Vicarium

Privacy statement

Last changed on 25 September 2026

Vicarium holds the information someone else needs to take over your business if you no longer can. That is exactly the kind of information you should be able to read up on. This statement is therefore as concrete as we could make it.

1. Who we are

Woon IoT BV, trading under the statutory name Viertron Install B.V., Achterzeedijk 57-40, 2992 SB Barendrecht, the Netherlands. Chamber of Commerce 76066843, VAT NL860495577B01. Reach us at info@vicarium.eu. We are the controller for the data described here.

The Vicarium brand and the intellectual property of the platform are held by LofStaet Groep B.V. (Chamber of Commerce 97333352, Dorpsstraat 205, 2995 XG Heerjansdam, the Netherlands). Your agreement and the processing of your data run through Woon IoT BV; LofStaet has no access to your vault.

2. The main point first: what we cannot read

Everything you put in your vault - passwords, recovery codes, notes on a system - is encrypted on your own device before it is sent to us, with a passphrase only you know. We do not store that passphrase and cannot restore it. What sits on our servers is unreadable to us.

Which also means: lose both your passphrase and your recovery code and the contents are gone for good, for us as well. That is not a shortcoming, it is the design.

3. What we do process

WhatWhyBasis
Your name and email address, and which provider you sign in with (Google or Microsoft) To recognise you at sign-in and to be able to reach you Performance of the contract
The names of the systems in your inventory, where they run, who can reach them today and what the successor must do This is the signpost your successor has to be able to read; it is stored readable Performance of the contract
The secrets attached to those systems Stored encrypted; unreadable to us Performance of the contract
The name of an emergency key holder, its serial number, and every time that key was offered, with date, time and IP address So we can warn you and you can refuse, and so it can be shown afterwards what happened. This log is a core part of the service Performance of the contract and legitimate interest (security)
Company name, amounts and the state of your payment Invoicing and bookkeepingLegal obligation

4. How long we keep it

5. Who we share with

We sell nothing and share only with parties needed to deliver the service.

PartyCountryPurpose
Hetzner Online GmbHGermany The servers the service runs on. Your data sits there on an encrypted disk.
MigaduSwitzerland Sending email, including the warning when someone offers your emergency key.
RevolutLithuania (EU)Handling payments.
Google or MicrosoftUnited States Only if you sign in with them. We then receive your name and email address; your password never reaches us.

6. Transfers outside the EU

Servers and storage are inside the EU. Switzerland holds an adequacy decision from the European Commission. Only if you choose to sign in with Google or Microsoft do your name and email address go to a US party, under the EU-US Data Privacy Framework and the standard contractual clauses. If you would rather not, simply do not use those providers.

7. Security

8. Your rights

You have the right of access, rectification, erasure, restriction, objection and portability. For the contents of your vault you can exercise most of these yourself: you see everything, you change everything, you delete everything. For anything else a message to info@vicarium.eu suffices; we respond within 30 days. If you disagree with how we handle your data you may complain to the Dutch Data Protection Authority.

9. Cookies

This website uses no tracking and no analytics cookies. During sign-in we set one technically necessary cookie that lives ten minutes and serves only to verify that the sign-in started with you and not with someone else.

10. Changes

If we change this statement we update the date at the top. If the change is material you will hear about it by email.