Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The notice states that for the Conversational Intelligence service, Twilio processes personal data within voice calls as an independent data controller rather than as a data processor acting under customer instructions.
This analysis describes what Segment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a distinct legal role for Twilio when processing voice call content through Conversational Intelligence, which affects how data subject rights requests are routed, how liability is allocated between Twilio and its enterprise customers, and what contractual protections apply to this processing outside the standard DPA processor relationship.
The updated policy establishes a new opt-out mechanism allowing users to decline having their data disclosed to third parties (other than service providers) or used for purposes materially different from the original collection purpose. The policy also explicitly discloses that Twilio Inc. is subject to FTC investigatory and enforcement powers, providing users with notice of the regulatory authority overseeing the company's privacy practices. You can exercise this opt-out right by contacting Segment through the mechanism specified in their privacy policy.
View change record →The updated terms establish clearer disclosure of how Segment transfers personal data internationally. Segment now explicitly certifies its compliance with the EU-U.S. Data Privacy Framework, UK Extension, and Swiss-U.S. Data Privacy Framework, and states that these DPF Principles take precedence if they conflict with other policy terms. The updated policy also adds specific rights allowing you to opt out of: (i) disclosure of your personal data to third parties other than service providers acting under Segment's instructions, or (ii) use of your personal data for purposes materially different from the original purpose or your subsequent authorization. You can exercise these rights by contacting privacy@twilio.com.
View change record →Under this clause, individuals whose voice calls are processed by Twilio's Conversational Intelligence service have a direct data subject rights relationship with Twilio as controller rather than solely with the enterprise customer deploying the service. The agreement establishes that this processing is governed by Twilio's privacy notice rather than solely by the customer's data processing instructions.
Cross-platform context
See how other platforms handle Conversational Intelligence Independent Controller Designation and similar clauses.
Compare across platforms →Monitoring
Segment has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Conversational Intelligence incorporates artificial intelligence and machine learning to transcribe and analyze voice calls into a structured format that allows our customers to drive their business processes. To translate voice calls into structured content, Twilio processes certain data, including personal data within voice calls, as an independent controller. This includes information provided to us by our customers through their use of the Conversational Intelligence Service.Excerpt from Segment's Privacy Policy
1) REGULATORY LANDSCAPE: This provision directly implicates GDPR and UK GDPR controller and processor definitions and associated obligations. An independent controller designation triggers obligations including maintaining a record of processing activities, establishing a lawful basis for processing, and directly handling data subject rights requests for the relevant processing. CCPA similarly distinguishes between businesses and service providers, with the controller designation potentially affecting whether Twilio can be classified as a service provider for CCPA purposes with respect to this service. 2) GOVERNANCE EXPOSURE: High. The designation of Twilio as an independent controller for voice call content processing through Conversational Intelligence creates a material divergence from the standard processor-controller relationship that most enterprise DPAs are structured around. Customers deploying this service may have compliance exposure if their own privacy notices do not accurately describe Twilio's independent controller role to end users. 3) JURISDICTION FLAGS: EU and UK organizations face the most immediate exposure, as GDPR and UK GDPR place specific obligations on both controllers and processors and require clear contractual demarcation. California organizations should evaluate whether this designation affects CCPA service provider classification for data processed through Conversational Intelligence. Healthcare and financial services organizations should assess whether voice call content subject to sectoral regulations retains those protections when processed by an independent controller. 4) CONTRACT AND VENDOR IMPLICATIONS: Standard DPA templates premised on a processor relationship may not adequately govern the independent controller scenario for Conversational Intelligence. Procurement and legal teams should verify whether controller-to-controller data sharing agreements or supplemental terms exist for this service. Liability allocation for data breaches or rights violations involving voice call content processed as an independent controller may differ from the standard DPA terms. 5) COMPLIANCE CONSIDERATIONS: Enterprise customers deploying Conversational Intelligence should update their own privacy notices to disclose Twilio's independent controller role for voice call processing. Data mapping exercises should separately categorize this processing stream. Legal teams should confirm that Twilio's legal basis for independent controller processing is compatible with the enterprise customer's own legal basis and end user disclosures.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a distinct legal role for Twilio when processing voice call content through Conversational Intelligence, which affects how data subject rights requests are routed, how liability is allocated between Twilio and its enterprise customers, and what contractual protections apply to this processing outside the standard DPA processor relationship.
Under this clause, individuals whose voice calls are processed by Twilio's Conversational Intelligence service have a direct data subject rights relationship with Twilio as controller rather than solely with the enterprise customer deploying the service. The agreement establishes that this processing is governed by Twilio's privacy notice rather than solely by the customer's data processing instructions.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Segment.