

Iterable
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •Regarding AI: it does not document ethical AI principles, which may raise concerns about bias and discrimination for those who contract its services.
- •Regarding Core Privacy: it does not specify data retention periods, which may impact the management of sensitive information in your company.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (2)
AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.
- •Iterable
- •does not inform about the retention period for AI prompts and responses, which can lead to uncertainties.
- •omits commitments to the ethical use of AI, raising bias risks.
- •it is advisable to require contractual clauses addressing these aspects to mitigate risks.
AI data retention (prompts and responses) is not disclosed
The policy mentions that they may record interactions, but does not inform about the retention period for user behavior data and marketing interactions.
Ethical AI principles and anti-bias measures not documented
The policy does not mention commitments to the ethical use of AI, which may raise concerns about bias and discrimination.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Iterable
- •clearly identifies the company as the data controller, facilitating transparency.
- •provides detailed information about legal entities and contact methods, promoting clarity in privacy matters.
- •these practices strengthen due diligence and trust in data management.
AI training opt-out control available
The policy mentions generic opt-out controls, but does not specifically address opt-out for AI training, which may lead to uncertainties.
Use of artificial intelligence clearly disclosed in policies
The policy mentions the use of automated systems, but implicitly, which may raise doubts about the application of AI.
Contestation and human review of AI decisions available
The policy ensures that users can contest automated decisions, promoting the protection of user rights.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data retention period not stated in the policy
The policy mentions data retention generically, but does not specify concrete periods or detailed criteria.
Data controller and processor roles clearly defined
The policy clearly identifies Iterable as the controller of user behavior data and marketing interactions, essential for transparency.
Data controller identity and contact clearly disclosed
The policy provides detailed information about Iterable's legal entities, facilitating contact for privacy matters.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: A ausência de princípios éticos pode impactar a reputação e a confiança dos clientes..
- •Período de retenção de dados não informado na política: A falta de informações sobre retenção pode gerar incertezas e riscos legais.
Conformance analysis (20)
Data controller and processor roles clearly defined
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Contact channel for privacy issues available
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Iterable Marketing Automation: Privacy and AI Governance Insights
Clear Data Controller Roles
Iterable excels in defining the roles of data controllers and processors, which is crucial for compliance with privacy regulations like GDPR and LGPD. This clarity helps users understand who is responsible for data handling, ensuring that accountability is maintained throughout the data lifecycle. With an OPTI Base (Privacy) Score of 81%, Iterable demonstrates a strong commitment to transparency, which is essential for building trust with customers and stakeholders. Users can leverage this clarity to ensure that their own data practices align with legal requirements, thereby reducing the risk of non-compliance penalties.
Transparent Data Processing Purposes
Another strength of Iterable is its clear listing of data processing purposes categorized by data type. This feature allows users to understand exactly how their data will be used, which is a key requirement under GDPR. By knowing the specific purposes for data collection, users can make informed decisions about what data to share and can better manage their privacy settings. This transparency not only enhances user trust but also aids in compliance with international data protection laws.
Undefined Retention Periods for Data
Despite its strengths, Iterable has significant weaknesses, particularly regarding the retention of AI prompts and responses. The absence of defined retention periods raises concerns about how long sensitive data may be stored. Users should be aware that without clear guidelines, they may inadvertently retain data longer than necessary, which could lead to compliance issues under GDPR and LGPD. To mitigate this risk, users should regularly audit their data retention policies and establish internal guidelines that align with best practices for data minimization.
Lack of Ethical AI Principles
Another critical weakness is Iterable's failure to document ethical AI principles and anti-bias measures. With an OPTI IA Score of 33%, this indicates a lack of transparency in how AI algorithms are managed, which can lead to potential biases in marketing automation outputs. Users should be cautious and consider implementing additional checks or using alternative tools that prioritize ethical AI practices. Engaging in regular audits of AI outputs can help identify and address any biases that may arise, ensuring fair treatment of all customer segments.
Practical Settings to Enhance Privacy
To enhance privacy while using Iterable, users should actively check their data settings. This includes reviewing the categories of data being collected and ensuring that only necessary data is processed. Users can also enable features that allow for data minimization, such as limiting the scope of data collection to what is strictly necessary for their marketing objectives. Regularly updating privacy settings in accordance with evolving regulations will help maintain compliance and protect user data.
Alternatives and Precautions
For users concerned about the weaknesses identified, considering alternative marketing automation platforms that offer stronger privacy and ethical AI governance may be prudent. Platforms with clear documentation on data retention and ethical AI practices can provide peace of mind. Additionally, users should stay informed about updates to Iterable’s policies and practices, as improvements in these areas could enhance their overall data governance strategy. Regular training on data privacy for team members can also ensure that everyone is aware of best practices and compliance requirements.
Other Marketing Automation software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents





