Baseten will ensure that each Sub-Processor shall be bound by a written agreement that includes terms which offer at least a level of protection for Customer Personal Data substantially similar to those set out in this DPA...
Zoom
· Zoom Sub-Processors
By flowing down equivalent DPA obligations to subprocessors, Zoom extends its own data protection commitments through the subprocessing chain, rather than allowing a lower standard at the subprocessor level.
When engaging any Subprocessor, Google will ensure via a written contract that if the processing of Customer Personal Data is subject to European Data Protection Legislation, the data protection obligations in these Data Processing Terms... are imposed on the Subprocessor.
Sub-processors are contractually required to meet data protection standards set by applicable law, not merely Segment's internal standards, meaning legal compliance obligations flow down through the sub-processing chain.
The written contract requirement—with the qualifier 'strict accordance'—means sub-processors cannot operate outside documented, binding terms, creating an enforceable framework for sub-processing conduct.
Subscribing to a Creator's publication on Substack results in the Creator receiving the subscriber's name and email address, transferring personal data to a third party outside Substack's direct control.
Twilio
· Twilio Privacy Notice
Where required by local law, we share Subscriber Records with local carriers or authorities solely to provide connectivity, maintaining the highest confidentiality for these records.
Meta
· Meta Platform Policy
ensure the Service Provider requires the Sub-Service Provider in writing to comply with the above requirements.
Zoom
· Zoom Sub-Processors
Suki may process the following data if the AI Clinical Notes feature is enabled: Customer Content and context
Suno
· Suno Terms of Service
Suno may preserve Content and your Voice Model and may also disclose Content and your Voice Model if required to do so by law or in the good faith belief that such preservation or disclosure is reasonably necessary to: (a) …
The clause establishes a categorical prohibition on two specific forms of commercial transfer of personal information to third parties.
if Synthesia undertakes or is involved in any merger, acquisition, reorganisation, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer, or share some or all of our assets, including your personal data...
We will not be responsible for any use, disclosure, modification or deletion of Customer Data that is transmitted to, or accessed by, a Non-Synthesia Product.
where we are under an obligation to disclose personal data such as, for example, if we receive a valid legal request for certain personal data (such as a search warrant), we will access, preserve and/or share your personal data...
we will share your information if and to the extent we are required or permitted to do so by law or where disclosure is reasonably necessary to (i) comply with applicable law; (ii) comply with a valid legal request...
In order to effectively verify the authenticity of submissions, we may use a third-party verification systems or vendors, including but not limited to Amazon Web Services EMEA SARL.
The clause establishes that Tabnine does not engage in the sale of Personal Information, which is relevant to privacy rights under laws such as the California Consumer Privacy Act.
We do not share sensitive Personal Information for cross-context behavioral advertising and we do not sell sensitive Personal Information.
We may use or share these groups, ad IDs, and insights with other brands to provide more tailored offers and ads, enhanced experiences, and campaign measurement.
Hinge
· Hinge Privacy Policy
User data flows to third-party advertising partners either through active sharing by Hinge or by granting those partners direct technical access to collect data from Hinge's own services.
Data sharing for advertising measurement can expose user data to third-party ad-tech companies through technical channels that may not be visible to users.
This may be considered a data "sale" or "sharing" as those terms are defined under the CCPA and other applicable US privacy laws.
SoFi
· SoFi Privacy Notice (Retired URL)
The information the cookies gather about you can be shared with other advertisers to measure the performance of their advertisements and may be used to build a profile to deliver personalized ads.
OpenAI
· OpenAI Sub-Processor List
Customer data across all OpenAI services is accessible to TaskUs in the Philippines for support purposes, and content and GPT moderation data for specific services is also processed there.
It establishes that data isolation is enforced at the team level even when teams share an organizational account.
Twilio
· Twilio Sub-Processors
This obligation means Twilio's sub-processors are contractually bound to meet data protection standards, extending the legal protection framework beyond Twilio itself to the third parties it engages.
Cursor
· Cursor Security Practices
This establishes that data protection obligations extend beyond Cursor itself to its model providers, through both technical and contractual mechanisms.
Meta
· Meta Platform Policy
You will only share Platform Data in compliance with these Terms, applicable law and regulations, and all other applicable terms and policies, and only in the following circumstances...
Meta
· Meta Platform Policy
With respect to Platform Data collected as a Tech Provider, solely as described below in Section 5.b ("Tech Providers")
Workday
· Workday Privacy Statement
If you consent to receive text messages from Workday, no mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of information disclosed or shared...exclude text messaging originator opt-in data and consent...