Legal

Policies and terms

How we handle personal data, the conditions under which the platform is contracted, and what the website stores in your browser.

Last updated: 2026年8月25日

Privacy Policy

What data Vigilioo processes, for what purpose, and what rights you have over it.

1. Who we are

Vigilioo is a unified endpoint management (UEM) platform built and operated by COIN NODES LTDA, registered under Brazilian tax ID (CNPJ) 49.670.293/0001-03, headquartered at Avenida Eng. Luiz Carlos Berrini, 1748, Sao Paulo/SP, Brazil.

This Privacy Policy applies to vigilioo.com, to the web platform and to the agent installed on monitored devices. It explains which personal data is processed, why, who it is shared with, and how to exercise your rights.

By contracting the platform or browsing the website, you confirm that you have read and understood this document, which complements the Terms of Use.

2. Key concepts

To make this Policy easier to read, the terms below carry the meaning given to them by the Brazilian General Data Protection Law (LGPD, Law 13.709/2018):

  • Personal data: any information relating to an identified or identifiable natural person.
  • Data subject: the natural person the personal data refers to.
  • Processing: any operation performed on personal data — collection, use, access, storage, transmission, deletion and so on.
  • Controller: the party that decides on the processing — what is collected, for what purpose, and for how long.
  • Processor: the party that processes personal data on behalf of the controller, following its instructions.
  • Customer: the legal entity that subscribes to Vigilioo and administers the monitored devices.
  • Data protection officer (DPO): the person designated to receive communications from data subjects and from the supervisory authority.
  • Cookies: small files a website stores in your browser to remember information between visits.

3. Who is controller and who is processor

This is the most important distinction in this document, because Vigilioo holds two different roles depending on which data is being discussed.

DataControllerVigilioo's role
Account, billing, support and browsing on vigilioo.comVigilioo (Coin Nodes)Controller — decides purposes and means
Data collected on monitored devices by the agentThe customer companyProcessor — acts on the customer's instructions

For monitoring, it is the customer who defines which devices are monitored, which policies apply, and how long records remain available. Vigilioo provides the tool and processes that data exclusively to deliver the contracted service.

The customer's responsibility

It is up to the customer to inform monitored people in advance, to establish the legal basis for the processing, and to ensure that use of the platform complies with applicable labour and data protection law. Vigilioo does not monitor anyone on its own initiative and does not decide what is collected on the customer's behalf.

If you are a monitored person and wish to exercise rights over that data, the request must first be addressed to the company that administers the device. If we receive such a request directly, we forward it to the customer and support them in responding, as required by article 39 of the LGPD.

4. What data is processed

The data varies according to your relationship with Vigilioo.

Website visitors: pages visited, referral source, preferred language, IP address, cookie identifiers, and whatever you submit through the contact form (name, email, phone, tax ID and message).

Platform administrators and users: name, work email, phone, job title, access credentials, authentication logs and records of actions performed in the console, plus the data required to bill the subscription.

Monitored devices, according to the configuration defined by the customer:

  • Device inventory: machine name, operating system, agent version, network and hardware identifiers.
  • Application and web page usage, with start and end times.
  • Screen captures at configurable intervals or in real time.
  • Key and disk mapping, where the contracted plan includes the feature and the customer enables it.
  • Active and idle time, for productivity reports.
  • Policy events: device, USB and Bluetooth blocks, and denied access attempts.
  • AI-generated analysis of the records above, on plans where the feature is available.

Vigilioo does not deliberately collect sensitive data and does not ask customers to provide any. Because screen captures record whatever is visible at that moment, the customer must configure the scope of monitoring so as to reduce the capture of content unrelated to professional activity.

6. When data is shared

Vigilioo does not sell personal data and does not share it for third-party advertising. Sharing happens only in the situations below:

  • With the customer, the natural recipient of monitoring data from its own devices.
  • With suppliers that support the operation — hosting, transactional email, payment processing and observability — always limited to what is necessary and contractually bound to protect the data.
  • With public authorities, where required by law, court order or regulation.
  • In a corporate reorganisation, maintaining the conditions of this Policy.

7. International transfers

Part of the infrastructure and some suppliers are located outside Brazil. In those cases, transfers take place with the safeguards required by chapter V of the LGPD — specific contractual clauses or countries offering an adequate level of protection.

8. How data is protected

  • Traffic encrypted in transit and data encrypted at rest.
  • Role-based access control, least privilege, and multi-factor authentication in the console.
  • Audit logging of administrative actions performed on the platform.
  • Logical segregation of each customer's data.
  • Code review, vulnerability analysis and dependency management throughout development.
  • Incident response plan, with notification to the customer and, where applicable, to the supervisory authority and data subjects.

No measure removes risk entirely. If we identify a security incident posing relevant risk to data subjects, we will notify those affected within the deadlines and in the manner set out in the legislation.

9. How long data is kept

  • Monitoring data: for the period configured by the customer. Once the contract ends, data remains available for export for 30 days and is then deleted.
  • Account and billing data: for the term of the contract and, after termination, for the statutory tax and limitation periods.
  • Contact form messages: up to 24 months after the last contact.
  • Website access logs: 6 months, as required by the Brazilian Internet Civil Framework.

10. Data subject rights

Article 18 of the LGPD gives you the right to:

  • Confirm whether we process your data and access it.
  • Correct incomplete, inaccurate or outdated data.
  • Request anonymisation, blocking or deletion of unnecessary data or data processed unlawfully.
  • Request portability of the data to another provider.
  • Be informed about who we share your data with.
  • Withdraw consent, where that is the applicable legal basis.
  • Object to processing based on legitimate interest.

Requests are handled free of charge. We may ask for additional information to confirm your identity before responding — that is a protection measure, not a barrier.

For monitoring data, address your request to the company that administers the device: it is the controller and the party that can decide on deletion, correction or access.

11. Changes to this Policy

This Policy may be revised to reflect changes to the platform, to the law or to our processes. The date of the last update is shown at the top of the page, and material changes are communicated to customers through the contact channels on file.

12. Contact and data protection officer

To exercise rights, clarify doubts or report an incident, write to contato@coinnodes.tech with the subject Privacy. The data protection officer responds through that same channel.

You may also file a complaint with the Brazilian National Data Protection Authority (ANPD).

Questions about these documents?

If something here is unclear, or if you want to exercise a right over your data, get in touch.

Talk to the team