- CloudLens connects with a read-only role. It reads billing, usage and configuration metadata, not the contents of your applications.
- We don't store card details. Payments are handled by our payment provider.
- This website loads analytics only if you accept cookies.
- You can export or delete your data at any time by writing to privacy@qarbix.com.
1. Who we are
CloudLens is built and operated by Qarbix. In this policy, "Qarbix", "we" and "us" mean the company that provides CloudLens FinOps, CloudLens Atlas and this website.
2. What we collect
- Account information. Your name, work email and organization name when you sign up. If you sign in with SSO, the basic profile your identity provider sends.
- Organization details. Team members, roles and billing contact details, used to run your subscription and multi-user access.
- Cloud account metadata. Through the read-only role you create (an AWS IAM role or an Azure service principal): account and subscription IDs, linked accounts and the resource identifiers needed to connect cost to resources.
- Cost and usage data. Billing exports (AWS Cost and Usage Reports, Azure Cost Management exports), commitment coverage and resource utilization metrics. This is what recommendations are calculated from.
- Security and configuration metadata (CloudLens Atlas). Resource configuration, network rules, IAM policies and relationships, vulnerability findings from services such as Amazon Inspector, and data-classification results produced in your account, such as the data types a classifier reports for a bucket. Atlas stores the result and its evidence, not the underlying records.
- Website enquiries. When you use the contact form: your name, work email, company, cloud spend band, number of accounts and your message. We use them only to reply to you.
3. What we do not collect
Minimal access is a design rule, not a setting:
- No application data. We don't read the contents of storage objects, database tables or application logs.
- No secret values. We don't read values stored in Secrets Manager, Parameter Store or Key Vault.
- No card data. Payment processing is handled entirely by our payment provider.
- No write access for visibility. The role used to see your cloud is read-only. Features that change resources, such as applying an approved proposal, need a separate role that you choose to create.
4. How we use it
- To calculate cost breakdowns, recommendations, anomalies and savings.
- To build the security graph, rank findings and score compliance controls.
- To send the alerts, reports and tickets you configure (for example to Slack, Microsoft Teams or Jira).
- To support you, and to fix problems in the product.
We don't sell data, and we don't use your cloud data to advertise to you.
5. Security and storage
- Encryption. Data is encrypted in transit (TLS) and at rest, including database backups.
- Access controls. Internal access to customer data is limited to the people who need it, with multi-factor authentication, and access is logged.
- Isolation. Each organization's data is kept logically separate and is never visible to another customer.
6. Service providers
We use a small number of providers to run CloudLens:
- Cloud infrastructure. Hosting for the application and its databases.
- Payments. A PCI DSS compliant payment provider. We never see or store your card details.
- Email. Transactional email and the alerts you opt into.
- Website analytics. Google Tag Manager on this website, loaded only after you accept cookies.
- Copilot. When an administrator turns Copilot on, questions and the cost data needed to answer them are sent to the AI model provider configured for your organization. Copilot is off until an admin enables it.
Providers are bound by contract to protect the data they process for us.
7. Retention and deletion
- Active accounts. We keep your data while your account is active, so trends and year-over-year comparisons work.
- Cancellation. After you cancel we keep your data for 30 days in case you come back, then delete it permanently within 60 days.
- On request. Ask for immediate deletion at any time and we'll process it within 7 business days.
- Website enquiries. Kept while we're in conversation with you, and deleted on request.
8. Your rights
Wherever you are, you can ask us to:
- Access. send you a copy of the data we hold about you and your organization.
- Export. provide your cost data, recommendations and reports in standard formats.
- Correct. fix inaccurate personal or organization details.
- Delete. remove your account and its data.
Write to privacy@qarbix.com. If you are in India, these requests also cover your rights under the Digital Personal Data Protection Act, 2023; if you are in the EU or UK, your rights under the GDPR.
9. Cookies
- Essential. The product uses cookies and local storage to keep you signed in and remember preferences.
- Website analytics. This website loads Google Tag Manager only after you choose Accept in the cookie banner. If you decline, no analytics tag is loaded. You can change your choice from the Cookie settings link in the footer.
We don't use advertising pixels.
10. International transfers
We serve customers in India, the United States, the European Union and elsewhere. When data moves across borders, we use safeguards that the applicable data protection laws require.
11. Changes to this policy
When we make a significant change, we'll email account owners and post a notice in the product before it takes effect. The date at the top of this page shows the latest version.
For anything about your data or this policy, write to us. Security reports have their own address.
