The register › twilio.com
twilio.com
A dated copy of the sub-processor list twilio.com publishes on their own site. We read it; nobody here reviewed it and twilio.com did not approve it.
hash 81fca05126
11 sub-processors
0 countries| Entity | Purpose | Country | Scope |
|---|---|---|---|
| Measures for allowing data portability and ensuring erasure | Customer is able to export or delete Customer Content using the self-service features of the Services as set forth in the applicable documentation for the Services available at https://www.twilio.com/docs. For an example of data portability self-service features, see: https://support.twilio.com/hc/en-us/articles/223183588-Exporting-SMS-and-Call-Logs. For an example of data portability self-service features, see: https://docs.sendgrid.com/ui/managing-contacts/create-and-manage-contacts#export-contacts. For an example of data erasure self-service features, see: https://support.twilio.com/hc/en-us/articles/223181008-Twilio-SMS-message-and-traffic-storage. For an example of data erasure self-service features, see: https://www.twilio.com/docs/sendgrid/api-reference/contacts/delete-contacts. | — | — |
| Measures for certification/assurance of processes and products | See Section 3 (Security Organization and Program) and Section 7 (Security Certifications and Attestations) of the Security Overview | — | — |
| Measures for ensuring accountability | Twilio has adopted Binding Corporate Rules which govern the global handling, processing and transfer of personal data within Twilio. | — | — |
| Measures for ensuring data quality and data minimisation | Where Twilio acts as a processor of Customer Personal Data and based on the instructions of the Customer, Twilio will assist Customer in complying with its obligation to keep personal data accurate and up to date. Where Customer informs Twilio that Customer Personal Data Twilio processes on its behalf is inaccurate, Twilio will assist Customer to update, correct, or erase such data without undue delay. Twilio will also take measures to inform its group members or third-party processors to whom such data has been disclosed of the need to update, correct, or erase such personal data. | — | — |
| Measures for ensuring events logging | See: https://www.twilio.com/docs/verify/viewing-logs-with-twilio-console and: https://docs.sendgrid.com/ui/analytics-and-reporting/email-activity-feed | — | — |
| Measures for ensuring limited data retention | Where Twilio acts as a processor of Customer Personal Data and based on the instructions of the Customer, Twilio will assist Customer in storing Customer Personal Data only for as long as is necessary for the purpose for which such data was initially collected. Where Customer instructs Twilio that Customer Personal Data Twilio processes on its behalf is no longer needed, Twilio will assist Customer to erase, restrict, or anonymize such data without undue delay and in accordance with the terms of the Agreement. Twilio will also take measures to inform its group members or third-party processors to whom such data has been disclosed of the need to erase, restrict, or anonymize that personal data. | — | — |
| Measures for ensuring system configuration, including default configuration | See: https://www.twilio.com/docs/runtime/functions-assets-api/api/logs and: https://docs.sendgrid.com/ui/analytics-and-reporting/email-activity-feed | — | — |
| Measures for the protection of data during storage | See Section 8 (Hosting Architecture and Data Segregation) and Section 12 (Encryption) of the Security Overview | — | — |
| Measures for the protection of data during transmission | See Section 12 (Encryption) and Section 17 (Customer Data Backups) of the Security Overview | — | — |
| Measures for user identification and authorisation | See Section 10 (Access Controls) of the Security Overview | — | — |
| Measures to be taken by third-party sub-processors | Where Twilio engages a sub-processor under Section 6.1 (Authorization for Sub-Processing), Twilio and the sub-processor enter into an agreement with data protection obligations substantially similar to those set forth in this Addendum. Each sub-processor agreement must ensure that Twilio is able to meet its obligations to Customer. In addition to implementing technical and organizational measures to protect personal data, sub-processors must (a) notify Twilio in the event of a Security Incident, so Twilio may notify Customer; (b) delete personal data where instructed by Twilio in accordance with Customer’s instructions to Twilio; (c) not engage additional sub-processors without Twilio’s authorization; (d) not change the location where personal data is processed; or (e) not process personal data in a manner which conflicts with Customer’s instructions to Twilio. | — | — |
Dated history
1 versionEach version is a snapshot taken when the business approved it, not a pointer at a list that can change underneath you. The hash covers the sorted set of entities, so reordering rows does not produce a new version.