Privacy Policy

Pvotal Technologies, Inc.

Effective Date: April 17, 2026
Last Revised: August 6, 2026

1. Introduction and Who We Are

Pvotal Technologies, Inc. ("Pvotal," "we," "our," or "us") is a corporation incorporated in the State of Delaware, United States, operating globally. We develop and distribute the Infrastream platform — a declarative, GitOps-native infrastructure automation platform.

This Privacy Policy explains how we collect, use, store, and disclose personal data in connection with our products and services (the "Services"), which include:

● pvotal.tech — Company Website
Infrastream Hub — our hosted portal at accounts.infrastream.io, through which customers authenticate, manage accounts, and access software artifacts
Infrastream Onboarding Portal — onboard.pvotal.tech, a project-based customer onboarding portal available to paid customers, delivered in partnership with Rocketlane
Infrastream Cloud and Infrastream Private Cloud — our infrastructure automation platform deployment options
● docs.infrastream.io — Public Documentation
Support and Professional Services — including the Onboarding Portal, Community Platform (Discord), and technical consulting

Deployment Models: Under Infrastream Cloud, Pvotal manages applicable platform components and cloud environments for the Customer. Under Infrastream Private Cloud, the platform is deployed and operated within the Customer's own infrastructure. The data boundaries for each model are described in Section 3.

This Policy governs the data processed across all Services, whether managed by Pvotal or deployed by the Customer.

2. Definitions

Term
Definition
Personal Data

Any information relating to an identified or identifiable natural person

Hub Account Data

Account registration and identity data processed through Infrastream Hub

Usage Data

Automatically collected data about how you interact with Pvotal-operated surfaces

Infrastream Hub

Pvotal's hosted portal at accounts.infrastream.io for account administration, subscription management, and artifact distribution

Software Artifacts

Compiled binaries, container images, executor packages, and agent releases distributed by Pvotal to licensed customers

Customer Infrastructure

The customer's own GCP or cloud environment in which Infrastream is deployed and operated

3. What Pvotal Does and Does Not Have Access To

3.1 What Pvotal Operates

Pvotal operates the following customer-facing surfaces:

Infrastream Hub (accounts.infrastream.io): Account authentication, license management, billing, and Software Artifact distribution
Infrastream Onboarding Portal (onboard.pvotal.tech): A structured, project-based onboarding experience for paid customers, powered by Rocketlane. This portal coordinates implementation milestones, task assignments, document sharing, and communication between Pvotal's onboarding team and Customer stakeholders
Infrastream Community Platform (Discord): A community forum for developers building with or evaluating Infrastream, providing peer support, announcements, release discussions, and access to Pvotal engineering staff on a best-effort basis. Join at discord.gg/infrastream

3.2 Data Boundaries and Access

Infrastream Cloud (Pvotal Managed): Pvotal and applicable service providers may process information as reasonably necessary to provide the Services, including: account and identity data, Customer Content, Customer Manifests, cloud project information, repository data, AI prompts/outputs, logs, telemetry, credentials, and billing information. The scope of processing depends on the Customer's configuration and plan.

Infrastream Private Cloud (Customer Deployed): Deployed within Customer Infrastructure. Features may transmit specific information to Pvotal or third parties as needed, such as: Customer Manifests, repository info, AI interactions, credentials, usage/billing data, telemetry, and information provided for support or onboarding. Other information remains within Customer Infrastructure unless explicitly transmitted or voluntarily provided.

4. Data We Collect

We collect data necessary to operate the Services, facilitate infrastructure automation, and provide technical support.

4.1 Account and Identity Data

Identity: Name, professional email address, and OpenID Connect identity token (from your configured identity provider)
Organization: Company name, primary domain
License Information: Subscription tier, licensed GCP Organization ID or cloud identifier (used to issue and validate license keys)
Billing: Company billing address, VAT/EIN number; payment card data is collected and processed exclusively by our PCI-DSS compliant payment processor (Stripe) and is never stored on Pvotal systems

4.2 Artifact Distribution Logs

When a licensed customer pulls a software artifact (binary release, container image, executor package) from Pvotal's artifact registry, we log:

● Artifact name and version
● Timestamp of the request
● Customer account identifier
● IP address of the requesting system

These logs are used for license enforcement, release tracking, and security monitoring. They do not contain any customer infrastructure data.

4.3 Hub Usage Data (Collected Automatically)

● IP address, browser type, operating system
● Pages visited within Infrastream Hub, time on page, navigation paths
● Upgrade requests initiated via the Hub (version from, version to, timestamp)
● Error and crash reports from the Hub UI (sanitized of any infrastructure data)

4.4 Website and Documentation Usage

● Standard web analytics (aggregate page views, referrer URLs, geographic region at country level)
● Form submissions: contact requests, demo requests, newsletter sign-ups

4.5 Onboarding Portal Data (onboard.pvotal.tech)

For paid customers using the Infrastream Onboarding Portal, we process:

Contact and identity information: Names and email addresses of Customer stakeholders invited to the onboarding project
Project and task data: Milestone plans, task statuses, due dates, implementation checklists, and phase completion records
Communications: Messages, comments, and discussions conducted within the Rocketlane-powered portal between Customer and Pvotal's onboarding team
Shared documents: Files and documents uploaded by Customer or Pvotal to the onboarding project workspace
Session and access logs: Login timestamps, portal activity, and notification preferences

This data is processed solely for the purpose of coordinating and delivering Customer's onboarding engagement. Onboarding Portal data is retained for as long as reasonably necessary to coordinate and deliver the onboarding engagement, maintain appropriate business and security records, comply with legal obligations, resolve disputes, and satisfy applicable Customer instructions or contractual requirements.

4.6 AI Functionality and Processing

When you use the Pvot AI Agent or other AI-assisted features, we process information to generate, analyze, and assist with infrastructure workflows. This includes processing AI prompts, manifest configurations, architectural context, logs, outputs, metadata, and feedback. AI outputs and related data may be processed to provide, secure, and improve our Services. Unless Customer expressly opts in or separate written terms state otherwise, Pvotal does not use Customer Confidential Information or Customer Personal Data to train generalized AI models for use by unrelated customers.

Pvotal's onboarding team may request and review Customer-provided architectural context (e.g., a description of existing GCP organization structure) to inform onboarding recommendations. This context is provided voluntarily by Customer and is handled as Confidential Information.

4.7 Community Platform Data (Discord)

The Infrastream developer community operates on Discord. When you join the Infrastream Discord server, Discord Inc. collects and processes your data in accordance with Discord's Privacy Policy. Pvotal additionally processes:

Identity: Discord username and any profile information you choose to share in the server
Messages and content: Posts, replies, threads, and files shared in Infrastream Discord channels
Participation data: Channel membership, join/leave events, and role assignments within the server

The Discord server is a public-facing community space. Do not share proprietary, confidential, cloud credentials, or personally identifying information in public channels. Communications from Pvotal staff in Discord do not constitute official support with SLA commitments.

4.8 Support and Communications

● Emails, support tickets, and chat messages you send to us
● Diagnostic information you voluntarily share with our support team

Depending on the applicable deployment model, Customer configuration, enabled telemetry, support request, integration, or Professional Services engagement, Pvotal may receive diagnostic, telemetry, configuration, or operational information. Information provided through support is used to investigate, resolve, secure, and administer the applicable Services and support request.

4.9 Cookies and Tracking

Category
Purpose
Opt-out
Strictly Necessary

Hub session management, OIDC token handling

No
Functional

Language/preference settings

Yes
Analytics

Aggregate usage statistics

Yes
Marketing

Interest-based outreach on third-party platforms

Yes

5. How We Use Your Data

Purpose
Legal Basis
Provisioning and operating your Hub account

Contract performance (Art. 6(1)(b) GDPR)

License key issuance and enforcement

Contract performance

Artifact distribution and release delivery

Contract performance

Billing and invoicing

Contract performance + Legal obligation

Security monitoring, fraud prevention, abuse detection

Legitimate interests (Art. 6(1)(f) GDPR)

Product analytics and platform improvement

Legitimate interests

Sending release notes and product update notices

Legitimate interests

Marketing emails and newsletters

Consent (Art. 6(1)(a) GDPR)

Non-essential cookies

Consent

Compliance with legal obligations

Legal obligation (Art. 6(1)(c) GDPR)

6. Data Sharing and Disclosure

Pvotal does not sell, rent, or trade Personal Data. We share data only in the following limited circumstances:

6.1 Sub-processors

Provider / Category
Purpose
Google Cloud

Cloud infrastructure, hosting, and artifact registry

Stripe

Payment processing

Rocketlane

Paid customer onboarding portal

GitHub / GitLab

Public documentation and source repository hosting

Discord

Community platform and developer engagement

Identity providers

Authentication and identity management

AI model providers

Infrastructure assistance and generative AI functionality

Analytics, security, support, and communications providers

Platform monitoring, incident management, and customer support

Information regarding applicable subprocessors may be requested through legal@pvotal.tech.

6.2 AI Model Providers

Pvotal may disclose prompts, infrastructure context, AI assisted outputs, and related operational metadata to authorized AI model providers where necessary to provide configured AI functionality. Processing may occur in regions determined by service availability, model routing, Customer location, provider infrastructure, or the nearest available AI processing region.

6.3 Business Transfers

In the event of a merger, acquisition, or asset sale, Personal Data may transfer as part of that transaction. You will be notified in advance where required by law.

7. International Data Transfers

Pvotal is incorporated in Delaware, United States. Pvotal controlled platform data is generally hosted using Google Cloud infrastructure in the United States. Certain third party services, including AI model providers used by Pvot AI Agent, may process Personal Data in other geographic regions based on service availability, model routing, Customer location, provider infrastructure, or the nearest available AI processing region. The locations used to host or process Personal Data may therefore depend on the applicable Service, Customer configuration, GCP services, subprocessors, and third party AI providers. A binding data residency commitment applies only if expressly stated in an executed Order Form or applicable Data Processing Addendum. Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, Pvotal may rely on lawful transfer mechanisms including:

● European Commission Standard Contractual Clauses;
● the applicable United Kingdom addendum or another valid United Kingdom transfer mechanism;
● adequacy decisions; or
● other safeguards permitted by applicable law.

Data Processing Addendum and international transfer requests may be submitted to legal@pvotal.tech.

8. Data Retention

Data Category
Retention Rationale
Hub account data

Retained as necessary to provide Services and manage account relationship

Billing records

Retained to comply with legal, tax, and financial reporting obligations

Artifact distribution logs

Retained for security monitoring, release tracking, and license enforcement

Support communications

Retained to resolve support cases and improve service quality

Marketing contact data

Retained until opt-out or as needed for marketing purposes

Analytics cookies

Retained for the duration specified by the analytics provider

OpenID session tokens

Retained for the duration of the active session

We retain data only as long as necessary for the purposes for which it was collected or to comply with legal requirements. Upon termination, data is deleted or anonymized in accordance with our data management policies and applicable law.

9. Security

Pvotal maintains administrative, technical, and organizational safeguards designed to protect information processed through our systems, which may include:

● encryption in transit; encryption at rest for applicable data; authentication and access controls; multi factor authentication for applicable privileged access; least privilege controls; dependency and vulnerability management; logging and monitoring; incident response procedures; and security testing.

The controls applicable to a particular Service may vary by deployment model, feature, configuration, and plan. No system is completely secure.

Responsible Disclosure

Pvotal accepts good-faith reports of suspected security vulnerabilities affecting Pvotal-operated systems.

To report a vulnerability:

● Email support@infrastream.io
● Provide affected surface, reproduction steps, impact, and contact details
● Do not send personal data or cloud credentials in the report

Safe harbour: Pvotal will not initiate legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy, and who do not access, modify, or exfiltrate customer data beyond what is minimally necessary to demonstrate the vulnerability.

Out of scope: Issues limited to Customer operated Infrastream Private Cloud deployments or Customer Infrastructure that do not affect a Pvotal operated system, denial of service testing, social engineering, physical security testing, and third party component findings without a demonstrated impact on a Pvotal operated system, unless Pvotal expressly authorizes the testing in writing.

Any acknowledgement, investigation, triage, remediation, or disclosure coordination period communicated by Pvotal is an operational target and not a contractual commitment unless expressly stated in an applicable agreement.

If you believe your account has been compromised, contact support@infrastream.io immediately.

10. Your Rights

10.1 GDPR Rights (EEA / UK Residents)

Access (Art. 15): Request a copy of your Personal Data
Rectification (Art. 16): Request correction of inaccurate data
Erasure (Art. 17): Request deletion ("right to be forgotten")
Restriction (Art. 18): Request limited processing
Portability (Art. 20): Receive your data in machine-readable format
Object (Art. 21): Object to processing based on legitimate interests
Withdraw Consent: At any time, without affecting prior processing

Submit requests to legal@pvotal.tech. Pvotal will respond within the period required by applicable law and may verify identity and authority before processing a request.

10.2 CCPA / CPRA Rights (California Residents)

● Right to know what personal information is collected, used, or shared
● Right to delete personal information
● Right to correct inaccurate information
● Right to opt-out of sale or sharing (Pvotal does not sell personal information)
● Right to limit use of sensitive personal information
● Right to non-discrimination for exercising rights

Submit requests via legal@pvotal.tech with subject line "CCPA Privacy Request." Pvotal will respond within the period required by applicable law and may verify identity and authority before processing a request.

11. Children's Privacy

Our Services are enterprise products not directed at individuals under 18. If you believe we have collected data from a minor, contact legal@pvotal.tech.

13. Changes to This Policy

We may update this Policy to reflect product, legal, or operational changes. We will update the Last Revised date and provide additional notice of material changes where required by applicable law or the applicable commercial agreement.

14. Contact Us

Pvotal Technologies, Inc. Privacy & Compliance Email: legal@pvotal.tech

Support and Security Incidents: support@infrastream.io Website: https://pvotal.tech

This Privacy Policy is governed by the laws of the State of Delaware, United States, without prejudice to applicable data protection laws in the jurisdiction of the data subject.