Bentley Privacy Statement
Last updated: August 01, 2026.
Bentley Systems, Incorporated and its controlled affiliates (“Bentley”, “we”, “us”, or “our”) respect your privacy. This statement explains how we collect, use, share, transfer and protect personal data, and the choices and rights you have.
It applies to Bentley websites, products, applications, cloud services, support, events, webinars, marketing activities, and other offerings that link to it or where it is otherwise provided. It also covers offline interactions, for example at events, during business development activities, and when you visit Bentley premises. Our use of cookies is described in the Cookie Statement.
“Personal data” means information that identifies or can reasonably be linked to you. It does not include anonymised, de-identified or aggregated data. “Personal data” also includes “personal information” where a particular law uses that term.
This statement describes how Bentley processes personal data for its own purposes as controller. Where we provide products and services to a business customer (“Subscriber”) and process personal data on that Subscriber’s behalf, we act as a processor. That processing is governed by our agreement with the Subscriber, including the applicable Data Processing Addendum, and not by this statement.
Note: This statement covers only data we collect; it does not cover third-party sites we link to, which have their own notices. From time to time, we may also show a just-in-time notice at the point we collect data, to explain a specific use.
Contents
- What information do we collect about you?
- How do we use your personal data?
- How and why do we share your personal data?
- Do we transfer your personal data across borders?
- How long do we keep your personal data?
- Do we use automated decision-making?
- How do we keep your data secure?
- How do we protect children and students?
- How do we use cookies, advertising and marketing?
- How do we handle AI and personal data?
- What choices and rights do you have?
- How do you contact us, and how will we tell you about changes?
Summary
| Topic | In short |
|---|---|
| What we collect | Information you give us, information we collect automatically when you use our services, and information from partners and reputable sources |
| Why we use it | To provide, secure and improve our services, communicate with you, and market where permitted |
| Who we share with | Affiliates, service providers, channel partners, and others as required by law. We do not sell your personal data |
| Transfers | We use Standard Contractual Clauses and additional safeguards for international transfers |
| Your rights | Access, correct, delete, port, object, and opt out, depending on where you are. To exercise any of these rights, you may submit a request to our Data Protection Officer |
| Contact | Data Protection Officer, Dublin, Ireland (full address below) |
1. What information do we collect about you?
We collect personal data in three ways: directly from you, automatically when you use our services, and from third parties and reputable sources. By category, this may include:
- Identifiers: your name and contact details, and your account, login and authentication credentials.
- Professional information: your role, organisation and industry, where you provide it.
- Commercial information: your subscriptions, the offerings you have purchased, used or expressed interest in, and events and webinars you register for or attend.
- Financial account information: billing details for your purchases (card payments are handled by our payment processors including: Adyen, PayPal, and Stripe, and we do not receive full card details).
- Internet and device activity: device, log and usage data such as IP address, browser type and language, pages viewed, links followed, and the date, time and features used. We require sign-in to activate and use our software, and monitor usage to operate, secure and improve the services.
- Geolocation: approximate location, such as region or country.
- Inferences: drawn from the data above to improve and personalise our services. We also use Bentley analytics programs and third-party analytics tools, such as Google Analytics. To learn more, see our Bentley analytics program page and subscription entitlement services page.
- Information from third parties: from channel partners and e-commerce providers when you purchase through them, and from reputable sources to keep our records accurate.
- Sensitive data: we do not request special categories of data through our general forms, and you should not submit such data unless we expressly request it for a stated purpose.
- Physical-characteristic data: where you use immersive, reality-capture or similar features, we may process limited physical-characteristic data to provide the feature; we do not use it to identify you.
- User content and communications: information you upload, submit, store or make available through Bentley offerings, including support tickets, comments, forum posts, profile information, files, models, metadata and collaboration activity, where Bentley processes that information for its own purposes or as otherwise described in a product-specific or just-in-time notice.
- Information you make public: where our services let you post content, comments or a profile, that information may be visible to others; please be mindful of what you share.
2. How do we use your personal data?
We use personal data to provide, operate, personalise and support our services and complete your transactions; to communicate with you, including service, billing, security and administrative messages that form part of the service; to send marketing and product information where permitted, which you can stop at any time; to carry out research and analytics to improve our products; and to secure our environments and prevent fraud, misuse or harm.
We rely on four legal bases: performing our contract with you; our legitimate interests, balanced against your rights; your consent, which you may withdraw; and compliance with our legal obligations. The bases that apply to people in the EU/EEA, the UK and Switzerland are set out in the supplement for that region below.
We may create and use anonymised or aggregated data that does not identify you, and we will not attempt to re-identify de-identified data except to confirm that it remains de-identified.
3. How and why do we share your personal data?
We do not sell your personal data. We share it with:
- Our affiliates
- Service providers who process data on our behalf under contract (hosting, support, payments, marketing and email, events)
- Authorised channel partners as needed to sell, market or support products you are interested in
- Counterparties in a merger, acquisition, financing or sale of assets, subject to this statement
- Others where we reasonably believe disclosure is necessary to comply with law, enforce our agreements, or protect rights, property or safety
Where a service is co-branded, the other company’s use of your data is governed by its own notice.
4. Do we transfer your personal data across borders?
We transfer personal data to the United States and other countries that may not provide the same level of protection as your own. Where we do, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum or Swiss equivalent, as applicable), supported by a transfer impact assessment and additional safeguards where needed.
Bentley also complies with the EU-U.S. Data Privacy Framework, the UK Extension to it, and the Swiss-U.S. Data Privacy Framework (collectively “DPF”) for personal data transferred from the EU, UK and Switzerland to the United States, and has certified its adherence to the Data Privacy Framework Principles. To learn more, see our DPF Certification page.
Note: If there is any conflict between this statement and the DPF Principles, the Principles govern for such data.
We commit to resolve DPF-related complaints; EU, UK and Swiss individuals may first contact us at [email protected], and unresolved complaints may be referred to our independent recourse mechanism at no cost to you. Our DPF commitments are subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.
5. How long do we keep your personal data?
We keep personal data only as long as necessary for the purposes in this statement, including to provide and support the services, maintain security, and meet legal, tax and accounting obligations, after which we delete or irreversibly anonymise it.
We set retention periods by reference to the nature of the data, the purpose for which we hold it, our contractual commitments, and applicable legal, tax and accounting requirements.
6. Do we use automated decision-making?
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. If this changes, we will tell you, explain the logic and consequences, and give you the right to human review, to express your view and to contest the decision.
7. How do we keep your data secure?
We use technical and organisational measures, including access controls and encryption in transit and, where appropriate, at rest, to protect personal data. No method is perfectly secure, and you are responsible for keeping your credentials confidential.
8. How do we protect children and students?
Our sites and services are intended for a general, professional audience, and we do not knowingly collect personal data from children below the minimum age that applies in their jurisdiction. If you believe a child has provided us data, contact us and we will delete it. Where we make offerings available for education, we handle any student personal data in line with applicable student-privacy laws.
9. How do we use cookies, advertising and marketing?
We and approved partners use cookies and similar technologies as described in the Cookie Statement, which explains your choices. We honour recognised browser-based opt-out signals, including the Global Privacy Control, where required by law.
10. How do we handle AI and personal data?
Some Bentley products use artificial intelligence to provide and improve features. Where we use third-party AI services, we do so under contracts that restrict use of your data, and we do not use personal data to train third-party models.
11. What choices and rights do you have?
You can manage marketing preferences or unsubscribe at any time, and you can exercise your privacy rights by submitting a request to our Data Protection Officer. The rights available to you depend on where you live; see the supplement for your region below.
To protect your data, we may ask you to verify your identity before we act on a request, and we may ask for additional verification depending on the nature of the data requested.
Where we process personal data based on consent, you may withdraw that consent at any time. You may withdraw consent through the relevant product setting, cookie preference tool, unsubscribe link, or by contacting us. We will not discriminate against you for withdrawing consent, but some optional features or communications may no longer be available.
12. How do you contact us, and how will we tell you about changes?
We post the “Last updated” date when we change this statement and, for material changes, give prominent notice or contact you directly where required.
For any privacy request or question, contact our Data Protection Officer and/or write to: Data Protection Officer, Bentley Systems International Limited, 6th Floor, 1 Cumberland Street, Fenian Street, Dublin 2, D02 AX07, Ireland.
Jurisdiction Specific Supplements
EU/EEA, UK and Switzerland
If you are in the EU/EEA, the controller is Bentley Systems International Limited, Dublin, Ireland. We process personal data on the bases of contract, legitimate interests, legal obligation, legal claims, vital interests and, where required, consent (which you may withdraw). You may:
- Confirm processing
- Access and receive a portable copy
- Rectify or erase
- Restrict or object
- Withdraw consent
- Complain to a supervisory authority, including our lead authority, the Irish Data Protection Commission
In the UK and Switzerland, equivalent rights apply under the UK GDPR and Swiss FADP, with complaints to the UK ICO or the Swiss FDPIC.
United States
This supplement applies to residents of US states with comprehensive privacy laws and prevails over the general statement as to your state-law rights. Subject to exceptions, you may:
- Confirm and access
- Correct
- Delete
- Receive a portable copy
- Opt out of targeted advertising, sale or sharing, and certain profiling
- Limit our use of sensitive personal information
We do not sell your personal data, and we honour the Global Privacy Control. To exercise rights or appeal a decision, contact our privacy team or call 1-800-BENTLEY; you may use an authorised agent and may contact your State Attorney General.
Nevada residents may opt out of any sale of covered information. California residents, including employees, job applicants and business contacts, also have the right not to be discriminated against for exercising their rights. This supplement does not apply where an exemption under applicable U.S. state privacy law applies.
China
Where we process the personal information of individuals in mainland China to provide our services, we do so under China’s Personal Information Protection Law. We obtain separate consent where required, including for cross-border transfers; we transfer personal information out of China only using a lawful mechanism or derogation (as applicable) and we maintain a local representative where required.
You may access, correct, delete and port your information, withdraw consent, and request an explanation of automated decision-making by contacting our privacy team.
Brazil
If you are in Brazil, Bentley processes your personal data under the LGPD, on the bases described above. You may:
- Confirm processing
- Access your data
- Correct incomplete, inaccurate or outdated data
- Anonymise, block or delete unnecessary or non-compliant data
- Obtain a portable copy
- Obtain information about the entities with which we share data and the safeguards for any international transfer
- Withdraw consent
The supervisory authority is the ANPD.
Additional rights by country
Other jurisdictions, including Canada (PIPEDA and Quebec Law 25 where relevant) and various Gulf and APAC laws, grant rights similar to those above. We honour them to the extent the applicable law requires. Contact our Data Protection Officer for jurisdiction-specific detail.
These include, in the Asia-Pacific region, Japan’s APPI, South Korea’s PIPA and Singapore’s PDPA, and, in the Americas, Mexico’s LFPDPPP and Quebec’s Law 25. Where these laws require it, you may access, correct, delete and port your data, withdraw consent, and lodge a complaint with the relevant authority.