Privacy Policy
Provided by Clara Systems Inc., doing business as PexLens
On This Page
PexLens is a brand and doing-business-as name of Clara Systems Inc., a United States company. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
By using the Services, you acknowledge the practices described in this Privacy Policy.
1 Scope and Our Role
This Policy applies to personal information processed through our website, the PexLens platform (including PexLens Sentinel and PexLens Proxy), account administration, sales, support, and marketing interactions. It does not apply to third-party websites or services that we do not control.
When PexLens processes Customer Data on behalf of a business customer under that customer’s instructions, PexLens generally acts as a service provider or processor and the customer generally acts as the business or controller. Requests concerning information controlled by a customer should be directed to that customer. PexLens acts as a business or controller for information it determines how and why to process, such as website visitor, account, billing, and direct business-contact information.
PexLens Sentinel scans devices to identify installed software packages and dependencies using package manifests and related technical signals; it is not designed to collect the broader contents of customer projects. PexLens Proxy evaluates package-installation requests against PexLens risk intelligence before allowing or blocking them. When component information is linked to a person, account, or device, we treat it as personal information.
2 Personal Information We Collect
|
Category |
Examples |
Source |
|
Identifiers and account information |
Name, work email, username, company, job title, account identifier, and password stored in protected hashed form |
You or your organization |
|
Internet and network activity |
IP address, browser, operating system, pages viewed, referring URL, approximate location derived from IP, and access logs |
Automatically from devices and browsers |
|
Cookies and similar technologies |
Session identifiers, preferences, and analytics identifiers |
Automatically through our website |
|
Device and agent information |
Machine name, operating system, organization, agent version, scan metadata, and unique device identifier |
PexLens Sentinel and customer configuration |
|
Package and dependency information |
Package names, versions, dependency relationships, manifest information, installation requests, risk levels, vulnerabilities, findings, and policy decisions |
Use of PexLens Sentinel, Proxy, extensions, APIs, and integrations |
|
Commercial and billing information |
Subscription, order, billing name, business address, transaction status, and limited payment-related information |
You, your organization, and payment processors |
|
Professional and correspondence information |
Job title, employer, support tickets, emails, contact forms, demo requests, and feedback |
You and your organization |
|
Inferences and security intelligence |
Risk classifications, reputation signals, anomalous behavior indicators, and policy recommendations derived from technical data |
Generated by the Services |
The Services are not designed to collect sensitive personal information such as health information, government identifiers, precise geolocation, financial-account credentials, or biometric information. Please do not submit such information through support requests or free-text fields.
3 How We Use Personal Information
- Provide, operate, authenticate, secure, support, and maintain the Services, including package evaluation, scanning, risk analysis, scoring, and policy enforcement.
- Create and administer accounts, subscriptions, orders, billing, and customer relationships.
- Respond to support requests, inquiries, security reports, and correspondence.
- Send administrative messages, security alerts, product notices, and service updates.
- Monitor, troubleshoot, analyze, and improve performance, reliability, security, and usability.
- Detect, investigate, prevent, and respond to fraud, abuse, malicious activity, vulnerabilities, and security incidents.
- Develop aggregated or de-identified threat intelligence and improve our detection capabilities, subject to contractual restrictions applicable to Customer Data.
- Comply with law, legal process, and contractual obligations and protect rights, safety, and property.
- Send marketing communications where permitted by law; recipients may opt out at any time.
4 How We Disclose Personal Information
We may disclose personal information as described below. We do not sell personal information or share it for cross-context behavioral advertising.
|
Recipient |
Purpose |
|
Service providers and processors |
Cloud hosting, security, analytics, email delivery, customer support, payment processing, and other services performed under contractual restrictions |
|
Your organization and authorized users |
Administer enterprise accounts, devices, policies, findings, investigations, and support |
|
Professional advisors |
Legal, accounting, audit, insurance, compliance, and risk-management services |
|
Business transaction participants |
Evaluate or complete a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards |
|
Government authorities and other parties |
Comply with applicable law or legal process; protect rights, property, safety, and service integrity; prevent fraud or security threats |
|
At your direction |
Complete an integration or disclosure that you or your organization requests or authorizes |
5 Cookies and Online Tracking
We use essential cookies for website and account functionality, functional cookies to remember settings, and analytics technologies to understand website use. You can manage non-essential technologies through our cookie preference tool, where available, and browser controls. Disabling certain technologies may affect functionality.
Because we do not sell personal information or share it for cross-context behavioral advertising, we do not currently offer a sale/share opt-out. Where legally required, we recognize applicable opt-out preference signals, such as Global Privacy Control, for the browser or device that sends the signal. We do not currently respond to other Do Not Track signals because no generally accepted standard applies to them.
6 Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit where appropriate, logging, and security review. No transmission or storage system can be guaranteed completely secure. Customers remain responsible for configuring the Services appropriately, protecting credentials, and maintaining complementary security controls.
7 Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and audit records, meeting legal and accounting obligations, resolving disputes, and enforcing agreements. Retention varies based on the nature and sensitivity of the information, operational needs, contractual commitments, and legal requirements.
When a customer terminates its PexLens license or subscription, we delete or anonymize Customer Data within 30 days unless an Order Form or data processing agreement provides otherwise or retention is reasonably necessary for legal compliance, security, dispute resolution, backup cycles, or enforcement. Backup copies may remain for a limited period until overwritten through ordinary backup processes.
8 Children
The Services are intended for business use and are not directed to children under 13 or to individuals under 18 for their personal use. We do not knowingly collect personal information from children. If you believe a child provided personal information to us, contact us so we can investigate and take appropriate action.
9 United States Privacy Rights
Depending on your state of residence and whether the applicable law covers PexLens and the relevant processing, you may have rights to request access to personal information, obtain a portable copy, correct inaccuracies, delete information, opt out of certain targeted advertising, sale, or profiling, and appeal a denied request. California residents may also request information about categories of personal information collected, sources, purposes, and categories of recipients, and have the right not to receive discriminatory treatment for exercising applicable rights.
PexLens has not sold personal information or shared personal information for cross-context behavioral advertising during the preceding 12 months. We do not use or disclose sensitive personal information for purposes that trigger a right to limit under California law. We do not offer financial incentives in exchange for personal information.
To submit a request, email [email protected] or [email protected] with the subject line “Privacy Request.” We will verify requests using information reasonably necessary to confirm identity and authority. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity verification. If we deny a request and applicable law provides an appeal right, reply to our decision with the subject line “Privacy Appeal.” You may also contact your state attorney general or privacy regulator.
10 International Users and Transfers
PexLens is based in the United States. Personal information may be transferred to and processed in the United States and other countries where we or our service providers operate, which may have different privacy laws. Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, we use recognized safeguards such as applicable Standard Contractual Clauses and supplementary measures.
11 Additional Rights Outside the United States
Where the GDPR, UK GDPR, or similar law applies, our legal bases may include performance of a contract, legitimate interests in operating and securing the Services, consent, and compliance with legal obligations. Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, or withdrawal of consent; object to certain processing; and complain to a supervisory authority.
12 Third Party Services
The Services may integrate with package registries, developer tools, cloud platforms, and other third-party services. Their privacy practices are governed by their own policies. PexLens is not responsible for third-party services that it does not control.
13 Changes to This Policy
We may update this Policy to reflect changes in our Services, practices, or legal obligations. We will post the updated version and revise the Effective Date. When required, we will provide additional notice through the Services, by email, or by another appropriate method.
14 Contact Us
Clara Systems Inc., doing business as PexLens
1879 Lundy Ave., Suite 228, San Jose, CA 95131, United States
Email: [email protected]
