Privacy Policy
Last updated: 4 April 2026
This Privacy Policy describes how prodxcloud Pte. Ltd. ("VxCloud", "we", "us", or "our"), a company registered at 68 Circular Road, #02-01, Singapore 049422, collects, uses, shares, and protects information when you access or use our websites, applications, APIs, AI agents, and managed cloud services (collectively, the "Services").
We are an AI-powered multi-cloud management and deployment platform. We help customers build, deploy, manage, secure, and optimize infrastructure and applications across cloud providers and customer-controlled environments. We are not a hosting provider. Customers control their own cloud accounts, infrastructure, and the content processed or stored in their environments.
1. Scope and roles
Depending on how you use the Services, we may act as:
- Controller — for account registration, billing, marketing, website analytics, and support data that we collect and process for our own purposes.
- Processor (or service provider) — for customer content and operational data that we process on your instructions when delivering managed services, AI agent operations, and cloud automation.
If you are an end user of a customer (for example, a member of your organization), your organization is typically the controller of your data and you should refer to their privacy practices.
2. Information we collect
2.1 Account and profile information
- Full name, email address, username, and password hash.
- Company/organization name, phone number, and country.
- Profile picture and display preferences.
- Support communications, language, and notification settings.
2.2 Authentication data
- When you sign in via OAuth providers (Google, GitHub, Microsoft, GitLab), we receive limited profile data (name, email, avatar) as authorized by your provider settings.
- We do not receive or store your third-party passwords.
- Authentication tokens and session identifiers.
2.3 Billing and transaction information
- Billing contact details, invoices, subscription plan identifiers, and payment status.
- Payment card data is handled by our payment processors (e.g., Stripe). We receive tokens and limited payment metadata (last 4 digits, expiry) but never full card numbers.
- Order history and account balance information.
2.4 Service and operational data
- Infrastructure metadata needed to deliver managed services (e.g., resource names, cloud regions, service configuration parameters, deployment events, audit trails).
- Logs, metrics, and diagnostic signals generated by or sent to the Services (e.g., job status, event timestamps, error traces, pipeline outputs).
- AI agent interaction data (prompts, recommendations, actions taken) to deliver and improve agentic automation features.
- Source code and configuration files you upload or connect through Git integrations (GitHub, GitLab) for CI/CD and deployment purposes.
2.5 Credentials and secrets
- API keys, SSH keys, access tokens, and service account credentials you provide to connect your cloud environments.
- These are encrypted at rest and in transit. We strongly recommend using least-privilege access and rotating credentials regularly.
- We access these credentials solely to deliver the Services as instructed by you.
2.6 Website usage and device data
- IP address, browser type and version, operating system, device identifiers.
- Pages visited, referral URLs, click patterns, and timestamps.
- Cookies and similar technologies as described in Section 5.
3. How we use information
We use the information we collect to:
- Provide and operate the Services — including cloud provisioning, deployment automation, AI agent operations, database management, and observability.
- Authenticate users — manage accounts, SSO sessions, and role-based access controls.
- Process payments — administer subscriptions, billing, invoicing, and cost tracking.
- Deliver AI and automation features — power agentic workflows, cost optimization recommendations, security scanning, and intelligent provisioning.
- Maintain security — detect threats, prevent fraud, investigate incidents, and enforce our Terms.
- Provide support — respond to requests, troubleshoot issues, and communicate service updates.
- Improve the Services — analyze usage patterns, performance metrics, and feedback to enhance features, reliability, and user experience.
- Comply with legal obligations — satisfy regulatory requirements, respond to lawful requests, and enforce our agreements.
4. Legal bases (where applicable)
Where required by applicable data protection law (such as the GDPR, PDPA, or similar regulations), we rely on one or more of the following legal bases:
- Performance of a contract — to deliver the Services you have subscribed to.
- Legitimate interests — to secure, improve, and operate the Services, prevent fraud, and provide customer support.
- Compliance with legal obligations — to meet regulatory, tax, and reporting requirements.
- Consent — for certain cookies, marketing communications, and optional data processing (which you can withdraw at any time).
5. Cookies and similar technologies
We use cookies and similar technologies for the following purposes:
- Essential cookies — required for authentication, session management, security (CSRF protection), and core functionality. These cannot be disabled.
- Preference cookies — remember your settings such as language, theme (light/dark mode), and dashboard layout.
- Analytics cookies — help us understand how pages are used, measure performance, and identify areas for improvement. We use aggregated data where possible.
You can control non-essential cookies through your browser settings. If you disable cookies, some features (such as persistent login sessions or theme preferences) may not function properly.
6. How we share information
We do not sell your personal information.
We may share information in the following circumstances:
- Vendors and subprocessors — trusted third parties that help us provide the Services (e.g., cloud hosting of our platform, payment processing, analytics tools, customer support systems, email delivery). They are bound by contractual obligations consistent with this policy and process data only as instructed.
- Cloud providers — when you authorize us to manage resources on your behalf, we interact with your cloud provider accounts (AWS, Azure, Google Cloud, Oracle Cloud, DigitalOcean, etc.) using credentials you provide.
- OAuth providers — when you authenticate via Google, GitHub, Microsoft, or GitLab, limited data is exchanged as part of the authentication flow.
- Customer-authorized recipients — when you direct us to share information (e.g., integrating third-party tools, connecting Git repositories, or granting team member access).
- Legal and safety — when required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect rights, safety, or prevent fraud.
- Business transfers — in connection with a merger, acquisition, restructuring, or sale of assets (subject to applicable protections and notice).
7. AI and automated processing
Our Services include AI agents and automated features that process your data to deliver infrastructure recommendations, cost optimizations, security insights, and operational automation.
- AI features may process infrastructure metadata, logs, configuration data, and usage patterns to generate recommendations and execute automated actions.
- We may use anonymized and aggregated interaction data to improve our AI models and features. We do not use your proprietary source code, credentials, or personally identifiable information to train general-purpose AI models.
- You can control the scope of AI agent access through permission settings in the Services.
- You have the right to request human review of significant decisions made by automated processing, where required by applicable law.
8. Data retention
We retain information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type:
- Account data — retained while your account is active and for up to 90 days after deletion request.
- Billing records — retained for up to 7 years to comply with tax and accounting regulations.
- Operational logs — retained for 30–90 days depending on log type, unless a longer retention is configured by you.
- Credentials and secrets — permanently deleted upon account termination or when you remove them.
- Website session logs — retained for up to 12 months.
Where feasible, we de-identify or aggregate information for analytics and product improvement purposes.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
- Role-based access controls (RBAC) and least-privilege principles.
- Audit logging and real-time monitoring for anomalous activity.
- Regular security assessments and vulnerability scanning.
- Secure software development practices and code reviews.
No security measure is perfect. You are responsible for protecting your own credentials, enforcing least-privilege access in your cloud environments, and conducting your own security assessments.
10. International transfers
We are based in Singapore. We may process information in Singapore and other countries where we or our vendors operate (which may include the United States, European Union, and other regions).
Where required by law (such as GDPR for transfers outside the EEA), we implement appropriate safeguards for cross-border transfers, including standard contractual clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms.
11. Your rights and choices
Depending on your location and applicable law, you may have the following rights regarding your personal information:
| Right | Description |
|---|---|
| Access | Request a copy of the personal information we hold about you. |
| Correction | Request correction of inaccurate or incomplete personal information. |
| Deletion | Request deletion of your personal information (subject to legal retention requirements). |
| Portability | Request export of your data in a structured, machine-readable format. |
| Restriction | Request that we limit processing of your personal information in certain circumstances. |
| Objection | Object to processing based on legitimate interests or for direct marketing purposes. |
| Withdraw consent | Withdraw consent where processing is based on consent, without affecting prior processing. |
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law (typically 30 days).
If we process your information on behalf of an organization, we may direct you to that organization to fulfil your request.
For California residents (CCPA/CPRA)
- We do not sell or share personal information for cross-context behavioral advertising.
- You have the right to know what personal information we collect, use, and disclose.
- You have the right to request deletion and to opt out of certain data uses.
- We will not discriminate against you for exercising your privacy rights.
For EEA/UK residents (GDPR/UK GDPR)
- You have the rights listed in the table above, including the right to lodge a complaint with your local supervisory authority.
- For cross-border transfers, we use standard contractual clauses or equivalent safeguards.
12. Children
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take steps to delete it.
13. Third-party links
The Services may contain links to third-party websites, tools, or services (including cloud provider consoles, documentation, and marketplace integrations). We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing them with your information.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or Services. We will notify you of material changes via email or a notice within the Services at least 14 days before they take effect. Your continued use of the Services after the updated policy takes effect constitutes your acceptance of the changes.
15. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us:
- Email: [email protected]
- Address: prodxcloud Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422
See also our Terms of Service for additional information about your use of the Services.