Cvent Global Privacy Statement 

Last modified August 18, 2026 

What's New: 

  • We included references to recent acquisitions.
  • We clarified Cvent’s role as a data controller and Cvent’s role as a service provider/data processor, where applicable.
  • We expanded the California Supplementary Notice to “U.S. State Supplementary Notice” to disclose the rights of all consumers in the U.S. where a U.S. State privacy law applies.
  • We removed references to products that have been sunset.
  • We changed and consolidated section titles for simplicity and clarification. 

 

Cvent Acquired Entities and Platforms Not Covered by this Privacy Statement 

For more information about the privacy practices of the following Cvent acquired entities and platforms, see their privacy statements or policies as indicated: 

 

Introduction 

Cvent, Inc., and its affiliated entities ("Cvent" or "We", "us"), respect Your privacy and we are committed to protecting Your privacy through our compliance with this Statement.  

This Privacy Statement describes our practices and Your data protection rights in relation to personal data, the types of which are identified below (“Personal Data”) We collect directly from our Customers from Cvent websites that link to this Privacy Statement (“Website(s)”) or when You attend our in-person and web-based marketing and learning events and from digital marketing activities.  

If You are an event registrant, attendee, guest, or business contact of a Cvent Customer (“Customer’s Client”, as defined below), we process Your information pursuant to our customer agreements.  If You have requests or further questions about the processing of Your information as a Customer's Client, please contact the Cvent Customer that You interact with directly (e.g. Your event host, Your hotel, or event exhibitor).  

This Privacy Statement also provides information about how Personal Data collected from Customer’s Clients by our Customers will be processed by Cvent as a service provider/data processor on behalf of our Customers through our software applications (collectively, our “Applications”).   

 

 

Who Does This Privacy Statement Apply To? 

This Privacy Statement applies to Customers and Visitors (“You” or “Your”), who are defined below:

VISITORS: Individuals and prospective customers who interact with our Websites as a non-Customer, to read about Cvent products and services, download a white paper, or sign up for an online demo); those who attend Cvent hosted marketing events (for instance, Cvent CONNECT®, Cvent live events and webinars); those who we meet at a tradeshow; or those who we collect from third parties or other external sources. 

CUSTOMERS: Customers are individuals that are employees or agents of Cvent’s customers (for example, event planners, travel buyers, meeting space providers, hospitality industry Suppliers (defined below)), including: customer personnel that are assigned a login ID or are otherwise authorized to access and use our Applications pursuant to a Cvent agreement, individuals under a temporary evaluation license, if available, and individuals who self-register to access our Applications. Cvent’s customers are organizations and businesses that use our Applications to process their Customer's Clients’ Personal Data. 

SUPPLIERS: If You represent a hospitality industry supplier, we collect some of Your information from You or from publicly available sources (such as first and last names, job title, job function, e-mail address, telephone number, work address and company information) to post on Cvent’s Supplier Network and Vendor Marketplace.  This enables Cvent to submit requests for proposals to Your organization from event planners and industry buyers that use Cvent’s Supplier Network and Vendor Marketplace to source trusted service providers for events - a key function of the Cvent Supplier Network and Vendor Marketplace.  

CUSTOMER'S CLIENTS: Cvent offers a wide range of products and Cvent processes Personal Data about Customer’s Clients in our Applications as a “data processor” or “service provider” according to our Customers’ instructions. Customer's Clients are individuals that interact with our Customers through our Applications.  These include our Customers’ current and prospective clients, members, event registrants, attendees, sponsors, exhibitors, marketing partners, hotel guests or other business contacts. For example, Customer's Clients include individuals that register for an event organized by a Customer, download an event-related mobile app, participate in a virtual event organized by a Customer, complete an online survey, or make a hotel or meeting space reservation using one of Cvent's Applications.   If You have questions about how a specific Cvent Customer uses Your data or want to exercise Your rights regarding Your Personal Data, You should direct Your request or inquiry to the Cvent Customer that controls Your data.  For example, if You have attended an event hosted by a Cvent Customer, You should direct Your data rights requests and inquiries to the host of Your event. Information about how Your data is processed by Cvent as a service provider/data processor can be found below in the section titled “Cvent as a Service Provider/Data Processor.”  

 

Personal Data We Collect, Purposes of Processing, and Legal Bases of Processing 

Source 

Personal Data 

Purpose 

Legal Basis of Processing  

Customer 

Name and contact data, organization information; application usage information; payment information 

To support our engagements and carry out software services and transactions requested by You (e.g. disclose Personal Data of a planner that is necessary for a supplier to respond to an RFP) 

Contract 

To improve our Applications and to create benchmark and other business intelligence products by using aggregate data 

Legitimate Interest 

To send or respond to requests for proposals 

Contract 

To conduct advertising and marketing to Customer. In particular. sending promotional communications, tailored advertising (i) on our Websites, (ii) on third-party sites and mobile apps not affiliated with Cvent, and (iii) through direct marketing (for example: e-mail, mail, SMS, phone), for ourselves and for Cvent Customers; presenting You with relevant offers, responding to Your queries submitted to our chat agent or through a form on our Website 

Legitimate Interest 

Consent 

Where permitted, we may rely on a “soft opt-in” individual consent to direct marketing where we have collected Your contact details in the course of a sale of our products and services and send You marketing for similar products and services. We rely on legitimate interests for this. 

 

To disclose to contractors, service providers, and other third parties as reasonably necessary or prudent to provide, maintain and support our Applications for our Customers, such as, for example, payment processors and data center or Web hosting providers  

Contract 

When a Customer uses their social media credentials to share information on their social media platform or to log into one of our Applications, we will share information with their social media account provider. The social media site’s use of the information we share will be governed by the social media site’s privacy policy 

Consent 

To respond to requests from public and government authorities including public and government authorities outside Your country of residence (with Customer’s cooperation where legally permissible) 

Legal Obligation 

For billing and payments 

Contract 

To post Supplier Customer’s contact information on Cvent’s Vendor Marketplace or Cvent Supplier Network 

Legitimate Interest 

Customer and Visitor 

Device and usage data, sales and customer support audio/video call recordings, sales and support chats/messages/emails  

 

To diagnose and resolve problems 

Legitimate Interest 

To securely identify Customers upon logging onto an Application  

Legitimate Interest 

To protect against or identify fraudulent transactions 

Legitimate Interest 

To provide customer support 

Contract 

 

Compliance with laws  

Legal Obligation 

Consent (where required by law) 

For training and coaching, process improvement, quality assurance, to gain insights into customer satisfaction, know Your language preference, to gain insight into website performance 

We may use data analytics tools to gain better insights into our interactions with customers.  We will always notify You before a call will be recorded and will obtain consent from You where required by law 

Legitimate Interest 

Consent (where required by law) 

To enhance or modify our Applications 

Legitimate Interest 

To determine the effectiveness of our promotional campaigns 

Legitimate Interest 

To improve our Applications and to create benchmark and other business intelligence products by using aggregate data 

 

Legitimate Interest 

To provide a more personalized sales or support experience, to improve our Websites and advertising, to identify prospective marketing opportunities, to make informed business decisions, and to improve the quality of our services.    

 

Legitimate Interest 

Visitor 

name, title, postal address, e-mail address, telephone number, social media account ID, company information 

To conduct advertising and marketing to You. In particular, for  sending promotional communications, tailored advertising (i) on our Websites, (ii) on third-party sites and mobile apps not affiliated with Cvent, and (iii) through direct marketing (for example: e-mail, mail, SMS, phone), for ourselves and for Cvent Customers; presenting You with relevant offers, responding to Your queries submitted to our chat agent or through a form on our Website 

Consent (where required) 

Legitimate Interest (in growing our business through direct marketing and promotion of our products and services) 

To analyze how our Websites are accessed 

 

Legitimate Interest 

To personalize Your browsing experience and present products or features that may be more applicable to You 

 

Legitimate Interest 

To identify website technical problems; to 

discover, investigate and remediate fraudulent or illegal activity 

 

Legitimate Interest 

To transmit notices to Customers related to product, service, or policy changes 

 

Contract 

Legitimate Interest 

To respond to product and service inquiries 

 

Legitimate Interest 

To Send You information such as product announcements, newsletters, whitepapers, other relevant offers, and upcoming promotions or events  

 

Consent 

Legitimate Interest 

To manage event registrations to plan and host events, tradeshows, webinars, online forums and social networks for which You have registered or that You attend or participate in.  To send related communications to You. 

Consent  

Contractual Necessity 

Legitimate Interest (in ensuring the safety and security of our events) 

Third Parties, Joint Marketing Partners, Social Media Platforms and Public Sources 

Visitor personal data: business contact information including first and last names, job title, job function and responsibilities, education, e-mail address, telephone number, postal address, company information, and social media account ID 

To conduct advertising and marketing to You or to contact You about professional opportunities 

 

Legitimate Interest 

 

 

 

 

Suppliers and Public Sources 

Supplier personal data: first and last names, job title, job function and responsibilities, e-mail address, telephone number, postal address, and company information.  

Cvent posts Supplier-provided and publicly sourced business contact information on Cvent’s Supplier Network and Vendor Marketplace. This enables Cvent to submit requests for proposals to Your organization from event planners and industry buyers, which use Cvent’s Supplier Network and Vendor Marketplace to source trusted service providers for events - a key function of the Cvent Supplier Network and Vendor Marketplace.  Cvent may also use Supplier Personal Data to facilitate the submission and response to RFPs and inquiries between Planner and Supplier customers of Cvent  

 

Where permitted, we also use Your business contact information to market our products and services to Your employer or to contact You about professional opportunities 

Legitimate Interest (in growing our business and increasing the efficacy of our products and services) 

 

Consent (where required for marketing) 

 

Contractual Necessity (when providing sourcing services to Planner and Supplier customers) 

We collect Visitor information directly from the Visitor through a form on our Website, queries submitted to our chat agent, an interaction with our sales or customer support team, when signing up for an event, contest entries, promotional enquiries, or through a response to one of our surveys or marketing emails. We use this information to provide You with additional details about our services, conduct research, provide whitepapers or to contact You after Your visit.  When visiting our Websites, attending Cvent marketing events or providing us with their Personal Data, Visitors may consent to the collection, processing and storage of their Personal Data as described above.

We also collect Personal Data from third party sources, such as third parties from whom we have purchased business contact information, public databases, joint marketing partners, and social media platforms.  For more information, see Cvent’s Article 14 Privacy Notice here.  

If You elect to do so, when You provide a customer reference, we collect Personal Data about Your referenced contacts, such as: 

  • Name
  • Work email
  • Organization
  • Phone number
  • City of residence
  • ZIP code 

When You provide us with Personal Data about Your referenced contacts, we will only use this information for the specific reason for which it is provided. 

 

 

Explanation of Legal Bases for Cvent to Process Personal Data 

For individuals that are from the European Economic Area (EEA), the United Kingdom (UK) or other regions that stipulate a lawful basis for processing Personal Data (such as under GDPR Article 6), our legal basis for collecting and using Your Personal Data will depend on the nature and circumstances of the processing activity. 

Where we process Personal Data on the basis of a legitimate interest, then – as required by data protection law – we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals’ interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of the notice.

Where we rely on contractual necessity or compliance with a legal obligation as specified above, the provision of Personal Data is mandatory in order to fulfill the contractual requirement or to comply with the legal obligation.  If Personal Data is not provided in these cases, we may be prevented from providing services to You or complying with the legal obligation. 

Where we rely on consent, the provision of Personal Data is optional. However, if You do not provide consent, it may impact our ability to offer certain features of our products, market to You, or optimise our products and services and Your experience. 

 

 

Your Privacy Rights 

Depending on applicable local data protection laws You may have certain rights relating to Your Personal Data, which may include the right to:  

  • Access Personal Data we process concerning You
  • Know more about how we process Your Personal Data
  • Erase or delete Your Personal Data
  • Rectify inaccurate Personal Data
  • Transfer Your Personal Data to another controller, to the extent possible
  • Object to the processing of Personal Data which is based on Cvent’s legitimate interests, or the processing of Personal Data for direct marketing purposes.
  • Restrict our processing of Your Personal Data
  • Withdraw Your consent at any time (where we rely on consent as our legal basis for processing Your Personal Data)
  • Complain about the use of Your Personal Data;
  • Opt-out of the sale or sharing of Your Personal Data
  • Not be subject to “Automated Decision-Making” (a decision based solely on automated processing, including profiling, which produces legal effects).  Cvent does not currently engage in the foregoing on our websites or in our products and services.
  • Not be discriminated against for exercising Your rights as described above 

To make a verifiable request, clickhere to submit a webform, call 1-833-724-0821, email us at privacy@cvent.com, or send a letter to: 

Cvent Representative 
1765 Greensboro Station Place, 7th Floor 
Tysons Corner, Virginia 22102 

You may also opt out of the sale or sharing of Personal Data by turning on the Global Privacy Control (“GPC”) browser signal.  To control types of cookies set, see “How to Manage and Control Cookies and Similar Technologies”. 

In some circumstances, these rights may be limited, for example if fulfilling Your request would reveal Personal Data about another person, or if You ask us to delete information which we are required by law or have compelling legitimate interests to keep. 

We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect. In such instances, we will inform the Customer about the legal obligations that prevent us from fulfilling the request. 

We will maintain an audit history of any requests referenced above to maintain a record of compliance with regulatory requirements. 

If You wish to update Your email preferences to tailor the topics You are most interested in receiving, or to unsubscribe from communications from Cvent, You may do so here:  https://www.cvent.com/subscriptionmanagement. 

 

 

Data Retention  

We retain Personal Data for no longer than is necessary for the purposes for which it was collected, taking into account our legal obligations, the nature of our relationship with You, and the rights available to You under applicable law.

Because the appropriate retention period varies depending on the context in which Your data was collected and the purpose for which it is used, we determine storage periods based on the following criteria: 

  • The duration of our contractual or business relationship with You 
  • Legal and regulatory obligations 
  • Applicable statutes of limitations 
  • Your choices and exercise of Your rights
  • Our legitimate operational needs 
     

Personal Data that is no longer required for any of the above purposes is securely deleted or anonymized in accordance with applicable internal data retention policies.

 

How We Share Your Personal Data 

Cvent may share Your Personal Data with the following parties: 

  • Cvent’s wholly owned subsidiaries and affiliates
  • Third party service providers contracted to provide services on our behalf as well as third parties who resell Cvent services.
  • Business partners to jointly offer products, services or other programs such as webinars or whitepapers and from time to time, we may share Personal Data if You purchase or show interest in any jointly-offered products or services.
  • Third party exhibitors and event sponsors if You attend a Cvent marketing event if a) You consent, b) if You permit Your badge to be scanned, or c) it is otherwise permissible under applicable law.
  • Third-party social media networks, advertising networks and websites, so that Cvent can market and advertise on third party platforms and websites;
  • Third parties in the event of a - or a process for a - merger, divestiture, restructuring, recapitalization, reorganization, dissolution or other sale or transfer of some or all Cvent’s assets or equity, whether as a continuing operating business or as part of bankruptcy, liquidation or similar proceeding.
  • Public authorities, such as law enforcement, judicial, and government authorities (to the extent we are compelled to disclose Personal Data to comply with our legal obligations)
  • Anyone using our communities, forums, blogs, etc. may view any Personal Data or other information You choose to submit and post. 

 

 

Children’s Data 

None of our Applications or Websites are directed by Cvent to children under 16 years of age. We do not directly solicit or knowingly collect personal data from children under 16. If we learn that we have inadvertently collected personal data from children under the age of 16, we will delete as soon as practicable.

This Privacy Statement does not apply to the practices of our Customers with which Your child may interact. You should review the applicable terms and policies for Customers to determine their appropriateness for Your child, including their data collection and use practices. 

Where we make our mobile applications available through third-party app stores, we participate in and rely on the age-rating, parental controls, and age-verification processes that those app stores make available and that are designed to support compliance with applicable age-related and children’s privacy and age-verification laws.  We do not control and are not responsible for how third-party app stores design or operate their age-verification tools, and we encourage parents and guardians to review and configure those settings appropriately. 

 

 

Cookies and Similar Technologies 

Cookies and Web Beacons 

We and authorized third parties use cookies or similar automatic data collection technologies as individuals interact with our Website or our Applications to collect certain information about their equipment, browsing actions and patterns, including details of Your visits to our Applications, such as the date and time You access our Applications, length of time You spend on our Applications, websites that linked to our Applications or websites linked from our Applications, the resources and content that You access and use on the Applications; information about Your computer and internet connection, such as Your IP Address, computer type, screen resolution, language, Internet browser type and version. We do not use any of these technologies to collect information from Customer's Clients for marketing or advertising purposes.  Our Customers may add cookies or other similar technologies through our Applications for their own purposes, including for marketing purposes. 

Browser Cookies.  A cookie is a small file placed on a computer hard drive.  Web browsers can be configured to restrict or entirely block cookies, to configure cookie notification settings and/or to delete cookies already present on the browser or device.  Information on how to do this is provided by the web browser’s help/reference section. Limiting or restricting certain types of cookies may prevent a Customer or Customer's Client from using certain portions of our Applications, depending on how the browser settings are configured.  For example, event registration cannot be completed successfully if cookies are disabled in the web browser. Unless the browser setting has been adjusted so that it will refuse cookies, our system will issue cookies when the browser interacts with our Applications.   

Purpose.  Our Website and Applications use cookies that serve the following purpose types:  

  • Strictly necessary (essential). Strictly necessary cookies make our Websites or Applications work, they are essential for the Websites or Applications to perform their basic functions.  
  • Performance.  Also known as “statistics cookies”, and including analytics cookies, performance cookies collect information about how You use a website, like which pages You visited and which links You clicked on. None of this information can be used to identify You. Their sole purpose is to improve website functions. This includes cookies from third-party analytics services as long as the cookies are for the exclusive use of the owner of the website visited. 
  • Functionality.  Also known as “preferences” cookies, these cookies allow a website to remember choices You have made in the past, like what language You prefer.  They are used to enhance the user experience of the Website or Application but are non-essential to their use, but without these cookies, certain functionality may become unavailable.  
  • Marketing.  These cookies track Your online activity to help advertisers deliver more relevant advertising or to limit how many times You see an ad. These cookies can share that information with other organizations or advertisers. These are persistent cookies and almost always of third-party provenance.  

Web Beacons and Pixels.  Where legally permitted, pages in our Applications and emails will contain small electronic files known as web beacons (also referred to as clear gifs, pixels, tags and single-pixel gifs).  Web beacons differ from cookies in that the information is not stored on Your hard drive, but invisibly embedded on web pages or in email.  Web beacons permit us to track online movements of web users, for example: to count users who have visited those pages or opened an e-mail and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).  Pixel based e-mail tracking and Web Beacons enables Cvent to confirm that our emails are reaching You, understand which communications are relevant, so we can tailor future messages to be more useful to you, and to provide a website experience more tailored to our users’ preferences and interests.   

More about Marketing Cookies.  We use information collected from our venue sourcing Customers to enable us to display advertisements from our Supplier Customers to their target audience of users through our network or our advertising service providers.  As one example, meeting space providers purchase advertisements that are presented selectively through the Cvent Supplier Network to meeting planners who have previously awarded a minimum volume of meetings business to that provider or to competing venues in the target metropolitan area.  Even though we do not disclose Personal Data for these purposes, if the venue sourcing user clicks on or otherwise interacts with an advertisement, the advertising Supplier Customer assumes that the venue sourcing user meets its target criteria. While we and our Supplier Customers leverage this technology to advertise to Customers, we never use our Customer's information to advertise to Customer's Clients.  We also use third parties (such as LinkedIn, Google, Facebook, YouTube) to serve advertisements that may be of interest to You on other websites.   

More about Performance Cookies.  We use third party analytics providers, including Google, Adobe, Mixpanel, Mouseflow and others, to collect information about the usage of our Applications and Websites to enable us to improve how they work.  The information allows us to see the overall patterns of usage on the Applications, helps us record any difficulties You have with the Applications, shows us whether our advertising is effective or not, and allows us to use responses to advertisements to optimize ad performance.  Google Analytics, Adobe and Mixpanel use cookies and other similar technologies to collect information about the usage of our Applications and to report website trends to us, without storing any Personal Data on external third-party analytics provider platforms.  

 

 

How to Manage and Control Cookies and Similar Technologies 

Cookie Controls: If You are visiting our Website from the EEA, UK or Switzerland, then we do not set non-essential cookies unless You accept all cookies on the “cookie banner” that launches when You land on our Website.  

You can manage Your preferences through the Cookies Setting link on the website You are visiting.

 

 

 

Do Not Track: Some browsers include a “Do Not Track” (DNT) setting that can send a signal to the websites You visit indicating You do not wish to be tracked.  We do not respond to browser ‘do not track’ signals, as we await for a uniform standard put forth by regulators or the privacy industry. 

Global Privacy Control: Some browsers and browser extensions support the Global Privacy Control (“GPC”) that can send a signal to the websites You visit indicating Your choice to opt-out from certain types of data processing, including data sales. If Your browser supports it, You can turn on the Global Privacy Control to opt-out of the “sale” or “sharing” of Your Personal Data. 

 

 

International Transfers 

To facilitate our business practices and delivery of our services, Personal Data may be transferred to (or otherwise accessed from) any country where we have facilities or in which we engage third party service providers, including: the United States, countries in the European Economic Area (EEA), Switzerland, and UK, India, Australia and Singapore. Therefore, Your Personal Data may be processed in countries other than the country in which You are located, including in places that are not subject to an adequacy decision by the European Commission.  To ensure that the data recipient offers an adequate level of security, Cvent will implement appropriate safeguards to protect Your Personal Data as defined in Article 46(2) of the GDPR, including the Standard Contractual Clauses adopted by the European Commission under Decision 2021/914/EU, issued on 4 June 2021) and the UK Addendum (under Article 46(2) of the UK GDPR).  To the extent Cvent participates in the EU-U.S. Data Privacy Framework as administered by the U.S. Department of Commerce, transfers to the United States may alternatively be made on the basis of Cvent’s certification thereunder.

For transfers of Personal Data originating from Hong Kong, Cvent implements contractual and organizational safeguards appropriate to the circumstances of the transfer, consistent with Cvent's obligations as a data user under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO"). 

 

 

Certifications 

Data Privacy Framework 

Cvent, Inc. (and its U.S.-based Affiliates: StarCite, Inc., Social Tables, Inc., Passkey International, Inc., Lanyon Solutions, Inc., Cvent OnArrival, Inc., IPOLIPO INC, dba, Jifflenow, Straight Shot Solutions, LLC, dba, iCapture.com, and One Clipboard, LLC, dba Splash, Inc.) complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. 

Cvent, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of Personal Data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.   

Cvent, Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/

Cvent is responsible for the processing of Personal Data it receives, under the Data Privacy Framework, and subsequently transfers to third parties acting as an agent on its behalf.  Cvent complies with the Data Privacy Framework Principles for all onward transfers of Personal Data from the EU, UK and Switzerland, including the Accountability for Onward Transfer principles. 

With respect to Personal Data received or transferred pursuant to the Data Privacy Framework, Cvent is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission.  In certain situations, Cvent may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. 

If You have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request

Under certain conditions, more fully described on the Data Privacy Framework website https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction, You will be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted. 

 

APEC CBPR and PRP Systems 
Cvent's privacy practices, described in this Privacy Statement, also comply with the APEC Cross Border Privacy Rules System. The APEC CBPR system provides a framework for organizations to ensure protection of Personal Data transferred among participating APEC economies.  

Cvent's privacy practices, described in this Privacy Statement, comply with the APEC Privacy Recognition for Processors (PRP) system.  The APEC PRP system provides a framework for organizations to ensure protection of Personal Data transferred among participating APEC economies.     

 

Security 
We use appropriate organizational, technical and administrative measures to protect Personal Data obtained as discussed in this Privacy Statement from accidental or unlawful destruction, loss, alteration, disclosure and access.  We follow generally accepted information security industry standards to protect the Personal Data submitted to us, both during transmission and once it is received.  We also require our personnel, contractors, and service providers with access to Personal Data to adhere to these standards.  Cvent has a dedicated security department responsible for implementing measures necessary to achieve the objectives of the information security program. 

 

Changes 
We will update this Privacy Statement from time to time to reflect changes to our information practices. If we make any material changes we will notify You by means of a notice on this Website prior to the changes becoming effective. We encourage You to periodically review this page for the latest information on our privacy practices. 

 

U.S. State Supplementary Notice 
The California Consumer Privacy Act of 2018 (“CCPA”) became effective on January 1, 2020, and created a variety of privacy rights for California consumers.  Since that time, the CCPA was amended and additional states (such as Virginia, Colorado, Connecticut, Utah, Florida, Iowa, Indiana, Tennessee, Texas, Montana, Oregon, Delaware, New Hampshire, New Jersey, Nebraska, Kentucky, Maryland, Minnesota, Rhode Island) have passed laws extending similar privacy rights to their consumers.  More U.S. States are anticipated to pass similar legislation in the future.  This U.S. State Supplementary Notice includes disclosures required by applicable U.S. State privacy laws in addition to the information we have provided in this Global Privacy Statement, that is pertinent to consumers residing in any of the U.S. States that have passed privacy laws.  For the purposes of this Section, “Personal Data” shall be understood as “Personal Information” as defined under the CCPA and other applicable U.S. State privacy laws. 

 

Categories of Personal Data Collected in the past 12 months 

  • Identifiers such as a real name, postal address, Internet Protocol address, email address, or other similar identifiers.  
  • Categories of Personal Data described in subdivision (e) of California Civil Code Section 1798.80 (e.g., name, address, telephone number). 
  • Commercial information, including records of products or services purchased or considered. 
  • Internet or other electronic network activity information. 
  • Geolocation data (not precise). 
  • Audio and visual information, such as customer service call recordings and photographs. 
  • Professional or employment-related information. 
  • Education information. 
  • Contents of SMS/text messages and chats. 
  • Inferences drawn from any of the information identified above.  

 

Categories of Sensitive Personal Data Collected in the past 12 months 
As a business or data controller, Cvent has not collected Sensitive Personal Data of Customers or Visitors in the preceding 12 months to the effective date of this Privacy Statement.  

 

Sources from Which Personal Data Is Collected 
See “Who does this Privacy Statement apply to”? 

 

Business Purpose for Collecting this Personal Data 
Personal Data is collected and used for carrying out Cvent’s operational purposes, or for our service providers’ operational purposes (“business and commercial purposes”), specific examples of which are provided in the section titled “Personal Data We Collect, Purposes of Processing, and Legal Bases of Processing.” 

 

Has Cvent “sold” or “shared” this information to third parties? 
As a service provider or data processor, Cvent does not share or sell the Personal Data of any Customer's Client.  

Cvent has sold or shared Personal Data of its customers (as the terms “sell” and “share” are defined by the CCPA and other applicable U.S. privacy law) as follows: 

Categories of Personal Data Shared 

Categories of Third-Party Recipients 

Purpose for Disclosure 

Platform Activity, Usage Data, Identifiers 

Social Media Platform Advertisers, Advertising Networks and Platforms, Advertising Related Technology Providers 

Cross-Context Behavioral Advertising (as defined by the CCPA and its implementing regulations) 

Platform activity, usage data, business contact information of Planner Customers. 

Supplier Customers of Cvent 

To enable hotelier and supplier Customers of Cvent to strategically identify, engage, prospect for business, and manage existing relationships with event planners. 

If a Customer or Visitor wishes to have their information excluded from this type of disclosure, click here to submit a “Do Not Sell” or “Do Not Share” request.  

 

Your Privacy Rights and How to Exercise Them 
Complimentary with the Rights detailed above, as a consumer You have rights regarding the Personal Data we collect about You and maintain as a business or data controller, subject to certain limitations:  

  • Right to Request to Know what Personal Data we collect, use, disclose, share and sell about You. 
  • Right to Request Deletion of Your Personal Data.
  • Right to Opt-Out of the Sale or Sharing of Personal Data. 
  • Right to Limit the Use and Disclosure of Sensitive Information. We do not use or disclose Your Sensitive Personal Data.  If we ever do for reasons other than the legitimate business purpose described by applicable U.S. privacy law, we will update this Privacy Statement to provide You with notice and details on how to limit our use of Your Sensitive Personal Data.  
  • Right to Request Correction of Your Personal Data if it is inaccurate. 
  • Right to Non-Discrimination if You exercise any of Your rights under applicable U.S. privacy law. 

You may exercise Your privacy rights as detailed above using the same methods provided under “Your Privacy Rights”. 

Furthermore, under the CCPA, You may designate an authorized agent to make a request on Your behalf, provided, we require the agent to provide proof that You gave the agent signed permission to submit the request (in which case we may still require You verify Your identity) or a copy of Your power-of-attorney document granting the agent the right to act on Your behalf. 

 

Hong Kong Supplementary Notice 

In accordance with the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of Hong Kong, this Hong Kong Supplementary Notice applies to Customers, Visitors, and Customers’ Clients whose Personal Data is collected in or from Hong Kong and supplements the information provided in this Global Privacy Statement.  

Under the PDPO, Cvent is a "data user" in relation to Personal Data it collects directly from Customers and Visitors in connection with Cvent's Websites, marketing activities, and software applications. As a data user, Cvent is responsible for ensuring that Personal Data is collected and handled in compliance with the Data Protection Principles ("DPPs") set out in the PDPO. 

Where Cvent processes Personal Data on behalf of its Customers — for example, Personal Data about Customer's Clients collected through Cvent's Applications — Cvent acts as a data processor under the instructions of its Customers, who are the relevant data users for those processing activities. 

Cvent collects Personal Data from Customers and Visitors only for lawful purposes directly related to Cvent's functions and activities, as described in the "Personal Data We Collect, Purposes of Processing, and Legal Bases of Processing" section of this Statement. Personal Data will not be used for any new purpose without Your prior consent, except as permitted by the PDPO. 

 

Transfers of Personal Data Outside Hong Kong 
Cvent operates globally, and Your Personal Data may be transferred to, stored in, or processed in jurisdictions outside of Hong Kong, including the United States, countries in the European Economic Area (EEA), the United Kingdom, India, Australia, and Singapore. When transferring Your Personal Data outside of Hong Kong, Cvent takes steps to ensure that appropriate safeguards are in place to protect Your Personal Data, consistent with the requirements of the PDPO and Cvent's obligations as a data user. 

Such safeguards may include, as applicable: 

contractual protections with recipients of Your Personal Data requiring them to maintain standards of data protection comparable to those under the PDPO; and 

other organizational and technical measures appropriate to the circumstances of the transfer. 

 

Your Rights Under the PDPO 
Under the PDPO, You have the right to: 

Access Your Personal Data held by Cvent and request a copy of it; and 

Correct any Personal Data held by Cvent that is inaccurate. 

To exercise these rights, please submit a request using the methods set out under "Your Privacy Rights" above.  

 

Retention of Personal Data 
Cvent retains Personal Data for no longer than is necessary to fulfill the purposes for which it was collected, as described in the "Data Retention" section of this Statement. 

 

Contact for Hong Kong Privacy Matters 
If You have any questions or concerns regarding the handling of Your Personal Data under the PDPO, please contact us at the points provided under “Contact Us” below. 

 

China Supplementary Notice   

This China Supplementary Notice is provided in accordance with the Personal Information Protection Law of the People's Republic of China ("PIPL") and applies solely to personal data of individuals located in the People's Republic of China ("PRC" or "China") that is processed by Cvent in a limited capacity as described below. 

Cvent collects limited amounts of business contact information from or about Suppliers located in the PRC for purposes outlined in section titled: Personal Data We Collect, Purposes of Processing, and Legal Bases of Processing.  

In its capacity as an Event Management SaaS service provider, Cvent is an “Entrusted Party” under the PIPL, acting solely on the instructions of Cvent's Planner Customers. Cvent processes Personal Data of Customer’s Clients as set forth in the section titled Cvent as a Service Provider/Data Processor below, only to the extent necessary to deliver the contracted services to its Customers, and does not process such Personal Data for its own commercial or marketing purposes.  

 

Lawful Basis for Processing 
Cvent processes Personal Data of PRC-resident Planners and Supplier representatives on the following lawful bases under PIPL Article 13: contractual necessity (where Cvent and Planners are parties to a service agreement) and legitimate interests (in operating the sourcing platform). 

 

Cross-Border Transfer of Personal Data
Cvent operates globally, and Personal Data processed through Cvent's Applications may be transferred to, stored in, or accessed from jurisdictions outside of the PRC, including the United States, countries in the European Economic Area, the United Kingdom, Singapore, India, and Australia.

Under the PIPL, the obligation to fulfil cross-border transfer regulatory requirements — including any applicable governmental filings, security assessments, or standard contract formalities — rests with thePersonal Information Handler that exports the Personal Data outside of China. Where Cvent's Customers are the Personal Information Handlers and data exporters, those Customers bear the primary responsibility for ensuring that any cross-border transfer of Personal Data complies with applicable PIPL requirements.

Cvent, as an Entrusted Party, is not the data exporter in these arrangements. However, where a Customer that is a Personal Information Handler requires Cvent's cooperation in connection with the Customer's cross-border transfer compliance obligations, Cvent will provide reasonable assistance to support the Customer's compliance efforts in accordance with the terms of its agreement with that Customer. 

 

Your Rights Under the PIPL 
As a PRC-resident supplier representative whose Personal Data is processed by Cvent as a Personal Information Handler, You have the following rights under the PIPL: 

  • Right to be informed about how Your Personal Data is processed; 
  • Right to access Your Personal Data held by Cvent and to obtain a copy; 
  • Right to correct inaccurate or incomplete Personal Data; 
  • Right to delete Your Personal Data in circumstances provided under the PIPL, including where the processing purpose has been fulfilled or the retention period has expired; 
  • Right to restrict or object to the processing of Your Personal Data in certain circumstances; 
  • Right to data portability, to the extent required by the PIPL and applicable CAC regulations; and 
  • Right to withdraw consent, where Cvent processes Your Personal Data on the basis of consent, without affecting the lawfulness of processing carried out prior to withdrawal. 

To exercise any of the above rights, please submit a request using the methods set out under "Your Privacy Rights" above.   

 

Retention 
Cvent retains Personal Data of PRC-resident Planners and Supplier representatives for no longer than is necessary to fulfil the purposes described above, including for as long as a Supplier's property or services are listed on CSN or the Vendor Marketplace and for a reasonable period thereafter, and consistent with Cvent's data retention practices and the Data Retention section of this Global Privacy Statement. 

 

 

Cvent as a Service Provider/Data Processor 

 

What types of Personal Data do our Customers collect? 
Customers can use our customizable Applications to collect Personal Data in a variety of ways as outlined in the examples below.  

  • When a Customer's Client voluntarily and explicitly enters Personal Data into our Applications. 
  • When our Customers enter their Clients into our Applications, when permitted, including by having a legitimate business interest or obtaining consent from a Customer's Client. 
  • Automatically, as Customers’ Clients interact with our Applications, using commonly used information gathering technologies such as cookies. For additional information about these technologies, see this statement regarding Cvent Application Cookies. 

Our Applications are flexible and allow our Customers to collect a variety of Personal Data from and about their Clients according to each Customer’s needs.  We encourage Customers’ Clients to review the data controller’s privacy policies to further understand the types of data collected in their individual instances.  Cvent cannot and does not take responsibility for the privacy practices of its Customers.   

Cvent’s use of Customers’ Clients Personal Data collected through our Applications are as described below.  We do not sell or share the Personal Data of Customers’ Clients unless You explicitly consent. 

Cvent Customers will determine and configure exactly what data to collect from event registrants and participants via Cvent forms.  Personal data types will vary by event.  Below is a non-exhaustive list of examples of what is typically (thought not always) collected: 

Source 

Personal Data (examples) 

Purpose 

Customer's Client  

(e.g., registrant end users, event attendees, event invitees, speakers, sponsors, exhibitors, hotel guests) 

 

(Personal data types will vary by event and Customer determines what to collect.  This is a non-exhaustive list of examples.)  

Name and contact data, title/occupation, organization information, social media account ID, (voluntarily provided) personal preferences, opinions, interests, meal preferences.  

To support our engagements and carry out software services and transactions requested by our Customers; to register for an event, to check into an event, administer online surveys, to reserve meeting space or a room, to personalize content and make recommendations, to send You information and announcements relating to an event You have registered for 

To disclose to contractors, service providers, and other third parties as reasonably necessary or prudent to provide, maintain and support our Applications for our Customers, such as, for example, payment processors and data center or Web hosting providers 

To protect Your identity by aggregating data 

When a Customer's Client uses their social media credentials to share information on their social media platform or to log into one of our Applications, we will share information with their social media account provider. The information we share will be governed by the social media site’s privacy policy.  

Name and contact data 

To enable both marketing and non-marketing communications to You on behalf of our Customers 

Device and usage data 

 

To diagnose and resolve problems 

Contact and payment data (where Cvent Payments is used) 

If You use one of our Applications to pay for event registration fees or other products and services using a credit cards, we will pass the credit card information to payment card processors to validate the payment information and complete the transactions 

 

Name and contact data, job title, organization name and organizational information, profile picture, survey responses, Q&A features, comments, messages, poll responses 

To disclose to event organizers, exhibitors, or other attendees, as directed by a Customer or consented to by a Customer's Client, such as by consenting to having an exhibitor scan their event badge to share their contact information, opting-in or clicking to give consent to receive exhibitor information, or actively consenting to share information in a Cvent Application 

 

As instructed by Customer, to connect Customer's Clients with one another by relying on matching algorithms to recommend compatible Customer's Clients for optional business networking. 

 

As elected by You, to recommend event content  

Group Manager 

Same as above 

Another individual at Your organization or an agent may provide us with Your Personal Data, which may include Personal Data and special categories of Personal Data, to the extent You consent to providing it and sharing it with us for event registrations or room block reservations 

How can a Customer's Client access and control their Personal Data? 
Cvent processes Customer's Clients’ Personal Data under the direction of our Customers and has no direct control or ownership of the Personal Data about You that we process. Customers are responsible for complying with any regulations or laws requiring notice, disclosure or obtaining consent prior to transferring the data to Cvent for processing purposes. Any Customer's Client that seeks to access, correct or delete data, should direct their query to the Customer, who is the data controller. If the Customer requests Cvent to delete, rectify or access the Personal Data of a Customer's Client to comply with data protection regulations, Cvent will process this request within the required time under the applicable regulation or law, or as otherwise required under its customer service agreement.

We will not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect. In such instances, we will inform the Customer about the legal obligations that prevent us from fulfilling the request.  

 

Contact Us 

If You have a privacy concern or question related to Cvent’s Global Privacy Statement for Cvent’s Legal Team or Data Protection Officer, please contact the (EU based) DPO at dpo@cvent.com.  You may also contact Cvent at: 

Cvent Representative 
1765 Greensboro Station Place, 7th Floor 
Tysons Corner, Virginia 22102 
privacy@cvent.com 

If You have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.