

Brevo
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

AI Trust Summary
- •In AI: it does not document ethical principles and anti-bias measures, which may lead to discrimination risks in its services.
- •In Core Privacy: it details the purposes of data processing, ensuring clarity and security in the use of customer information.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •Brevo
- •does not mention ethical AI principles, which may raise concerns about bias.
- •omits anti-bias measures in its AI practices, increasing the risk of discrimination.
- •it is advisable to require specific clauses in the contract to mitigate these risks.
Ethical AI principles and anti-bias measures not documented
No mentions of ethical principles in the use of AI were found, which may raise concerns about bias and discrimination.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Brevo
- •documents data processing purposes clearly and in detail.
- •provides a Data Processing Agreement (DPA) for business customers.
- •these practices strengthen due diligence and trust in data management.
Contestation and human review of AI decisions available
The policy ensures users can contest automated decisions, promoting additional control over their data.
AI features clearly identified with their purposes
The policy describes functionalities that use AI, such as chatbots, and their purposes, ensuring clarity for users.
AI data retention policy clearly documented
The policy defines the retention period for contact data and marketing interactions, ensuring they are deleted after use.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller identity and contact clearly disclosed
The policy clearly states the name and address of the controlling company, ensuring transparency for Brevo's customers.
Data controller and processor roles clearly defined
The policy clarifies the roles of controller and processor, essential for understanding responsibilities in data management.
Processing purposes clearly listed by data category
The policy presents a detailed table connecting contact data and marketing interaction categories with their specific purposes.
Source: vendor public documents
Critical Alerts
- •Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública.
- •Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública
Conformance analysis (20)
Data controller's identity clearly informed
Reference: ISO/IEC 27701 (7.3)
Data controller and processor roles clearly defined
Reference: ISO/IEC 27701 (7.3)
Purposes of processing clearly listed by data category
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Brevo Marketing Automation: Privacy and Security Insights
Transparency in Data Processing
Brevo excels in providing transparency regarding its data processing practices, which is crucial for users concerned about privacy. With an impressive OPTI Base (Privacy) Score of 94%, Brevo clearly lists the purposes for data processing by category. This means users can easily understand how their data will be used, which aligns with the principles of GDPR and LGPD. By ensuring that data processing purposes are explicitly defined, Brevo empowers users to make informed decisions about their data. This level of clarity not only enhances user trust but also ensures compliance with legal frameworks that prioritize user rights.
Legal Basis for Data Processing
Another strength of Brevo lies in its application of a legal basis for executing contracts related to essential data. This is particularly important for businesses that rely on data to fulfill contractual obligations. The presence of a Data Processing Agreement (DPA) for enterprise clients further solidifies Brevo's commitment to privacy. Users can rest assured that their data is handled in accordance with legal requirements, reducing the risk of non-compliance penalties. For users, this means that they can engage with Brevo’s services with confidence, knowing that their data is protected under established legal frameworks.
Lack of Ethical AI Documentation
Despite its strengths, Brevo has notable weaknesses, particularly concerning its AI practices. The absence of documented ethical principles and anti-bias measures raises concerns about potential discrimination in its services. With an OPTI IA Score of 63%, users should be cautious about how AI-driven features may impact their marketing strategies. Without clear guidelines, there is a risk that AI algorithms could inadvertently favor certain demographics over others, leading to unfair treatment of customers. Users should critically evaluate how they utilize AI features within Brevo and consider the implications of biased outcomes.
Insufficient Privacy Documentation
Another significant weakness is the lack of mention of privacy aspects in the vendor documentation. This oversight can leave users in the dark about how their data is being managed, especially in terms of compliance with privacy regulations like GDPR and LGPD. Users should proactively seek clarification from Brevo regarding their privacy policies and practices. It is advisable to review the documentation thoroughly and request additional information if necessary. Being informed will help users mitigate risks associated with data handling and ensure that they are compliant with legal standards.
Practical Settings to Enhance Privacy
To maximize privacy while using Brevo, users should take advantage of available settings. Ensure that data processing purposes are clearly understood and that any unnecessary data collection features are disabled. Regularly review and update consent settings to align with user preferences. Additionally, users should familiarize themselves with the DPA provided for enterprise clients, as it outlines the responsibilities of both parties in data handling. By actively managing these settings, users can enhance their privacy and security while using Brevo’s marketing automation tools.
Alternatives and Precautions
For users concerned about the weaknesses identified, it may be worthwhile to explore alternative marketing automation platforms that prioritize ethical AI practices and comprehensive privacy documentation. Consider platforms that have a higher OPTI IA Score and provide detailed information about their AI governance. Additionally, users can implement precautionary measures such as conducting regular audits of their data usage and ensuring compliance with privacy regulations. By being proactive and informed, users can navigate the complexities of marketing automation while safeguarding their data privacy.
Other Marketing Automation software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Brevo:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents





