PRIVACY POLICY
Vegvisir Systems Limited — vegvisir.ie
Version 1.5 — 25 September 2026
1. Who we are
Vegvisir Systems Limited ("Vegvisir", "we", "us"), registered in Ireland, company no. 739905, registered office 23 Newtown Manor, Castletroy, Limerick, V94 6N70, Ireland. We make Traffic Dictator, a Segment Routing traffic-engineering controller. For anything in this policy — including to exercise any of the rights in Section 5 — contact us at info@vegvisir.ie or at that address.
We are not required to appoint a Data Protection Officer and have not appointed one. Data protection questions go to info@vegvisir.ie and are handled by the company directly.
We are the controller of the personal data described in Section 2, with one exception: where support materials (such as diagnostic files, logs, configurations or packet captures) are sent to us as part of a support request, we act as processor for any personal data they contain, on behalf of the customer that sends them — usually your organisation — which remains the controller (see Technical support in Section 2, and Schedule 1 to our End User Licence Agreement or the data-processing terms of a signed agreement). The personal data we process, and why, are described in Section 2; for the most part, it is business contact details.
2. What we collect, why, and on what legal basis
General enquiries. If you email us (info@, sales@, support@ or any other vegvisir.ie address) or use a contact form, we process your name, email address, company and the content of your message — to respond. Legal basis: our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). Retention: see Section 4 — correspondence is kept while the relationship is live and for so long as we may need it to defend a legal claim.
Reports of misuse. If you report a suspected misuse of intellectual property under Section 7 of our Website Terms of Use, we process your name, contact details and the content of your report in order to consider it. We may share your report, including your name and contact details, with the person whose use of the material is concerned, with our professional advisers and, where required by law, with competent authorities. Legal basis: our legitimate interest (Art. 6(1)(f)) in dealing with reports and in protecting our own and others' rights. Retention: as for general enquiries (Section 4).
Marketing preferences. We do not currently send marketing communications. If you ask us not to send you any, we keep your email address and the date of your request so that we can respect it. Legal basis: our legitimate interest (Art. 6(1)(f)) in respecting your request and complying with the rules on commercial communications. Retention: see Section 4.
Sales and quotes. If you ask about buying a licence, we process the same details to prepare quotes and follow up. Legal basis: steps prior to entering a contract at your request (Art. 6(1)(b)) where you are the prospective counterparty; otherwise our legitimate interest (Art. 6(1)(f)) in responding to a business enquiry made on your employer's behalf. Same retention as general enquiries.
Licence administration. When your company purchases a licence, we process the business contact details of the people handling the order (name, role, business email, business phone) so that we can issue quotes, invoices and licence keys, provide support, and send renewal reminders. Legal basis: our legitimate interests (Art. 6(1)(f)) in administering our contract with your company, getting paid, and keeping licensing records — weighed against your interests as an individual — and, for the accounting records we must keep, legal obligation (Art. 6(1)(c)). The data is limited to business contact details and is used for the relationship between our two companies and for the other purposes described in this policy; we do not use it for unrelated purposes. If you no longer want to be your organisation's contact with us, ask your organisation to nominate someone else, or write to us (see Section 5). We will then update our records, but invoices and other accounting records that name you must be kept for the period set out in Section 4.
Technical support. Support requests may include support materials — diagnostic files, logs, configurations, topology snapshots or packet captures — from your network. These can contain IP addresses and other personal data. For personal data contained in support materials, we act on the instructions of the customer that sends them — usually your organisation — solely to diagnose and resolve the issue.
Where your organisation licenses the Software under our End User Licence Agreement, the data-processing terms in Schedule 1 to that Agreement apply to that data. This includes evaluation and research use: downloading, installing or using the Software is acceptance of the EULA. Where your organisation has a signed data-processing agreement with us covering the same processing, that agreement applies instead of Schedule 1. If support materials reach us in any other circumstances, we handle them in the way Schedule 1 describes.
We delete support materials within 6 months after your organisation's paid subscription ends or, if it has none, within 12 months after we close its most recent support request, or sooner if your organisation asks — and if it would rather have them returned than deleted, we will return them and delete our copies. Schedule 1 sets out your organisation's rights here. We remain controller of the ticket itself (your contact details and our correspondence), except that email messages that carry support materials are deleted together with them — legal basis: our legitimate interest (Art. 6(1)(f)) in responding to support requests and evidencing the support we provide. A complete diagnostic bundle cannot really be pseudonymised, and sending one is often the fastest route to a fix — so we do not ask you to strip it. Where you can reasonably reduce or redact what you send without making the problem harder to diagnose, please do. Please do not send us passwords, keys, tokens or community strings: we do not need them, and if you do send them, treat them as disclosed and rotate them.
Where we get your details from someone else. Sometimes we receive business contact details from your employer rather than from you — for example, when your company names you as the billing, technical or licensing contact on an order, or when your details appear on a purchase order or in correspondence. In that case we process your name, job role, business email address and business phone number, obtained from your employer or from the document your employer sent us, for the purposes and on the legal bases described above. We also screen customer contact names and counterparties against publicly available sanctions lists before entering into an order or issuing a licence key; the source of that data is those published lists. Everything in Sections 3, 4 and 5 applies to this data in the same way. If we hold your details and you have not heard from us directly, this paragraph is our notice to you under Article 14 GDPR; write to info@vegvisir.ie if you want to know more.
The Software does not send us anything, and we see your network data only if you send it to us. As of the date of this policy and all currently released versions, Traffic Dictator transmits no telemetry, no usage data and no automatic update checks to Vegvisir; licence keys activate and are validated entirely locally, with no connection to Vegvisir's servers. The Software runs on your systems and under your control. It handles network configuration and topology data — which may include IP addresses and other identifiers — but it does so entirely within your infrastructure. Vegvisir has no access to it, is neither controller nor processor of it, and sees it only if you choose to send it to us with a support request. Downloads and updates are actions you initiate from our website or from Docker Hub (pulls from Docker Hub are subject to Docker's own privacy terms, not ours). If any future version changes this, we will update this policy before that version is released.
Research and teaching licences. If you apply for a research or teaching licence key, we process the name and contact details of the person applying and of the responsible individual, the institution (where there is one), and the description of the research or teaching purpose, so that we can decide on the application, issue and administer the key, and keep a record of the keys we have issued. Legal basis: our legitimate interest (Art. 6(1)(f)) in deciding who receives research and teaching keys and keeping a record of them; where you apply as an individual on your own behalf, steps prior to entering a contract at your request (Art. 6(1)(b)). We keep the application and the record of the key for the term of the key and for 6 years afterwards.
Security vulnerability reports. If you report a security issue to us, we process your name, contact details and the content of your report so that we can investigate, fix the issue and get back to you, and so that we can credit you if you want that. We may share the technical content of your report with the maintainers of any affected component and with competent authorities, and publish it in a security advisory once a fix or mitigation is available; we name you in an advisory only if you agree, and share your name or contact details with them only where that is needed for the purpose or required by law. Legal basis: our legitimate interest (Art. 6(1)(f)) in the security of our products and in maintaining a working channel with security researchers.
Regulatory reporting. Under Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847), which applies from 11 September 2026, we are required to report actively exploited vulnerabilities and severe incidents to the Irish CSIRT and ENISA. Those reports are about the software, not about people, and we include personal data in them only where the reporting requirements call for it. Where they do, our legal basis is legal obligation (Art. 6(1)(c)).
Sanctions screening. Before we enter into an order or issue a licence key, we check the names of customer contacts and counterparties, and the countries they are in, against publicly available sanctions lists and against the countries we do not supply. We record the check — who and what was checked, against which lists, when, the result and our decision. Legal basis: legal obligation (Art. 6(1)(c)) for checks required by EU sanctions law, which prohibits making our products available to listed persons or to entities they own or control; our legitimate interest (Art. 6(1)(f)) for checks against other lists and against the countries we do not supply as our own commercial decision. We keep the record with the customer record (Section 4).
Website. Our hosting provider keeps standard access logs (IP address, requested page, timestamp and browser user agent) for security and troubleshooting, for the period stated in Section 4. Legal basis: our legitimate interest (Art. 6(1)(f)) in running a secure website.
Analytics. With your consent, we use Google Analytics 4 to understand how the site is used. Analytics cookies are set only if you accept them in the cookie banner; you can withdraw consent at any time using the cookie settings control. Data is transferred to Google LLC in the United States. Google LLC is certified under the EU–US Data Privacy Framework, and the transfer relies on the European Commission's adequacy decision for that framework (Commission Implementing Decision (EU) 2023/1795). The framework has been challenged in the EU courts; the General Court dismissed that challenge on 3 September 2025 (Latombe v Commission, T-553/23), and further challenges remain possible. If the adequacy decision is annulled, suspended or withdrawn, we will move to Standard Contractual Clauses or stop using Google Analytics, and we will update this policy. Legal basis: consent (Art. 6(1)(a) GDPR).
Legal claims and compliance. We may also use any of the personal data described above where necessary to establish, exercise or defend legal claims, to comply with legal obligations or requests from competent authorities, or in connection with a sale or reorganisation of our business. Legal basis: our legitimate interest (Art. 6(1)(f)) or, where the law requires the processing, legal obligation (Art. 6(1)(c)).
3. Who we share data with
We use a small number of service providers to run our business:
What they do | Where they process | Transfer safeguard |
|---|---|---|
Business email and document storage, including support correspondence, any files you send us, and our invoicing records | United States | EU–US Data Privacy Framework |
Website hosting, content delivery, contact-form submissions and server logs | Ireland for server-side processing. Pages are delivered through the provider's global network, so your request may be handled outside the EEA | EU–US Data Privacy Framework; Standard Contractual Clauses |
Google Analytics 4 — Google LLC (only if you accept analytics cookies) | United States | EU–US Data Privacy Framework |
We also operate our own servers in Ireland. Those are our own systems and are not operated by a service provider.
This table describes our providers as at the version date of this policy. They process personal data on our instructions — as our processors or, for support materials, as our sub-processors. We have switched off the Google Analytics settings that would let Google use analytics data for its own purposes, so that Google processes this data as our processor.
For support materials, Schedule 1 to our End User Licence Agreement (or the data-processing terms of a signed agreement) sets out how customers can obtain a current list naming each sub-processor and how we notify changes. We may also share personal data to the extent needed with our professional advisers (for example, our accountant sees invoice contact details); with courts, competent authorities and others involved in legal proceedings or regulatory matters; with the other recipients described in Section 2 (such as the person concerned by a misuse report, or the maintainers of a component affected by a reported vulnerability); and — if our business is ever sold or reorganised — with the parties to that transaction under confidentiality. We do not sell personal data, and we do not share it with anyone else except where the law requires.
Where a provider processes personal data outside the EEA, we rely on the safeguard stated in the table above — an adequacy decision or the European Commission's Standard Contractual Clauses. You can ask us at info@vegvisir.ie for a copy of the relevant clauses or details of the safeguard used.
4. Retention — summary
Data | Kept for |
|---|---|
Enquiries (including misuse reports), sales contacts and customer correspondence | Kept while the relationship is live and for so long as we may need it to establish, exercise or defend a legal claim — up to 6 years after the last transaction or the last contact, matching the limitation period for contract claims (Statute of Limitations 1957, s. 11). We review correspondence periodically and delete what we no longer need; we do not delete it automatically on a fixed schedule. Email messages that carry support materials are an exception: they are deleted together with those materials, as set out below. |
Marketing opt-out requests | For as long as we need them to respect your request |
Contract and invoicing records | For the duration of the contract, and 6 years from the end of the financial year in which the contract ended or the transaction was completed (Companies Act 2014, s. 285; Taxes Consolidation Act 1997, s. 886). |
Sanctions screening records | With the related contract records, as above; where no contract follows, 6 years from the check. |
Support materials (diagnostic files, logs, configurations and similar) | Deleted from all our systems, including any email messages to which they are attached, within 6 months after the organisation's paid subscription ends or, if it has none, within 12 months after its most recent support request is closed — sooner if your organisation asks, or returned to it instead if it prefers. |
Server access logs | 30 days |
Analytics (Google Analytics 4) | Event and user data: the retention period configured in our Google Analytics property, currently 14 months from collection. Cookie lifetimes are in the cookie table, Section 6. |
Security reports | Your name and contact details: for the life of the related issue, plus 24 months. The technical content of a report may be kept for longer as part of our product security records. |
Regulatory notifications under the Cyber Resilience Act (only where they contain personal data) | 10 years |
Research and teaching licence applications and key records | Term of the key, plus 6 years. Applications that are not granted: as for general enquiries. |
In every case except support materials, we may keep personal data for longer where it is needed for a legal claim that is live or reasonably anticipated — until the claim is resolved and for 6 years afterwards (Statute of Limitations 1957, s. 11) — or where the law requires it. Support materials are kept longer only where the law requires it.
5. Your rights
Subject to the conditions and exceptions set out in data protection law, you have the right to access your personal data and receive a copy of it, to have it corrected or deleted, and to restrict our processing. Where we process your data by automated means on the basis of your consent, or of a contract with you or steps towards one, you can ask us to give it to you in a portable, machine-readable format. Where processing is based on consent, you can withdraw that consent at any time; this does not affect the lawfulness of processing before you withdraw it.
Wherever Section 2 names our legitimate interests as the legal basis, you have the right to object at any time on grounds relating to your particular situation. Email info@vegvisir.ie. We will stop unless we can show compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims. For direct marketing, we always stop, no reasons needed. Analytics runs on your consent (see Section 6) — withdraw it via the cookie settings control rather than objecting. You can ask us for more information about how we weighed our legitimate interests against your rights.
Support materials. For personal data in support materials, we act as processor for the customer that sent them (Section 1). If you ask us to exercise a right in respect of that data, we will pass your request to that customer where we can identify it; the customer is responsible for responding, and we will assist it as required.
We do not make automated decisions with legal or similarly significant effects about you.
Giving us personal data is not a statutory requirement. It is, however, necessary for entering into and administering a licence: if a customer's contact details are not provided, we cannot issue quotes, invoices or licence keys, provide support, or complete the sanctions checks we carry out before entering into an order.
To exercise any right, write to info@vegvisir.ie. We may ask for information to confirm your identity before we act on a request. Where we cannot identify you from the data we hold — for example, in server logs or analytics data — we may be unable to act on a request unless you give us additional information that allows us to identify you. You can also complain to the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.
6. Cookies
Placing a cookie or similar technology on your device, or reading information already stored there, requires your consent under Regulation 5(3) of the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. 336/2011) — the Irish ePrivacy rules — unless it is strictly necessary to provide the service you asked for (Regulation 5(5)). Separately, where the information a cookie generates is personal data, we also need a legal basis under the GDPR; for analytics that basis is your consent (Art. 6(1)(a)).
The only cookie we set without asking is the one that remembers your cookie choice. It is strictly necessary under Regulation 5(5): without it we would have to ask you on every page. Everything else is set only if you accept it.
Cookie | Set by | First/third party | Purpose | Duration |
|---|---|---|---|---|
Our cookie-consent cookie | vegvisir.ie | First party | Remembers your cookie choice, so that we do not have to ask you on every page. Strictly necessary under Reg. 5(5) of S.I. 336/2011. | 6 months |
_ga | Google Analytics | First party (set on vegvisir.ie by Google Analytics; data is sent to Google) | Distinguishes visitors | Up to 2 years (browsers may set a shorter limit) |
_ga_<container-id> | Google Analytics | First party (set on vegvisir.ie by Google Analytics; data is sent to Google) | Persists session state | Up to 2 years (browsers may set a shorter limit) |
This table lists the cookies and similar technologies this site uses as at the version date of this policy. The two Google Analytics cookies are set only if you accept analytics in the banner, and the Google Analytics script does not load until you do. We do not use advertising, social-media or cross-site tracking cookies.
Google sets the names and lifetimes of the Google Analytics cookies and may change them; the table reflects Google's documentation as at the version date of this policy.
Your choice. When you first visit, a banner lets you accept or decline analytics cookies — declining is exactly as easy as accepting, with no pre-ticked boxes. You can change your choice at any time using the cookie settings control on the site. If you withdraw consent, Google Analytics stops loading; you can also delete cookies already set by clearing cookies in your browser. We will ask you to confirm your choice again at least every 6 months, in line with Irish Data Protection Commission guidance. No analytics cookie is placed on your device before you accept.
7. Changes
We may update this policy from time to time. The current version and its date are published at https://vegvisir.ie/privacy. Previous versions are available on request from info@vegvisir.ie. Where the law requires us to tell you about a change directly — for example, before we use personal data for a new purpose — we will do so. Changes to the sub-processors that handle support materials are notified as set out in Schedule 1 to our End User Licence Agreement or the data-processing terms of a signed agreement.
