Privacy Policy
Welcome to Vijilan!
Vijilan is owned and operated by Vijilan Security, LLC.
Vijilan values your privacy and the protection of your personal data. This privacy policy describes what information we collect from you, how we collect it and how we use it. It also explains how we obtain your consent, how long we keep it in our databases and, if necessary, with whom we share it.
By using the website and cybersecurity monitoring services, you are accepting the practices described in this privacy policy. Use of the website and services is also subject to our terms and conditions. In this privacy policy, the words “website” refers to the Vijilan website, “we”, “us”, “our” and “Vijilan” refers to Vijilan and “you” “client” and “user” refers to you, the Vijilan user.
This privacy policy may change from time to time. Your continued use of the website and services after we make changes is deemed to be acceptance of those changes, so please check the policy periodically for updates. This Privacy Policy has been prepared and is maintained in accordance with all applicable national and international laws and regulations and specifically with the California Consumer Privacy Act (CCPA), the Florida Information Protection Act of 2014 (FIPA), The Personal Information Protection and Electronic Documents Act (PIPEDA), the Data Protection Act 2018, the Privacy Act 1988 (Privacy Act) and the General Data Protection Regulation (GDPR – European regulations).
- GENERAL INFORMATION
The personal data of the users that are collected and processed through the website:
Will be under responsibility and in charge of:
- Vijilan Security, LLC.
- Phone: +1 (954) 334-9988
- Email: info@vijilan.com
- Address: Aventura Onyx Tower 1010 S Federal Hwy, Suite 1400 Hallandale Beach, FL 33009.
(Hereinafter referred to as Vijilan).
- TYPES OF INFORMATION GATHERED
The information we learn from customers helps personalize and continually improve your experience at Vijilan. Here are the types of information we gather:
Information You Give Us. You provide information when you search, read and view content on our website, contract our services (cybersecurity monitoring services), register and access our portal, provide information through our services and/or communicate with us through our contact information, our chat or our contact forms. As a result of those actions, you might supply us with the following information:
- First and last name
- Organization name
- Username
- Password
- Work Email
- City/State/Country
- Phone number
- Any additional information relating to you that you provide to us directly or indirectly through our website and services.
Vijilan will not collect any personally identifiable information about you, unless you provide it.
Information Collected Automatically: By accessing and using the website you automatically provide us with the following information:
- The device and usage information you use to access the website
- Your IP address
- Browser and device characteristics
- Operating system
- Referring URLs
If you access the website through a mobile phone, we will collect the following information:
- Mobile device ID
- Model and manufacturer
- Operating system
- Version information
- IP address
reCAPTCHA: We use the third-party reCaptcha system to perform security checks on our website. The information provided through the reCAPTCHA system will be processed solely and exclusively to perform security checks on the website. The information will be treated in accordance with our privacy policy and the privacy policy of the reCaptcha system provider.
Payment information: Your payment information will be processed by the payment processors available in Vijilan, which will treat and store your data securely and for the sole purpose of processing the payment of services by the client. Vijilan reserves the right to contract any payment platform available in the market, which will treat your data with the sole purpose of processing the payment of the services by the client.
GOOGLE Analytics. We use Google Analytics provided by Google, Inc., USA (“Google”). These tool and technologies collect and analyze certain types of information, including IP addresses, device and software identifiers, referring and exit URLs, feature use metrics and statistics, usage history, media access control address (MAC Address), mobile unique device identifiers, and other similar information via the use of cookies. The information generated by Google Analytics (including your IP address) may be transmitted to and stored by Google on servers in the United States. We use the GOOGLE Analytics collection of data to enhance the website and improve our service.
Please consult Google’s privacy policy here:
Facebook Pixel: Our website uses the Facebook Pixel. Through the Facebook Pixel we can collect user information for different purposes. We use the Facebook Pixel for the following purposes:
- Collect statistics about our website (for example, the number of users who visited a page).
- Collect information about how you interact with our website (for example, whether you opened or followed links contained in them).
- Personalize online services and marketing communications.
- Tailor advertisements to users and optimize advertising campaigns.
The information collected through the Facebook Pixel will be collected and stored by Facebook and will be treated in accordance with its privacy policy. The information we collect through the Facebook Pixel does not personally identify the user and will never be used for purposes other than those contained in this privacy policy and Facebook’s privacy policy.
Please consult Facebook’s privacy policy here:
Social Media: On our website you will find links and functions linked to different social networks, in which you can share your information. It is advisable to consult the privacy policy and data protection of each social network used on our website.
- Facebook: https://www.facebook.com/privacy/explanation
- Linkedin: https://www.linkedin.com/legal/privacy-policy?
- Twitter: https://twitter.com/privacy
- HOW LONG WE KEEP YOUR DATA
Personal data provided by users through the website and services will be retained for as long as necessary for the provision of cybersecurity monitoring services and providing our partner portal or until the client or our partners decide to close the user account on the partner portal. Vijilan may be allowed to retain personal data for a longer period whenever the user has given consent to such processing, as long as such consent is not withdrawn. Furthermore, Vijilan may be obliged to retain personal data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority. Once the retention period expires, personal data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
- HOW WE USE YOUR INFORMATION.
In general, we use the information we collect primarily to provide, maintain, protect and improve our current website and services. We use personal information collected through our website as described below:
- Identify you as a user in our system.
- Provide the services (cybersecurity monitoring services).
- Provide our demo.
- Provide our subscriptions.
- Provide the partner portal.
- Send invoices for services to clients.
- Improve our services, website, and how we operate our business.
- Understand and enhance your experience using our website and services.
- Respond to your comments or questions through our support team.
- Send you related information, including confirmations, invoices, technical notices, updates, security alerts and support and administrative messages.
- Communicate with you about upcoming events, offers and news about services offered by Vijilan and our selected partners.
- Marketing purposes of Vijilan.
- Link or combine your information with other information we get from third parties to help understand your needs and provide you with better service.
- Protect, investigate and deter against fraudulent, unauthorized or illegal activity.
- HOW DO YOU GET MY CONSENT?
By contracting our services, providing information through our services, requesting a demo, registering in the partner portal, contacting us through our contact forms or our contact information, and providing personal information for us to contact you, you consent to our collection, storage and use of your information on the terms contained in this privacy policy. You may withdraw your consent by sending us your request via the contact information or the contact page.
- HOW WE SHARE YOUR INFORMATION
The personal information of our customers and users is an important and fundamental part of our business. Under no circumstances will we sell or share information with third parties that has not been previously authorized by the user, client or owner of the personal data. We share user and customer information only and exclusively as described below.
Cloud Services: Some of our services are provided through third party cloud services. Data stored and processed through the cloud services will be processed in accordance with our privacy policy, data processing agreement and the information security policies of the third party cloud services.
See the privacy policy of Amazon Web Services, Google Cloud Platform and Google Suite here:
- https://aws.amazon.com/privacy/
- https://cloud.google.com/terms/cloud-privacy-notice
- https://policies.google.com/privacy
Third-Party Service Providers. We use third-party services to perform functions on our website. Examples include: creating and hosting the website, sending emails, analyzing data (Google Analytics), creating ads (Facebook, Google), providing marketing services and providing search results.
These third-party services and tools may have access to personal information needed to perform their functions, but may not use that information for other purposes. Information shared with these third-party services will be treated and stored in accordance with their respective privacy policies and our privacy policy. Please refer to the privacy policy of these third-party services.
Email marketing: We use the information provided by users to conduct marketing campaigns and send relevant information to our users. By providing us with your email address, you authorize us to use your information for email marketing. We will use third party services to conduct email marketing, so we may share certain information with some of these third parties for the sole and exclusive purpose of sending emails through email marketing and in accordance with our privacy policy.
Business Transfers. In the event that Vijilan creates, merges with, or is acquired by another entity or company, your information will likely be transferred. Vijilan will send you an email or post a prominent notice on our platform before your information becomes subject to another privacy policy and the transfer and handling of your private information will comply with all applicable requirements.
Protection of Vijilan and others. We release personal information when we believe release is appropriate to comply with the law, enforce or apply our Terms and conditions and other agreements, or protect the rights, property, or safety of Vijilan, our users or others. This includes exchanging information with other companies and organizations for fraud protection and credit risk reduction.
With Your Consent. Other than as set out above, you will receive notice when personally identifiable information about you might go to third parties, and you will have an opportunity to choose not to share the information.
Anonymous Information. Vijilan uses the anonymous browsing information collected automatically by our servers primarily to help us administer and improve the Website. We may also use aggregated anonymous information to provide information about the Website to potential business partners and other unaffiliated entities. This information is not personally identifiable.
- PROTECTING YOUR INFORMATION
We work to protect the security of your information during transmission by using Secure Sockets Layer (SSL) software, which encrypts information you provide through the website. We restrict authorized access to your personal information to those persons who have a legitimate purpose to know that information and to those persons you have authorized to have access to that information. Vijilan follows generally accepted industry standards to protect the personal information submitted to us, both during transmission and once Vijilan receives it. No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while Vijilan strives to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. We will not sell, distribute, or lease your personal information to third parties unless we have your permission or are required by law to do so.
- RIGHTS
Users who provide information through our website, as data subjects and data owners, have the right to access, rectify, download or delete their information, as well as to restrict and object to certain processing of their information. While some of these rights apply generally, others apply only in certain limited circumstances. We describe these rights below:
- Access and portability: to access and know what information is stored in our servers, you can send us your request through our contact information.
- Rectify, Restrict, Limit, Delete: You can also rectify, restrict, limit or delete much of your information.
- Right to be informed: Users of our website will be informed, upon request, about what data we collect, how it is used, how long it is retained and whether it is shared with third parties.
- Object: When we process your information based on our legitimate interests as explained above, or in the public interest, you may object to this processing in certain circumstances. In such cases, we will stop processing your information unless we have compelling legitimate reasons to continue processing it or where it is necessary for legal reasons.
- Revoke consent: Where you have previously given your consent, such as to allow us to process and store your personal information, you have the right to revoke your consent to the processing and storage of your information at any time. For example, you may withdraw your consent by updating your settings. In certain cases, we may continue to process your information after you have withdrawn your consent if we have a legal basis for doing so or if your withdrawal of consent was limited to certain processing activities.
- Complaint: If you wish to file a complaint about our use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local supervisory authority. Users can exercise all these rights by contacting us through the contact information or the contact page.
- Rights related to automated decision-making, including profiling: website users may request that we provide a copy of the automated processing activities we conduct if they believe that data is being unlawfully processed.
Users may exercise their rights in relation to the personal data they provide to Vijilan, at any time, by sending us their request through our contact information and we will process and respond to their request as soon as possible.
- CHILDREN’S ONLINE PRIVACY PROTECTION
We comply with the requirements of the California Consumer Privacy Act (CCPA), the Florida Information Protection Act of 2014 (FIPA), The Personal Information Protection and Electronic Documents Act (PIPEDA), the Data Protection Act 2018, the Privacy Act 1988 (Privacy Act) and the General Data Protection Regulation (GDPR – European regulations), regarding the protection of the personal data of minors. We do not collect any information from anyone under 18 years of age. Our website and services are all directed to people who are at least 18 years old or older. If you become aware that your child has provided us with personal information, please contact us. If we become aware that a child has provided us with personal information, we will take steps to delete that information, terminate that person’s account, and restrict access to that person.
- THIRD PARTIES
Except as otherwise expressly included in this privacy policy, this document addresses only the use and disclosure of information Vijilan collects from you. If you disclose your information to others, whether other users or suppliers on Vijilan, different rules may apply to their use or disclosure of the information you disclose to them. Vijilan does not control the privacy policies of third parties, and you are subject to the privacy policies of those third parties where applicable. Vijilan is not responsible for the privacy or security practices of other websites on the Internet, even those linked to or from the Vijilan website. Vijilan encourages you to ask questions before you disclose your personal information to others.
- Google Workspace
This Private Policy aims to provide our clients with a comprehensive understanding of our practices in collecting, using, disclosing, and safeguarding their information through Google Workspace log collection integration. As part of our commitment to transparency and data privacy, we adhere to strict policies outlined in our Privacy Policy and Google API Scopes.
The Google Workspace App serves as a powerful tool that enables us to monitor and analyze activities seamlessly across Google Workspace from a single centralized location.
Through our dashboard, we can provide our customers with detailed insights into user, login activities, and administrative action information. Additionally, these dashboards offer full visibility into alerts generated by the Google Workspace Alert Center, empowering them to investigate and correlate alerts effectively and monitor potential threats across Google Workspace.
In the following sections, we will delve into the specifics of how we collect and utilize logs within Google Workspace to ensure the security and integrity of our client’s data while maintaining compliance with privacy regulations.
Important!
Our client’s Google Apps credentials are not retained by Vijilan, and we do not have access to their Google Apps account specifics. Vijilan solely stores OAuth tokens that are generated post-authentication and authorization.
Refer to Google’s Reports API: Prerequisites documentation for further information. Throughout Google’s OAuth consent flow, you will also be prompted to grant Vijilan’s app permission to utilize the Reports API.
Google Workspace Apps Audit Source
Vijilan may need access to some Google Apps to have a source related to the alerts and detections. Those are embedded in the Google Activities list and the ones related to the following apps can be collected:
- Admin: Logs from the Admin Console, providing information on different administrative activities.
- Calendar: Logs from the Google Calendar app, detailing various calendar-related activities.
- Drive: Logs from Google Drive, providing details on various drive-related activities. Available only for Google Workspace Business and Enterprise customers.
- Login: Logs from login activities, providing account-related information.
- Mobile: Logs from mobile device auditing, detailing various device-related activities.
- Rules: Logs related to rule activities.
- Token: Logs from token applications, providing account-related information on token activities.
- Context-Aware Access: Logs related to context-aware access, detailing events of user access denial due to context-based access rules.
- Data studio: Logs from Data Studio, detailing various Data Studio-related activities.
- Keep: Logs from Google Keep, detailing various Keep-related activities. Available only for Google Workspace Business and Enterprise customers.
- Chat: Logs from Google Chat, including various chat-related activities.
- Google+: Logs from Google+, detailing various Google+ related activities.
- Groups: Logs from Google Groups, providing details on group-related activities.
- Meet: Logs from Google Meet, detailing various auditing activities.
- Enterprise Groups: Logs related to enterprise group activities.
Purpose of collecting Google Workspace Logs
At Vijilan, we are committed to ensuring that the logs collected through our services, including our Google Workspace log collection integration, are utilized solely for the purpose of security monitoring and analysis in accordance with our policies and Google API Services User Data Policy.
Our services related to Google Workspace include:
- Logs ingestion
- Alert generation
- Reports generation
Logs Ingestion
This guide details the process of gathering logs from Google Workspace and integrating them into Vijilan’s portal.
Configuration | Requires OAuth flow with redirection and token acquisition. |
Type of Authentication | Authentication is based on user consent and token exchange. |
Main Use | For applications that require user interaction to grant access. |
Access Delegation | Requires a user to explicitly authorize access. |
Use Cases | Suitable for log ingestion in MSP and Enterprise accounts. |
Access Level | The access level is limited to the scope granted by the user. |
The permission process for Google Workspace log collection is done through the Vijilan Portal with the following steps:
- Login to Vijilan portal
- Connectors > Google Workspace
- Run app – Google performs the App authentication and Requests resources
- The user consents to the ingestion of logs using the Consent Page, where is possible to see the logs type (Activity, Event, Parameter) that will ingested
- Request for scopes with credentials
- Returns access token with approved scopes
- Invokes API
Log types
Google Workspace Logs: This is the main entity representing the logs.
Activity: Each log contains multiple activities. Attributes include for example ownerDomain, and applicationName.
Event: Each activity comprises various events. That is the component on the Google Workspace we use to generate alerts in our system.
The Google Workspace apps related to the logs collection on Vijilan are:
- Google Login
- Google Admin
- Google Drive
- Google Token
Google Workspace Login App
The event that comes from this App is used to provide alerts and/or create alerts with the detections related to Login. We collect those logs for:
- Status and activities related to two-factor authentication (2FA). Using status as timestamp, user_email, reason, ip_address.
- Login attempts are related to the number of attempts made by a user.
- Unauthorized users are related to the attempt of unauthorized user to login into an account as the Google documentation related to login_challenges: https://support.google.com/a/answer/6002699?hl=en
Google Workspace Admin App
The event that comes from this App is used to provide alerts and/or create alerts with the detections related to the Admin. We collect those logs for:
- System errors related to the Admin usage
- Account and permission changes
- Policies changes
- New users creation
- Events related to User Settings, Group Settings and Device Settings
Google Workspace Token App
The event that comes from this App is used to provide alerts and/or create alerts with the detections related to the Token. We collect those logs for:
- Token issued, renewed, revoked
- Other token events related
Google Workspace Drive App
The event that comes from this App is used to provide alerts and/or create alerts with the detections related to the Drive. We collect those logs for:
- Large data export
- Files unusual detections (related only to Google’s type of documents such as Documents, Spreadsheet, Books, and Presentations)
Alert generation
We use the data received from the Google Apps permitted by the client to relate the Events above and use the Google Alert Center to create an interaction between all data received. All alerts received have a JSON format and the information related to the Alert and types from Google are listed on the Google Alert Center.
- CONTACT US
If you have questions or concerns about this privacy policy and the handling and security of your data, please contact us through our contact forms, our chat or by using the contact information below:
Vijilan.
Phone: +1 (954) 334-9988
Email: info@vijilan.com
Address: 20803 Biscayne Blvd 302 Aventura, Florida 33180.