

Attio
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •In AI: it does not document a specific opt-out mechanism for AI training, limiting options for customers.
- •In Privacy Baseline: it ensures that the data retention period is clearly informed, reducing uncertainties for those who contract its services.
Safer Alternatives
Higher-rated software in the same category
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Attio
- •Documents data processing purposes, connecting categories to specific objectives.
- •Clearly identifies recipients of personal data, ensuring transparency.
- •These practices strengthen due diligence and trust in data management.
Use of artificial intelligence clearly disclosed in policies
The Terms and Conditions declare the use of AI, essential for transparency on how contact data is used.
AI training opt-out control available
The policy offers generic controls, but not a specific opt-out for AI training, limiting options for customers.
AI data retention policy clearly documented
The policy mentions the retention of interaction data, but does not provide a clear timeframe, creating uncertainties for customers.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller and processor roles clearly defined
The policy clearly defines Attio as a data controller and processor, essential for managing relationships and sales.
Personal data recipients clearly identified in the policy
The policy specifies categories of recipients, ensuring transparency about how contact data is shared.
Processing purposes clearly listed by data category
The policy connects contact data categories with specific purposes, essential for sales management.
Source: vendor public documents
Critical Alerts
- •Controle de opt-out para treinamento de IA disponível: A falta de um opt-out específico pode impactar a confiança dos clientes em relação ao uso de seus dados..
- •Política de retenção de dados de IA claramente documentada: A falta de clareza sobre retenção de dados pode gerar preocupações de privacidade.
Conformance analysis (20)
Roles of data controller and processor clearly defined
Reference: ISO/IEC 27701 (7.3)
Recipients of personal data clearly identified in the policy
Reference: ISO/IEC 27701 (7.3)
Purposes of processing clearly listed by data category
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Attio CRM: Privacy and AI Governance Insights for Users
Transparency in Data Processing Purposes
Attio excels in providing clarity regarding the purposes of data processing. With a high OPTI Base (Privacy) Score of 94%, users can trust that their data is being handled transparently. The software categorizes data types and explicitly states the purposes for which each category is processed. This level of transparency is crucial for compliance with regulations like GDPR and LGPD, as it empowers users to understand how their data is utilized. For users, this means less uncertainty and a stronger sense of control over their personal information.
Clear Identification of Data Recipients
Another strength of Attio is its clear identification of data recipients within its privacy policy. Users can easily find out who has access to their personal data, which is essential for maintaining trust and ensuring compliance with privacy laws. This feature helps users make informed decisions about their data sharing preferences. When considering the implications of sharing data, users should regularly review the list of data recipients to ensure they are comfortable with the entities involved.
Lack of Safeguards for Sensitive Data
Despite its strengths, Attio has notable weaknesses, particularly concerning the handling of sensitive data. The absence of documented additional safeguards for sensitive data processing raises concerns. Users should be aware that sensitive data, such as health information or financial details, may not be adequately protected. To mitigate this risk, users should avoid inputting sensitive information into the CRM unless absolutely necessary and consider implementing additional security measures, such as data encryption or access controls.
Limited Options for AI Training Opt-Out
Attio's OPTI IA Score of 38% indicates significant weaknesses in its AI governance. One critical issue is the lack of a specific opt-out mechanism for AI training. This means that user data may be used to train AI models without explicit consent, which can be a violation of user rights under GDPR and LGPD. Users concerned about their data being used for AI training should reach out to Attio's support team for clarification on how to manage their data preferences and explore alternative solutions that offer clearer opt-out options.
Recommendations for Data Retention Policies
While Attio does provide clear information about data retention periods, the lack of a documented policy for AI data retention is concerning. Users should take proactive steps to understand how long their data will be retained and under what circumstances it may be deleted. Regularly reviewing the retention settings in the software can help users ensure they are not retaining data longer than necessary, which aligns with best practices under ISO 27701 and other privacy frameworks.
Practical Steps for Enhanced Privacy and Security
To enhance privacy and security while using Attio, users should regularly audit their settings. This includes checking data sharing preferences, reviewing the list of data recipients, and ensuring that sensitive data is not unnecessarily stored. Additionally, users should stay informed about updates to Attio's privacy policies and AI governance practices. Engaging with the community and seeking feedback from other users can also provide valuable insights into best practices for using the software securely. By taking these steps, users can better protect their data and maintain compliance with relevant privacy regulations.
Other Sales CRM software
Dive into in-depth research and analysis of each player

Salesforce Sales Cloud

Oracle Sales Cloud

Nutshell

Salesflare
Folk CRM

Capsule CRM

Agile CRM

Microsoft Dynamics 365 Sales
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Attio:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents