Old version
May 5, 2026 06:38 UTC
8aa34d875deca43dc028e30e5b310acd78aaa2c08ec1ee04ae93e035e3836716
CA-V-001336
New version
May 19, 2026 01:14 UTC
a4a3739040fcfcfee702f9dde1f1911f4986a957578b5fbc26065971ffb592c4
CA-V-002734
Share 𝕏 Share in Share
Change Summary
Segment updated its privacy policy on May 19, 2026 to provide more detailed disclosure of its Data Privacy Framework (DPF) compliance certifications and mechanisms. The policy now explicitly states that Twilio Inc. and subsidiary Stytch Inc. have certified compliance with the EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF frameworks, and clarifies that if these frameworks conflict with other policy terms, the DPF Principles govern. The policy also added specific opt-out rights for third-party disclosure and non-originally-authorized uses of personal data, and replaced a reference to a dispute resolution provider with the named provider JAMS.
medium severity
12 Sentences added
0 Sentences removed
3 Sentences modified
211 Sentences before
223 Sentences after
Added
Removed
Modified
BeforeAfter
63Please note that if we share your personal data with a third-party acting on our behalf, Twilio remains liable under the DPF Principles (defined below) if that third-party processes your data in a way that violates those Principles, unless we prove we were not responsible for the violation.
90Whether we are transferring data internally within the Twilio group or externally to trusted third parties, we rely on the following legal safeguards: Data Privacy Frameworks (or “DPF”): Primary mechanism for transfers from the EU, UK and Switzerland to the U.S. Binding Corporate Rules (or “BCRs”): EU-approved rules covering transfers to Twilio group companies globally.91Whether we are transferring data internally within the Twilio group or externally to trusted third parties, we rely on the following legal safeguards: Data Privacy Frameworks (or “DPF”): Twilio Inc. and our subsidiary Stytch Inc. comply with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.
92Twilio Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.
93Twilio Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
94If there is any conflict between the terms in this Privacy Notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.
95To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/ .
96Binding Corporate Rules (or “BCRs”): EU-approved rules covering transfers to Twilio group companies globally.
131Additional Rights Depending on your jurisdiction, you may exercise specific controls over your data: Sensitive Data: Restrict the use of sensitive personal data to what is strictly necessary for Service delivery.137Data Privacy Framework Choices & Means In accordance with the Data Privacy Framework Principles, opt of (i) your personal data being disclosed to a third party (other than to our service providers performing tasks on our behalf under our instructions); or, (ii) your personal data being used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by you.
138How to Exercise Rights: Contact privacy@twilio.com Additional Rights Depending on your jurisdiction, you may exercise specific controls over your data: Sensitive Data: Restrict the use of sensitive personal data to what is strictly necessary for Service delivery.
200If we are unable to resolve your concern to your satisfaction, you may pursue further resolution through the following channels: Data Protection Frameworks (“DPF”): For practices covered by our DPF certification, contact our U.S.-based third party dispute resolution provider (free of charge) at https://www.jamsadr.com/DPF-Dispute-Resolution .207If we are unable to resolve your concern to your satisfaction, you may pursue further resolution through the following channels: Data Protection Frameworks (“DPF”): For practices covered by our DPF certification, contact our U.S.-based third party dispute resolution provider JAMS, (free of charge) at https://www.jamsadr.com/DPF-Dispute-Resolution .
213UK Residents: If you have a concern about our privacy practices, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).
214In accordance with the UK Data (Use and Access) Act, you are required to first submit your complaint directly to Twilio to allow us the opportunity to resolve the matter.
215We will acknowledge your complaint within 30 days and work to provide a substantive response without undue delay.
216If you remain unsatisfied after receiving our final response, you may then escalate your complaint to the ICO (www.ico.org.uk).
219In addition to the above regulatory bodies, Twilio Inc. is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
Watch this before it changes again

Follow unlimited companies, monitor the clauses that matter across every platform, and get the full institutional analysis on what each change obligates you to do.