

Bloomreach
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •Regarding AI: it does not mention retention of AI interaction data, which may create uncertainty about the use of such data.
- •Regarding Core Privacy: it clearly documents the availability of a Data Processing Agreement, ensuring compliance with LGPD and GDPR.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (2)
AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.
- •Bloomreach
- •Does not document AI data retention, which creates uncertainty about the processing of AI inputs and outputs.
- •Omission of AI ethics principles and anti-bias measures may impact the company's accountability.
- •It is advisable to require contractual clauses that address these critical points.
AI data retention (prompts and responses) is not disclosed
There is no specific mention of AI interaction data retention, which may create uncertainty for users.
Ethical AI principles and anti-bias measures not documented
There is no specific mention of bias or discrimination in AI, which may impact the company's accountability.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Bloomreach
- •Provides a Data Processing Agreement (DPA) for enterprise clients, ensuring compliance with LGPD and GDPR.
- •Clearly defines its roles as a data controller, which is crucial for accountability in digital marketing.
- •These practices facilitate due diligence and increase customer trust.
AI features clearly identified with their purposes
The policy describes how AI is used to personalize marketing campaigns, increasing the effectiveness of strategies.
Use of artificial intelligence clearly disclosed in policies
The company declares the use of AI in its functionalities, which is essential for transparency in marketing campaigns.
AI training opt-out control available
Cookie controls exist that allow users to customize their preferences, but a specific opt-out for AI is missing.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Sensitive data processing without additional documented safeguards
There is no mention of sensitive data or specific safeguards, which represents a risk to user privacy.
Transparency about international data transfers documented
The policy identifies Bloomreach as a controller outside the EU, ensuring compliance with international transfers.
Data Processing Agreement (DPA) available for business customers
The policy mentions the availability of a DPA, ensuring that data processing complies with LGPD and GDPR.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: Importante para garantir práticas éticas em marketing digital..
- •Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Crucial para proteger dados sensíveis em campanhas de marketing.
Conformance analysis (20)
Transparency on international data transfer documented
Reference: ISO/IEC 27701 (7.3)
Data Processing Agreement (DPA) available for enterprise clients
Reference: ISO/IEC 27701 (8.2) + LGPD Art. 39 + GDPR Art. 28
Data controller and processor roles clearly defined
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Understanding Privacy and Security with Bloomreach Marketing Automation
Transparency in Data Processing Agreements
Bloomreach stands out for its commitment to transparency in privacy practices, particularly through its Data Processing Agreement (DPA) available for enterprise clients. This agreement ensures that users are informed about how their data is processed, aligning with the requirements of regulations like LGPD and GDPR. For users, this means that you have a clear understanding of your rights and the obligations of Bloomreach regarding your data. The presence of a DPA is crucial as it outlines the roles of data controllers and processors, which can help you feel more secure about how your data is handled. Make sure to review the DPA thoroughly to understand the specifics of data usage and your rights under these regulations.
Defined Roles for Data Controllers and Processors
Another strength of Bloomreach is its clear definition of roles between data controllers and processors. This clarity is essential for users who want to ensure that their data is managed responsibly. Knowing who is responsible for what can help mitigate risks associated with data mishandling. Users should take the time to familiarize themselves with these roles as outlined in the DPA. This understanding can empower you to ask the right questions and ensure compliance with privacy regulations, ultimately enhancing your trust in the platform.
Uncertainty in AI Data Retention Policies
Despite its strengths, Bloomreach has notable weaknesses, particularly regarding the lack of clarity around the retention of AI interaction data, such as prompts and responses. This absence of information can create uncertainty for users about how long their data is stored and how it may be used in the future. For users, this means you should be cautious when using AI features within the platform. It’s advisable to limit the sharing of sensitive information in AI interactions until more transparency is provided. Regularly check for updates from Bloomreach regarding their data retention policies to stay informed.
Lack of Documentation on Ethical AI Principles
Another significant weakness is the absence of documented ethical AI principles and anti-bias measures. This gap raises concerns about the potential for bias in AI-generated outputs, which can affect marketing strategies and outcomes. Users should be aware that without these safeguards, there is a risk of unintentionally perpetuating biases in marketing campaigns. To mitigate this risk, consider implementing your own review processes for AI-generated content and outputs. Regular audits of the AI's performance can help identify any biases and allow for adjustments to be made.
Precautions for Handling Sensitive Data
Bloomreach's handling of sensitive data without additional documented safeguards is another area of concern. This lack of documentation means that users may not have a clear understanding of how their sensitive data is protected. For users, it’s crucial to take precautions when inputting sensitive information into the platform. Ensure that you are only sharing necessary data and consider using anonymization techniques where possible. Additionally, keep an eye on Bloomreach’s updates regarding their data protection measures to ensure that your sensitive information remains secure.
Practical Steps for Enhanced Privacy
To enhance your privacy while using Bloomreach, there are several practical steps you can take. First, regularly review your account settings to ensure that you are aware of what data is being collected and how it is used. Enable any privacy features available within the platform, such as data access requests or data deletion options. Additionally, consider using alternative tools or features that offer more robust privacy protections if you have concerns about Bloomreach's current practices. Staying informed and proactive can help you navigate the complexities of data privacy while leveraging the benefits of Bloomreach's marketing automation capabilities.
Other Marketing Automation software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Bloomreach:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents





