Cornerstone Website Privacy Policy

Cornerstoneondemand.com - Website Privacy Policy

**This policy was last updated September 2025**

About Cornerstone OnDemand

Cornerstone, a leader in workforce agility solutions delivered via Software-as-a-Service (SaaS). As such, our customers use our system to manage the personal information of their employees and candidates across the world. Such personal information falls under different national and international regulations regarding the management and protection of same.

To learn more about the Cornerstone applications, visit our platforms page.

Scope

Cornerstone OnDemand, Inc. and its subsidiaries (collectively, “Cornerstone” or “we”) have developed this Website Privacy Policy (the “Policy”) out of respect for the privacy of visitors to www.cornerstoneondemand.com (the “Website”). This Policy describes the personal information we collect, use, and disclose about individuals who visit or interact with the Website, or who use the Website to inquire about any of our products or services.

Whenever you visit the Website, we will collect some information from you automatically simply by you visiting and navigating through the Website, and some voluntarily when you submit information via the Website, such as when you submit a form, utilize the chatbot feature, book a demo, watch a webinar, attend an event, subscribe to our newsletter or marketing communications, request information about our products or services, or use any of the other interactive portions of the Website. Through the Website, we will collect information that can identify you and/or your activity.

The term “personal information” in this policy, means any information collected by Cornerstone that can reasonably be used to identify an individual and includes similar terms as defined by various jurisdictions.

Personal information does not include:

  1. Publicly available information from government records.
  2. Information Cornerstone reasonably believes is legally available to the public from a consumer, independent contractor, applicant, or widely distributed media.
  3. Information made available by a person to whom a consumer, independent contractor, or applicant has disclosed the information if the consumer, independent contractor, or applicant has not restricted the information to a specific audience.
  4. Deidentified or aggregated information.

For the purpose of clarity, this policy does not apply to personal information that we process on behalf of our customers in our role as a data processor or service provider. For such processing activities, customers remain the data controllers, and their respective privacy notices apply. If you are an employee, contractor, or job applicant of an organization that uses Cornerstone’s products and services, please contact your employer for any privacy related inquiries.

This policy does not apply to information collected from or about job applicants regarding their application for employment or candidacy with Cornerstone. If you are a job applicant, please email us at dpo@csod.com with any privacy related inquiries.

This policy does not apply to Cornerstone’s current and former employees; if you are a current or former employee of Cornerstone or a family member, dependent, or beneficiary of any of our current or former employees, you may request access to our Employee Privacy Policy by sending an email to talentservicecenter@csod.com

International Visitors

By providing personal information to us through this Website, you agree that it may be usedfor the purposes described herein, and you further understand and consent to the collection, maintenance, processing, and transfer of such information in and to the United States and other countries and territories, which may have different privacy laws from your country of residence, and which may afford varying levels of protection for your personal information. Where the laws provide less protection than the protections afforded by this Policy, however, we will treat the privacy of your information in accordance with this Policy. By providing your personal information to the Website, you consent to us transmitting and processing your information in any jurisdiction, in accordance with this Policy.

Consent to Terms and Conditions

By using the Website, you consent to all terms and conditions expressed in this Policy.

How Cornerstone Collects Your Personal Information

Cornerstone collects and uses personal information for various reasons. When we do so, we will use it in accordance with applicable laws.

Some jurisdictions, including the European Economic Area (“EEA”), the United Kingdom (“UK”), and Switzerland, require a legal basis, which means a reason why Cornerstone is legally allowed to collect and use your personal information.

Below, we describe (1) in what instances we collect your information, (2) the categories of information we collect in those instances, (3) our purposes for collection, and (4) the legal bases for collection. If we need to collect other personal information from you, we will explain which information we need and why at the time we collect it.

Source: Visitors to our Site

Data Elements

  • First Name
  • Company
  • Job Title
  • Address
  • Phone Number
  • Email Address
  • We collect information such as IP address, device type, unique device identification numbers, browser type, broad geographic location (including country or city-level location based on public IP address), performance data, and other technical and usage details. This includes information about interactions with our websites (such as referring pages, visited pages, and features used), emails, content, and site features (for example, opening marketing emails, clicking embedded links, watching videos, or using the chat function). Some information is gathered through cookies and similar tracking technologies, as detailed in our Cookie Statement. We do not collect “sensitive personal information” as defined by California law and similar regulations globally and therefore do not offer a method to request limitations on the use of sensitive personal information.

Purpose/Legal Basis

To fulfill the purpose(s) for which the information was collected or provided, including to communicate with you and respond to your inquiries and requests.

To:

  • Understand our website visitors, where they are visiting the website from, and their interests to improve site quality and relevance through internal analytics.
  • Operate and maintain our websites, provide requested content, and display country-specific information.
  • Protect security and prevent misuse by tracking usage, verifying accounts, investigating suspicious activity, and enforcing terms and policies.

The Website may include social media features, such as video links and other functionality to demonstrate your interest in the Website and other materials and may set a cookie to enable such functionality. This functionality may be hosted by a third party or hosted directly on the Website. When provided or hosted by a third party, your use and interactions with these features is at your discretion and is governed by the privacy policy of the companies providing them.


Legal Basis
: Legitimate Interest

Source: Third Parties or Publicly Available Sources (including purchased business contact information)

Data Elements:

  • First name
  • Last name
  • Business Email
  • Telephone number
  • Company name
  • Job level
  • Functional role
  • Business street address
  • Online identifier
  • Work related information

Purpose/Legal Basis:

We use this data for our internal customer analytics, to identify prospective customer marketing opportunities, and to improve the relevance of Website content and our advertising.

We may collect or receive personal information from third parties including from our affiliates, marketing companies, job posting websites, and recruiting firms. Cornerstone may license this data from third parties, or it may be available publicly.

Analytics information and to administer and enable the use of the Website.

Legal Basis: Legitimate Interest

Source: Directly from you as a user of our services

Data Elements:

  • First name
  • Last name
  • Business Email
  • Telephone number
  • Company name
  • Emergency contact (in some instances)
  • Dietary preferences (in some instances)
  • Health and safety information (in some instances)
  • Billing information (such as billing name, billing address, and credit card number)

Purpose/Legal Basis:

If you register to attend a Cornerstone-sponsored event, we may require certain data.

Legal Basis: Performance of Contract & Legitimate Interest

Source: Analytics Information from the Use of the Website (“Usage Data”)

Data Elements:

  • IP address
  • Mobile Phone Number
  • User Settings
  • Mobile Advertising and Other Unique Identification Numbers
  • Browser, Device and Operating System Details
  • Location information (inferred from your IP address)
  • Internet Service Provider
  • Clickstream Data
  • Cookie Data (see below)

Information about how you interact with and use the services.

Purpose/Legal Basis:

Our Website collects data such as access frequency, visit events, aggregated usage, performance metrics, and your IP address. We use this information to analyze, improve, and develop our Website.

Legal basis: Consent for device-level data processing and legitimate interests for other Usage Data as required by law.

Use of Cookies, Pixels, and Other Tracking Technologies

The Website may store or retrieve information on your browser, mostly in the form of cookies. A cookie is a small piece of data (text file) that a website – when visited by a user – places on the user’s device to remember information about the user, such as the user’s language preference or login information.

We also incorporate cookies and similar technologies, such as pixels, tags, and web beacons, from outside the Website’s domain (“third-party cookies”). Third-party cookies gather information to enable our vendors to provide a range of services to us, including targeted advertising and measuring the success of our advertising campaigns.

For more information about the technologies, we use and how you can control these technologies please see our Cookie Statement

Consent to Use of AI Technology

Certain Website features may be supported by third party vendors that utilize AI technology. When utilizing the chatbot and other features of our website, our AI vendor(s) such as ZoomInfo and 6sense may record and transcribe information and may access the information in real-time and use the information for their own purposes, including to train their AI model. By using the Website and the chatbot, you consent to the collection and analysis of any personal information provided. If you do not consent to such use and disclosure, please do NOT use the Website. For more information on how 6sense may use or disclose personal information, please review their privacy policy HERE. For more information on how ZoomInfo may use or disclose personal information, please review their privacy policy HERE.

External Links

The Website contains links to other sites. We are not responsible for the privacy practices or the content of such websites. To help ensure the protection of your privacy, we recommend that you review the privacy policy of any site you visit via a link from the Website.

Sharing and Disclosing Personal Information

Cornerstone does not sell personal information to third parties. The term “sell,” as defined by relevant laws, refers to the disclosure of personal information to third parties in exchange for monetary or other valuable considerations.

The following sections explain how we may share your personal information.

Affiliates:

Personal information may be disclosed between Cornerstone entities if necessary to fulfill a specific request.

Third Parties (Vendors/Service Providers):

We may work with third parties such as vendors or service providers to complete requested tasks; conduct marketing and advertising; operate, secure, and optimize the Website; and collaborate with partners.

Contracts with these third parties specify that they act on our behalf and only under our direction. These agreements include confidentiality and data protection terms, ensuring that third parties use personal information solely as needed to perform contracted services in accordance with our instructions and the purposes outlined.

Additional Disclosures

Personal information may also be disclosed as necessary to:

  1. Provide webinars.
  2. Support administration and business operations or maintain records of relationships.
  3. Comply with legal obligations or respond to lawful requests from authorities.
  4. Manage litigation, audits, and investigations, including the protection of rights and investigation of potential fraudulent or illegal activity.
  5. Protect against unauthorized use of the Website.
  6. Support personal safety or property of users or the public.
  7. Facilitate activities in connection with mergers, asset sales, restructurings, financing, or acquisitions, including transferring contact data.
  8. Share information in an aggregated, de-identified, or anonymized format; and
  9. When consent is provided.

Except as described in this Policy, personal information will not be released to unknown or unaffiliated third parties, nor will it be cross-referenced with the information of other Website visitors.

Do We Sell Your Information?

We do NOT and will not sell or share your PI in exchange for monetary consideration. However, we may share some of your PI with third parties for other valuable consideration, as noted below.

We may share your PI for the following business or commercial purposes:

  1. To improve your experience on our Website.
  2. To send you advertisements that are tailored to your interests.
  3. To generate leads for advertising and marketing.
  4. To fulfill contractual obligations with our vendors.

Other than these exceptions, we do not and will not disclose your PI to any third party in exchange for monetary or other valuable consideration or share your PI for cross-context behavioral advertising.

International Transfers

Cornerstone operates as a global business and complies with applicable legal requirements when we need to transfer, store, or process your personal information in a country outside your jurisdiction.

We take appropriate safeguards to protect your privacy, your fundamental rights and freedoms, and the ability to exercise your rights. For example, if we transfer personal information from the EEA, the UK, or Switzerland to another country such as the United States, we will implement an appropriate data transfer solution such as entering into “standard contractual clauses” approved by the European Commission or competent governmental authority (as applicable) with the data importer.

If you reside in the European Economic Area, European Union, the United Kingdom, or Switzerland, submitted personal information to Cornerstone, and want to request a copy of, correct, delete, or limit the ways the Cornerstone uses the information, send an email to DPO@csod.com indicating your request. Cornerstone will use reasonable and appropriate measures to honor your request.

Data Privacy Framework

Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C. and SumTotal Systems L.L.C. have self-certified commitment with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.

Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C and SumTotal Systems L.L.C. have certified to the U.S. Department of Commerce that they adhere to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.

Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C and SumTotal Systems L.L.C. have certified to the U.S. Department of Commerce that they adhere to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.

If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov.

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C and SumTotal Systems L.L.C commit to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C. and SumTotal Systems L.L.C. at: DataPrivacyFramework@csod.com

In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C and SumTotal Systems L.L.C. commit to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF in the context of the employment relationship.

As required under the principles, when we receive information under the Data Privacy Framework and then transfer it to a third-party service provider acting as an agent on our behalf, we have certain liability under the Data Privacy Framework if the agent processes the information in a manner inconsistent with the Data Privacy Framework and we are responsible for the event giving rise to the damage.

We encourage you to contact us at DPO@csod.com should you have a Data Privacy Framework related (or general privacy-related) complaint. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact the independent recourse mechanism listed below:

UK Information Commissioner's Office (ICO)

EU Data Protection Authorities (DPAs)

We have committed to cooperating and complying with the information and advice provided by an informal panel of data protection authorities in the European Economic Area, and/or the Swiss Federal Data Protection and Information Commissioner (as applicable) in relation to unresolved complaints (as further described in the Data Privacy Framework Principles). You may also contact your local data protection authority within the European Economic Area or Switzerland (as applicable) for unresolved complaints.

Under certain conditions, more fully described on the Data Privacy Framework website, including when other dispute resolution procedures have been exhausted, you may invoke binding arbitration.

Cornerstone OnDemand, Inc., Saba Software, Inc., EdCast L.L.C. and SumTotal Systems L.L.C. are subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).

Retaining Personal Information

We will retain each category of personal information in accordance with our established data retention policy and practice. In deciding how long to retain each category of personal information that we collect, we consider many criteria, including but not limited to the business purposes for which the personal information was collected; relevant federal, state and local recordkeeping laws; applicable statute of limitations for claims to which the information may be relevant; and legal preservation of evidence obligations.

We apply our data retention procedures on an annual basis to determine if the business purposes for collecting the personal information, and legal reasons for retaining the personal information, have both expired. If so, we will purge the information in a secure manner.

Your Privacy Rights

Under applicable privacy laws, depending on residence, you may be entitled to exercise some or all the following rights, regarding our collection, use, and sharing of your personal information:

Right to Know

You may request, (1) the categories of personal information we have collected about you, (2) the categories of sources from which the personal information was collected, (3) the business or commercial purpose for collecting, selling, or sharing this information, (4) the categories of third parties with whom we share or have shared your personal information, (5) as applicable, the categories of personal information that we have shared about you and the categories of third parties to whom the personal information was shared, by category or categories of personal information for each category of third parties to whom the personal information was sold or shared, (6) the categories of personal information that we have disclosed about you for a business purpose and the categories of persons to whom it was disclosed for a business purpose, and (7) a list of the specific third parties to whom we sell personal data.

Right to Access

You may receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal information to another person.

Right to Portability

You may receive a copy of the personal information you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal information to another person.

Right to Confirm

You may confirm if we are processing your Personal Information and to access your personal information, as just stated above.

Right to Delete

You may request that we delete personal information that we collected from you, subject to certain exceptions.

Right to Correct

You may request we correct inaccurate personal information (to the extent such an inaccuracy exists) that we maintain about you.

Right to Opt-Out

You may, depending on your jurisdiction of residence, have the right to opt-out of certain uses or disclosures of your personal information, including opting out of the selling of your personal information or the sharing of such information for cross-context behavioral advertising purposes. To learn more about this right and how to exercise it, please refer to the detailed discussion in the section above.

Right to Non-Discrimination

You have the right to not be discriminated against or retaliated against for exercising any of the above rights.

Right to Appeal

You may, depending on your jurisdiction of residence, have the right to appeal our refusal to take action on a request.

To protect your privacy and security, we take reasonable steps to verify your identity before granting access to your personal information. Please follow the instructions below based on your relationship with Cornerstone and provide the requested information to allow us to adequately address your request.

We will respond to your request within a reasonable timeframe and as otherwise required by applicable law in your jurisdiction.

If you are not a California resident and would like to request access to your personal information or request erasure (right to be forgotten) of personal information previously provided, please email us at dpo@csod.com

You may contact Cornerstone with any questions or concerns at dpo@csod.com

California Rights – California Privacy Notice

For California residents, The California Consumer Privacy Act (“CCPA”) provides certain privacy-related rights. If you are a California resident, please see Cornerstone’s California Privacy Notice.

Do Not Track

Some internet browsers may be configured to send “Do Not Track” signals to the websites that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please click here.

How We Protect Your Personal Information

The protection of the information that we collect about visitors to the Website is of the utmost importance to us and we have implemented commercially reasonable measures designed to ensure that protection, including the following:

  • We utilize physical, technical, and administrative controls and procedures designed to safeguard the information we collect, prevent unauthorized access or disclosure, to maintain data accuracy of your personal information, and to restrict the processing of your personal information as set forth in this Policy.
  • We restrict access to personal information to those who need such access in the course of their duties for us. Certain of our employees who have been granted access to your personal information are made aware of their responsibilities to protect the confidentiality, integrity, and availability of that information and have been provided training and instruction on how to do so.
  • We utilize a variety of physical and logical access controls, firewalls, intrusion detection and prevention systems, network and database monitoring, anti-virus, and backup systems. We use encrypted sessions when collecting or transferring sensitive data through the Website.
  • For additional information regarding Cornerstone’s commitment to cybersecurity, please refer to the Cornerstone Trust Center.

Children Under the Age of 13

This Website is not directed at children under the age of thirteen. We do not knowingly collect personal information from children under the age of thirteen on our Website. If we become aware that we have inadvertently received personal information from a visitor under the age of thirteen on our Website, we will delete the information from our records.

Website Visitors with Disabilities

This policy is in a form that is accessible to website visitors with disabilities.

Changes To This Policy

As our Website evolves and we perceive the need or desirability of using information collected in other ways, we may from time to time amend this Policy. We encourage you to check the Website frequently to see the current Policy in effect and any changes that may have been made to it. If we make material changes to this Policy, we will post the revised Policy and the revised effective date on the Website. Please check back here periodically or contact us at the address listed at the end of this Policy.

Questions About the Policy

This website is owned and operated by Cornerstone. If you have any questions about this Policy, please contact us at dpo@csod.com.