Version

1.4

Jan 21, 2026

Legal

/

Privacy Policy

LeyesX respects privacy as a core principle of its work. This Privacy Policy explains how LeyesX collects, uses, stores, and protects information in connection with its website and services (collectively, the “Services”).

By accessing or using the Services, you acknowledge and agree to this Privacy Policy.

1. Information We Collect

We collect only information necessary to operate, secure, and deliver our Services. Depending on your interaction with LeyesX, this may include:

  • Provided Information
    Information you voluntarily submit, such as name, role, organization, and contextual details when requesting access or engaging with LeyesX.

  • Engagement & Usage Data
    Limited technical data related to website usage, including browser type, device information, and interaction patterns, collected for security and operational purposes.

  • Communications
    Information shared during inquiries, onboarding, advisory discussions, or confidential reviews.

LeyesX does not require consumer-style accounts and does not collect unnecessary personal data.

2. How We Use Information

Information is used strictly for legitimate and defined purposes, including:

  • Providing and operating the Services

  • Conducting identity risk assessments and advisory work

  • Improving methodologies and internal systems

  • Maintaining security, integrity, and abuse prevention

  • Fulfilling legal, regulatory, or contractual obligations

LeyesX does not use personal information for advertising, profiling, or resale.

3. Confidentiality & Data Handling

Confidentiality is fundamental to LeyesX operations.

  • Information shared with LeyesX is treated as sensitive and confidential by default.

  • Access to data is restricted to authorized personnel on a need-to-know basis.

  • Internal controls are designed to minimize exposure and retention.

LeyesX does not disclose client identities, engagement details, or findings without explicit authorization, except where legally required.

4. Data Sharing

LeyesX does not sell personal information.

Information may be shared only:

  • With trusted infrastructure or service providers strictly necessary to operate the Services

  • To comply with applicable laws, lawful requests, or enforce legal rights

  • To protect the safety, security, or integrity of LeyesX, its clients, or others

All third-party access is limited, controlled, and purpose-bound.

5. Cookies & Tracking Technologies

LeyesX may use limited cookies or similar technologies for:

  • Security

  • Performance monitoring

  • Basic analytics

These technologies are not used for behavioral advertising. You may adjust browser settings to restrict cookies, though some site functionality may be affected.

6. Data Security

LeyesX implements administrative, technical, and organizational safeguards appropriate to the sensitivity of the information handled.

While no system can guarantee absolute security, LeyesX takes reasonable and proportional measures to reduce risk and prevent unauthorized access, disclosure, or misuse.

7. Data Retention

Information is retained only for as long as necessary to:

  • Deliver the Services

  • Maintain continuity of advisory work

  • Comply with legal or regulatory obligations

Retention periods vary depending on the nature of the engagement and applicable requirements.

8. Individual Rights

Where applicable under law, you may have rights to:

  • Access information held about you

  • Request correction of inaccurate data

  • Request deletion, subject to legal and operational constraints

Requests are evaluated carefully to balance privacy, security, and legal obligations.

9. Children’s Privacy

The Services are not intended for individuals under the age of 18. LeyesX does not knowingly collect information from minors.

10. Changes to This Policy

LeyesX may update this Privacy Policy periodically. Updates will be reflected by a revised effective date. Continued use of the Services constitutes acceptance of the updated policy.

11. Jurisdiction

This Privacy Policy is governed by applicable data protection and privacy laws, without regard to conflict-of-law principles.