Skip to main content
Bloomreach logo

Bloomreach

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

C-
AITS IA

AI Trust Summary

AI Training
Possibly (generic mention of service improvement)
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
C-
BasePrivacy
B-
  • Regarding AI: it does not mention retention of AI interaction data, which may create uncertainty about the use of such data.
  • Regarding Core Privacy: it clearly documents the availability of a Data Processing Agreement, ensuring compliance with LGPD and GDPR.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (2)

AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.

  • Bloomreach
  • Does not document AI data retention, which creates uncertainty about the processing of AI inputs and outputs.
  • Omission of AI ethics principles and anti-bias measures may impact the company's accountability.
  • It is advisable to require contractual clauses that address these critical points.

AI data retention (prompts and responses) is not disclosed

There is no specific mention of AI interaction data retention, which may create uncertainty for users.

Ethical AI principles and anti-bias measures not documented

There is no specific mention of bias or discrimination in AI, which may impact the company's accountability.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Bloomreach
  • Provides a Data Processing Agreement (DPA) for enterprise clients, ensuring compliance with LGPD and GDPR.
  • Clearly defines its roles as a data controller, which is crucial for accountability in digital marketing.
  • These practices facilitate due diligence and increase customer trust.

AI features clearly identified with their purposes

The policy describes how AI is used to personalize marketing campaigns, increasing the effectiveness of strategies.

Use of artificial intelligence clearly disclosed in policies

The company declares the use of AI in its functionalities, which is essential for transparency in marketing campaigns.

AI training opt-out control available

Cookie controls exist that allow users to customize their preferences, but a specific opt-out for AI is missing.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Sensitive data processing without additional documented safeguards

There is no mention of sensitive data or specific safeguards, which represents a risk to user privacy.

Transparency about international data transfers documented

The policy identifies Bloomreach as a controller outside the EU, ensuring compliance with international transfers.

Data Processing Agreement (DPA) available for business customers

The policy mentions the availability of a DPA, ensuring that data processing complies with LGPD and GDPR.

Source: vendor public documents

Critical Alerts

  • Princípios de IA ética e medidas anti-viés não documentados: Importante para garantir práticas éticas em marketing digital..
  • Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Crucial para proteger dados sensíveis em campanhas de marketing.

Conformance analysis (20)

Premium Feature
AITS Criterion 15
Compliant

Transparency on international data transfer documented

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 20
Compliant

Data Processing Agreement (DPA) available for enterprise clients

Reference: ISO/IEC 27701 (8.2) + LGPD Art. 39 + GDPR Art. 28

AITS Criterion 9
Compliant

Data controller and processor roles clearly defined

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Understanding Privacy and Security with Bloomreach Marketing Automation

Transparency in Data Processing Agreements

Bloomreach stands out for its commitment to transparency in privacy practices, particularly through its Data Processing Agreement (DPA) available for enterprise clients. This agreement ensures that users are informed about how their data is processed, aligning with the requirements of regulations like LGPD and GDPR. For users, this means that you have a clear understanding of your rights and the obligations of Bloomreach regarding your data. The presence of a DPA is crucial as it outlines the roles of data controllers and processors, which can help you feel more secure about how your data is handled. Make sure to review the DPA thoroughly to understand the specifics of data usage and your rights under these regulations.

Defined Roles for Data Controllers and Processors

Another strength of Bloomreach is its clear definition of roles between data controllers and processors. This clarity is essential for users who want to ensure that their data is managed responsibly. Knowing who is responsible for what can help mitigate risks associated with data mishandling. Users should take the time to familiarize themselves with these roles as outlined in the DPA. This understanding can empower you to ask the right questions and ensure compliance with privacy regulations, ultimately enhancing your trust in the platform.

Uncertainty in AI Data Retention Policies

Despite its strengths, Bloomreach has notable weaknesses, particularly regarding the lack of clarity around the retention of AI interaction data, such as prompts and responses. This absence of information can create uncertainty for users about how long their data is stored and how it may be used in the future. For users, this means you should be cautious when using AI features within the platform. It’s advisable to limit the sharing of sensitive information in AI interactions until more transparency is provided. Regularly check for updates from Bloomreach regarding their data retention policies to stay informed.

Lack of Documentation on Ethical AI Principles

Another significant weakness is the absence of documented ethical AI principles and anti-bias measures. This gap raises concerns about the potential for bias in AI-generated outputs, which can affect marketing strategies and outcomes. Users should be aware that without these safeguards, there is a risk of unintentionally perpetuating biases in marketing campaigns. To mitigate this risk, consider implementing your own review processes for AI-generated content and outputs. Regular audits of the AI's performance can help identify any biases and allow for adjustments to be made.

Precautions for Handling Sensitive Data

Bloomreach's handling of sensitive data without additional documented safeguards is another area of concern. This lack of documentation means that users may not have a clear understanding of how their sensitive data is protected. For users, it’s crucial to take precautions when inputting sensitive information into the platform. Ensure that you are only sharing necessary data and consider using anonymization techniques where possible. Additionally, keep an eye on Bloomreach’s updates regarding their data protection measures to ensure that your sensitive information remains secure.

Practical Steps for Enhanced Privacy

To enhance your privacy while using Bloomreach, there are several practical steps you can take. First, regularly review your account settings to ensure that you are aware of what data is being collected and how it is used. Enable any privacy features available within the platform, such as data access requests or data deletion options. Additionally, consider using alternative tools or features that offer more robust privacy protections if you have concerns about Bloomreach's current practices. Staying informed and proactive can help you navigate the complexities of data privacy while leveraging the benefits of Bloomreach's marketing automation capabilities.

Other Marketing Automation software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Analyzed Sources

Public documents used in the audit of Bloomreach:

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents