1. Introduction and Who We Are
Infrastream, Inc. ("Pvotal," "we," "our," or "us") is a corporation incorporated in the State of Delaware, United States, operating globally. We develop and distribute the Infrastream platform — a declarative, GitOps-native infrastructure automation platform.
This Privacy Policy explains how we collect, use, store, and disclose personal data in connection with our products and services (the "Services"), which include:
- pvotal.tech — Company Website
- Infrastream Hub — our hosted portal at accounts.infrastream.io, through which customers authenticate, manage accounts, and access software artifacts
- Infrastream Onboarding Portal — onboard.pvotal.tech, a project-based customer onboarding portal available to paid customers, delivered in partnership with Rocketlane
- Infrastream Cloud and Infrastream Private Cloud — our infrastructure automation platform deployment options
- docs.infrastream.io — Public Documentation
- Support and Professional Services — including the Onboarding Portal, Community Platform (Discord), and technical consulting
*Deployment Models:* Under Infrastream Cloud, Pvotal manages applicable platform components and cloud environments for the Customer. Under Infrastream Private Cloud, the platform is deployed and operated within the Customer's own infrastructure. The data boundaries for each model are described in Section 3.
This Policy governs the data processed across all Services, whether managed by Pvotal or deployed by the Customer.
2. Definitions
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person |
| Hub Account Data | Account registration and identity data processed through Infrastream Hub |
| Usage Data | Automatically collected data about how you interact with Pvotal-operated surfaces |
| Infrastream Hub | Pvotal's hosted portal at accounts.infrastream.io for account administration, subscription management, and artifact distribution |
| Software Artifacts | Compiled binaries, container images, executor packages, and agent releases distributed by Pvotal to licensed customers |
| Customer Infrastructure | The customer's own GCP or cloud environment in which Infrastream is deployed and operated |
3. What Pvotal Does and Does Not Have Access To
3.1 What Pvotal Operates
Pvotal operates the following customer-facing surfaces:
- Infrastream Hub (accounts.infrastream.io): Account authentication, license management, billing, and Software Artifact distribution
- Infrastream Onboarding Portal (onboard.pvotal.tech): A structured, project-based onboarding experience for paid customers, powered by Rocketlane. This portal coordinates implementation milestones, task assignments, document sharing, and communication between Pvotal's onboarding team and Customer stakeholders
- Infrastream Community Platform (Discord): A community forum for developers building with or evaluating Infrastream, providing peer support, announcements, release discussions, and access to Pvotal engineering staff on a best-effort basis. Join at discord.gg/infrastream
3.2 Data Boundaries and Access
*Infrastream Cloud (Pvotal Managed):* Pvotal and applicable service providers may process information as reasonably necessary to provide the Services, including: account and identity data, Customer Content, Customer Manifests, cloud project information, repository data, AI prompts/outputs, logs, telemetry, credentials, and billing information. The scope of processing depends on the Customer's configuration and plan.
*Infrastream Private Cloud (Customer Deployed):* Deployed within Customer Infrastructure. Features may transmit specific information to Pvotal or third parties as needed, such as: Customer Manifests, repository info, AI interactions, credentials, usage/billing data, telemetry, and information provided for support or onboarding. Other information remains within Customer Infrastructure unless explicitly transmitted or voluntarily provided.
4. Data We Collect
We collect data necessary to operate the Services, facilitate infrastructure automation, and provide technical support.
4.1 Account and Identity Data
- Identity: Name, professional email address, and OpenID Connect identity token (from your configured identity provider)
- Organization: Company name, primary domain
- License Information: Subscription tier, licensed GCP Organization ID or cloud identifier (used to issue and validate license keys)
- Billing: Company billing address, VAT/EIN number; payment card data is collected and processed exclusively by our PCI-DSS compliant payment processor (Stripe) and is never stored on Pvotal systems
4.2 Artifact Distribution Logs
When a licensed customer pulls a software artifact (binary release, container image, executor package) from Pvotal's artifact registry, we log:
- Artifact name and version
- Timestamp of the request
- Customer account identifier
- IP address of the requesting system
These logs are used for license enforcement, release tracking, and security monitoring. They do not contain any customer infrastructure data.
4.3 Hub Usage Data (Collected Automatically)
- IP address, browser type, operating system
- Pages visited within Infrastream Hub, time on page, navigation paths
- Upgrade requests initiated via the Hub (version from, version to, timestamp)
- Error and crash reports from the Hub UI (sanitized of any infrastructure data)
4.4 Website and Documentation Usage
- Standard web analytics (aggregate page views, referrer URLs, geographic region at country level)
- Form submissions: contact requests, demo requests, newsletter sign-ups
4.5 Onboarding Portal Data (onboard.pvotal.tech)
For paid customers using the Infrastream Onboarding Portal, we process:
- Contact and identity information: Names and email addresses of Customer stakeholders invited to the onboarding project
- Project and task data: Milestone plans, task statuses, due dates, implementation checklists, and phase completion records
- Communications: Messages, comments, and discussions conducted within the Rocketlane-powered portal between Customer and Pvotal's onboarding team
- Shared documents: Files and documents uploaded by Customer or Pvotal to the onboarding project workspace
- Session and access logs: Login timestamps, portal activity, and notification preferences
This data is processed solely for the purpose of coordinating and delivering Customer's onboarding engagement. Onboarding Portal data is retained for as long as reasonably necessary to coordinate and deliver the onboarding engagement, maintain appropriate business and security records, comply with legal obligations, resolve disputes, and satisfy applicable Customer instructions or contractual requirements.
4.6 AI Functionality and Processing
When you use the Pvot AI Agent or other AI-assisted features, we process information to generate, analyze, and assist with infrastructure workflows. This includes processing AI prompts, manifest configurations, architectural context, logs, outputs, metadata, and feedback. AI outputs and related data may be processed to provide, secure, and improve our Services. Unless Customer expressly opts in or separate written terms state otherwise, Pvotal does not use Customer Confidential Information or Customer Personal Data to train generalized AI models for use by unrelated customers.
Pvotal's onboarding team may request and review Customer-provided architectural context (e.g., a description of existing GCP organization structure) to inform onboarding recommendations. This context is provided voluntarily by Customer and is handled as Confidential Information.
4.7 Community Platform Data (Discord)
The Infrastream developer community operates on Discord. When you join the Infrastream Discord server, Discord Inc. collects and processes your data in accordance with Discord's Privacy Policy. Pvotal additionally processes:
- Identity: Discord username and any profile information you choose to share in the server
- Messages and content: Posts, replies, threads, and files shared in Infrastream Discord channels
- Participation data: Channel membership, join/leave events, and role assignments within the server
The Discord server is a public-facing community space. Do not share proprietary, confidential, cloud credentials, or personally identifying information in public channels. Communications from Pvotal staff in Discord do not constitute official support with SLA commitments.
4.8 Support and Communications
- Emails, support tickets, and chat messages you send to us
- Diagnostic information you voluntarily share with our support team
Depending on the applicable deployment model, Customer configuration, enabled telemetry, support request, integration, or Professional Services engagement, Pvotal may receive diagnostic, telemetry, configuration, or operational information. Information provided through support is used to investigate, resolve, secure, and administer the applicable Services and support request.
4.9 Cookies and Tracking
| Category | Purpose | Opt-out |
|---|---|---|
| Strictly Necessary | Hub session management, OIDC token handling | No |
| Functional | Language/preference settings | Yes |
| Analytics | Aggregate usage statistics | Yes |
| Marketing | Interest-based outreach on third-party platforms | Yes |
5. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Provisioning and operating your Hub account | Contract performance (Art. 6(1)(b) GDPR) |
| License key issuance and enforcement | Contract performance |
| Artifact distribution and release delivery | Contract performance |
| Billing and invoicing | Contract performance + Legal obligation |
| Security monitoring, fraud prevention, abuse detection | Legitimate interests (Art. 6(1)(f) GDPR) |
| Product analytics and platform improvement | Legitimate interests |
| Sending release notes and product update notices | Legitimate interests |
| Marketing emails and newsletters | Consent (Art. 6(1)(a) GDPR) |
| Non-essential cookies | Consent |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
6. Data Sharing and Disclosure
Pvotal does not sell, rent, or trade Personal Data. We share data only in the following limited circumstances:
6.1 Sub-processors
| Provider / Category | Purpose |
|---|---|
| Google Cloud | Cloud infrastructure, hosting, and artifact registry |
| Stripe | Payment processing |
| Rocketlane | Paid customer onboarding portal |
| GitHub / GitLab | Public documentation and source repository hosting |
| Discord | Community platform and developer engagement |
| Identity providers | Authentication and identity management |
| AI model providers | Infrastructure assistance and generative AI functionality |
| Analytics, security, support, and communications providers | Platform monitoring, incident management, and customer support |
Information regarding applicable subprocessors may be requested through legal@pvotal.tech.
6.2 AI Model Providers
Pvotal may disclose prompts, infrastructure context, AI assisted outputs, and related operational metadata to authorized AI model providers where necessary to provide configured AI functionality. Processing may occur in regions determined by service availability, model routing, Customer location, provider infrastructure, or the nearest available AI processing region.
6.3 Business Transfers
In the event of a merger, acquisition, or asset sale, Personal Data may transfer as part of that transaction. You will be notified in advance where required by law.
6.4 Legal Requirements
We may disclose data if required by law, court order, or governmental authority, or where reasonably necessary to protect the rights, property, or safety of Pvotal, our customers, or the public.
7. International Data Transfers
Pvotal is incorporated in Delaware, United States. Pvotal controlled platform data is generally hosted using Google Cloud infrastructure in the United States. Certain third party services, including AI model providers used by Pvot AI Agent, may process Personal Data in other geographic regions based on service availability, model routing, Customer location, provider infrastructure, or the nearest available AI processing region. The locations used to host or process Personal Data may therefore depend on the applicable Service, Customer configuration, GCP services, subprocessors, and third party AI providers. A binding data residency commitment applies only if expressly stated in an executed Order Form or applicable Data Processing Addendum. Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, Pvotal may rely on lawful transfer mechanisms including:
- European Commission Standard Contractual Clauses;
- the applicable United Kingdom addendum or another valid United Kingdom transfer mechanism;
- adequacy decisions; or
- other safeguards permitted by applicable law.
Data Processing Addendum and international transfer requests may be submitted to legal@pvotal.tech.
8. Data Retention
| Data Category | Retention Rationale |
|---|---|
| Hub account data | Retained as necessary to provide Services and manage account relationship |
| Billing records | Retained to comply with legal, tax, and financial reporting obligations |
| Artifact distribution logs | Retained for security monitoring, release tracking, and license enforcement |
| Support communications | Retained to resolve support cases and improve service quality |
| Marketing contact data | Retained until opt-out or as needed for marketing purposes |
| Analytics cookies | Retained for the duration specified by the analytics provider |
| OpenID session tokens | Retained for the duration of the active session |
We retain data only as long as necessary for the purposes for which it was collected or to comply with legal requirements. Upon termination, data is deleted or anonymized in accordance with our data management policies and applicable law.
9. Security
Pvotal maintains administrative, technical, and organizational safeguards designed to protect information processed through our systems, which may include:
- encryption in transit; encryption at rest for applicable data; authentication and access controls; multi factor authentication for applicable privileged access; least privilege controls; dependency and vulnerability management; logging and monitoring; incident response procedures; and security testing.
The controls applicable to a particular Service may vary by deployment model, feature, configuration, and plan. No system is completely secure.
Responsible Disclosure
Pvotal accepts good-faith reports of suspected security vulnerabilities affecting Pvotal-operated systems.
*To report a vulnerability:*
- Email support@infrastream.io
- Provide affected surface, reproduction steps, impact, and contact details
- Do not send personal data or cloud credentials in the report
*Safe harbour:* Pvotal will not initiate legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy, and who do not access, modify, or exfiltrate customer data beyond what is minimally necessary to demonstrate the vulnerability.
*Out of scope:* Issues limited to Customer operated Infrastream Private Cloud deployments or Customer Infrastructure that do not affect a Pvotal operated system, denial of service testing, social engineering, physical security testing, and third party component findings without a demonstrated impact on a Pvotal operated system, unless Pvotal expressly authorizes the testing in writing.
Any acknowledgement, investigation, triage, remediation, or disclosure coordination period communicated by Pvotal is an operational target and not a contractual commitment unless expressly stated in an applicable agreement.
If you believe your account has been compromised, contact support@infrastream.io immediately.
10. Your Rights
10.1 GDPR Rights (EEA / UK Residents)
- Access (Art. 15): Request a copy of your Personal Data
- Rectification (Art. 16): Request correction of inaccurate data
- Erasure (Art. 17): Request deletion ("right to be forgotten")
- Restriction (Art. 18): Request limited processing
- Portability (Art. 20): Receive your data in machine-readable format
- Object (Art. 21): Object to processing based on legitimate interests
- Withdraw Consent: At any time, without affecting prior processing
Submit requests to legal@pvotal.tech. Pvotal will respond within the period required by applicable law and may verify identity and authority before processing a request.
10.2 CCPA / CPRA Rights (California Residents)
- Right to know what personal information is collected, used, or shared
- Right to delete personal information
- Right to correct inaccurate information
- Right to opt-out of sale or sharing (Pvotal does not sell personal information)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising rights
Submit requests via legal@pvotal.tech with subject line "CCPA Privacy Request." Pvotal will respond within the period required by applicable law and may verify identity and authority before processing a request.
11. Children's Privacy
Our Services are enterprise products not directed at individuals under 18. If you believe we have collected data from a minor, contact legal@pvotal.tech.
12. Third-Party Links and Integrations
Our documentation and Hub may link to third-party services (GitHub, GitLab, Google Cloud Console, identity providers). This Policy does not apply to those third-party services. For Infrastream Private Cloud, repository synchronization may occur directly between Customer Infrastructure and Customer VCS. Certain features, integrations, support workflows, or Customer configurations may transmit repository information, Customer Manifests, or related information to Pvotal or applicable third party service providers.
13. Changes to This Policy
We may update this Policy to reflect product, legal, or operational changes. We will update the Last Revised date and provide additional notice of material changes where required by applicable law or the applicable commercial agreement.
14. Contact Us
**Infrastream, Inc.** Privacy & Compliance Email: legal@pvotal.tech
Support and Security Incidents: support@infrastream.io Website: https://pvotal.tech (opens in a new tab)
*This Privacy Policy is governed by the laws of the State of Delaware, United States, without prejudice to applicable data protection laws in the jurisdiction of the data subject.*