P1. Overview & Scope
Crescent Value Partners, LLC ("CVP," "we," "us," or "our") provides software services for managed service providers and businesses, including the Lens network and attack-surface assessment platform. This policy covers:
- Platform users who sign into a CVP product or interact with a customer workspace.
- Website visitors who browse emberix.com or use its forms.
- Business contacts who communicate with sales, support, billing, or security teams.
The Lens Privacy Supplement applies to Lens and controls where it is more specific. Separately branded properties may publish their own notices.
P2. Responsibility for Information
CVP is the controller of personal information used for this website, account and billing administration, sales, support, security, and our own business operations.
When CVP processes assessment, workspace, or other customer-provided data on behalf of an MSP or business customer, that customer generally determines why and how the data is processed. In that context, the customer is the controller or business and CVP acts as its processor or service provider under the applicable agreement.
P3. Information We Collect
Information you or your organization provide
- Account and business-contact information, such as name, work email, company, role, memberships, and invitations.
- Authentication and session information, such as password hashes, session-token records, and identifiers received from an identity provider.
- Billing and subscription information, including billing contacts, plan, invoice, tax, transaction, and payment-method metadata. Payment providers process full card or bank-account details; CVP does not store full payment-card numbers.
- Content, configuration, files, targets, and other data entered into a CVP workspace or collected through an authorized customer deployment.
- Contact-form submissions, support correspondence, survey responses, and other communications.
Information collected automatically
- IP address, browser and device information, referring and requested pages, timestamps, request identifiers, and security logs.
- Login activity, feature interactions, diagnostic events, and information needed to operate, troubleshoot, and secure the services.
- Essential cookies, local storage, and similar technologies described in P8.
P4. Sources of Information
We receive information directly from you and your organization, from customer-deployed software, from payment and identity providers, from devices and browsers used to reach our services, and from service providers supporting our operations. Some products also use public records and third-party technical intelligence sources as described in their product-specific notice.
P5. How We Use Information
- Provide, maintain, authenticate, administer, and secure our websites and services.
- Provision accounts and workspaces, enforce permissions and entitlements, and support collaboration.
- Process subscriptions, invoices, payments, and related commercial operations.
- Respond to sales, support, privacy, and security requests.
- Send invitations, password-setup messages, service communications, security notices, and other transactional messages.
- Detect, investigate, and prevent security incidents, fraud, misuse, and violations of our agreements.
- Improve our services using usage information and aggregated or de-identified data.
- Comply with legal obligations and establish, exercise, or defend legal claims.
P6. Legal Bases for Processing
Where the GDPR or UK GDPR applies, our legal basis depends on the activity. We process information as needed to perform a contract, pursue legitimate interests such as operating and securing our services and communicating with business contacts, comply with legal obligations, and act with consent where consent is required. You may contact us for the basis applicable to a specific activity.
P7. Sharing & Disclosure
CVP does not sell personal information or share it for cross-context behavioral advertising. We may disclose information:
- To vendors and service providers that host, secure, support, communicate for, or process payments for our services.
- To identity providers when you or your organization chooses federated sign-in.
- To a customer or workspace administrator responsible for the account through which you use a service.
- When reasonably necessary to comply with law or legal process, protect rights, safety, or property, or investigate misuse.
- In connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality protections.
- At your direction or with your consent.
Our current providers and product data sources are described on the Service Providers & External Data Sources page.
P8. Cookies & Similar Technologies
CVP services use essential cookies to maintain secure sessions and complete sign-in, including short-lived cookies used during federated authentication. The website uses local storage to remember display preferences and Cloudflare security technology to protect forms and traffic. Optional analytics may be enabled where disclosed and, when required, after consent. Blocking essential technologies may prevent sign-in or other features from working.
P9. Retention
We retain information for the period reasonably needed to provide the applicable service, satisfy the customer agreement and plan, secure our systems, comply with legal and accounting obligations, resolve disputes, and enforce agreements. Retention depends on the data type, customer configuration, commercial terms, and whether a legal or security hold applies.
When information is no longer required, we delete or de-identify it through our normal processes. Backup copies may remain until they expire through ordinary backup rotation. Product-specific notices may describe additional retention considerations.
P10. Security
We use administrative, technical, and organizational safeguards intended to protect information, including encryption in transit and provider-managed encryption at rest, centralized secrets management, access controls, tenant-scoped application authorization, and security audit records. No system is perfectly secure, and these measures cannot guarantee that information will never be accessed, used, or disclosed improperly.
Report a suspected vulnerability or security incident to [email protected]. Report suspected abuse or misuse to [email protected].
P11. International Processing
CVP operates from the United States and uses providers with global operations and networks. Information may therefore be processed in the United States and other countries. Where applicable law requires a transfer safeguard, we use an approved mechanism such as contractual protections or another legally recognized basis.
P12. U.S. Privacy Rights
Depending on your state and whether its law applies to CVP, you may have rights to request access to, correction of, or deletion of personal information; obtain a portable copy; opt out of certain processing; or appeal a decision about a request. CVP does not sell personal information or share it for cross-context behavioral advertising.
Submit a request to [email protected]. We may need to verify your identity and authority. We will not discriminate against you for exercising an applicable privacy right.
P13. EEA & UK Rights
If the GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict, object to processing, and receive portable personal data. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also complain to the data-protection authority responsible for your location.
If your information is controlled by a CVP customer, please direct your request to that customer. We will support the customer as required by the applicable agreement and law.
P14. Children's Privacy
CVP services are designed for businesses and are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us so we can investigate and take appropriate action.
P15. Changes & Contact
We may update this policy as our services, providers, and legal obligations change. We will update the effective date and provide additional notice of material changes when appropriate.
Contact
Privacy questions and requests: [email protected]. Legal-document questions: [email protected]. Please do not email passwords, payment-card numbers, or other unnecessary secrets.