Opens in a new tab
Pricing
PEXLENS

Privacy Policy

Clara Systems Inc., doing business as PexLens ("PexLens," "we," "us," or "our") provides the PexLens software supply-chain security platform, including our website, products, agents, browser and developer extensions, APIs, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information and how individuals may exercise applicable privacy rights.
Effective Date: September 17, 2026
Provided by Clara Systems Inc., doing business as PexLens

On This Page

PexLens is a brand and doing-business-as name of Clara Systems Inc., a United States company. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

By using the Services, you acknowledge the practices described in this Privacy Policy.

1 Scope and Our Role

This Policy applies to personal information processed through our website, the PexLens platform (including PexLens Sentinel and PexLens Proxy), account administration, sales, support, and marketing interactions. It does not apply to third-party websites or services that we do not control.

When PexLens processes Customer Data on behalf of a business customer under that customer’s instructions, PexLens generally acts as a service provider or processor and the customer generally acts as the business or controller. Requests concerning information controlled by a customer should be directed to that customer. PexLens acts as a business or controller for information it determines how and why to process, such as website visitor, account, billing, and direct business-contact information.

PexLens Sentinel scans devices to identify installed software packages and dependencies using package manifests and related technical signals; it is not designed to collect the broader contents of customer projects. PexLens Proxy evaluates package-installation requests against PexLens risk intelligence before allowing or blocking them. When component information is linked to a person, account, or device, we treat it as personal information.

2 Personal Information We Collect

Category 

Examples 

Source 

Identifiers and account information 

Name, work email, username, company, job title, account identifier, and password stored in protected hashed form 

You or your organization 

Internet and network activity 

IP address, browser, operating system, pages viewed, referring URL, approximate location derived from IP, and access logs 

Automatically from devices and browsers 

Cookies and similar technologies 

Session identifiers, preferences, and analytics identifiers 

Automatically through our website 

Device and agent information 

Machine name, operating system, organization, agent version, scan metadata, and unique device identifier 

PexLens Sentinel and customer configuration 

Package and dependency information 

Package names, versions, dependency relationships, manifest information, installation requests, risk levels, vulnerabilities, findings, and policy decisions 

Use of PexLens Sentinel, Proxy, extensions, APIs, and integrations 

Commercial and billing information 

Subscription, order, billing name, business address, transaction status, and limited payment-related information 

You, your organization, and payment processors 

Professional and correspondence information 

Job title, employer, support tickets, emails, contact forms, demo requests, and feedback 

You and your organization 

Inferences and security intelligence 

Risk classifications, reputation signals, anomalous behavior indicators, and policy recommendations derived from technical data 

Generated by the Services 

The Services are not designed to collect sensitive personal information such as health information, government identifiers, precise geolocation, financial-account credentials, or biometric information. Please do not submit such information through support requests or free-text fields.

3 How We Use Personal Information

  • Provide, operate, authenticate, secure, support, and maintain the Services, including package evaluation, scanning, risk analysis, scoring, and policy enforcement.
  • Create and administer accounts, subscriptions, orders, billing, and customer relationships.
  • Respond to support requests, inquiries, security reports, and correspondence.
  • Send administrative messages, security alerts, product notices, and service updates.
  • Monitor, troubleshoot, analyze, and improve performance, reliability, security, and usability.
  • Detect, investigate, prevent, and respond to fraud, abuse, malicious activity, vulnerabilities, and security incidents.
  • Develop aggregated or de-identified threat intelligence and improve our detection capabilities, subject to contractual restrictions applicable to Customer Data.
  • Comply with law, legal process, and contractual obligations and protect rights, safety, and property.
  • Send marketing communications where permitted by law; recipients may opt out at any time.

4 How We Disclose Personal Information

We may disclose personal information as described below. We do not sell personal information or share it for cross-context behavioral advertising.

Recipient 

Purpose 

Service providers and processors 

Cloud hosting, security, analytics, email delivery, customer support, payment processing, and other services performed under contractual restrictions 

Your organization and authorized users 

Administer enterprise accounts, devices, policies, findings, investigations, and support 

Professional advisors 

Legal, accounting, audit, insurance, compliance, and risk-management services 

Business transaction participants 

Evaluate or complete a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards 

Government authorities and other parties 

Comply with applicable law or legal process; protect rights, property, safety, and service integrity; prevent fraud or security threats 

At your direction 

Complete an integration or disclosure that you or your organization requests or authorizes 

5 Cookies and Online Tracking

We use essential cookies for website and account functionality, functional cookies to remember settings, and analytics technologies to understand website use. You can manage non-essential technologies through our cookie preference tool, where available, and browser controls. Disabling certain technologies may affect functionality.

Because we do not sell personal information or share it for cross-context behavioral advertising, we do not currently offer a sale/share opt-out. Where legally required, we recognize applicable opt-out preference signals, such as Global Privacy Control, for the browser or device that sends the signal. We do not currently respond to other Do Not Track signals because no generally accepted standard applies to them.

6 Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit where appropriate, logging, and security review. No transmission or storage system can be guaranteed completely secure. Customers remain responsible for configuring the Services appropriately, protecting credentials, and maintaining complementary security controls.

7 Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and audit records, meeting legal and accounting obligations, resolving disputes, and enforcing agreements. Retention varies based on the nature and sensitivity of the information, operational needs, contractual commitments, and legal requirements.

When a customer terminates its PexLens license or subscription, we delete or anonymize Customer Data within 30 days unless an Order Form or data processing agreement provides otherwise or retention is reasonably necessary for legal compliance, security, dispute resolution, backup cycles, or enforcement. Backup copies may remain for a limited period until overwritten through ordinary backup processes.

8 Children

The Services are intended for business use and are not directed to children under 13 or to individuals under 18 for their personal use. We do not knowingly collect personal information from children. If you believe a child provided personal information to us, contact us so we can investigate and take appropriate action.

9 United States Privacy Rights

Depending on your state of residence and whether the applicable law covers PexLens and the relevant processing, you may have rights to request access to personal information, obtain a portable copy, correct inaccuracies, delete information, opt out of certain targeted advertising, sale, or profiling, and appeal a denied request. California residents may also request information about categories of personal information collected, sources, purposes, and categories of recipients, and have the right not to receive discriminatory treatment for exercising applicable rights.

PexLens has not sold personal information or shared personal information for cross-context behavioral advertising during the preceding 12 months. We do not use or disclose sensitive personal information for purposes that trigger a right to limit under California law. We do not offer financial incentives in exchange for personal information.

To submit a request, email [email protected] or [email protected] with the subject line “Privacy Request.” We will verify requests using information reasonably necessary to confirm identity and authority. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity verification. If we deny a request and applicable law provides an appeal right, reply to our decision with the subject line “Privacy Appeal.” You may also contact your state attorney general or privacy regulator.

10 International Users and Transfers

PexLens is based in the United States. Personal information may be transferred to and processed in the United States and other countries where we or our service providers operate, which may have different privacy laws. Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we use recognized safeguards such as applicable Standard Contractual Clauses and supplementary measures.

11 Additional Rights Outside the United States

Where the GDPR, UK GDPR, or similar law applies, our legal bases may include performance of a contract, legitimate interests in operating and securing the Services, consent, and compliance with legal obligations. Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, or withdrawal of consent; object to certain processing; and complain to a supervisory authority.

12 Third Party Services

The Services may integrate with package registries, developer tools, cloud platforms, and other third-party services. Their privacy practices are governed by their own policies. PexLens is not responsible for third-party services that it does not control.

13 Changes to This Policy

We may update this Policy to reflect changes in our Services, practices, or legal obligations. We will post the updated version and revise the Effective Date. When required, we will provide additional notice through the Services, by email, or by another appropriate method.

14 Contact Us

Clara Systems Inc., doing business as PexLens
1879 Lundy Ave., Suite 228, San Jose, CA 95131, United States
Email: [email protected]