Segment · Segment Sub-Processors · View original document ↗

AI Vendor Sub-Processing of Customer-Defined Workflow Data

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Segment changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Segment recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Segment Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision discloses that Anthropic, Amazon Bedrock, Microsoft Azure, and OpenAI are authorized sub-processors for all Twilio AI products, each processing personal data contained in customer-defined workflows or communications, with processing located in the USA (and EU for Microsoft Azure).

This analysis describes what Segment's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that personal data from customer-defined workflows is processed by multiple generative AI vendors under the Twilio sub-processor framework, which may have implications for customers' own privacy notices, AI governance policies, and data processing agreements if these vendors were not previously identified in the customer's vendor risk register.

Interpretive note: The document does not specify data retention periods, training data use restrictions, or output data handling practices for the listed AI sub-processors, leaving the operational scope of personal data processing by these vendors partially undefined from this document alone.

Consumer impact (what this means for users)

Under these provisions, personal data contained in customer-defined workflows processed through Twilio AI products is shared with OpenAI, Anthropic, Amazon Bedrock, and Microsoft Azure, each acting as a sub-processor under written contracts with Twilio. Customers using Twilio AI products should assess whether their own privacy notices and data processing documentation reflect these AI vendor sub-processing relationships.

Cross-platform context

See how other platforms handle AI Vendor Sub-Processing of Customer-Defined Workflow Data and similar clauses.

Compare across platforms →

Monitoring

Segment has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Anthropic All AI Products Personal data contained in communications sent through Flex. Vendor for AI functionality in product USA ... Amazon Bedrock All AI Products Personal data contained in customer defined workflows Vendor for AI functionality in product USA ... Microsoft Azure All AI Products Personal data contained in customer defined workflows Vendor for AI functionality in product USA, EU ... OpenAI All AI Products Personal data contained in customer defined workflows Vendor for AI functionality in product USA

Excerpt from Segment's Sub-Processors

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision engages GDPR Article 28 requirements for sub-processing chains involving AI vendors, as well as emerging EU AI Act transparency and data governance obligations that may apply to AI system providers. The EDPB has issued guidance on the use of AI tools in data processing contexts. For US customers, the FTC's AI-related guidance on data practices and its Section 5 authority are relevant. Healthcare-adjacent customers should assess whether personal data in customer workflows implicates HIPAA business associate requirements with respect to AI vendors. 2) GOVERNANCE EXPOSURE: High. The description of processed data as personal data contained in customer-defined workflows is broad and does not specify data categories, retention periods, or training data use restrictions for these AI vendors. Customers deploying AI features should assess whether their use cases result in sensitive data categories being processed by these vendors and whether that is reflected in their own risk assessments. 3) JURISDICTION FLAGS: EU customers face heightened exposure under GDPR and the EU AI Act, particularly regarding transparency obligations for automated processing and AI system use. California customers should assess CCPA service provider chain obligations for AI sub-processors. Healthcare, financial services, and public sector customers in any jurisdiction should conduct enhanced due diligence given the sensitivity of workflow data potentially processed by generative AI vendors. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should verify that DPAs with Twilio explicitly authorize AI vendor sub-processing and that the scope of data processed (customer-defined workflow personal data) is acceptable under the customer's own data minimization and purpose limitation obligations. Teams should also assess whether OpenAI and Anthropic's own terms prohibit using personal data for model training and whether Twilio's contracts with these vendors include equivalent restrictions. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should update privacy notices and records of processing activities to reflect AI vendor sub-processing where Twilio AI products are deployed, assess whether data subject rights (access, deletion, portability) can be fulfilled across the AI vendor sub-processing chain, and evaluate whether AI use constitutes automated decision-making subject to GDPR Article 22 obligations. Teams should also confirm that customer-facing AI feature disclosures are consistent with the sub-processor relationships disclosed in this document.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over AI-related data practices and sub-processor data sharing arrangements, including representations about how personal data is processed by AI vendors under service provider relationships.
    File a complaint →

Provision details

Document information
Document
Segment Sub-Processors
Entity
Segment
Document last updated
July 6, 2026
Tracking information
First tracked
July 7, 2026
Last verified
July 9, 2026
Record ID
CA-P-015694
Document ID
CA-D-00937
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
eb0c920c72df0732ba3434b4acbc87ddf3cac2ad805f3e24639ec619d81bba39
Analysis generated
July 7, 2026 00:28 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Segment
Document: Segment Sub-Processors
Record ID: CA-P-015694
Captured: 2026-07-07 00:28:28 UTC
SHA-256: eb0c920c72df0732…
URL: https://conductatlas.com/platform/segment/segment-sub-processors/provision/CA-P-015694/ai-vendor-sub-processing-of-customer-defined-workflow-data/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Segment's AI Vendor Sub-Processing of Customer-Defined Workflow Data clause do?

This provision discloses that personal data from customer-defined workflows is processed by multiple generative AI vendors under the Twilio sub-processor framework, which may have implications for customers' own privacy notices, AI governance policies, and data processing agreements if these vendors were not previously identified in the customer's vendor risk register.

How does this clause affect you?

Under these provisions, personal data contained in customer-defined workflows processed through Twilio AI products is shared with OpenAI, Anthropic, Amazon Bedrock, and Microsoft Azure, each acting as a sub-processor under written contracts with Twilio. Customers using Twilio AI products should assess whether their own privacy notices and data processing documentation reflect these AI vendor sub-processing relationships.

Is ConductAtlas affiliated with Segment?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Segment.