Skip to main content
Capsule CRM logo

Capsule CRM

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

D+
AITS IA

AI Trust Summary

AI Training
Possibly (generic mention of service improvement)
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
D+
BasePrivacy
A-
  • In AI: it does not document the retention of AI inputs and outputs, which creates uncertainties about information processing.
  • In Core Privacy: it clearly identifies data recipients, facilitating understanding of information sharing.

Attention Points in AI (3)

AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.

  • Capsule CRM
  • Does not mention the retention of AI inputs and outputs, which could compromise information security.
  • Does not document a mechanism for contesting AI decisions, impacting customer trust.
  • It is necessary to demand contractual clauses that address these critical points.

AI data retention (prompts and responses) is not disclosed

The policy does not specify the retention of AI inputs and outputs, which can create uncertainties about the processing of contact information and sales data.

Ethical AI principles and anti-bias measures not documented

There is no mention of ethical AI principles, which could compromise customer trust in the use of their contact information and sales data.

AI decision contestation mechanism not available

There is no specific mention of human review of automated decisions, which could impact customer trust in decisions made based on their information.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Capsule CRM
  • The policy specifies clear data retention criteria, ensuring that information is kept only for as long as necessary.
  • Identifies categories of data recipients, ensuring transparency in sharing.
  • These practices strengthen due diligence and trust in data management.

Policy on data use for AI training clearly stated

The policy mentions the use of data to improve the service, but is unclear about how contact information and sales data are used.

AI features clearly identified with their purposes

The policy describes specific AI functionalities, ensuring that customers understand how their contact information and sales data are used.

AI training opt-out control available

The company offers generic controls, but not a specific opt-out for the use of contact information and sales data in AI training.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Sensitive data processing without additional documented safeguards

The Customer Terms prohibit the upload of sensitive data, but do not document additional safeguards, which could compromise information security.

Data controller and processor roles clearly defined

The policy clearly identifies the company as the data controller, essential for ensuring legal compliance when managing customer relationships.

Data controller identity and contact clearly disclosed

The policy provides clear information about the identity and contact of the controller, facilitating communication on privacy matters.

Source: vendor public documents

Critical Alerts

  • Mecanismo de contestação de decisões de IA não disponível: Importante para garantir que os clientes possam contestar decisões automatizadas que afetam suas informações..
  • Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Crucial para a proteção de dados sensíveis dos clientes.

Conformance analysis (20)

Premium Feature
AITS Criterion 9
Compliant

Roles of data controller and processor clearly defined

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 10
Compliant

Identity and contact of the data controller clearly informed

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 11
Compliant

Contact channel for privacy issues available

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Capsule CRM Privacy and AI Governance: Strengths, Weaknesses, and Practical Guidance

Understanding Capsule CRM's Privacy Strengths

Capsule CRM has garnered an impressive OPTI Base (Privacy) Score of 86%, indicating a strong commitment to user privacy. One of its standout features is the clear communication regarding data retention periods. Users can easily find information on how long their data will be stored, which is crucial for compliance with regulations like the GDPR and LGPD. This transparency not only builds trust but also empowers users to make informed decisions about their data.

Another significant strength is the clear identification of data recipients in Capsule CRM's privacy policy. Users can see exactly who their data is being shared with, which is essential for understanding potential risks associated with data sharing. This clarity helps users feel more secure in their interactions with the software, knowing that their information is handled responsibly.

Clear Data Controller Identification

Capsule CRM also excels in providing the identity and contact information of the data controller. This is a vital aspect of privacy compliance, as it allows users to reach out directly with any concerns or inquiries regarding their data. Knowing who to contact can significantly enhance user confidence and satisfaction with the service. Users should take advantage of this feature by familiarizing themselves with the contact details provided in the privacy policy, ensuring they know how to address any issues that may arise.

Recognizing Capsule CRM's Privacy Weaknesses

Despite its strengths, Capsule CRM does have notable weaknesses that users should be aware of. The OPTI IA Score of 38% highlights concerns regarding the handling of AI-related data. Specifically, the retention of AI inputs and outputs is not documented, which can lead to uncertainties about how this information is processed and stored. Users should be cautious about the data they input into the system, especially if it includes sensitive information.

Additionally, there is no mechanism for contesting AI decisions within Capsule CRM. This lack of recourse can be problematic, particularly for users relying on AI for critical business functions. Users should consider this when evaluating the software, as it may impact their ability to challenge or understand AI-driven outcomes.

Risks of Handling Sensitive Data

Another significant weakness is the treatment of sensitive data without documented additional safeguards. This raises concerns about compliance with privacy regulations like GDPR and LGPD, which require stringent protections for sensitive information. Users should assess the types of data they plan to input into Capsule CRM and consider whether additional measures, such as encryption or anonymization, are necessary to protect their information.

Practical Guidance for Capsule CRM Users

To maximize the benefits of Capsule CRM while mitigating risks, users should take proactive steps. First, review the privacy settings within the software to ensure that data sharing preferences align with your privacy expectations. Users should also regularly check for updates to the privacy policy, as changes may affect how their data is handled.

In light of the weaknesses identified, users should be cautious about the types of data they enter into Capsule CRM. Avoid inputting sensitive information unless absolutely necessary. If sensitive data must be used, consider implementing additional security measures, such as using secure channels for data entry and storage.

Exploring Alternatives and Enhancements

If the weaknesses in Capsule CRM's AI governance and data handling raise concerns, users might explore alternative CRM solutions that offer more robust AI documentation and user rights mechanisms. Look for platforms that provide clear documentation on AI data retention and offer options for users to contest AI decisions. Additionally, consider CRM systems that emphasize compliance with ISO 27701 standards, which can provide an added layer of assurance regarding privacy and data protection.

By understanding both the strengths and weaknesses of Capsule CRM, users can make informed decisions about how to leverage the software while safeguarding their data privacy.

Other Sales CRM software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Analyzed Sources

Public documents used in the audit of Capsule CRM:

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents