Contents
- P1. Overview & Scope
- P2. Controller Identity
- P3. Information We Collect
- P4. How We Use Information
- P5. Legal Basis for Processing (GDPR)
- P6. Information Sharing & Disclosure
- P7. Data Retention
- P8. Security
- P9. International Data Transfers
- P10. California Consumer Rights (CCPA/CPRA)
- P11. EU & UK Data Subject Rights
- P12. Children's Privacy
- P13. Changes to This Policy & Contact
P1. Overview & Scope
Crescent Value Partners, LLC ("CVP," "we," "us," "our") operates the Decision Diagnostics Platform, a suite of technology applications including Verto, Throughline, Lens, Navigator, and Commander (collectively, the "Platform"). This Privacy Policy explains how CVP collects, uses, stores, shares, and protects information in connection with the Platform and CVP's related websites and services.
This Policy applies to:
- Platform Users: individuals who access any CVP Platform application, including employees and contractors of CVP customers (Verto), CVP's consulting clients (Throughline, Lens), and CVP staff.
- Website Visitors: individuals who visit crescentvaluepartners.com or any CVP web property.
- Contact Inquiries: individuals who contact CVP through web forms, email, or other channels.
This Policy does not apply to third-party websites, products, or services that CVP does not control, even if they are accessible from the Platform.
P2. Controller Identity
For purposes of applicable data protection law, the Data Controller for personal data processed in connection with CVP's own operations and this website is:
Crescent Value Partners, LLC
Houston, Texas, United States
Privacy Contact: privacy@crescentvaluepartners.com
Verto Customer Data: Where CVP processes personal data on behalf of Verto customers (e.g., a customer's employee or client records stored in Verto), CVP acts as a Data Processor. The applicable Verto customer is the Data Controller and their privacy practices govern the collection and use of such data. CVP processes this data only per the Verto Data Processing Agreement (Exhibit A of the Verto Terms of Service).
EU/UK Representative: CVP is evaluating its obligation to appoint an EU or UK representative under GDPR Article 27 and UK GDPR Article 27, respectively, based on the nature and volume of data processing involving EU/UK data subjects. Pending that determination, privacy inquiries from EU or UK data subjects may be directed to the privacy contact above.
P3. Information We Collect
P3.1 Information You Provide Directly
- Account Registration: Name, business email address, company name, job title, and password (hashed).
- Contact Forms: Name, email address, phone number, company, and the content of your message.
- Billing Information: Payment card details (processed and stored by our third-party payment processor; CVP does not store full card numbers).
- Platform Content: Data, documents, project information, and other content you input into Platform applications.
- Support Communications: Information provided in support requests, feedback, or correspondence with CVP.
P3.2 Information Collected Automatically
- Log Data: IP address, browser type and version, operating system, referring URLs, pages visited, access times, and session duration.
- Device Information: Device type, screen resolution, and hardware identifiers where relevant.
- Cookies & Tracking: See Section P3.4 below.
- Usage Analytics: Aggregated, de-identified information about feature usage, workflow patterns, and application performance.
P3.3 Information from Third Parties
- Single Sign-On (SSO): If you authenticate via Microsoft 365 or Google, we receive your name, email address, profile picture, and authentication token from that provider. We do not receive your third-party account password.
- Business Data Providers: CVP may supplement contact records with publicly available professional information from business data providers for prospecting and relationship management purposes.
P3.4 Cookies
CVP uses the following types of cookies and similar technologies:
| Type | Purpose | Duration |
|---|---|---|
| Essential | Session management, authentication, security | Session / up to 30 days |
| Functional | User preferences (theme, language) | Up to 1 year |
| Analytics | Aggregate usage statistics (no cross-site tracking) | Up to 2 years |
| Third-Party | Apollo.io website tracker (lead identification) | Session / persistent |
You may manage cookie preferences through your browser settings. Disabling essential cookies may impair Platform functionality.
P4. How We Use Information
CVP uses collected information for the following purposes:
- Providing the Platform: Account creation, authentication, feature delivery, and customer support.
- Billing & Transactions: Processing payments, invoicing, and managing subscriptions.
- Communications: Sending transactional notifications, service updates, security alerts, and responding to inquiries. We do not send marketing emails without consent.
- Security & Fraud Prevention: Monitoring for unauthorized access, abuse, and security threats; enforcing our Terms of Service and Acceptable Use Policy.
- Platform Improvement: Analyzing aggregated usage data to improve features, fix bugs, and enhance performance. This analysis uses de-identified data.
- Legal Compliance: Complying with applicable laws, regulations, legal process, or governmental requests.
- Business Operations: Internal record-keeping, audit, and analytics for CVP's own business management.
CVP does not sell or rent personal data to third parties. CVP does not use personal data for behavioral advertising or cross-context behavioral advertising.
P5. Legal Basis for Processing (GDPR)
For individuals in the European Economic Area (EEA) or United Kingdom, CVP relies on the following legal bases under GDPR Article 6:
- Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Platform pursuant to the Verto SaaS Subscription Agreement or a CVP engagement.
- Legitimate Interests (Art. 6(1)(f)): Platform security and fraud prevention; improving Platform functionality using aggregated data; business relationship management. CVP has conducted legitimate interests assessments and determined that these interests are not overridden by data subjects' rights.
- Legal Obligation (Art. 6(1)(c)): Compliance with applicable EU or UK law.
- Consent (Art. 6(1)(a)): Where CVP relies on consent (e.g., optional communications), you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
P6. Information Sharing & Disclosure
CVP does not sell personal data. CVP shares information only in the following circumstances:
P6.1 Service Providers
CVP engages third-party vendors to help operate the Platform, including cloud infrastructure, email delivery, payment processing, authentication, and logging/monitoring providers. These vendors are authorized to process personal data only to provide services to CVP and are bound by data processing agreements with security and confidentiality obligations equivalent to those in this Policy. The current list of sub-processors is published at crescentvaluepartners.com/legal/sub-processors.
P6.2 Legal Requirements
CVP may disclose information if required by law, court order, subpoena, or other legal process, or where CVP in good faith believes disclosure is necessary to: (a) comply with applicable law; (b) protect the rights, property, or safety of CVP, its users, or the public; or (c) detect, prevent, or address fraud, security, or technical issues.
P6.3 Business Transfers
In the event of a merger, acquisition, sale of assets, or other business combination, personal data may be transferred to the acquiring entity. CVP will provide notice before personal data is transferred and becomes subject to a materially different privacy policy.
P6.4 Consent
CVP may share information with third parties when you have given explicit consent.
P6.5 No Advertising Networks
CVP does not share personal data with advertising networks, data brokers, or third parties for cross-context behavioral advertising.
P7. Data Retention
CVP retains personal data for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law:
- Account Data: Retained for the duration of the active account, plus up to two (2) years after account closure for legal and audit purposes.
- Customer Data (Verto): Retained for the Subscription Term and for thirty (30) days after termination to allow Customer export, then deleted unless required by law. See Exhibit A, Section A.8.
- Log Data: Retained for up to ninety (90) days for security monitoring, then deleted or anonymized.
- Financial Records: Retained for seven (7) years in accordance with tax and accounting requirements.
- Legal Holds: Where CVP reasonably anticipates litigation or regulatory inquiry, relevant data may be retained beyond standard periods until the matter is resolved.
Upon expiration of applicable retention periods, CVP uses secure deletion methods to destroy personal data.
P8. Security
CVP implements administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, use, alteration, or destruction. These measures include:
- Encryption of personal data in transit (TLS 1.2+) and at rest
- Role-based access controls and least-privilege principles
- Multi-factor authentication for Platform access
- Regular security assessments and vulnerability management
- Employee security training and confidentiality obligations
- Incident response procedures with defined notification timelines
No security system is impenetrable. In the event of a data breach affecting your personal data, CVP will notify you as required by applicable law. If you believe your account has been compromised, contact us immediately at security@crescentvaluepartners.com.
P9. International Data Transfers
CVP is based in the United States. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data may be transferred to and processed in the United States or other countries that may not provide the same level of data protection as your jurisdiction.
CVP relies on the following safeguards for international transfers:
- EU-U.S. Data Privacy Framework (DPF): CVP is evaluating participation in the EU-U.S. DPF administered by the U.S. Department of Commerce.
- Standard Contractual Clauses (SCCs): CVP uses the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914) as a transfer mechanism where applicable.
- UK IDTA: For transfers from the United Kingdom, CVP uses the UK International Data Transfer Agreement (IDTA) or addendum to SCCs.
You may request a copy of applicable transfer safeguards by contacting privacy@crescentvaluepartners.com.
P10. California Consumer Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides certain rights regarding your personal information.
P10.1 Categories of Personal Information Collected
In the preceding twelve months, CVP has collected the following categories as defined under CCPA: identifiers (name, email, IP address); commercial information (subscription records); professional or employment-related information; internet activity (log data, usage data); and inferences drawn from above to create a profile about preferences.
P10.2 Sources & Purposes
CVP collects personal information directly from you, automatically through Platform use, and from SSO providers. CVP uses personal information for business and commercial purposes as described in Section P4. CVP does not sell personal information. CVP does not share personal information for cross-context behavioral advertising.
P10.3 Your California Rights
You have the right to: (a) Know: request disclosure of categories and specific pieces of personal information collected; (b) Delete: request deletion of personal information CVP holds about you, subject to exceptions; (c) Correct: request correction of inaccurate personal information; (d) Opt-Out of Sale/Sharing: CVP does not sell or share personal information, so this right is not applicable; (e) Limit Use of Sensitive PI: CVP does not use sensitive personal information beyond permitted purposes; (f) Non-Discrimination: CVP will not discriminate against you for exercising CCPA rights.
P10.4 How to Exercise California Rights
Submit requests to privacy@crescentvaluepartners.com. CVP will verify your identity before processing requests. CVP will respond within 45 days (extendable by 45 additional days with notice). You may designate an authorized agent by providing written authorization.
P11. EU & UK Data Subject Rights
If you are located in the European Economic Area or United Kingdom, you have the following rights under GDPR or UK GDPR:
- Access (Art. 15): Request a copy of the personal data CVP holds about you.
- Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Erasure (Art. 17): Request deletion of your personal data where there is no legitimate reason for CVP to continue processing it.
- Restriction (Art. 18): Request that CVP restrict processing of your personal data in certain circumstances.
- Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller, where technically feasible.
- Objection (Art. 21): Object to processing based on legitimate interests, including for direct marketing purposes.
- Withdraw Consent: Where processing is based on consent, withdraw consent at any time without affecting prior processing.
To exercise these rights, contact privacy@crescentvaluepartners.com. CVP will respond within one (1) month (extendable by two additional months for complex requests, with notice). You also have the right to lodge a complaint with your applicable supervisory authority.
P12. Children's Privacy
The Platform and CVP's services are not directed to individuals under the age of 18. CVP does not knowingly collect personal data from children under 18. If CVP learns that it has collected personal data from a child under 18, CVP will promptly delete such information. If you believe CVP has inadvertently collected information from a minor, contact us at privacy@crescentvaluepartners.com.
P13. Changes to This Policy & Contact
P13.1 Policy Updates
CVP may update this Privacy Policy from time to time. Material changes will be communicated via: (a) an updated "Effective Date" at the top of this page; and (b) where technically practicable, in-app notification or email to registered users. Your continued use of the Platform following the effective date of any update constitutes acceptance of the revised Policy. CVP maintains an archive of prior versions available upon request.
P13.2 Contact
Privacy Inquiries & Data Subject Requests
Email: privacy@crescentvaluepartners.com
Security Issues: security@crescentvaluepartners.com
Legal Notices: legal@crescentvaluepartners.com
Crescent Value Partners, LLC · Houston, Texas