Os resumos, navegação e metadados das políticas estão localizados. O corpo jurídico completo usa como fallback o texto canônico em inglês, exceto quando já mantemos uma versão traduzida específica.
01Scope
This policy describes how LENS Corporation ("LENS", "we", "us") processes personal data. It applies to: (a) visitors to lenscorp.ai and its locale variants; (b) prospects and customers who contact us; (c) end-users of LENS-operated demos and free tools; and (d) data subjects whose data is processed by LENS products under contract with our customers, where LENS acts as a processor.
Where LENS is a processor — for example, when a city operates ICCC on its own infrastructure with LENS software — the controller is the customer and their privacy notice governs the substantive processing. This policy still describes the security, service-provider and assistance commitments we extend.
02Who we are
The "controller" is the legal entity that decides why and how your personal data is processed. LENS Corporation is a brand name covering three operating entities; the controller in any given context is the entity that holds your relationship with us:
- India · primary entity
- LENSCORP AI Private Limited — 5144, 5th Floor, DLF Forum, DLF Cyber City, DLF Phase 3, Sector 24, Gurugram, Haryana 122002. Operations also in Noida.
- United States
- LENS, Inc. — 448 E Osage Ln Unit 1B, Palatine, IL 60074.
- Saudi Arabia
- LENS AI LLC — Riyadh, Saudi Arabia.
- Data Protection Officer
- aishvary@lenscorp.ai
For most public-website interactions, LENSCORP AI Private Limited acts as the controller. Where the relationship is with a regional entity (a US contract, a Saudi deployment), that entity is the controller and joint-controller responsibilities are addressed in the relevant agreement.
03Data we process
Identifiers & contact
Name, work email, work phone, company, role, country. Collected when you fill a contact form, subscribe to the field journal, or request a demo.
Usage & technical
IP address, approximate city / region / country (derived from IP), browser, OS, referrer, pages viewed, timestamps. Collected automatically when you visit our website. We do not use third-party advertising trackers.
Sensor & biometric data (in deployments only)
When LENS products are deployed by a customer, the system may process video, audio, IR, thermal, LIDAR or RADAR feeds — and biometric templates derived from them (face, gait, voice, iris, fingerprint). LENS is a processor for this data. We never aggregate or reuse customer-deployment data for our own purposes, and we never train shared models on customer data without a separate written agreement.
LENS does not operate a consumer biometric database. Biometric processing happens exclusively under contract with named customers (governments, enterprises) on infrastructure they control or LENS dedicated tenancy.
04Purposes & legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Respond to enquiries | Identifiers, contact | Art. 6(1)(b) — pre-contract |
| Send the Field journal | Email, name | Art. 6(1)(a) — consent |
| Operate & secure the website | IP, technical | Art. 6(1)(f) — legitimate interest |
| Comply with legal obligations | As required | Art. 6(1)(c) |
| Provide LENS products to a customer | Sensor / biometric | Processor under Art. 28 DPA |
06Retention
- Sales enquiries — 24 months from last contact, then deleted or anonymised.
- Newsletter subscribers — until unsubscribe; we re-confirm dormant subscriptions every 18 months.
- Web logs — 90 days.
- Customer-deployment data — per the customer's contract; LENS does not set retention for processor data.
07Security
LENS operates an ISO 27001-certified information security programme. Controls include: encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access, hardware MFA for production, quarterly access reviews, and an incident response runbook committing us to notify customers within 72 hours of a confirmed incident, and within 5 business days for a HIPAA Breach. Detailed controls live in the security disclosures.
08Your rights
Subject to applicable law, you may exercise the following rights over your personal data. We respond within the statutory deadline that applies to you. The region-specific notices later in this policy state the exact period, and we tell you in writing if a complex request needs the extension your law allows.
| Right | What it means |
|---|---|
| Access | Get a copy of the personal data we hold about you. |
| Rectification | Correct data that is inaccurate or incomplete. |
| Erasure | Delete your data, where processing is no longer necessary. |
| Restriction | Pause processing while a dispute is resolved. |
| Portability | Receive your data in a machine-readable format. |
| Objection | Object to processing based on legitimate interest. |
| Withdraw consent | Where processing relies on consent (e.g. newsletter). |
| Lodge a complaint | With your local supervisory authority. |
Region-specific notices: India / DPDPA · EU & UK / GDPR · US health / HIPAA · California / CCPA · Brazil / LGPD.
09International transfers
LENS operates from India through LENSCORP AI Private Limited (Gurugram), with regional entities in the US (LENS, Inc., Palatine, IL) and Saudi Arabia (LENS AI LLC, Riyadh). Where personal data crosses borders, we rely on:
- EU/UK → India — Standard Contractual Clauses (2021 EU SCCs + UK addendum) plus a transfer impact assessment.
- US health (PHI) — Business Associate Agreements per HIPAA; data residency in US-East regions.
- Brazil → outside — LGPD Art. 33 contracts, with prior data-subject information.
10Children
Our website and products are not directed to children. We apply the highest age threshold that applies in each market: 18 in India under the Digital Personal Data Protection Act, 2023, 16 in the EEA and the UK, and 13 in the United States. We do not knowingly collect personal data from children. Where a customer deployment may incidentally process children's data (e.g. school-safety contexts), the customer is responsible for parental consent and we provide configuration to support it.
11Changes to this policy
Material changes are announced 30 days in advance via the field journal and a banner on this page. The version history is available on request from solutions@lenscorp.ai.
12Contact & DPO
For privacy questions, rights requests, or complaints:
- Data Protection Officer · aishvary@lenscorp.ai
- EU / UK data subjects · An Article 27 representative is in the process of being appointed. Until then, contact the DPO directly.
- India · grievance · Mr. Aishvary Pratap Singh — aishvary@lenscorp.ai · see DPDPA notice
- US health · HIPAA · LENS, Inc., Palatine, IL — debayan@lenscorp.ai
- Postal · DPO, LENSCORP AI Private Limited, 5144, 5th Floor, DLF Forum, DLF Cyber City, DLF Phase 3, Sector 24, Gurugram, Haryana 122002, India
Precisa de um aviso regional?
Publicamos avisos complementares para Índia, UE/Reino Unido, saúde nos EUA, Califórnia e Brasil.
