Pvotal Technologies, Inc.
Pvotal Technologies, Inc. ("Pvotal," "we," "our," or "us") is a corporation incorporated in the State of Delaware, United States, operating globally. We develop and distribute the Infrastream platform — a declarative, GitOps-native infrastructure automation platform.
This Privacy Policy explains how we collect, use, store, and disclose personal data in connection with our products and services (the "Services"), which include:
● pvotal.tech — Company Website
● Infrastream Hub — our hosted portal at accounts.infrastream.io, through which customers authenticate, manage accounts, and access software artifacts
● Infrastream Onboarding Portal — onboard.pvotal.tech, a project-based customer onboarding portal available to paid customers, delivered in partnership with Rocketlane
● Infrastream Cloud and Infrastream Private Cloud — our infrastructure automation platform deployment options
● docs.infrastream.io — Public Documentation
● Support and Professional Services — including the Onboarding Portal, Community Platform (Discord), and technical consulting
Deployment Models: Under Infrastream Cloud, Pvotal manages applicable platform components and cloud environments for the Customer. Under Infrastream Private Cloud, the platform is deployed and operated within the Customer's own infrastructure. The data boundaries for each model are described in Section 3.
This Policy governs the data processed across all Services, whether managed by Pvotal or deployed by the Customer.
Any information relating to an identified or identifiable natural person
Account registration and identity data processed through Infrastream Hub
Automatically collected data about how you interact with Pvotal-operated surfaces
Pvotal's hosted portal at accounts.infrastream.io for account administration, subscription management, and artifact distribution
Compiled binaries, container images, executor packages, and agent releases distributed by Pvotal to licensed customers
The customer's own GCP or cloud environment in which Infrastream is deployed and operated
Pvotal operates the following customer-facing surfaces:
● Infrastream Hub (accounts.infrastream.io): Account authentication, license management, billing, and Software Artifact distribution
● Infrastream Onboarding Portal (onboard.pvotal.tech): A structured, project-based onboarding experience for paid customers, powered by Rocketlane. This portal coordinates implementation milestones, task assignments, document sharing, and communication between Pvotal's onboarding team and Customer stakeholders
● Infrastream Community Platform (Discord): A community forum for developers building with or evaluating Infrastream, providing peer support, announcements, release discussions, and access to Pvotal engineering staff on a best-effort basis. Join at discord.gg/infrastream
Infrastream Cloud (Pvotal Managed): Pvotal and applicable service providers may process information as reasonably necessary to provide the Services, including: account and identity data, Customer Content, Customer Manifests, cloud project information, repository data, AI prompts/outputs, logs, telemetry, credentials, and billing information. The scope of processing depends on the Customer's configuration and plan.
Infrastream Private Cloud (Customer Deployed): Deployed within Customer Infrastructure. Features may transmit specific information to Pvotal or third parties as needed, such as: Customer Manifests, repository info, AI interactions, credentials, usage/billing data, telemetry, and information provided for support or onboarding. Other information remains within Customer Infrastructure unless explicitly transmitted or voluntarily provided.
We collect data necessary to operate the Services, facilitate infrastructure automation, and provide technical support.
● Identity: Name, professional email address, and OpenID Connect identity token (from your configured identity provider)
● Organization: Company name, primary domain
● License Information: Subscription tier, licensed GCP Organization ID or cloud identifier (used to issue and validate license keys)
● Billing: Company billing address, VAT/EIN number; payment card data is collected and processed exclusively by our PCI-DSS compliant payment processor (Stripe) and is never stored on Pvotal systems
When a licensed customer pulls a software artifact (binary release, container image, executor package) from Pvotal's artifact registry, we log:
● Artifact name and version
● Timestamp of the request
● Customer account identifier
● IP address of the requesting system
These logs are used for license enforcement, release tracking, and security monitoring. They do not contain any customer infrastructure data.
● IP address, browser type, operating system
● Pages visited within Infrastream Hub, time on page, navigation paths
● Upgrade requests initiated via the Hub (version from, version to, timestamp)
● Error and crash reports from the Hub UI (sanitized of any infrastructure data)
● Standard web analytics (aggregate page views, referrer URLs, geographic region at country level)
● Form submissions: contact requests, demo requests, newsletter sign-ups
For paid customers using the Infrastream Onboarding Portal, we process:
● Contact and identity information: Names and email addresses of Customer stakeholders invited to the onboarding project
● Project and task data: Milestone plans, task statuses, due dates, implementation checklists, and phase completion records
● Communications: Messages, comments, and discussions conducted within the Rocketlane-powered portal between Customer and Pvotal's onboarding team
● Shared documents: Files and documents uploaded by Customer or Pvotal to the onboarding project workspace
● Session and access logs: Login timestamps, portal activity, and notification preferences
This data is processed solely for the purpose of coordinating and delivering Customer's onboarding engagement. Onboarding Portal data is retained for as long as reasonably necessary to coordinate and deliver the onboarding engagement, maintain appropriate business and security records, comply with legal obligations, resolve disputes, and satisfy applicable Customer instructions or contractual requirements.
When you use the Pvot AI Agent or other AI-assisted features, we process information to generate, analyze, and assist with infrastructure workflows. This includes processing AI prompts, manifest configurations, architectural context, logs, outputs, metadata, and feedback. AI outputs and related data may be processed to provide, secure, and improve our Services. Unless Customer expressly opts in or separate written terms state otherwise, Pvotal does not use Customer Confidential Information or Customer Personal Data to train generalized AI models for use by unrelated customers.
Pvotal's onboarding team may request and review Customer-provided architectural context (e.g., a description of existing GCP organization structure) to inform onboarding recommendations. This context is provided voluntarily by Customer and is handled as Confidential Information.
The Infrastream developer community operates on Discord. When you join the Infrastream Discord server, Discord Inc. collects and processes your data in accordance with Discord's Privacy Policy. Pvotal additionally processes:
● Identity: Discord username and any profile information you choose to share in the server
● Messages and content: Posts, replies, threads, and files shared in Infrastream Discord channels
● Participation data: Channel membership, join/leave events, and role assignments within the server
The Discord server is a public-facing community space. Do not share proprietary, confidential, cloud credentials, or personally identifying information in public channels. Communications from Pvotal staff in Discord do not constitute official support with SLA commitments.
● Emails, support tickets, and chat messages you send to us
● Diagnostic information you voluntarily share with our support team
Depending on the applicable deployment model, Customer configuration, enabled telemetry, support request, integration, or Professional Services engagement, Pvotal may receive diagnostic, telemetry, configuration, or operational information. Information provided through support is used to investigate, resolve, secure, and administer the applicable Services and support request.
Hub session management, OIDC token handling
Language/preference settings
Aggregate usage statistics
Interest-based outreach on third-party platforms
Contract performance (Art. 6(1)(b) GDPR)
Contract performance
Contract performance
Contract performance + Legal obligation
Legitimate interests (Art. 6(1)(f) GDPR)
Legitimate interests
Legitimate interests
Consent (Art. 6(1)(a) GDPR)
Consent
Legal obligation (Art. 6(1)(c) GDPR)
Pvotal does not sell, rent, or trade Personal Data. We share data only in the following limited circumstances:
Cloud infrastructure, hosting, and artifact registry
Payment processing
Paid customer onboarding portal
Public documentation and source repository hosting
Community platform and developer engagement
Authentication and identity management
Infrastructure assistance and generative AI functionality
Platform monitoring, incident management, and customer support
Information regarding applicable subprocessors may be requested through legal@pvotal.tech.
Pvotal may disclose prompts, infrastructure context, AI assisted outputs, and related operational metadata to authorized AI model providers where necessary to provide configured AI functionality. Processing may occur in regions determined by service availability, model routing, Customer location, provider infrastructure, or the nearest available AI processing region.
In the event of a merger, acquisition, or asset sale, Personal Data may transfer as part of that transaction. You will be notified in advance where required by law.
We may disclose data if required by law, court order, or governmental authority, or where reasonably necessary to protect the rights, property, or safety of Pvotal, our customers, or the public.
Pvotal is incorporated in Delaware, United States. Pvotal controlled platform data is generally hosted using Google Cloud infrastructure in the United States. Certain third party services, including AI model providers used by Pvot AI Agent, may process Personal Data in other geographic regions based on service availability, model routing, Customer location, provider infrastructure, or the nearest available AI processing region. The locations used to host or process Personal Data may therefore depend on the applicable Service, Customer configuration, GCP services, subprocessors, and third party AI providers. A binding data residency commitment applies only if expressly stated in an executed Order Form or applicable Data Processing Addendum. Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, Pvotal may rely on lawful transfer mechanisms including:
● European Commission Standard Contractual Clauses;
● the applicable United Kingdom addendum or another valid United Kingdom transfer mechanism;
● adequacy decisions; or
● other safeguards permitted by applicable law.
Data Processing Addendum and international transfer requests may be submitted to legal@pvotal.tech.
Retained as necessary to provide Services and manage account relationship
Retained to comply with legal, tax, and financial reporting obligations
Retained for security monitoring, release tracking, and license enforcement
Retained to resolve support cases and improve service quality
Retained until opt-out or as needed for marketing purposes
Retained for the duration specified by the analytics provider
Retained for the duration of the active session
We retain data only as long as necessary for the purposes for which it was collected or to comply with legal requirements. Upon termination, data is deleted or anonymized in accordance with our data management policies and applicable law.
Pvotal maintains administrative, technical, and organizational safeguards designed to protect information processed through our systems, which may include:
● encryption in transit; encryption at rest for applicable data; authentication and access controls; multi factor authentication for applicable privileged access; least privilege controls; dependency and vulnerability management; logging and monitoring; incident response procedures; and security testing.
The controls applicable to a particular Service may vary by deployment model, feature, configuration, and plan. No system is completely secure.
Pvotal accepts good-faith reports of suspected security vulnerabilities affecting Pvotal-operated systems.
To report a vulnerability:
● Email support@infrastream.io
● Provide affected surface, reproduction steps, impact, and contact details
● Do not send personal data or cloud credentials in the report
Safe harbour: Pvotal will not initiate legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy, and who do not access, modify, or exfiltrate customer data beyond what is minimally necessary to demonstrate the vulnerability.
Out of scope: Issues limited to Customer operated Infrastream Private Cloud deployments or Customer Infrastructure that do not affect a Pvotal operated system, denial of service testing, social engineering, physical security testing, and third party component findings without a demonstrated impact on a Pvotal operated system, unless Pvotal expressly authorizes the testing in writing.
Any acknowledgement, investigation, triage, remediation, or disclosure coordination period communicated by Pvotal is an operational target and not a contractual commitment unless expressly stated in an applicable agreement.
If you believe your account has been compromised, contact support@infrastream.io immediately.
● Access (Art. 15): Request a copy of your Personal Data
● Rectification (Art. 16): Request correction of inaccurate data
● Erasure (Art. 17): Request deletion ("right to be forgotten")
● Restriction (Art. 18): Request limited processing
● Portability (Art. 20): Receive your data in machine-readable format
● Object (Art. 21): Object to processing based on legitimate interests
● Withdraw Consent: At any time, without affecting prior processing
Submit requests to legal@pvotal.tech. Pvotal will respond within the period required by applicable law and may verify identity and authority before processing a request.
● Right to know what personal information is collected, used, or shared
● Right to delete personal information
● Right to correct inaccurate information
● Right to opt-out of sale or sharing (Pvotal does not sell personal information)
● Right to limit use of sensitive personal information
● Right to non-discrimination for exercising rights
Submit requests via legal@pvotal.tech with subject line "CCPA Privacy Request." Pvotal will respond within the period required by applicable law and may verify identity and authority before processing a request.
Our Services are enterprise products not directed at individuals under 18. If you believe we have collected data from a minor, contact legal@pvotal.tech.
Our documentation and Hub may link to third-party services (GitHub, GitLab, Google Cloud Console, identity providers). This Policy does not apply to those third-party services. For Infrastream Private Cloud, repository synchronization may occur directly between Customer Infrastructure and Customer VCS. Certain features, integrations, support workflows, or Customer configurations may transmit repository information, Customer Manifests, or related information to Pvotal or applicable third party service providers.
We may update this Policy to reflect product, legal, or operational changes. We will update the Last Revised date and provide additional notice of material changes where required by applicable law or the applicable commercial agreement.
Pvotal Technologies, Inc. Privacy & Compliance Email: legal@pvotal.tech
Support and Security Incidents: support@infrastream.io Website: https://pvotal.tech
This Privacy Policy is governed by the laws of the State of Delaware, United States, without prejudice to applicable data protection laws in the jurisdiction of the data subject.