- What Personal Data Do We Receive?
- How Do We Use Personal Data?
- How Do We Share Personal Data?
- Who Can See, Share, and Process My Personal Data When I Join Meetings and Use Other Zoom Products and Services?
- Privacy Rights and Choices
- How to Contact Us
- European Data Protection Specific Information
- California Privacy Rights
- Changes to This Privacy Statement
Personal data is any information from or about an identified or identifiable person, including information that Zoom can associate with an individual person. We may collect, or process on behalf of our customers, the following categories of personal data when you use or interact with Zoom products and services:
- Account Information: Information associated with an account that licenses Zoom products and services, which may include administrator name, contact information, account ID, billing and transaction information, and account plan information.
- Profile and Participant Information:Information associated with the Zoom profile of a user who uses Zoom products and services under a licensed account or that is provided by an unlicensed participant joining a meeting, which may include name, display name, picture, email address, phone number, job information, stated locale, user ID, or other information provided by the user and/or their account owner.
- Contacts and Calendar Integrations: Contact information added by accounts and/or their users to create contact lists on Zoom products and services, which may include contact information a user integrates from a third-party app, or provided by users to process referral invitations. Users can also integrate their calendars from other services with their Zoom profile or account.
- Email Information: Email information, including email content, headers and metadata, if account owners and/or their users integrate their emails with products and services offered or made available by Zoom, such as business analytics tools like ZoomIQ.
- Settings: Information associated with the preferences and settings on a Zoom account or user profile, which may include audio and video settings, recording file location, screen sharing settings, and other settings and configuration information.
- Registration Information: Information provided when registering for a Zoom meeting, webinar, Zoom Room, or recording, which may include name and contact information, responses to registration questions, and other registration information requested by the host.
- Device Information: Information about the computers, phones, and other devices used when interacting with Zoom products and services, which may include information about the speakers, microphone, camera, OS version, hard disk ID, PC name, MAC address, IP address (which may be used to infer general location at a city or country level), device attributes (like operating system version and battery level), WiFi information, and other device information (like Bluetooth signals).
- Content and Context from Meetings, Webinars, Messaging, and Other Collaborative Features: Content generated in meetings, webinars, or messages that are hosted on Zoom products and services, which may include audio, video, in-meeting messages, in-meeting and out-of-meeting whiteboards, chat messaging content, transcriptions, transcript edits and recommendations, written feedback, responses to polls and Q&A, and files, as well as related context, such as invitation details, meeting or chat name, or meeting agenda. Content may contain your voice and image, depending on the account owner’s settings, what you choose to share, your settings, and what you do on Zoom products and services.
- Product and Website Usage:Information about how people and their devices interact with Zoom products and services, such as: when participants join and leave a meeting; whether participants sent messages and who they message with; performance data; mouse movements, clicks, keystrokes or actions (such as mute/unmute or video on/off), edits to transcript text, where authorized by the account owner and other inputs that help Zoom to understand feature usage, improve product design, and suggest features; which third-party apps are added to a meeting or other product or service and what information and actions the app is authorized to access and perform; use of third-party apps and the Zoom App Marketplace; features used (such as screen sharing, emojis, or filters); and other usage information and metrics. This also includes information about when and how people visit and interact with Zoom’s websites, including what pages are accessed, interaction with website features, and whether or not the person signed up for a Zoom product or service.
- Communications with Zoom:Information about your communications with Zoom, including relating to support questions, your account, and other inquiries.
- Information from Partners: Zoom obtains information about account owners and their users from third-party companies, such as market data enrichment services, including information about an account owner’s company size or industry, contact information, or activity of certain enterprise domains. Zoom may also obtain information from third-party advertising partners who deliver ads displayed on Zoom products and services, such as whether you clicked on an ad they showed you.
Zoom employees do not access meeting, webinar, or messaging content (specifically, audio, video, files, in-meeting whiteboards, and messages), or any content generated or shared as part of other collaborative features (such as out-of-meeting whiteboards or emails), unless directed by an account owner, or as required for legal, safety, or security reasons, as discussed below. Zoom uses personal data to conduct the following activities:
- Provide Zoom Products and Services: To provide products and services to account owners, their users, and those they invite to join meetings and webinars hosted on their accounts, including to customize Zoom products and services and recommendations for accounts or their users. Zoom also uses personal data, including contact information, to route invitations and messages to recipients when users send invitations and messages using Zoom products and services. This may also include using personal data for customer support, which may include accessing audio, video, files, messages, and other content or context, at the direction of the account owner or their users. We also use personal data to manage our relationship and contracts with account owners and others, including billing, compliance with contractual obligations, facilitating payment to third-party developers in relation to purchases made through the Zoom App Marketplace, and related administration.
- Advanced Voice and Video Features: If you elect to use certain video features, such as filters, avatars, and gestures, information about your movements or the positioning of your face or hands may be processed on your device to apply the selected features. Such data does not leave your device, is not retained, and cannot be used to identify you. If certain features are enabled, such as transcription generation for recordings, Zoom may use technology that analyzes the meeting’s audio recording to distinguish one speaker from another in order to create an accurate transcript. The audio analysis is not retained after the transcript is generated.
- Product Research and Development: To develop, test, and improve Zoom products and services, including, for example, content-related features (such as background and other filters), and to troubleshoot products and services.
- Marketing, Promotions, and Third-Party Advertising: To permit Zoom and/or its third party marketing partners to market, advertise, and promote Zoom products and services, including based on your product usage, information we receive from third-party partners, information you provide to process referral invitations, or if you visit our websites, information about how and when you visit, and your interactions with them. We may also use this information to provide advertisements to you relating to Zoom products and services or to engage third party partners to analyze your interactions on our website or app or to deliver advertising to you. Zoom does not use meeting, webinar, or messaging content (specifically, audio, video, files shared, in-meeting whiteboards, and messages), or any content generated or shared as part of other collaborative features (such as out-of-meeting whiteboards or emails) for any marketing or promotions.
- Authentication, Integrity, Security, and Safety: To authenticate accounts and activity, detect, investigate, and prevent malicious conduct or unsafe experiences, address security threats, protect public safety, and secure Zoom products and services.
- Communicate with You:We use personal data (including contact information) to communicate with you about Zoom products and services, including product updates, your account, and changes to our policies and terms. We also use your information to respond to you when you contact us.
- Legal Reasons: To comply with applicable law or respond to valid legal process, including from law enforcement or government agencies, to investigate or participate in civil discovery, litigation, or other adversarial legal proceedings, and to enforce or investigate potential violations of our Terms of Service or policies.
Zoom uses advanced tools to automatically scan content such as virtual backgrounds, profile images, and files uploaded or exchanged through chat, for the purpose of detecting and preventing violations of our terms or policies and illegal or other harmful activity, and its employees may investigate such content where required for legal, safety, or security reasons.
Zoom provides personal data to third parties only with consent or in one of the following circumstances (subject to your prior consent where required under applicable law):
- Resellers: If an account owner licensed or purchased Zoom products and services from a third-party reseller of Zoom products and services, the reseller may be able to access personal data and content for users, including meetings, webinars, and messages hosted by the account owner.
- Vendors: Zoom works with third-party service providers to provide, support, and improve Zoom products and services and technical infrastructure, and for business services such as payment processing, including in relation to purchases made through the Zoom App Marketplace. Zoom may also work with third-party service providers to provide advertisements and business analytics regarding Zoom products and services. These vendors can access personal data subject to contractual and technical requirements for protecting personal data and prohibiting them from using personal data for any purpose other than to provide services to Zoom or as required by law. Zoom may integrate third-party technology to provide advanced features, such as Apple’s TrueDepth technology, to process information on your device about face or hand dimensions and gestures to provide video effects. This information is processed on your device, and such information is neither received nor stored by either the third party, or Zoom.
- For Legal Reasons: Zoom may share personal data as needed to: (1) comply with applicable law or respond to, investigate, or participate in valid legal process and proceedings, including from law enforcement or government agencies; (2) enforce or investigate potential violations of its Terms of Service or policies; (3) detect, prevent, or investigate potential fraud, abuse, or safety and security concerns, including threats to the public; (4) meet our corporate and social responsibility commitments; (5) protect our and our customers’ rights and property; and (6) resolve disputes and enforce agreements.
- Marketing, Advertising, and Analytics Partners: Zoom uses third-party marketing, advertising, and analytics providers: to provide statistics and analysis about how people are using Zoom products and services, including our website; and to provide advertising and marketing for Zoom products and services, including targeted advertising based on your use of our website. These third-party partners may receive information about your activities on Zoom’s website through third-party cookies placed on Zoom’s website. To opt out of our use of third-party cookies that share data with these partners, visit our cookie management tool, available in Cookies Settings. Where required by law, Zoom will first obtain your consent before engaging in the marketing or advertising activities described.
- Corporate Affiliates: Zoom shares personal information with corporate affiliates, such as Zoom Voice Communications, Inc., to provide integrated and consistent experiences across Zoom products and services (such as enabling an account owner or their user to integrate a Zoom Phone call into a meeting) and to detect, investigate, and prevent fraud, abuse, and threats to public safety.
- Change of Control: We may share personal data with actual or prospective acquirers, their representatives and other relevant participants in, or during negotiations of, any sale, merger, acquisition, restructuring, or change in control involving all or a portion of Zoom’s business or assets, including in connection with bankruptcy or similar proceedings.
- Third-Party Developers:If you purchase a third-party app or integration from the Zoom App Marketplace, Zoom may share information about the purchase with the third-party developer, to provide the app or integration.
Who Can See, Share, and Process My Personal Data When I Join Meetings and Use Other Zoom Products and Services?
When you send messages or join meetings and webinars on Zoom, other people and organizations, including third parties outside the meeting, webinar, or message, may be able to see content and information that you share:
- Account Owner: An account owner is the organization or individual that signs up for a Zoom account. Typically, an account owner designates one or more people (called an “administrator”) to manage their account and can grant privileges to users on the account. Depending on their license with Zoom, the account owner can authorize additional users on their account, and the account owner can create and/or access the profile information for all users on their account. The account owner and their users can invite others (including guests not on their account and unlicensed participants) to meetings or webinars hosted on their account.
Zoom gives account owners controls and features that they can use to determine whether certain types of content, such as recordings or out-of-meeting messages, can be created or sent, and what third-party apps can be used, for meetings and webinars hosted on their account. Depending on their settings, account owners and the users they designate can access personal data for participants who join meetings and webinars on their account or send messages to users on their account. Specifically, account owners may have access to:
- Account Usage:
- Product Usage: Information about how users and their devices interact with their account, which may include who sent messages to their users in chat, email addresses, IP addresses, device information, and other information about who joined meetings or webinars on their account, whether their users viewed or downloaded a recording, how long participants participated in their meetings, the time a message was sent, information about Zoom Phone integrations, and other usage information and feedback metrics.
- Participant List: Information about the participants in a Zoom meeting, webinar, or chat, which may include name, display name, email address, phone number, and participant or user ID.
- Registration Information: Information provided during registration for a webinar, meeting, Zoom Room, or recording hosted by the account.
- Zoom Team Chat Out-of-Meeting Messages: If enabled on their account, account owners and those they authorize can see information about who sent and received out-of-meeting messages to users on their account along with information about the message (for example, date and time, and number of participants). Depending on their settings, account owners also can see sender and receiver information, and other messaging data, along with the content of messages sent to and from users on their account, unless the account owner has enabled Advanced Chat Encryption. Depending on their settings, account owners and those they authorize may also see the content shared through collaborative features, including whiteboards, files, and images shared in out-of-meeting chat.
- In-Meeting/Webinar Messages: Depending on their settings, account owners can see sender and receiver information, along with the content of messages sent to and from users on their account, in the following circumstances:
- Messages sent to Everyone in a meeting that is recorded
- Messages sent to panelists in a webinar that is recorded
- Direct messages if the account owner has enabled archiving
- If a participant in a meeting is subject to archiving, their account owner will have access to messages sent to Everyone in the meeting, as well as direct messages sent to that participant.
- Recordings: Account owners can watch the content of recordings of meetings and webinars hosted on their account. They can also view, share, and enable advanced features for transcripts of meeting audio.
- Polling, Q&A, and Feedback: Account owners can see information about who provided responses to their polls, Q&A, or post meeting or webinar feedback requests, including name and contact information, together with the responses or feedback, unless responses are submitted anonymously.
- Account Usage:
- Meeting Hosts, Participants, and Invitees: Hosts, participants, and invitees may be able to see your email, display name, and profile picture. Meeting hosts, participants, and invitees can also see and (depending on the account owner’s settings) record or save meeting content, audio transcripts, messages sent to Everyone or to them directly, and files, whiteboards or other information shared during a meeting. Hosts may also be able to see responses to Q&A and polls generated during the meeting.
- Webinar Panelists and Attendees: Only panelists may be visible to attendees during a webinar, but attendees who agree to unmute can be heard by other attendees. If an attendee agrees to become a panelist during a webinar, they may be visible to other attendees, depending on settings. Panelists and attendees may be able to see the name of a participant who asks a question during a Q&A, along with their question, unless the participant submits the question anonymously.
- Livestreams: Meeting and webinar hosts can choose to livestream to a third-party site or service, which means anyone with access to the livestream will be able to see the meeting or webinar.
- Apps and Integrations:
- Account owners can choose to add Zoom-developed apps and third-party apps to their account and the Zoom Products they use, including via use of the Zoom App Marketplace, and they can also control whether their users can add and use specific Zoom and third-party apps, including in meetings, webinars, and chats hosted on their account.
- Account owners can also choose to integrate other content – such as email communications on their corporate account – to apps and services that they use, such as Zoom IQ (a Zoom-developed application that provides insights and business analytics related to businesses when they use Zoom Products). Further, account owners may choose to have Zoom analyze the meeting’s audio recording to distinguish one speaker from another in order to create an accurate transcript. The audio analysis is not retained after the transcript is generated.
- Depending on their settings, account owners’, users’ and guests’ personal data and content may be shared with apps and integrations approved by account owners, which may include all of the personal data categories listed above, such as account information, profile and contact information, registration information, participants list, settings, content, product usage, device information, or emails that have been shared with the app.
- Other participants in the meeting may be able to see the app that you are using in a meeting, if the app is receiving content (including audio and video) from the meeting.
- Third-party developers may also integrate or embed Zoom meetings into their website or app experiences or build versions of Zoom that enable access to Zoom Products from a third-party app.
- Personal information shared by account owners and users with third-party apps and integrations is collected and processed in accordance with the app developers’ terms and privacy policies, not Zoom’s.
If you are in the European Economic Area (EEA), Switzerland, or the UK, or a resident of California, please refer to the respective dedicated sections below. Otherwise, at your request, and as required by applicable law, we will:
- Inform you of what personal data we have about you that is under our control;
- Amend or correct such personal data or any previous privacy preferences you selected, or direct you to
applicable tools; and/or
- Delete such personal data or direct you to applicable tools.
In order to exercise any of your rights as to personal data controlled by Zoom, please click here. Where legally permitted, we may decline to process requests that are unreasonably repetitive or systematic, require disproportionate technical effort, or jeopardize the privacy of others. As an account owner or a user under a licensed account, you may also take steps to affect your personal data by visiting your account and modifying your personal data directly.
Zoom does not allow children under the age of 16 to sign up for a Zoom account.
For educational organizations that use Zoom products and services to provide educational services to children under 18, Zoom’s Children’s Educational Privacy Statement is available here.
You can also contact us by writing to the following address:
Zoom Video Communications, Inc.
Attention: Data Privacy Officer
55 Almaden Blvd, Suite 600
San Jose, CA 95113
Or to our representative in the EU or UK:
Lionheart Squared Ltd
Attn: Data Privacy
2 Pembroke House
Upper Pembroke Street 28-32
Republic of lreland
Lionheart Squared Limited
Attn: Data Privacy
17 Glasshouse Studios
Fryern Court Road
You can contact our Data Protection Officer by sending an email to firstname.lastname@example.org.
We retain personal data for as long as required to engage in the uses described in this Privacy Statement, unless a longer retention period is required by applicable law.
The criteria used to determine our retention periods include the following:
- The length of time we have an ongoing relationship with you and provide Zoom products and services to you (for example, for as long as you have an account with us or keep using our products);
- Whether account owners modify or their users delete information through their accounts;
- Whether we have a legal obligation to keep the data (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); or
- Whether retention is advisable in light of our legal position (such as in regard to the enforcement of our agreements, the resolution of disputes, and applicable statutes of limitations, litigation, or regulatory investigation).
Data Subjects Rights
If you are in the EEA, Switzerland, or the UK, your rights in relation to your personal data processed by us as a controller specifically include:
- Right of access and/or portability: You have the right to access any personal data that we hold about you and, in some circumstances, have that data provided to you so that you can provide or “port” that data to another provider;
- Right of erasure: In certain circumstances, you have the right to the erasure of personal data that we hold about you (for example, if it is no longer necessary for the purposes for which it was originally collected);
- Right to object to processing: In certain circumstances, you have the right to request that we stop processing your personal data and/or stop sending you marketing communications;
- Right to rectification: You have the right to require us to correct any inaccurate or incomplete personal data;
- Right to restrict processing: You have the right to request that we restrict processing of your personal data in certain circumstances (for example, where you believe that the personal data we hold about you is not accurate or lawfully held).
To exercise your rights, please click here. If you have any other questions about our use of your personal data, please send a request at the contact details specified in the How to Contact Us section of this Privacy Statement. Please note that we may request you to provide us with additional information in order to confirm your identity and ensure that you are entitled to access the relevant personal data.
You also have the right to lodge a complaint to a data protection authority. For more information, please contact your local data protection authority.
Legal Basis for Processing Personal Data
We only use your information in a lawful, transparent, and fair manner. Depending on the specific personal data concerned and the factual context, when Zoom processes personal data as a controller for individuals in regions such as the EEA, Switzerland, and the UK, we rely on the following legal bases as applicable in your jurisdiction:
- As necessary for our contract:When we enter into a contract directly with you, we process your personal data on the basis of our contract in order to prepare and enter into the contract, as well as to perform and manage our contract (i.e., providing Zoom products and services, features and services to account owners, their users, and those they invite to join meetings and webinars hosted on their accounts, and manage our relationship and contract, including billing, compliance with contractual obligations, and related administration). If we do not process your personal data for these purposes, we may not be able to provide you with all products and services;
- Consistent with specific revocable consents:We rely on your prior consent in order to utilize cookies to engage advertising and analytics partners to deliver tailored advertising and analysis of our website usage. You have the right to withdraw your consent at any time by visiting our cookie management tool, available Cookies Settings;
- As necessary to comply with our legal obligations:We process your personal data to comply with the legal obligations to which we are subject for the purposes of compliance with EEA laws, regulations, codes of practice, guidelines, or rules applicable to us, and for responses to requests from, and other communications with, competent EEA public, governmental, judicial, or other regulatory authorities. This includes detecting, investigating, preventing, and stopping fraudulent, harmful, unauthorized, or illegal activity (“fraud and abuse detection”) and compliance with privacy laws;
- To protect your vital interests or those of others:We process certain personal data in order to protect vital interests for the purpose of detecting and preventing illicit activities that impact vital interests and public safety, including child sexual abuse material; and
- As necessary for our (or others’) legitimate interests, unless those interests are overridden by your interests or fundamental rights and freedoms, which require protection of personal data:We process your personal data based on such legitimate interests to (i) enter and perform the contract with the account
owner and/or reseller providing you with the products and services (which includes billing, compliance with contractual obligations, and related administration and support); (ii) develop, test, and improve our products and services and troubleshoot products and services; (iii) ensure authentication, integrity, security, and safety of accounts, activity, and products and services, including detect and prevent malicious conduct and violations of our terms and policies, prevent or investigate bad or unsafe experiences, and address security threats; (iv) send marketing communications, advertising, and promotions related to the products and services; and (v) comply with non-EEA laws, regulations, codes of practice, guidelines, or rules applicable to us and respond to requests from, and other communications with, competent non-EEA public, governmental, judicial, or other regulatory authorities, as well as meet our corporate and social responsibility commitments, protect our rights and property and the ones of our customers, resolve disputes, and enforce agreements.
International Data Transfers
Zoom operates globally, which means personal data may be transferred, stored (for example, in a data center), and processed outside of the country or region where it was initially collected where Zoom or its service providers have customers or facilities – including in countries where meeting participants or account owners hosting meetings or webinars that you participate in or receiving messages that you send are based.
Therefore, by using Zoom products and services or providing personal data for any of the purposes stated above, you acknowledge that your personal data may be transferred to or stored in the United States where we are established, as well as in other countries outside of the EEA, Switzerland, and the UK. Such countries may have data protection rules that are different and less protective than those of your country.
We protect your personal data in accordance with this Privacy Statement wherever it is processed and take appropriate contractual or other steps to protect it under applicable laws. Where personal data of users in the EEA, Switzerland, or the UK is being transferred to a recipient located in a country outside the EEA, Switzerland, or the UK which has not been recognized as having an adequate level of data protection, we ensure that the transfer is governed by the European Commission’s standard contractual clauses. Please contact us if you would like further information in that respect.
California Consumer Privacy Act
Under the California Consumer Privacy Act of 2018 (CCPA), California residents may have a right to:
- Access the categories and specific pieces of personal data Zoom has collected, the categories of sources from which the personal data is collected, the business purpose(s) for collecting the personal data, and the categories of third parties with whom Zoom has shared personal data;
- Delete personal data under certain circumstances; and
for interest-based advertising purposes by clicking the Do Not Sell My Personal Information link, also on our homepage, and setting your preferences. You will
need to set your preferences from each device and each web browser from which you wish to opt out. This feature uses a cookie to remember your preference, so if you clear all cookies from your browser, you will need to reset your settings.
Zoom will not discriminate against you for exercising any of these rights, which is further in line with your rights under the CCPA.
We will acknowledge receipt of your request within 10 business days, and provide a substantive response within 45 calendar days, or inform you of the reason and extension period (up to 90 days) in writing.
Under the CCPA, only you or an authorized agent may make a request related to your personal data. Note that to respond to your requests to access or delete personal data under the CCPA, we must verify your identity. We may do so by requiring you to log into your Zoom account (if applicable), provide information relating to your account (which will be compared to information we have, such as profile information), give a declaration as to your identity under penalty of perjury, and/or provide additional information. You may designate an authorized agent to submit your verified consumer request by providing written permission and verifying your identity, or through proof of power of attorney.
California’s Shine the Light Law
California Civil Code Section 1798.83, also known as “Shine The Light” law, permits California residents to annually request information regarding the disclosure of your Personal Information (if any) to third parties for the third parties’ direct marketing purposes in the preceding calendar year. We do not share Personal Information with third parties for the third parties’ direct marketing purposes.
We may update this Privacy Statement periodically to account for changes in our collection and/or processing of personal data, and will post the updated Privacy Statement on our website, with a “Last Updated” date at the top. If we make material changes to this Privacy Statement, we will notify you and provide you an opportunity to review before you choose to continue using our products and services.