Privacy Policy
Effective June 15, 2025 · Last updated June 15, 2026
Status Notice
AegisID is currently in active development. Certain features and data processing activities described in this Privacy Policy reflect planned production functionality and may change prior to general availability. Where applicable, this policy describes intended production behaviour.
1. Introduction
This Privacy Policy explains how Vanguard Cloud Services (“Vanguard”, “we”, “our”, or “us”) collects, uses, stores, protects, and discloses personal information when you use the AegisID wallet application and related services (collectively, the “Service”).
Vanguard Cloud Services is the organization responsible for determining how personal information is collected and processed through the AegisID Service.
By installing or using AegisID and accepting the applicable Terms of Service, you acknowledge the practices described in this Privacy Policy.
2. Definitions
- AegisID means the decentralized identity platform and wallet application operated by Vanguard Cloud Services.
- Credential means a cryptographically signed decentralized digital credential issued through the Service.
- Wallet means the secure software application that stores your credentials on your device.
- Verifier means an organization or service requesting proof of information contained within your credential.
- Issuer means Vanguard Cloud Services or another authorized organization that issues credentials.
- Personal Information means information that identifies or can reasonably identify an individual, as defined by applicable privacy legislation.
- Public Ledger means the Hyperledger Indy distributed ledger used to publish public credential schemas, credential definitions, decentralized identifiers (DIDs), and revocation registries.
3. What AegisID Is
AegisID issues decentralized digital credentials using the Hyperledger Indy / AnonCreds framework. Unless explicitly stated otherwise, your credentials are stored locally within your wallet on your device and remain under your control. You decide when, where, and with whom to share your credential. AegisID is designed to minimize the collection and disclosure of personal information and does not passively monitor or track how you use your credential outside AegisID-operated services.
4. Information We Collect
We collect only the information reasonably necessary to issue, maintain, verify, and secure your credential.
- Identity attributes required to issue your credential, including your full name, date of birth, place of birth, and a unique AegisID identifier.
- Contact information, including your email address where provided, for account administration, identity verification, and service communications.
- Credential metadata, including registration dates and technical identifiers required to establish secure credential exchanges and maintain credential lifecycle operations.
- Organizational access associations where AegisID is used to grant access to an organization’s systems or services.
We do not collect advertising identifiers, location history, or behavioural tracking information through the AegisID wallet.
5. Information Stored on the Public Ledger
The Hyperledger Indy public ledger stores only public cryptographic artifacts required for decentralized identity operations, including credential schemas, credential definitions, revocation registries, and public DIDs. Personal information is never written to the public ledger. Because the public ledger is distributed and intentionally immutable, information published to the ledger generally cannot be modified or deleted.
6. How We Use Your Information
We collect and use personal information only as necessary to provide, secure, and maintain the Service, including credential issuance, verification, organizational access management, security, auditing, fraud prevention, and legal compliance. We do not sell personal information, do not use it for advertising, and disclose it only as described in this policy, with your authorization, or as required by law.
7. Service Providers
We may use carefully selected third-party providers for hosting, cloud services, email delivery, monitoring, logging, security operations, and technical support. They process personal information only on our behalf under contractual safeguards.
8. Verification and Your Control
Credential presentation is initiated and controlled by you. Verification outside AegisID-operated services generally occurs directly between your wallet and the verifier.
9. How Your Information Is Protected
We use encryption in transit and at rest, role-based access controls, authentication requirements, audit logging, security monitoring, and periodic reviews. No system can guarantee absolute security.
10. Data Retention
We retain personal information only as long as necessary to provide the Service, maintain credentials, support audits, resolve disputes, and comply with legal obligations.
11. International Data Processing
Personal information may be processed or stored outside your jurisdiction. Where this occurs, appropriate contractual and security safeguards are applied.
12. Security Incident Notification
Where required by law, affected individuals and regulators will be notified of qualifying security incidents involving personal information.
13. Your Privacy Rights
You may request access, correction, credential revocation, or deletion of personal information where permitted by law.
14. Children’s Privacy
The Service is not directed to individuals under 18 years of age, and we do not knowingly collect personal information from children under 18.
15. Website Information
Our websites may collect standard technical information and use cookies or similar technologies for functionality, security, analytics, and user preferences.
16. Changes to This Privacy Policy
We may update this policy periodically. Material changes will be communicated through the Service, our website, or other reasonable means.
17. Contact Us
Vanguard Cloud Services
[Mailing Address]
Email: info@vanguardcs.ca
Website: https://vanguardcs.ca