Privacy Policy
Last updated: August 23, 2026
1. Who we are
Provvy Inc. ("Provvy", "we", "us") provides a self-serve platform for automating IT onboarding and offboarding at small and mid-sized companies. This policy describes what personal data we collect, how we use it, who we share it with, and the choices you have.
2. Data we collect
- •Account data: your name, work email, company, hashed password.
- •Configuration data: the identity provider, MDM, HR system and SaaS tools you connect, and the workflow configurations you build.
- •Execution data: workflow runs, dry-run reports, and audit findings scoped to your workspace.
- •Product analytics: anonymised page views and feature usage to improve the product.
3. How we use it
We use your data to operate Provvy, run the workflows you configure, provide support, secure the service, and comply with legal obligations. We do not sell personal data and we do not train third-party AI models on your workspace data.
4. Sub-processors
We use a short list of vetted infrastructure sub-processors (cloud hosting, database, transactional email, error monitoring). A current list is available on request from security@provvy.app.
5. Security
Data in transit uses TLS 1.3. Data at rest is encrypted with AES-256. Secrets and OAuth tokens live in an isolated vault with key rotation. Provvy uses short-lived tokens and never keeps standing admin credentials.
6. Retention
Audit logs are retained per your plan (30 days on Free, up to 3 years on Scale). Workspace data is deleted within 30 days of account termination unless a longer retention is required by law.
7. Your rights
You can access, correct, export or delete your personal data at any time by contacting privacy@provvy.app. If you are in the EU, EEA or UK you also have the right to lodge a complaint with your local data protection authority.
8. Contact
Questions? Email privacy@provvy.app.
This page is provided for informational purposes and is not legal advice.