vigilis
Product
Bandwidth on Demand (Vigilis Flux)
Scale circuits to demand, stop paying for idle bandwidth
Expense Management (TEM)
AI audits every invoice and catches overcharges
Contract Management
Track every contract, kill silent auto-renewals
MACD / MACE Management
Moves, adds, changes, disconnects, handled in the portals
RFP Management
Structure requirements, responses, pricing, and scoring
Integrations
Your carriers, Slack, Teams, and more
See the full platform →
Solutions
Outsourced TEM
Full telecom expense management as a managed service
Telecom Inventory Management
One source of truth for every line, circuit, and asset
Network as a Service
Compare provider, managed, and hybrid operating models
Wireless Expense Management
Mobile carrier invoices, line ownership, plans, and allocations
Healthcare
TEM built around clinical uptime
Manufacturing
Multi-site telecom control with production context
Financial Services
Traceable charges, allocations, approvals, and outcomes
For CIOs
Cost control and visibility for technology leaders
Pricing Calculator Resources
About
Why Vigilis exists
Partners
Embed the Vigilis bandwidth calculator
Customers
Who trusts Vigilis with their spend
Case Studies
Real outcomes in real numbers
Contact
Talk to the team
Help Center
Product documentation and support
App Login Book a demo Start free trial
Product Solutions Pricing Calculator Resources Partners Company App Login Book a demo
← Legal Center

Data Processing Addendum

Version 1.0 · Effective July 10, 2026

This Data Processing Addendum (“DPA”) is entered into by and between Socium IT LLC DBA Vigilis, a Georgia limited liability company (“Vigilis”), and the customer identified in the applicable Agreement (“Customer”), and is incorporated into and forms part of the agreement between Vigilis and Customer for Vigilis’s services (the “Agreement”). This DPA is effective as of the effective date of the Agreement or, if executed separately, the date of last signature below (the “Effective Date”).

It is Exhibit C to the Vigilis Services Agreement and is incorporated by reference at Section 9.4 of that Agreement.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1.1 “Applicable Data Protection Laws” means all United States federal and state laws and regulations applicable to the Processing of Personal Data under the Agreement, including, to the extent applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations (“CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, and other U.S. state comprehensive privacy laws in effect during the term of the Agreement, in each case as amended, superseded, or replaced from time to time. Applicable Data Protection Laws expressly exclude the EU General Data Protection Regulation (EU) 2016/679, the UK GDPR, and any other non-U.S. data protection law, which are outside the scope of this DPA as described in Section 12.

1.2 “Personal Data” means any information that identifies, relates to, describes, or is reasonably capable of being associated with an identified or identifiable natural person, in each case that Vigilis Processes on behalf of Customer in connection with the Services. Personal Data includes “personal information” as defined under the CCPA and equivalent terms under other Applicable Data Protection Laws.

1.3 “Processing” (and “Process”) means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, use, retrieval, disclosure, deletion, or destruction.

1.4 “Services” means the services provided by Vigilis to Customer under the Agreement, as further described in Annex 1.

1.5 “Subprocessor” means any third party engaged by Vigilis to Process Personal Data on Vigilis’s behalf in connection with the Services.

1.6 “Consumer Request” means a verified request by a natural person (or their authorized agent) to exercise rights granted under Applicable Data Protection Laws, including rights of access, deletion, correction, portability, or to opt out of sale, sharing, or targeted advertising.

1.7 “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data Processed by Vigilis. Security Incident does not include unsuccessful attempts or activities that do not compromise Personal Data, such as unsuccessful login attempts, pings, port scans, or denial-of-service attacks.

1.8 The terms “Business,” “Service Provider,” “Sell,” “Share,” “Controller,” “Processor,” and “Third Party” have the meanings given under Applicable Data Protection Laws. For purposes of this DPA, Customer is the Business/Controller and Vigilis is the Service Provider/Processor with respect to Personal Data.

2. Scope and Roles

2.1 Roles. Customer, as Business/Controller, determines the purposes and means of Processing. Vigilis, as Service Provider/Processor, Processes Personal Data solely on behalf of and at the direction of Customer.

2.2 Scope of Processing. Vigilis will Process Personal Data only: (a) to provide the Services described in the Agreement and Annex 1; (b) in accordance with Customer’s documented instructions, which include the Agreement, this DPA, and Customer’s configuration of and use of the Services; and (c) as otherwise required by applicable law, in which case Vigilis will inform Customer of that legal requirement before Processing unless the law prohibits such notice.

2.3 Details of Processing. The subject matter, nature and purpose, duration, categories of Personal Data, and categories of data subjects are set out in Annex 1.

3. Service Provider Obligations and Restrictions

Vigilis certifies that it understands and will comply with the following restrictions, and that it will notify Customer if it determines it can no longer meet its obligations under Applicable Data Protection Laws. Vigilis will not:

(a) Sell or Share Personal Data;

(b) retain, use, or disclose Personal Data for any purpose other than the specific business purpose of providing the Services, including any commercial purpose other than providing the Services, except as permitted by Applicable Data Protection Laws;

(c) retain, use, or disclose Personal Data outside the direct business relationship between Vigilis and Customer, except as permitted by Applicable Data Protection Laws; or

(d) combine Personal Data received from Customer with personal information received from another source or collected from Vigilis’s own interactions with the individual, except as permitted by Applicable Data Protection Laws for a Service Provider.

Customer may take reasonable and appropriate steps to verify that Vigilis Processes Personal Data consistently with Customer’s obligations under Applicable Data Protection Laws, and may, upon reasonable notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data.

4. Confidentiality

4.1 Vigilis will restrict access to Personal Data to personnel and Subprocessors who need access to perform the Services.

4.2 Vigilis will require that all personnel authorized to Process Personal Data are bound by written or statutory obligations of confidentiality with respect to that Personal Data, and that such obligations survive termination of their engagement.

5. Security

5.1 Vigilis will implement and maintain reasonable administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Personal Data, appropriate to the nature of the Personal Data Processed. Vigilis’s current security measures are described in Annex 2.

5.2 Vigilis may update its security measures from time to time, provided the updates do not materially reduce the overall protection of Personal Data.

6. Subprocessors

6.1 Authorization. Customer provides general authorization for Vigilis to engage Subprocessors to Process Personal Data in connection with the Services. Vigilis maintains its current Subprocessor list at vigilis.io/legal/subprocessors (the “Subprocessor Page”), incorporated into this DPA by reference as Annex 3.

6.2 Flow-Down. Vigilis will enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA, to the extent applicable to the services the Subprocessor provides.

6.3 Changes. Vigilis will update the Subprocessor Page and notify Customer in writing (email sufficient) at least fifteen (15) days before adding or replacing a Subprocessor. Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith within thirty (30) days, Customer may terminate the affected portion of the Services upon written notice, as its sole remedy.

6.4 Liability. Vigilis remains responsible for its Subprocessors’ performance of obligations under this DPA to the same extent Vigilis would be liable if performing the Services directly.

7. Assistance with Consumer Requests

7.1 Forwarding. If Vigilis receives a Consumer Request directly relating to Personal Data it Processes on Customer’s behalf, Vigilis will not respond substantively (except to direct the individual to Customer) and will forward the request to Customer within five (5) business days.

7.2 Assistance. Taking into account the nature of the Processing, Vigilis will provide reasonable assistance to Customer in fulfilling Customer’s obligation to respond to Consumer Requests, including by deleting, correcting, or providing a copy of the relevant Personal Data within the timeframe Customer reasonably requires to meet its statutory deadlines. Customer is responsible for verifying the identity of requesters and determining the validity of Consumer Requests.

7.3 Other Assistance. Vigilis will provide reasonable assistance to Customer, at Customer’s expense where the assistance is material, with data protection assessments and regulatory inquiries relating to Vigilis’s Processing under this DPA.

8. Security Incident Notification

8.1 Vigilis will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident.

8.2 The notification will, to the extent then known, describe: (a) the nature of the Security Incident; (b) the categories and approximate number of individuals and records affected; (c) the measures taken or planned to address and mitigate the incident; and (d) a contact point for further information. Vigilis may provide information in phases as it becomes available.

8.3 Vigilis’s notification of or response to a Security Incident is not an acknowledgment of fault or liability. Customer is solely responsible for any legally required notifications to individuals or regulators, unless the parties agree otherwise in writing.

9. Deletion and Return of Personal Data

9.1 During the Term. Upon Customer’s written request, Vigilis will delete specified Personal Data within forty-five (45) days of the request, except where retention is required by applicable law or the data resides in routine backups, in which case Vigilis will isolate and protect the Personal Data from further Processing and delete it in the ordinary course of backup rotation.

9.2 At Termination. Upon termination or expiration of the Agreement, at Customer’s election, Vigilis will return Personal Data to Customer in a commonly used, machine-readable format and/or delete Personal Data, in each case within forty-five (45) days of the effective date of termination, subject to the same backup and legal-retention exceptions in Section 9.1. If Customer makes no election within thirty (30) days after termination, Vigilis may delete the Personal Data.

9.3 Certification. Upon Customer’s written request, Vigilis will certify in writing that it has completed deletion under this Section 9.

10. Audits

10.1 Upon Customer’s reasonable written request, no more than once per twelve (12) month period (except following a Security Incident or where required by a regulator), Vigilis will make available information reasonably necessary to demonstrate compliance with this DPA, which may include completed security questionnaires, summaries of third-party assessments, or relevant policies.

10.2 If the information provided under Section 10.1 is not reasonably sufficient, Customer may conduct (directly or through a mutually agreed independent third party bound by confidentiality) an audit of Vigilis’s Processing of Personal Data, during normal business hours, upon at least thirty (30) days’ written notice, at Customer’s expense, and in a manner that does not unreasonably disrupt Vigilis’s operations or compromise the security or confidentiality of other customers’ data.

11. Customer Obligations

11.1 Customer will comply with its own obligations under Applicable Data Protection Laws, including providing all required notices to and obtaining any required consents from individuals whose Personal Data is Processed under the Agreement.

11.2 Customer warrants that its instructions to Vigilis, and its provision of Personal Data to Vigilis, comply with Applicable Data Protection Laws. Customer is solely responsible for the accuracy, quality, and lawful collection of Personal Data provided to Vigilis.

12. Territorial Scope; Excluded Data

12.1 U.S.-Only Service. The Services are offered for use with Personal Data of individuals located in the United States. Vigilis does not intend to, and does not agree to, Process Personal Data subject to the GDPR, UK GDPR, or other non-U.S. data protection laws (“Excluded Data”).

12.2 Customer Warranty. Customer warrants that it will not submit, and will not permit its users to submit, Excluded Data to the Services, including personal data of individuals located in the European Economic Area, the United Kingdom, or Switzerland.

12.3 Remediation. If either party becomes aware that Excluded Data has been submitted to the Services, Customer will promptly instruct Vigilis to delete it, and Vigilis will delete it in accordance with Section 9.1. Vigilis has no obligations under this DPA or the Agreement with respect to Excluded Data other than deletion under this Section.

12.4 Future Expansion. If the parties later agree that the Services will Process personal data subject to the GDPR or UK GDPR, they will execute a supplementary annex to this DPA incorporating the required processor terms and appropriate cross-border transfer mechanisms (for example, Standard Contractual Clauses). Annex 4 is reserved for that purpose and is intentionally not in effect as of the Effective Date.

13. Term, Precedence, and General

13.1 Term. This DPA is effective as of the Effective Date and continues until Vigilis ceases to Process Personal Data under the Agreement.

13.2 Order of Precedence. If this DPA conflicts with the Agreement with respect to the Processing of Personal Data, this DPA controls. If a provision of this DPA conflicts with a mandatory requirement of Applicable Data Protection Laws, the statutory requirement controls to the extent of the conflict.

13.3 Assignment. Vigilis may assign this DPA and the Agreement, in whole, without Customer’s consent: (a) to any affiliate; or (b) in connection with a merger, reorganization, spin-off, or sale of all or substantially all of the assets or business to which this DPA relates, provided the assignee assumes Vigilis’s obligations under this DPA. Any other assignment requires the other party’s prior written consent, not to be unreasonably withheld. This DPA binds and benefits the parties and their permitted successors and assigns.

13.4 Liability. Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement, and this DPA does not enlarge either party’s aggregate liability beyond what the Agreement provides.

13.5 Changes in Law. If a change in Applicable Data Protection Laws requires modification of this DPA, the parties will negotiate in good faith to amend it as reasonably necessary.

13.6 Governing Law. This DPA is governed by the law governing the Agreement. If this DPA is executed as a standalone document or the Agreement does not specify governing law, this DPA is governed by the laws of the State of Georgia, without regard to conflict-of-laws principles.

13.7 Notices. Notices to Vigilis under this DPA, including Subprocessor objections under Section 6.3, deletion requests under Section 9, and Security Incident communications under Section 8, must be sent to comms@vigilis.io. Notices to Customer will be sent to the email address associated with Customer’s account or as designated in the Agreement. Notices are deemed given one (1) business day after email transmission without a delivery failure.

Signature Block

(Required only if executed separately from the Agreement.)

VigilisCustomer
Legal entitySocium IT LLC DBA Vigilis
Signature
Name
Title
Date

Annex 1 · Details of Processing

A. Subject Matter and Duration. Processing of Personal Data as necessary to provide the Services under the Agreement, for the duration of the Agreement plus the wind-down period in Section 9.

B. Nature and Purpose of Processing. Vigilis Processes Personal Data to:

  1. Maintain contact records in Vigilis’s service-delivery systems (CRM), including association of contacts with accounts, projects, and account-management activities, for the purpose of delivering and supporting the Services;
  2. Maintain a service inventory of business mobile devices and lines, including the business cell phone numbers assigned to Customer’s users, for the purpose of inventory tracking and expense management;
  3. Provide related support, reporting, and administration of the Services.

C. Categories of Data Subjects.

  1. Customer’s employees, contractors, and other authorized users of the Services;
  2. Customer’s business contacts associated with accounts or projects managed through the Services.

D. Categories of Personal Data.

  1. Business contact information: name, business email address, business phone number (including business cell phone number), job title, employer/account affiliation;
  2. Service and inventory data associated with an identifiable user: assigned device and line identifiers, carrier/plan information, and expense data attributable to a user’s line.

E. Sensitive Data. None. The Services are not designed to Process, and Customer agrees not to submit, sensitive personal information (for example, government identifiers, precise geolocation, health or biometric data, financial account credentials) or personal data of minors.

F. Location of Processing. United States.

Annex 2 · Security Measures

Vigilis maintains the following measures, at a minimum:

  1. Access control. Role-based access to systems containing Personal Data; access limited to personnel with a business need; unique credentials per user, except designated shared role mailboxes (for example, support, invoicing, PMO) whose access is limited to authorized personnel; multi-factor authentication enforced on all systems containing Personal Data; access revoked promptly upon role change or offboarding.
  2. Encryption. Encryption of Personal Data in transit (TLS 1.2 or higher). Encryption at rest for systems under Vigilis’s control and, for hosted third-party systems (for example, CRM), reliance on the provider’s documented at-rest encryption.
  3. Vendor management. Use of reputable hosted service providers with published security programs; Subprocessor agreements per Section 6.
  4. Personnel. Confidentiality obligations for all personnel with access to Personal Data.
  5. Data minimization and retention. Collection limited to the data categories in Annex 1; deletion practices per Section 9.
  6. Incident response. Documented process for identifying, escalating, and remediating Security Incidents, supporting the notification commitments in Section 8.
  7. Backups and recovery. Routine backups of production data; backup media protected with access controls consistent with production systems.

Annex 3 · Subprocessors

Vigilis’s current Subprocessor list, including each Subprocessor’s function and processing location, is maintained at vigilis.io/legal/subprocessors (the “Subprocessor Page”) and is incorporated into this DPA by reference. The Subprocessor Page is updated in accordance with Section 6.3, which also sets out Customer’s notice and objection rights. Upon Customer’s written request, Vigilis will provide a written copy of the Subprocessor list as in effect on the Effective Date or the date of the request.

Services that Customer connects to the platform under Customer’s own credentials or authority (for example, Customer’s carrier accounts under a Letter of Agency, Customer’s CRM, or Customer’s identity provider) act at Customer’s direction and are not Subprocessors.

Annex 4 · GDPR and International Transfer Terms

[RESERVED. Not in effect.] This Annex will be completed and executed by the parties only if the Services are expanded to Process personal data subject to the GDPR, UK GDPR, or other non-U.S. data protection laws, per Section 12.4.

Prior versions are archived and linked from each page.

vigilis

Telecom cost control across every line, contract, and circuit, run by real people inside your carrier portals.

Product
Bandwidth on Demand (Vigilis Flux) Expense Management (TEM) Contract Management MACD / MACE Management RFP Management Integrations Pricing Savings calculator
Solutions
Outsourced TEM Telecom Inventory Management Network as a Service Wireless Expense Management Healthcare Manufacturing Financial Services For CIOs
Resources
Resource Center Lumen Internet On-Demand Telecom RFP template Platform comparisons Savings calculator Case studies
Company
About Partners Customers Case studies Newsroom Contact Help Center
Legal
Legal Center Terms Privacy Cookies Do Not Sell or Share My Personal Information
© 2026 Socium IT LLC d/b/a Vigilis. Privacy Terms
All systems operational

We use Google Analytics, Microsoft Clarity and LinkedIn to understand how this site is used. Nothing loads until you accept. See our Cookie Policy.