48 Total
8 High severity
13 Medium severity
27 Low severity

Key Facts

Does Segment make exceptions to its standard processing rules?
Segment makes exceptions to its standard processing rules as necessary to investigate issues of fraud and abuse.
If a customer uses Regional Twilio, where is Customer Content stored and processed?
If a customer uses Regional Twilio for supported products, Customer Content is stored and processed in the region the customer selects, which is either Ireland or Australia.
What regions can the customer select?
If a customer uses Regional Twilio for supported products, Customer Content is stored and processed in the region the customer selects, which is either Ireland or Australia.
Do Segment's sub-processors process personal data on behalf of Twilio customers?
Segment's sub-processors process personal data on behalf of Twilio customers and in accordance with customer instructions as communicated by Twilio.
Do they process personal data in accordance with customer instructions as communicated by Twilio?
Segment's sub-processors process personal data on behalf of Twilio customers and in accordance with customer instructions as communicated by Twilio.
Does Segment impose obligations on its sub-processors to implement appropriate technical and organizational measures?
Segment imposes obligations on its sub-processors to implement appropriate technical and organizational measures ensuring that sub-processing of personal data is protected to the standards required by applicable data protection laws.
Does Segment require that sub-processing occurs in strict accordance with the terms of a written contract?
Segment requires that sub-processing occurs in strict accordance with the terms of a written contract between Twilio and the sub-processor.
Where engaging a sub-processor requires a cross-border transfer of personal data, what has Segment performed?
Where engaging a sub-processor requires a cross-border transfer of personal data, Segment has performed Transfer Impact Assessments for such data transfers.
Does Segment use AWS as an infrastructure provider?
Segment uses AWS as an infrastructure provider for hosting and storage services, with the location being either the USA or EU (Dublin) as selected by customers.
Where is the location of AWS services as selected by customers?
Segment uses AWS as an infrastructure provider for hosting and storage services, with the location being either the USA or EU (Dublin) as selected by customers.
Stay ahead of the changes
Track Segment and get the diff the day its terms change.
Summary

This document describes the third-party companies Segment uses to process customer data, how those companies are required to protect that data, and where the data is stored. Your data is handled only according to your instructions (passed through Twilio), under binding contracts, and stays in the geographic region you select. You can subscribe to receive notifications whenever the list of sub-processors changes.

Analysis

This document establishes the framework governing Segment's use of sub-processors to process personal data on behalf of Twilio customers. Sub-processors operate strictly under customer instructions as communicated by Twilio, pursuant to written contracts that impose appropriate technical and organizational measures aligned with applicable data protection laws. Personal data is processed for the duration of active customer use and any retention periods set out in the customer's agreement with Twilio, with Customer Content stored in the geographic region the customer selects. Where sub-processor engagements require cross-border transfers, Segment has performed Transfer Impact Assessments; Segment also maintains a current named list of all sub-processors and provides customers the ability to subscribe to change notifications. Segment retains discretion to process personal data outside its standard rules when investigating fraud or abuse.

What this means for you

As an individual whose data is processed through Segment, your personal data is handled only by sub-processors bound by written contracts and required to meet applicable data protection standards. The data is retained only for as long as you actively use the relevant service and for any periods your agreement with Twilio specifies, and it is stored in the geographic region you or your organization selects—either Ireland or Australia for Regional Twilio, or the USA or EU (Dublin) for AWS-hosted services. Segment may process personal data outside its standard rules when investigating fraud or abuse. One concrete action available: Twilio customers can subscribe to Segment's sub-processor change notification service to receive updates whenever sub-processors are added or changed.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

Featured, High severity
Featured, Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

48 provisions
12 featured
7 clause types
8 high severity
Platform Discretion 1 1 high
Stay ahead of the changes

Monitoring

Segment has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Fraud And Abuse Investigation Processing Exception and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 7, 2026 00:21 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000937
Version ID CA-V-004548
SHA-256 eb0c920c72df0732ba3434b4acbc87ddf3cac2ad805f3e24639ec619d81bba39
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans