to act on 24 hours, and then they are deleted automatically
The IP addresses your super administrators have signed in from, read from the login audit log, and the country they correspond to Showing you where the accounts that control the whole tenant are normally signed in from, and warning you if a country appears in which no previous sign-in was on record 24 hours, and then they are deleted automatically

After those 24 hours the report still says how many accounts were affected by each finding, but no longer who. To see it again you only have to run a new scan.

About the people in your organisation

It is worth saying plainly: a report names employees of yours who have never used Vigía and have never consented to anything. That is why their information is the only kind with a short, automatic deletion deadline, and why it is the least possible: the e-mail address, the finding that affects them and —only in the case of super administrators— the IP address they signed in from, because without it there is no way to tell you that one of those accounts has started being used from somewhere else. Nothing more. It never includes the content of their messages, their files or the rest of their activity.

Those IP addresses never leave this server. The country is worked out here, with a local file: no geolocation service is queried, because doing so would mean sending your organisation's administrators' addresses to one more company.

What is never done

Limited use of Google data

Vigía's use of information received through the Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: the data is used only to provide and improve the user-facing functionality of the product, it is not transferred to third parties except as strictly necessary to provide the service or where the law requires it, it is not used for advertising purposes, and no person reads it, except with your explicit permission, for security reasons, to comply with the law, or when it is aggregated and anonymised.

The third parties involved

Vigía does not sell or pass on data, but providing the service involves these providers. All of them are listed, including those that only see technical metadata:

ProviderWhat it seesWhy
Google (Admin SDK and Cloud Identity) The read requests made to it It is the source of the data being analysed
Cloudflare The IP address and connection metadata of whoever visits the site; it terminates the TLS encryption It publishes the site and protects it
Zoho (e-mail) Your alert address and the subject and body of the message, which includes your domain name and the titles of your findings Delivering the e-mail alerts you have switched on
Public DNS resolvers (Cloudflare 1.1.1.1, Google 8.8.8.8) The domain names being queried Checking SPF, DKIM, DMARC and the rest of the public records

The list above is the four providers involved. The database that turns an IP address into a country is not one of them: it is a downloaded file, queried on this server, not a service, so it receives nothing. It uses DB-IP IP-to-Country Lite, published under CC BY 4.0, whose licence requires this attribution.

Vigía loads nothing from third parties in the browser: the fonts are served from this same domain and there are no scripts, analytics, telemetry or external images on any page. You can check this in your browser's network tab.

Your rights

You can exercise your rights of access, rectification, erasure, restriction, objection and portability at any time by writing to diego@diegofarina.com. The answer arrives within a maximum of one month.

Two of them, moreover, you can exercise yourself, immediately and without asking anybody's permission: erasure by pressing 'Disconnect', and objection by removing access from your own Google account. How to do it is in Your data.

If you consider that the processing is not right, you can complain to the data protection authority that applies to you: in Spain the Agencia Española de Protección de Datos (AEPD), in the United Kingdom the Information Commissioner's Office (ICO).

Security

Changes to this policy

If anything substantial changes —what data is processed, how long it is kept or which third parties are involved— the date in the footer will be updated and, if the change affects you, notice will be sent by e-mail to the connected administrator address.