Skip to main content
Brevo logo

Brevo

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

B-
AITS IA
Privacy Rating by TrustThis — Verified Seal

AI Trust Summary

AI Training
Possibly (generic mention of service improvement)
Data Retention
Retention policy documented
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
B-
BasePrivacy
A+
  • In AI: it does not document ethical principles and anti-bias measures, which may lead to discrimination risks in its services.
  • In Core Privacy: it details the purposes of data processing, ensuring clarity and security in the use of customer information.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (1)

AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.

  • Brevo
  • does not mention ethical AI principles, which may raise concerns about bias.
  • omits anti-bias measures in its AI practices, increasing the risk of discrimination.
  • it is advisable to require specific clauses in the contract to mitigate these risks.

Ethical AI principles and anti-bias measures not documented

No mentions of ethical principles in the use of AI were found, which may raise concerns about bias and discrimination.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Brevo
  • documents data processing purposes clearly and in detail.
  • provides a Data Processing Agreement (DPA) for business customers.
  • these practices strengthen due diligence and trust in data management.

Contestation and human review of AI decisions available

The policy ensures users can contest automated decisions, promoting additional control over their data.

AI features clearly identified with their purposes

The policy describes functionalities that use AI, such as chatbots, and their purposes, ensuring clarity for users.

AI data retention policy clearly documented

The policy defines the retention period for contact data and marketing interactions, ensuring they are deleted after use.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Data controller identity and contact clearly disclosed

The policy clearly states the name and address of the controlling company, ensuring transparency for Brevo's customers.

Data controller and processor roles clearly defined

The policy clarifies the roles of controller and processor, essential for understanding responsibilities in data management.

Processing purposes clearly listed by data category

The policy presents a detailed table connecting contact data and marketing interaction categories with their specific purposes.

Source: vendor public documents

Critical Alerts

  • Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública.
  • Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública

Conformance analysis (20)

Premium Feature
AITS Criterion 10
Compliant

Data controller's identity clearly informed

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 9
Compliant

Data controller and processor roles clearly defined

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 12
Compliant

Purposes of processing clearly listed by data category

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Brevo Marketing Automation: Privacy and Security Insights

Transparency in Data Processing

Brevo excels in providing transparency regarding its data processing practices, which is crucial for users concerned about privacy. With an impressive OPTI Base (Privacy) Score of 94%, Brevo clearly lists the purposes for data processing by category. This means users can easily understand how their data will be used, which aligns with the principles of GDPR and LGPD. By ensuring that data processing purposes are explicitly defined, Brevo empowers users to make informed decisions about their data. This level of clarity not only enhances user trust but also ensures compliance with legal frameworks that prioritize user rights.

Legal Basis for Data Processing

Another strength of Brevo lies in its application of a legal basis for executing contracts related to essential data. This is particularly important for businesses that rely on data to fulfill contractual obligations. The presence of a Data Processing Agreement (DPA) for enterprise clients further solidifies Brevo's commitment to privacy. Users can rest assured that their data is handled in accordance with legal requirements, reducing the risk of non-compliance penalties. For users, this means that they can engage with Brevo’s services with confidence, knowing that their data is protected under established legal frameworks.

Lack of Ethical AI Documentation

Despite its strengths, Brevo has notable weaknesses, particularly concerning its AI practices. The absence of documented ethical principles and anti-bias measures raises concerns about potential discrimination in its services. With an OPTI IA Score of 63%, users should be cautious about how AI-driven features may impact their marketing strategies. Without clear guidelines, there is a risk that AI algorithms could inadvertently favor certain demographics over others, leading to unfair treatment of customers. Users should critically evaluate how they utilize AI features within Brevo and consider the implications of biased outcomes.

Insufficient Privacy Documentation

Another significant weakness is the lack of mention of privacy aspects in the vendor documentation. This oversight can leave users in the dark about how their data is being managed, especially in terms of compliance with privacy regulations like GDPR and LGPD. Users should proactively seek clarification from Brevo regarding their privacy policies and practices. It is advisable to review the documentation thoroughly and request additional information if necessary. Being informed will help users mitigate risks associated with data handling and ensure that they are compliant with legal standards.

Practical Settings to Enhance Privacy

To maximize privacy while using Brevo, users should take advantage of available settings. Ensure that data processing purposes are clearly understood and that any unnecessary data collection features are disabled. Regularly review and update consent settings to align with user preferences. Additionally, users should familiarize themselves with the DPA provided for enterprise clients, as it outlines the responsibilities of both parties in data handling. By actively managing these settings, users can enhance their privacy and security while using Brevo’s marketing automation tools.

Alternatives and Precautions

For users concerned about the weaknesses identified, it may be worthwhile to explore alternative marketing automation platforms that prioritize ethical AI practices and comprehensive privacy documentation. Consider platforms that have a higher OPTI IA Score and provide detailed information about their AI governance. Additionally, users can implement precautionary measures such as conducting regular audits of their data usage and ensuring compliance with privacy regulations. By being proactive and informed, users can navigate the complexities of marketing automation while safeguarding their data privacy.

Other Marketing Automation software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Analyzed Sources

Public documents used in the audit of Brevo:

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents