PEXLENS

Privacy Policy

PexLens Private Limited (“PexLens,” “we,” “us,” or “our”) provides the PexLens software supply-chain security platform, including our website, product, and related services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our website, create an account, or use the Services, and describes the rights available to you under applicable law, including the California Consumer Privacy Act (CCPA) and other U.S. state privacy laws, the EU/UK General Data Protection Regulation (GDPR), and India’s Digital Personal Data Protection Act, 2023 (DPDP Act). We do not sell personal data, and we do not use it for cross-context behavioral advertising.
Effective Date: September 10th, 2026

On This Page

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Services.

1. Scope of This Policy

This Policy applies to personal data we process through our website the PexLens platform (including PexLens Sentinel and the PexLens Proxy), and our sales, support, and marketing interactions. It does not apply to third-party websites or services we do not control, even if linked from our Services.

PexLens Sentinel scans devices to identify installed software packages and dependencies, using information from package manifest files (such as package.json); it does not collect the broader contents of your projects. The PexLens Proxy evaluates package installation requests (such as npm install) against PexLens’s risk intelligence before allowing them to proceed. This information generally relates to software components rather than individuals, but where it is combined with information that identifies a specific person or device (such as a device owner or organization account), we treat it as personal data under this Policy.

2. Personal Data We Collect

We collect the following categories of personal data: 

Category 

Examples 

Source 

Account & Contact Data 

Name, work email, username, company, job title, password (stored as a salted hash) 

Provided directly by you 

Website Visitor Data 

IP address, browser type, device/OS type, pages visited, referring URL, approximate location derived from IP 

Collected automatically 

Cookies & Similar Technologies 

Session identifiers, preference cookies, analytics identifiers 

Collected automatically 

Sentinel Device & Agent Data 

Machine name, operating system, organization, agent version, scan information, and a unique device identifier for each device running PexLens Sentinel 

Generated through your use of PexLens Sentinel 

Package & Dependency Data 

Package and dependency information read from manifest files (such as package.json) and from package installation requests evaluated by the PexLens Proxy, together with resulting risk levels, vulnerabilities, findings, and policy decisions 

Generated through your use of the Services 

Correspondence Data 

Information you provide via support tickets, emails, contact forms, or demo requests 

Provided directly by you 

Billing Data 

Billing name, business address, and payment details (processed by our payment processor) 

Provided directly by you 

 

We do not knowingly collect sensitive personal data (such as health, financial account, or government ID information) through the Services, and we ask that you not submit such data in support requests or free-text fields. 

3. How We Use Personal Data

We use personal data for the following purposes:

Provide, operate, secure, and maintain the Services, including scanning devices with PexLens Sentinel, evaluating package installation requests through the PexLens Proxy, and providing risk analysis, scoring, and policy enforcement features

Create and manage customer and user accounts

Process orders, subscriptions, and billing

Respond to support requests, inquiries, and correspondence

Send administrative communications, including security alerts and service updates

Monitor, analyze, and improve the performance, reliability, and usability of the Services

Detect, investigate, and prevent fraud, abuse, and security incidents

Comply with legal obligations and enforce our agreements

With your consent, send product updates and marketing communications (you may opt out at any time)

4. Legal Bases for Processing (EEA, UK, and Similar Jurisdictions)

Where the GDPR or UK GDPR applies, we rely on the following legal bases to process personal data:

Contractual necessity – to provide the Services under our Terms of Use, including account provisioning, billing, and support.

Legitimate interests – to secure and improve the Services, prevent fraud and abuse, and communicate with customers, provided these interests are not overridden by your rights.

Consent – for optional marketing communications and certain non-essential cookies, which you may withdraw at any time.

Legal obligation – where processing is required to comply with applicable law.

5. How We Share Personal Data

We do not sell personal data. We share personal data only in the following circumstances: 

Category 

Who 

Purpose 

Service Providers 

Cloud hosting and infrastructure providers (including Google Cloud Platform), email delivery, customer support, and payment processing vendors 

To operate and deliver the Services on our behalf 

Professional Advisors 

Auditors, lawyers, accountants, and insurers 

Compliance, risk management, and corporate governance 

Business Transfers 

An acquirer or successor entity 

In connection with a merger, acquisition, financing, or sale of assets 

Legal & Safety 

Law enforcement, regulators, and courts 

To comply with legal process or protect the rights, property, or safety of PexLens, our users, or the public 

 

All service providers are bound by contractual obligations to protect personal data and to use it only for the purposes we specify. 

6. Cookies and Tracking Technologies

We use cookies and similar technologies on our website to operate core functionality, remember preferences, and understand website usage. We use the following categories: 

  • Essential Cookies – required for core website and account functionality. 
  • Functional Cookies – remember your preferences and settings. 
  • Analytics Cookies – help us understand how visitors use our website so we can improve it. 

You can manage cookies through your browser settings or our cookie preference tool. Disabling certain cookies may limit some website functionality. Our website does not currently respond to browser “Do Not Track” signals, as no common industry standard for interpreting them has been adopted. 

7. Data Security

We use administrative, technical, and physical safeguards designed to protect personal data from unauthorized access, use, alteration, or disclosure, including encryption in transit, access controls, and regular security review of our systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. 

8. Data Retention

We retain personal data for as long as necessary to provide the Services and fulfill the purposes described in this Policy. Where you or your organization opts out of or otherwise terminates your PexLens license or subscription, we delete or anonymize your customer data within 30 days of that date, except where we are required to retain certain information for a longer period to comply with our legal obligations, resolve disputes, or enforce our agreements. To determine retention periods for other personal data, such as website visitor and correspondence data, we consider the amount, nature, and sensitivity of the data, the purpose for which it is processed, and applicable legal requirements.

9. Children’s Privacy

The Services are intended for business use and are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child, we will take steps to delete it.

10. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. India-based customers and users are governed by Indian law, including the DPDP Act; customers and users in the United States are governed by applicable U.S. federal and state privacy laws, including the CCPA; and customers and users in the EEA, UK, and Switzerland are governed by the GDPR or UK GDPR, as applicable and further described below. To exercise any of these rights, contact us using the details in Section 13. 

United States 

If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have the right to: 

  • Know what personal data we collect, use, and disclose about you 
  • Access a copy of your personal data 
  • Correct inaccurate personal data 
  • Delete personal data we hold about you, subject to certain exceptions 
  • Opt out of the sale or “sharing” of personal data (we do not sell or share personal data for cross-context behavioral advertising) 
  • Not receive discriminatory treatment for exercising your privacy rights 

You may designate an authorized agent to submit requests on your behalf, subject to verification. Because we do not collect sensitive personal data as described in Section 2, the CCPA “right to limit” use of sensitive personal information does not apply to our processing. If you are a Nevada resident, you also have the right to opt out of the sale of certain personal data; as noted above, we do not sell personal data. 

India – Digital Personal Data Protection Act, 2023 

If you are located in India, as a Data Principal you have the right to: 

  • Obtain a summary of the personal data we process about you and the processing activities undertaken 
  • Request correction, completion, and updating of your personal data 
  • Request erasure of your personal data that is no longer necessary for the purpose it was collected 
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal 
  • Nominate another individual to exercise your rights in the event of death or incapacity 
  • Register a grievance with our Grievance Officer, and if unresolved, with the Data Protection Board of India 

Our Grievance Officer under the DPDP Act can be reached at [email protected]. 

European Economic Area, UK, and Switzerland – GDPR 

If the GDPR or UK GDPR applies to you, you have the right to: 

  • Access – request confirmation of and access to the personal data we hold about you. 
  • Rectification – request correction of inaccurate or incomplete personal data. 
  • Erasure – request deletion of your personal data, subject to certain exceptions. 
  • Restriction – request that we limit how we process your personal data. 
  • Portability – request a copy of your personal data in a structured, machine-readable format. 
  • Objection – object to processing based on legitimate interests, including direct marketing. 
  • Withdraw consent – withdraw consent at any time where processing is based on consent. 
  • Lodge a complaint – with your local data protection supervisory authority. 

11. International Data Transfers

We are a global business, and personal data we collect may be transferred to, stored, and processed in countries other than the one in which it was originally collected, including the United States and India, including through our use of cloud infrastructure providers such as Google Cloud Platform. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards recognized under applicable law, such as Standard Contractual Clauses, to protect that data. 

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or applicable law. We will post the updated Policy on this page and update the “Effective Date” above. Material changes will be communicated through the Services or by email where appropriate. Your continued use of the Services after an update constitutes acceptance of the revised Policy. 

13. Contact Us

If you have questions, requests, or complaints about this Privacy Policy or our data practices, please contact us at: 

PexLens Private Limited 

Email: [email protected] or [email protected] 

Address: 2127/C, Sector 63, Chandigarh, PIN: 160047, India