Skip to main content
Nutshell logo

Nutshell

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

C-
AITS IA

AI Trust Summary

AI Training
NO — explicit policy
Data Retention
Partially mentioned (no defined period)
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
C-
BasePrivacy
C+
  • In AI: does not mention ethical principles or measures against bias, which may compromise accountability in AI use.
  • In Core Privacy: does not document safeguards for international transfers, exposing data to significant risks.

Attention Points in AI (1)

AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.

  • Nutshell
  • Does not document ethical AI principles, which may raise concerns about responsible use.
  • Does not mention safeguards for international transfers, exposing data to risks.
  • Requires contractual clauses addressing these aspects to mitigate risks.

Ethical AI principles and anti-bias measures not documented

Nutshell does not mention ethical AI principles or measures against bias, which may raise concerns about the responsible use of AI.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Nutshell
  • Documents data processing purposes by category, ensuring clarity of use.
  • Clearly identifies the data controller and provides multiple contact channels.
  • These practices facilitate communication and transparency, essential for due diligence.

Policy on data use for AI training clearly stated

Nutshell explicitly states that contact and interaction data are not used to train AI models, ensuring user privacy.

Use of artificial intelligence clearly disclosed in policies

Nutshell clearly informs about the use of artificial intelligence in its functionalities, promoting transparency for users.

AI features clearly identified with their purposes

Nutshell mentions functionalities that use AI, such as chatbots, although it does not detail all specific purposes.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Safeguards for international transfers are not mentioned

Nutshell does not mention specific safeguards for international transfers, which may expose data to risks.

Data controller and processor roles clearly defined

The policy clearly identifies Nutshell as the controller of contact data, sales interactions, and customer history, ensuring transparency.

Data controller identity and contact clearly disclosed

Nutshell provides clear information about its identity and contact channels, facilitating communication about contact and interaction data.

Source: vendor public documents

Critical Alerts

  • Salvaguardas para transferência internacional não são mencionadas: Importante para a proteção de dados em transferências internacionais..
  • Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Crucial para a proteção de dados sensíveis que podem ser coletados.

Conformance analysis (20)

Premium Feature
AITS Criterion 9
Compliant

Data controller and processor roles clearly defined

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 10
Compliant

Identity and contact of the data controller clearly informed

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 11
Compliant

Contact channel for privacy issues available

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Nutshell CRM: Understanding Privacy Strengths and Weaknesses

Clear Purpose of Data Processing

Nutshell excels in its transparency regarding the purposes of data processing. The software clearly lists the objectives for handling various categories of data, which is crucial for users who want to understand how their information is utilized. This clarity helps users make informed decisions about what data they share and for what purposes. A well-defined purpose can also aid in compliance with regulations like GDPR and LGPD, ensuring that users' rights are respected and upheld. By knowing the specific uses of their data, users can better assess the value and risks associated with the software.

Transparent Data Controller Information

Another strength of Nutshell is its clear communication regarding the identity and contact details of the data controller. This is vital for users who may have concerns or queries about their data. Having direct access to the data controller enhances accountability and trust, allowing users to reach out easily if they need clarification or wish to exercise their rights under privacy laws. This transparency is a positive aspect that can significantly enhance user confidence in the platform.

Lack of Ethical AI Principles

Despite its strengths, Nutshell has notable weaknesses, particularly in the realm of AI governance. The absence of documented ethical principles and anti-bias measures raises concerns about the responsible use of AI within the software. For users, this means that while the software may offer AI-driven features, there is no assurance that these features are free from bias or ethical dilemmas. Users should be cautious and consider the implications of using AI tools that lack these safeguards, especially in sensitive applications where fairness and accountability are paramount.

Risks of International Data Transfers

Another significant weakness is the lack of documented safeguards for international data transfers. This exposes users' data to potential risks, especially if the data is transferred to countries with less stringent privacy laws. Users should be aware that without these safeguards, their personal information may not be adequately protected. To mitigate this risk, users should consider reviewing their data sharing settings and limiting the information shared with the platform, especially if they are concerned about international data transfers. Additionally, users can inquire with Nutshell about their data transfer policies and any measures they plan to implement to enhance data protection.

Handling of Sensitive Data

Nutshell's approach to handling sensitive data is another area of concern. The lack of documented additional safeguards for sensitive data processing means that users may be at risk if their sensitive information is mishandled. Users should take proactive steps to protect their sensitive data by utilizing the software's privacy settings to limit the type of information shared. It may also be wise to avoid inputting highly sensitive information into the platform unless absolutely necessary. Users should also stay informed about any updates from Nutshell regarding their data handling practices.

Practical Guidance for Users

To enhance their privacy and security while using Nutshell, users should regularly review their privacy settings and familiarize themselves with the software's data handling policies. Enabling two-factor authentication can provide an additional layer of security for user accounts. Users should also consider conducting regular audits of their data within the platform to ensure that only necessary information is stored. If users have concerns about the lack of ethical AI practices or international data transfer safeguards, they may want to explore alternative CRM solutions that prioritize these aspects. Ultimately, being proactive and informed can help users navigate the privacy landscape effectively while using Nutshell.

Other Sales CRM software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Analyzed Sources

Public documents used in the audit of Nutshell:

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents