-
Rumble
· Rumble Privacy Policy
The policy states that Rumble may update or revise the Privacy Policy at any time with or without notice to users, with changes indicated by an updated date at the top of the document, and that more prominent notice may be provided for substantial changes....
Why it matters: This provision reserves the right to modify data collection and processing terms without mandatory prior notice to users, with the date update serving as the sole required indicator of change for non-substantial modifications. Applicable laws in certain jurisdictions may impose notice requirements for material changes to privacy policies that are not fully reflected in this provision....
-
Rumble
· Rumble Privacy Policy
The policy states that Rumble and third-party advertising partners collect usage activity, device identifiers, unique identifiers, IP addresses, and potentially hashed email addresses, and use this data combined across devices and websites to build behavioral profiles for targeted advertising....
Why it matters: This provision authorizes cross-device and cross-site behavioral profiling for advertising by both Rumble and third-party partners, using data categories including hashed email addresses that may qualify as Personal Information under certain data protection laws. The involvement of third-party advertising partners means data collected on Rumble may be combined with data from other sites those partners operate across....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses that Thomson Reuters collects biometric data including fingerprints and facial geometry scans, and states that such data will be permanently destroyed within the timeframe specified by applicable law or when the collection purpose ends, whichever comes first....
Why it matters: This provision establishes biometric data collection and a destruction schedule tied to legal timelines or cessation of purpose, triggering obligations under the Illinois Biometric Information Privacy Act and analogous statutes in Texas, Washington, and other states that impose specific written consent, retention schedule, and destruction requirements before or at the point of collection....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy states that using or interacting with Thomson Reuters Services constitutes authorization for cross-border transfer of personal data to countries, including the United States, that may offer lesser privacy protections than the user's home country....
Why it matters: This provision asserts that the act of interacting with Services constitutes consent to international data transfers, including to jurisdictions with lower privacy standards. Whether this mechanism satisfies the specificity and granularity requirements of GDPR Article 49 derogations or UK GDPR transfer adequacy provisions warrants regulatory evaluation, as broad behavioral consent embedded in a privacy notice may not meet the standards those frameworks require....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses that Thomson Reuters collects and processes the content of user queries submitted to its Services, explicitly including artificial intelligence prompts, as a category of personal information....
Why it matters: This provision establishes that AI prompt content constitutes a collected personal data category subject to the full range of uses described in the statement, including service improvement, product development, annotating and tagging content, and sharing with third-party business partners. Organizations using Thomson Reuters AI products such as CoCounsel should evaluate whether client-confidential or privileged content submitted as AI prompts is subject to these data handling practices....
-
These provisions have changed before
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses that Thomson Reuters provides services and content incorporating user personal information to third-party customers, including through aggregated listings, reports, profiles, and professional directories, and acknowledges that under certain local laws this may constitute a sale of personal information....
Why it matters: This provision establishes that personal information, including that aggregated from public and private sources into attorney directories and professional profiles, may be made available to all users of Thomson Reuters services and acknowledges that this constitutes a potential sale under applicable law. California residents and residents of other states with sale opt-out rights may exercise those rights, but individuals whose information appears in public records products face a structurally distinct regime governed by the supplemental Public Records Privacy Statement....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy authorizes sharing personal information with third-party data brokers, advertising and marketing agencies, analytics providers, and credit agencies that support Thomson Reuters business, as well as with third parties for marketing their own products or services to users....
Why it matters: This provision authorizes disclosure of personal information to data brokers and advertising partners, which in combination with the broad categories of personal information collected including browsing activity, usage history, device identifiers, and inferences from personal information, may engage CCPA/CPRA opt-out rights and analogous state law protections for users in applicable jurisdictions....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses collection of sensitive personal information categories including political and religious beliefs, sexual orientation, racial or ethnic origin, union membership, medical records, disability information, government identifiers such as social security numbers, and passport or driver's license numbers....
Why it matters: This provision establishes that Thomson Reuters collects multiple categories of special category data under GDPR Article 9, sensitive personal information under CCPA/CPRA, and analogously protected categories under other data protection frameworks, each of which imposes heightened lawful basis, consent, and data subject rights requirements beyond those applicable to ordinary personal data....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy commits Thomson Reuters to refer unresolved DPF-related complaints from EU, UK, and Swiss individuals to JAMS for alternative dispute resolution at no cost to the complainant, with the FTC confirmed as the governing enforcement authority for DPF compliance....
Why it matters: This provision establishes the dispute resolution pathway for EU, UK, and Swiss individuals whose personal data is transferred to the United States under the DPF, including a binding arbitration option as a last resort mechanism under DPF Annex I, and confirms FTC enforcement jurisdiction over Thomson Reuters' DPF adherence....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy reserves the right to update the Privacy Statement at any time for any reason, with notification provided solely by updating the 'last updated' date on the posted statement; email reminders may be sent periodically but are not guaranteed....
Why it matters: This provision establishes that changes to data handling practices may take effect upon posting without individualized notice to users, placing the responsibility on users to monitor the statement for updates. Under GDPR, material changes to processing purposes or legal bases may require renewed consent or advance notice beyond a date-stamp update, a tension the provision does not address....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy describes data subject rights including access, correction, deletion, restriction, objection, portability, and opt-out of profiling and targeted advertising, and provides three submission channels (portal, email, phone), while noting that these rights are subject to exceptions and are only applicable where Thomson Reuters acts as a data controller....
Why it matters: This provision establishes the operational mechanisms for exercising data subject rights but conditions fulfillment on Thomson Reuters acting as a controller for the relevant data, which may limit rights for individuals whose data is processed through Thomson Reuters as a data processor on behalf of enterprise customers. The 2024 California metrics disclose an 87% rejection rate for data access requests and a 51% rejection rate for deletion requests, which may warrant documentation review for compliance adequacy....
-
Thomson Reuters
· Thomson Reuters Privacy
The policy discloses collection of precise geolocation data, device and advertising identifiers, cookie and tracker identifiers, IP addresses, browsing and search history, session replays, and user journey history including clicks, navigation, and user actions....
Why it matters: This provision establishes that Thomson Reuters collects precise geolocation and session replay data in addition to advertising identifiers and behavioral tracking across its Services. Precise geolocation is designated as sensitive personal information under CCPA/CPRA, triggering opt-out rights, and session replay data may engage additional scrutiny under state wiretapping statutes in certain jurisdictions....
-
Kick
· Kick Privacy Policy
The policy states that changes take effect immediately upon posting and apply to previously collected personal information, with continued use of the service treated as acknowledgment of updated terms....
Why it matters: This provision establishes a retroactive update mechanism that asserts changes apply to data already collected at the time of the update, and treats continued platform use as acknowledgment of new terms without requiring affirmative re-consent. The clause includes the qualifier 'to the extent permitted by law,' which acknowledges that applicable legal frameworks may limit the enforceability of retroactive application....
-
Kick
· Kick Privacy Policy
Creators must provide government-issued identification and tax identification numbers before cashing out earnings or KICKs, with this information collected directly by named and unnamed third-party identity verification providers on Kick's behalf....
Why it matters: This provision establishes a mandatory identity and background check requirement tied to creator payout eligibility, involving collection of government-issued IDs and tax numbers by third-party processors whose identities are not fully disclosed in the provided policy text. This creates a layered data processing structure where sensitive personal data is handled by subprocessors operating under their own terms....
-
Kick
· Kick Privacy Policy
The policy authorizes sharing of hashed email addresses and user IDs with third-party advertising partners and social media platforms including Facebook, Twitter, Instagram, and LinkedIn for cross-device user identification and targeted advertising purposes....
Why it matters: This provision authorizes the transmission of pseudonymized user identifiers to named social media advertising platforms and unnamed advertising partners for cross-device targeting and retargeting. The use of hashed email addresses as cross-device identifiers is a common but regulated practice that may constitute sharing or selling of personal information under certain state privacy laws....
-
Kick
· Kick Privacy Policy
The policy states that age assurance is handled entirely by third-party provider K-ID, with personal information for this process collected directly by K-ID and governed by K-ID's own privacy policy rather than Kick's policy....
Why it matters: This provision establishes that age assurance data is collected and processed by K-ID under K-ID's privacy policy, removing this processing from the scope of Kick's privacy commitments. Users providing information for age assurance are subject to a separate privacy framework that Kick does not control or represent....
-
Kick
· Kick Privacy Policy
The policy authorizes Kick to analyze collected personal information and data from external sources to build interest and preference profiles for advertising targeting, and to use personal information for fraud detection and credit risk assessment....
Why it matters: This provision establishes that Kick conducts profiling of users by combining first-party data with externally sourced data, and applies profiling outputs to advertising and fraud or credit risk assessment. The reference to credit risk assessment is operationally distinct and may engage specific regulatory frameworks depending on how it is implemented....
-
Kick
· Kick Privacy Policy
The policy states that all User Content, including profile information, is posted publicly, and that User Content licenses in the Terms of Service may prevent complete deletion of certain publicly posted information upon request....
Why it matters: This provision establishes that public User Content may not be fully deletable due to license terms in the Terms of Service, which may limit the practical scope of data deletion rights asserted elsewhere in the policy. The interaction between content licensing and data deletion rights is a compliance consideration for jurisdictions where the right to erasure or deletion is a legally established right....
-
Kick
· Kick Privacy Policy
The policy states that personal data is transferred to and stored in countries outside users' jurisdictions, including the United States, and that transfers from the EEA, UK, and Switzerland are conducted under adequacy decisions or standard contractual clauses adopted by the European Commission....
Why it matters: This provision establishes that personal data of EEA, UK, and Swiss users is processed in the United States and other third countries, relying on adequacy decisions or standard contractual clauses as the stated transfer mechanism. The UK's post-Brexit transfer framework and Switzerland's own adequacy assessment framework operate separately from EU GDPR and should be evaluated independently....
-
Kick
· Kick Privacy Policy
The policy states Kick's services are not directed to children under 13, that Kick does not knowingly collect personal information from this age group, and that upon learning of such collection Kick will promptly delete the information....
Why it matters: This provision establishes a COPPA-aligned age threshold and a reactive deletion commitment for data collected from children under 13. The policy relies on the age assurance mechanism (delegated to K-ID) and user self-representation as the primary gatekeeping mechanisms, rather than describing a verified parental consent process....
-
ClickUp
· ClickUp Privacy Policy
The policy states that ClickUp shares user data with third parties for analytics, error tracking, and marketing, and that outside contractors including hosting providers, credit card processors, and mailing list services may access personally identifiable information in the course of providing services to ClickUp....
Why it matters: This provision identifies the categories of third parties that receive user data and the stated purposes for sharing, which are relevant to CCPA sharing definitions and GDPR data processor and controller determinations. The policy requires contractors to protect personal data consistent with the Privacy Policy or Data Protection Addendum and to use it only for contracted purposes....
-
ClickUp
· ClickUp Privacy Policy
The policy states that personal data may be transferred to and processed in countries including the United States, and that continued use of the platform constitutes consent to such international transfers....
Why it matters: This provision asserts that consent to international data transfers is obtained through platform use, which may require evaluation under GDPR Chapter V, which establishes specific lawful transfer mechanisms. The policy defers more detailed transfer safeguards to a separate Data Protection Addendum for contractual customers....
-
ClickUp
· ClickUp Privacy Policy
The policy reserves the right to transfer all user data, including personally identifiable information, to a third party in the event of a business sale, merger, asset transfer, or bankruptcy proceeding, subject to the acquirer agreeing to adhere to the policy's terms....
Why it matters: This provision establishes that user data may be transferred to a new entity following a corporate transaction, with the stated condition that the recipient agrees to the existing policy terms. The practical enforceability of that condition in insolvency or acquisition scenarios may depend on contractual and jurisdictional factors not addressed in the policy....
-
ClickUp
· ClickUp Privacy Policy
The policy states that deletion requests will be honored for actively used databases and readily searchable media, but that copies of personal data may persist in backup systems in a form that is difficult or impossible to locate or remove....
Why it matters: This provision identifies a limitation on deletion request fulfillment, noting that backup copies of personal data may persist after a deletion request is processed. This limitation may require evaluation against GDPR's right to erasure requirements and CCPA deletion obligations, which may recognize technical impossibility exceptions but impose requirements on how such exceptions are documented and communicated....
-
ClickUp
· ClickUp Privacy Policy
The policy requests that users avoid submitting sensitive personal data categories including health information, biometrics, racial or ethnic origin, and criminal background through the service, but states that submission of such data in user-generated content constitutes consent to its processing under the policy....
Why it matters: This provision establishes that consent to process sensitive personal data categories is obtained through the act of submission rather than through a distinct affirmative consent mechanism. This approach may require evaluation under GDPR Article 9, which requires explicit consent for processing special categories of personal data, and CCPA sensitive personal information provisions, which impose additional handling requirements....
-
ClickUp
· ClickUp Privacy Policy
The policy states that ClickUp does not honor Do Not Track browser signals and takes no action in response to such requests....
Why it matters: This provision discloses that browser-level Do Not Track signals are not acted upon by ClickUp, meaning tracking technologies including cookies and similar tools operate regardless of browser-level opt-out signals. California law requires disclosure of Do Not Track response practices, which this provision satisfies....
-
ClickUp
· ClickUp Privacy Policy
The policy states that significant changes to data use or disclosure will be communicated by email, while non-significant changes may be posted without direct notification, with continued platform use constituting acceptance of non-significant changes....
Why it matters: This provision distinguishes between significant and non-significant policy changes, reserving email notification for significant changes while treating continued use as acceptance of non-significant changes. The characterization of whether a change is significant or non-significant is determined by ClickUp under the terms as written....
-
ClickUp
· ClickUp Privacy Policy
The policy enumerates GDPR data subject rights including access, rectification, erasure, restriction, portability, objection, consent withdrawal, and supervisory authority complaint, exercisable by contacting support@clickup.com or the postal address provided....
Why it matters: This provision discloses the GDPR data subject rights available to users and the mechanism for exercising them, which is relevant for EEA and UK users and for enterprise customers assessing ClickUp's compliance with GDPR processor obligations. The provision also notes the right to complain to the UK ICO directly....
-
ClickUp
· ClickUp Privacy Policy
The policy asserts CCPA and CPRA compliance, states that ClickUp does not sell personal information, and provides California consumers with a request mechanism at support@clickup.com for exercising CCPA rights, including identity verification using account information or government identification....
Why it matters: This provision establishes ClickUp's stated position under CCPA and CPRA, including the no-sale assertion and the consumer request mechanism. Whether data shared with advertising and market research partners constitutes sharing under CPRA's cross-context behavioral advertising definition is a separate question from whether it constitutes a sale, and may require further evaluation....
-
ClickUp
· ClickUp Privacy Policy
The policy states that the ClickUp Service is not directed to children under 16 and that ClickUp does not knowingly collect personally identifiable information from individuals it actually knows are under 16....
Why it matters: This provision establishes the age threshold for the service and the scope of the children's data protection commitment, which is framed as applying to individuals ClickUp actually knows are under 16 rather than establishing a verified age-gating mechanism. This framing is relevant to COPPA applicability assessments....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that Whatnot sells and shares personal information with advertising technology companies and advertisers for cross-context behavioral advertising, and provides California residents with a right to opt out of this practice via a designated link....
Why it matters: This provision triggers disclosure, opt-out notice, and Global Privacy Control signal compliance obligations under the California Consumer Privacy Act as amended by the California Privacy Rights Act; the terms authorize ongoing data sharing with advertising and analytics partners unless the user actively exercises the opt-out right....
-
Whatnot
· Whatnot Legal Terms
The policy states that Whatnot collects precise geolocation data from user devices, subject to device-level permission, and uses this data for service delivery, analytics, and advertising purposes....
Why it matters: Precise geolocation constitutes sensitive personal information under CPRA, triggering a separate and distinct opt-out right from the general sale and sharing opt-out; and under GDPR may require explicit consent or a documented legitimate interest assessment depending on the purpose and data flows involved....
-
Whatnot
· Whatnot Legal Terms
The policy states that personal information is retained for as long as necessary to fulfill collection purposes and meet legal obligations, without specifying fixed retention periods for most data categories....
Why it matters: The absence of defined retention timelines for most data categories may require evaluation under GDPR Article 5(1)(e), which establishes a storage limitation principle requiring that personal data be kept no longer than necessary for specified purposes with defined periods where practicable....
-
Whatnot
· Whatnot Legal Terms
The policy authorizes sharing of personal information with advertising partners, analytics providers, and social media companies for targeted advertising and measurement, with those third parties permitted to deploy their own tracking technologies across the user's browsing activity....
Why it matters: This provision authorizes third-party advertising and analytics partners to independently collect user data via tracking technologies deployed across Whatnot's services, which may constitute a sale or sharing of personal information under CCPA/CPRA and requires evaluation under GDPR's lawful basis and ePrivacy consent frameworks....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that personal information may be transferred to and processed in the United States and other countries with potentially different data protection standards than the user's country of residence....
Why it matters: Cross-border transfers of personal data from EU and UK residents to the United States require a lawful transfer mechanism under GDPR such as Standard Contractual Clauses or adequacy decisions; the policy's acknowledgment of differing data protection standards is a disclosure obligation but does not confirm that specific transfer mechanisms are in place....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that Whatnot and its third-party partners deploy cookies, pixel tags, web beacons, mobile analytics software, and log files to support service delivery, analytics, and interest-based advertising....
Why it matters: The deployment of non-essential tracking technologies for advertising and analytics purposes requires user consent under the EU ePrivacy Directive and GDPR, and must be implemented through a consent management mechanism that captures freely given, specific, and informed consent prior to activation of non-essential trackers....
-
Whatnot
· Whatnot Legal Terms
The policy discloses that users in certain jurisdictions have rights to access, delete, correct, and receive a portable copy of their personal information, with the specific rights available depending on the user's location....
Why it matters: This provision establishes the framework under which users may exercise regional statutory privacy rights; the practical availability of these rights depends on Whatnot's response procedures, the exceptions asserted in the policy, and the verification requirements imposed on requesters....
-
Whatnot
· Whatnot Legal Terms
The policy states that Whatnot's services are not directed to children under 13 and that Whatnot does not knowingly collect personal information from that age group, with a commitment to delete such data if discovered....
Why it matters: This provision directly implicates the Children's Online Privacy Protection Act (COPPA), which requires verifiable parental consent before collecting personal information from children under 13; the policy's commitment not to knowingly collect such data is the standard COPPA safe harbor formulation, but operational enforcement of age screening is a separate compliance question....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement authorizes Mixpanel to build and continuously update individual behavioral profiles by combining on-platform activity data with third-party business intelligence data, for the purpose of predicting future interest in Mixpanel's services....
Why it matters: This provision authorizes automated, real-time construction of individual profiles using combined first-party behavioral data and third-party enrichment data, which may engage GDPR Article 22 automated processing safeguards and CCPA profiling disclosure requirements depending on the jurisdiction of the user....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement states that Mixpanel may purchase personal data about users from third-party sources including social networks, location service providers, co-brand partners, and public databases, and combines this data with information collected directly....
Why it matters: This provision authorizes external data enrichment through purchase of personal data from social networks and other third-party data sources, which may engage GDPR Article 14 transparency obligations regarding data obtained from sources other than the data subject and CCPA source disclosure requirements....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement reserves Mixpanel's right to derive de-identified data from personal data and to use and disclose that de-identified data to third parties for any purpose, at Mixpanel's sole discretion, subject to applicable law....
Why it matters: This provision asserts broad discretion over the secondary use and third-party disclosure of data derived from personal information, conditioned on de-identification rather than on user consent or specified purpose limitations. The practical scope of this reservation depends on the robustness of the de-identification standard applied and applicable law in relevant jurisdictions....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement discloses that Mixpanel's use of interest-based advertising services may constitute CCPA 'sharing' of Identifiers and Internet or Network Information with advertising partners, from which California residents may opt out; the agreement separately states Mixpanel does not 'sell' Personal Information under the CCPA definition....
Why it matters: This provision operationalizes CCPA opt-out rights for cross-contextual behavioral advertising sharing, including GPC signal compliance, and distinguishes between 'sharing' (disclosed as occurring) and 'selling' (asserted as not occurring) under CCPA definitions. The distinction is legally significant for California residents' opt-out rights and enforcement scope....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement states that Mixpanel relies on the EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework for cross-border personal data transfers from EU, UK, and Switzerland, and accepts ongoing liability for onward transfers to third-party agents that process data inconsistently with the Frameworks....
Why it matters: This provision establishes Mixpanel's cross-border data transfer legal basis and accepts liability for downstream agent non-compliance with Data Privacy Framework Principles, which is a material contractual and regulatory commitment. The provision also states that Framework Principles govern over conflicting Privacy Statement terms, creating a hierarchy of applicable standards....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement discloses that third-party advertising partners deploy cookies and tracking technologies to collect interaction data across browsers and devices, and that Mixpanel may share user information with these partners to enable interest-based advertising on other platforms, including lookalike audience targeting....
Why it matters: This provision authorizes both direct third-party tracker deployment on Mixpanel properties and outbound data sharing with advertising partners for cross-platform and lookalike audience advertising, with the named third-party cookie list including AdRoll, AppNexus, DoubleClick, Facebook, Google, LinkedIn, Twitter, and others....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement authorizes transfer of users' personal data to acquirers or counterparties in connection with mergers, acquisitions, divestitures, financing transactions, and insolvency, bankruptcy, or receivership proceedings, including during negotiation phases prior to transaction completion....
Why it matters: This provision permits personal data disclosure during transaction negotiations as well as on transaction completion, and expressly covers insolvency and bankruptcy scenarios where data may transfer to creditors or administrators outside the ordinary commercial relationship....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement states that Mixpanel's services are not intended for users under 13 and provides a contact mechanism for parents or guardians who believe their child's data has been collected, but does not describe an active age verification mechanism....
Why it matters: The provision establishes an age 13 minimum for service use consistent with COPPA thresholds but does not describe technical or procedural controls for preventing collection of data from users under 13. The CCPA section separately confirms no actual knowledge of sale or sharing of under-16 personal information....
-
Mixpanel
· Mixpanel Privacy Statement
The agreement grants access, correction, and deletion rights exercisable through Account Settings or by emailing compliance@mixpanel.com, while reserving the right to charge a fee or decline requests deemed unreasonable or excessive, prohibited by law, or where the requester cannot be authenticated....
Why it matters: This provision establishes the procedural mechanism for exercising data subject rights but reserves the right to impose fees or decline requests on grounds that include 'unreasonable or excessive' thresholds, which may require evaluation under GDPR Article 12 and CCPA nondiscrimination provisions in specific jurisdictions....
-
Segment
· Segment Privacy Policy
The notice states that Twilio uses personal data including customer content, communications usage data, and customer support and feedback data to train AI and machine learning models for purposes including security, fraud detection, network optimization, and research and innovation....
Why it matters: This provision establishes that AI and ML training is conducted across multiple stated processing purposes and draws on data categories including customer content such as email bodies, text bodies, media files, and transcripts. Enterprise customers whose contracts govern Twilio's use of customer content as a data processor should evaluate whether the Data Protection Addendum limits or addresses this training use....
-
Segment
· Segment Privacy Policy
The notice states that for the Conversational Intelligence service, Twilio processes personal data within voice calls as an independent data controller rather than as a data processor acting under customer instructions....
Why it matters: This provision establishes a distinct legal role for Twilio when processing voice call content through Conversational Intelligence, which affects how data subject rights requests are routed, how liability is allocated between Twilio and its enterprise customers, and what contractual protections apply to this processing outside the standard DPA processor relationship....
-
Segment
· Segment Privacy Policy
The notice states that Twilio may derive aggregated, anonymized, or de-identified data from personal data and use it for any purpose, subject to a stated commitment not to attempt re-identification and to share only with parties bound to maintain de-identification....
Why it matters: This provision authorizes unrestricted use of data derived from personal data once it has been classified as de-identified or anonymized. The scope of this authorization depends on whether de-identification standards applied by Twilio satisfy the thresholds required under applicable law, which varies by jurisdiction....