

Insightly
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

AI Trust Summary
- •In AI: it does not document ethical principles and anti-bias measures, which can lead to discrimination risks in AI systems.
- •In Core Privacy: it does not provide a Data Processing Agreement (DPA) for customers, which compromises the security of processed information.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •Insightly
- •Data Processing Agreement (DPA) not available to customers, which exposes the company to legal risks.
- •Does not address bias or discrimination in AI systems, which can compromise data ethics.
- •Require the provision of a DPA and document ethical AI principles.
Ethical AI principles and anti-bias measures not documented
The policy mentions data protection principles, but does not specifically address bias or discrimination in AI systems.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Insightly
- •Clearly identifies the data controller and offers multiple contact channels.
- •Connects data categories with specific purposes, ensuring clarity on information usage.
- •These practices facilitate due diligence and trust in data management.
AI features clearly identified with their purposes
The policy describes specific Copilot AI functionalities, detailing how these tools improve the user experience.
Automated AI decisions explained in an understandable way
Explains the factors used to generate the context of AI decisions, promoting transparency in interactions.
AI data retention policy clearly documented
The policy details the retention of AI interaction data, but does not specify clear deletion periods.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data Processing Agreement (DPA) not available for customers
The policy mentions that appropriate contracts are executed, but there is no clear evidence of a DPA available to customers.
Data controller and processor roles clearly defined
The policy clearly identifies Insightly as responsible, defining the scope and distinctions between controlled and processed data.
Transparency about international data transfers documented
The policy explicitly mentions that data may be stored anywhere in the world, ensuring compliance with international standards.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: Risco de discriminação e falta de ética no uso de IA..
- •Período de retenção de dados claramente informado: Risco de retenção indefinida de dados, impactando a privacidade dos clientes.
Conformance analysis (20)
Roles of data controller and processor clearly defined
Reference: ISO/IEC 27701 (7.3)
Transparency on international data transfer documented
Reference: ISO/IEC 27701 (7.3)
Adequate safeguards for international transfer documented
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Insightly CRM: Privacy and Security Insights for Informed Users
Transparency in Data Control
Insightly excels in providing clear information regarding the identity and contact details of the data controller. This transparency is crucial for users who are concerned about data privacy, as it allows them to know who is responsible for their information. With an impressive OPTI Base (Privacy) Score of 86%, Insightly ensures that users can easily access the purposes for which their data is being processed. This clarity not only fosters trust but also aligns with regulations like GDPR and LGPD, which emphasize the importance of informed consent and data processing transparency.
Clear Data Processing Purposes
Another strength of Insightly lies in its detailed listing of data processing purposes categorized by data type. This feature is particularly beneficial for users who want to understand how their information is utilized within the CRM. By clearly defining these purposes, Insightly helps users ensure compliance with legal frameworks such as ISO 27701, which mandates that organizations must specify the reasons for data collection. Users can leverage this information to make informed decisions about their data sharing practices and maintain control over their personal information.
Lack of Data Processing Agreement (DPA)
Despite its strengths, Insightly has notable weaknesses that users should be aware of. One significant concern is the absence of a Data Processing Agreement (DPA) for clients. A DPA is essential for outlining the responsibilities and liabilities of both parties regarding data handling. Without this agreement, users may face increased risks related to data breaches and non-compliance with privacy regulations. This shortcoming is particularly alarming given the current emphasis on data protection laws like GDPR, which require clear contractual terms for data processing.
Ethical AI Practices Not Documented
Another area of concern is Insightly's lack of documentation on ethical AI principles and anti-bias measures. With an OPTI IA Score of 79%, users should be cautious about potential discrimination risks in AI-driven features. The absence of documented ethical guidelines may lead to unintended biases in data processing, which can affect user experience and decision-making. Users are advised to remain vigilant and consider the implications of using AI features without clear ethical oversight.
Practical Settings and Precautions
To mitigate the risks associated with the lack of a DPA, users should proactively engage with Insightly's support team to clarify data handling practices. Additionally, users can implement precautionary measures by regularly reviewing their data sharing settings within the CRM. This includes limiting access to sensitive information and ensuring that only necessary data is shared with third parties. By taking these steps, users can enhance their data security and ensure compliance with privacy regulations.
Exploring Alternatives for Enhanced Security
Given the identified weaknesses, users may want to explore alternative CRM solutions that offer more robust privacy protections, including a comprehensive DPA and documented ethical AI practices. It is essential to compare different CRM options based on their privacy scores and compliance with regulations like GDPR and LGPD. Users should prioritize platforms that provide clear contractual agreements and demonstrate a commitment to ethical data handling practices. By making informed choices, users can better protect their data and maintain compliance with relevant privacy laws.
Other Sales CRM software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Insightly:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents






