Privacy Policy
Effective December 16th, 2025
Your data, your ownership
You retain full ownership of all content you create. We never claim rights to your work.
EU-hosted infrastructure
All data stored in Frankfurt, Germany (AWS eu-central-1) under GDPR protection.
No AI training
Your content is never used to train AI models. Third-party AI is contractually restricted.
Isolated access
Row-level security ensures you only see your organisation's data. No shared datasets.
No data selling
We don't sell your data or share it for advertising. Period.
Full data rights
Access, correct, delete, or export your data anytime. GDPR and CCPA compliant.
1. Introduction
Segment8 ('we', 'our', or 'us') respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, share, and protect your information when you use our GTM management platform (the 'Service').
By using our Service, you agree to the collection and use of information in accordance with this policy. We will not use or share your information with anyone except as described in this Privacy Policy.
Segment8 acts as a data controller for account information, billing data, and marketing communications. When processing customer content uploaded to the Service (such as competitive intelligence, messaging frameworks, and launch materials), Segment8 acts as a data processor on behalf of the customer.
2. Information We Collect
We collect information necessary to provide our GTM management services, which falls into the following categories:
- Account Information: When you register for an account, we collect information such as your name, email address, organization name, job title, and account credentials.
- Usage Data: We automatically collect information about how you interact with our Service, including pages visited, features used, time spent on the platform, and other analytics data.
- Marketing Content: We collect the content you create, upload, or store in our platform, including competitive intelligence data, messaging frameworks, product launch plans, and related documents. Customers retain all rights, title, and interest in their Marketing Content. Segment8 does not claim ownership over customer content.
- Communication Data: If you contact us directly, we may receive additional information about you such as your name, email address, phone number, and the contents of your message.
- Device Information: We collect information about your device, including IP address, browser type, operating system, and referral URLs.
These categories of information correspond to identifiers, internet activity information, professional or employment-related information, and customer communications, as defined under the CCPA.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service, including to process transactions, send confirmation notices, and respond to your requests.
- Develop new products, services, features, and functionality.
- Personalize and customize your experience based on your preferences and usage patterns.
- Communicate with you about the Service, including sending you updates, security alerts, administrative messages, and information about new features. You may unsubscribe from non-essential marketing communications at any time using the unsubscribe link in our emails or by contacting us.
- Monitor and analyze trends, usage, and activities in connection with our Service to improve performance.
- Detect, investigate, and prevent fraudulent transactions and other illegal activities.
- Generate aggregated, de-identified usage insights (such as feature adoption and workflow trends) that do not identify individual customers, organisations, or specific content.
3a. Legal Basis for Processing
Segment8 processes personal data on the following lawful bases under applicable data protection laws:
- Performance of a contract to provide the Service
- Legitimate interests in operating, securing, and improving the Service
- Compliance with legal obligations
- Consent, where required
3b. Use of Data for AI Processing
Segment8 may use third-party AI services to process customer inputs only where required to deliver a specific product feature. Customer content is used solely to provide the requested functionality and is not used to train machine learning models or AI systems.
Where third-party AI providers are used, they act as sub-processors and are required to be contractually restricted from using customer data for their own model training or other purposes beyond delivering the requested service.
Aggregated, de-identified usage data may be used to improve product functionality and performance, but does not include customer content or identifiable customer data.
4. Internal Access to Customer Data
Segment8 restricts access to customer data to authorised personnel only. Customer data is not accessed as part of routine operations outside defined support, security, or legal workflows. Production data is stored in managed PostgreSQL instances with authenticated admin credentials required for access.
Administrative access is limited to essential operational purposes, including:
- Responding to customer support requests
- Performing service maintenance
- Investigating security concerns
- Meeting legal compliance obligations
We do not proactively review customer content. Access to customer data for support purposes occurs only when required to respond to a specific request, investigate a service issue, or resolve a security concern.
Authentication events are logged, and database access is restricted to controlled credentials over secure, encrypted connections.
5. Data Segregation and Access Controls
We apply the principle of least privilege to all internal systems and data access.
Customer data is logically isolated within our database using Row Level Security (RLS) policies, ensuring customers can only access data associated with their own organisation. There is no shared customer-visible dataset.
Customer access is enforced at the database level, with separate credentials used for administrative access and application access. Administrative access is restricted to a minimal number of authorised accounts, and multi-factor authentication is enforced on all admin accounts.
7. Data Security and Encryption
We protect customer data using industry-standard encryption and security practices:
- Data is encrypted in transit using TLS
- Data is encrypted at rest using managed encryption provided by our infrastructure partners
- Secrets and credentials are stored using secure environment and secrets management
Segment8 maintains logging and monitoring appropriate to the nature and scale of the Service. This includes authentication events, API requests, and database connections.
Segment8 does not maintain continuous row-level audit logs of all data access by default. Logs are retained for operational and troubleshooting purposes. Access investigations rely on authentication logs, system logs, and scoped operational access records appropriate to the scale of the Service.
8. Incident Response
Segment8 maintains procedures to detect, respond to, and mitigate security incidents.
We use monitoring and alerts to detect abnormal system behaviour, and security incidents are investigated promptly by authorised personnel. Where required by law, affected customers will be notified without undue delay.
While we implement appropriate technical and organisational security measures, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
9. Data Retention and Deletion
We retain customer data only for as long as necessary to provide the Service. Customer data is retained for the duration of an active account.
You may delete content or close your account at any time through the platform or by contacting us. Upon account closure, data is removed from active systems within a reasonable timeframe, subject to backup retention schedules and any legal obligations requiring longer retention.
Backup data is securely deleted in accordance with our infrastructure providers' retention policies. Generally, we retain:
- Account information for the duration of your active subscription and for up to 3 years after account closure for legal and compliance purposes
- Usage data and analytics information for up to 2 years to improve our Service
- Support communications for up to 1 year to maintain service quality
10. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information, including:
- Access: The right to request copies of your personal information
- Rectification: The right to request correction of inaccurate or incomplete information
- Erasure: The right to request deletion of your personal information
- Portability: The right to request transfer of your data to another service provider
- Objection: The right to object to certain types of processing
- Restriction: The right to request restriction of processing in certain circumstances
Where applicable, California residents also have the right to limit the use of sensitive personal information. Segment8 does not use or disclose sensitive personal information for purposes beyond providing the Service.
To exercise these rights, please contact us using the information provided below. We may need to verify your identity before processing certain privacy requests, which may require confirming information associated with your account. We reserve the right to decline requests where identity cannot be reasonably verified to protect against unauthorised access to personal information.
10a. California Privacy Rights
If you are a California resident, you have the rights described in this Privacy Policy under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). These include:
- The right to know what personal information we collect, use, and disclose
- The right to request deletion or correction of personal information
- The right to access or receive a copy of your personal information
- The right not to be discriminated against for exercising your privacy rights
Segment8 does not sell personal information or share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA.
California residents may exercise their rights by contacting us using the details provided in Section 14.
11. Data Storage and International Transfers
Customer data is stored on secure servers located in the European Union (EU), specifically in the AWS eu-central-1 region (Frankfurt, Germany).
Segment8 uses EU-based infrastructure to host and process customer data, ensuring it remains subject to EU data protection laws, including the GDPR.
For customers located outside the EU, personal data may be accessed from outside the EU in the course of providing the Service, but is processed and stored within the EU.
If data is transferred outside the EU, we use legally approved safeguards (such as standard contractual clauses) to ensure it remains protected to EU standards.
For enterprise customers, a Data Processing Addendum (DPA) is available upon request.
Where required by local law, jurisdiction-specific disclosures or supplementary privacy notices may be provided.
12. Children's Privacy
Our Service is not intended for children under the age of 16, and we do not knowingly collect personal information from children under 16.
If we become aware that we have collected personal information from a child under 16, we will take steps to remove that information from our servers promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
We will notify you of any material changes by posting the updated policy on our website and, if you have an account with us, by sending you an email notification. The updated policy will be effective from the date of posting unless otherwise specified.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
- Email: [email protected]
- Address: Segment8 Ltd., 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE
We aim to respond to privacy inquiries within 30 days, or sooner where required by law.