What we collect
- Account data: name, business e-mail, organisation details, credentials in protected form, plan and account events.
- Workspace data: asset facts, files, evidence, module inputs and outputs, comments, tasks, invitations and audit records.
- Collaboration data: expert proposals and evidence, counterparty RFI responses, submitted load profiles, submission notes, comments, and the security and expiry metadata needed to operate purpose-limited links. If a recipient contributes without creating an account, PV8 records the verified e-mail address, verification time and contributions for that single shared record.
- Usage and device data: requests, security logs, feature events, browser/device information and error diagnostics.
- Marketing attribution: campaign parameters, referring domain and, when configured, LinkedIn attribution identifiers on public pages.
- Support and billing data: messages, billing status and transaction references. Payment-card entry is handled by the payment provider rather than PV8.
Why we use it
We process data to create and secure accounts, provide modules and reports, maintain owner-controlled sharing, operate billing, answer support requests, prevent misuse, improve reliability, understand campaign performance, comply with law and establish or defend legal claims. The applicable legal bases may include performance of a contract, legitimate interests, legal obligations and consent where required.
Demo, PV8 Concierge and AI features
Representative demo assumptions are synthetic and visibly marked; they are not evidence about your asset. PV8 Concierge is the optional AI-assist layer. If you use PV8 Concierge — an AI agent (such as evidence extraction from an uploaded document, opportunity prioritisation, evidence-request drafting, counterparty briefs, tender drafting, bid normalisation, portfolio monitoring or decision papers) or another AI-assisted action — the data needed for that task — including the content of documents you submit to that action — is sent to PV8’s AI model provider (currently Anthropic PBC) for processing under PV8’s provider agreement. Under the applicable API terms the provider does not use this data to train its models, and PV8 transmits only what the chosen task needs. AI agents return proposals that you review and confirm; nothing an agent produces changes your asset record, sends a message or creates a commitment without your confirmation, and each agent invocation is logged. Do not submit data to an optional AI action unless it is appropriate for that task and your organisation permits it.
Who receives data
Data may be processed by personnel who need it and by service providers supporting hosting, storage, e-mail, maps, analytics, AI features you choose, security, support and billing. External experts and share-link recipients receive only the material the owner shares. A counterparty invited through an RFI receives only the purpose-limited request and context chosen by the owner. Its secure submission link expires after seven days by default. A response returns to the owner’s Evidence Inbox as pending material and does not change an asset or output until the owner approves it. We may disclose data where law requires it or in connection with a corporate transaction subject to appropriate safeguards.
International transfers
Some providers may process data outside your country. Where required, PV8 uses recognised transfer mechanisms and contractual safeguards.
Retention
Account and workspace data is retained while needed to provide the service and for legitimate contractual, security, backup and legal purposes. Retention depends on the record type and applicable agreement. Asset owners can delete assets and revoke links or experts; short-lived backup or audit copies may remain for a limited period where needed for integrity, recovery or law.
Security
PV8 uses organisational and technical measures proportionate to the service, including tenant-scoped authorisation, protected password storage, secure session cookies, signed purpose-limited submission links, access expiry, upload checks and audit records. No internet service can promise absolute security. See the Security page for the current product controls.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier processing. You may also complain to the competent data-protection authority. Workspace administrators can manage asset records, invitations and links directly.
Cookies and local storage
PV8 uses secure session cookies for sign-in and local storage for interface preferences and recoverable drafts. Low-data first-party events help PV8 understand whether core journeys work; they exclude asset facts, files and free-text workspace content. Campaign attribution and the LinkedIn Insight Tag are enabled only after you choose “Allow LinkedIn measurement”, and the LinkedIn tag never loads inside the authenticated workspace. You can choose “Essential only”, use a supported Global Privacy Control signal, or .
Contact
Privacy questions and rights requests: data@pv8.ai. General support: pv8@pv8.ai. Security: security@pv8.ai.