

Postmark
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026
AI Trust Summary
- •On AI: does not document commitments to ethical AI principles, which may generate distrust among users.
- •On Core Privacy: provides a Data Processing Agreement, ensuring that data processing complies with applicable legislation.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (2)
AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.
- •Postmark
- •Does not document ethical AI principles, which may generate reputational risks.
- •Does not mention a mechanism for contesting AI decisions, which may generate distrust.
- •It is recommended to require clauses that address human review of automated decisions.
Ethical AI principles and anti-bias measures not documented
The policy does not mention commitments to the ethical use of AI, which may generate reputational and trust risks.
AI decision contestation mechanism not available
The policy does not mention human review of automated decisions, which may generate distrust among users.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Postmark
- •Offers a specific contact channel for privacy issues, facilitating communication with users.
- •Provides a Data Processing Agreement, ensuring that data processing complies with legislation.
- •These practices strengthen due diligence and customer trust.
Automated AI decisions explained in an understandable way
The policy explains how automated decisions impact users, promoting transparency in email interactions.
AI data retention policy clearly documented
The policy mentions retention of usage data, but does not clearly specify retention periods for email interaction data.
Policy on data use for AI training clearly stated
The policy mentions the use of email interaction data to improve services, but is not clear about AI model training.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Performance of contract is not cited as legal basis for essential data
The policy does not mention contract performance as a legal basis, which may generate uncertainties about compliance.
Personal data recipients clearly identified in the policy
The policy clearly identifies the recipients of email interaction data and the purposes of sharing, ensuring transparency.
Transparency about international data transfers documented
The policy clearly discloses international transfers of email interaction data, ensuring compliance with regulations.
Source: vendor public documents
Critical Alerts
- •Mecanismo de contestação de decisões de IA não disponível: A falta de um mecanismo de contestação pode impactar a aceitação de decisões em email marketing..
- •Execução de contrato não é citada como base legal para dados essenciais: A falta de uma base legal clara pode impactar a confiança em email marketing.
Conformance analysis (20)
Recipients of email interaction data clearly identified
Reference: ISO/IEC 27701 (7.3)
Transparency on international data transfer documented
Reference: ISO/IEC 27701 (7.3)
Adequate safeguards for international transfer documented
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Postmark Email Marketing: Privacy and AI Governance Insights
Transparency in Privacy Practices
Postmark stands out in the email marketing landscape with a commendable AITS Privacy Score of 72%. One of its key strengths is the availability of a dedicated contact channel for privacy-related inquiries. This feature allows users to directly address any concerns they may have regarding their data, fostering a sense of trust and transparency. Users can feel more secure knowing that they have a direct line to the company for resolving privacy issues. This proactive approach is essential for businesses that prioritize customer trust and compliance with regulations such as GDPR and LGPD.
Comprehensive Data Processing Agreement
Another significant strength of Postmark is its provision of a Data Processing Agreement (DPA) for enterprise clients. This agreement outlines the responsibilities and obligations regarding data processing, ensuring compliance with applicable laws. For users, this means that their data is handled with care and in accordance with legal standards, which is crucial for maintaining customer relationships and avoiding potential legal pitfalls. Businesses should ensure they review and understand the DPA to fully leverage its protections.
Lack of Ethical AI Documentation
Despite its strengths, Postmark has notable weaknesses, particularly in its AI governance. The AITS AI Score of 33% indicates a lack of transparency regarding ethical AI principles and anti-bias measures. For users, this raises concerns about how AI is utilized within the platform, especially in automated email marketing campaigns. Without documented commitments to ethical AI practices, users may be wary of potential biases in targeting and messaging. It is advisable for users to remain vigilant and monitor their campaigns for any unintended biases or inaccuracies.
Absence of AI Decision Contestation Mechanism
Another critical weakness is the absence of a mechanism for contesting AI decisions. This means that if users encounter issues with AI-generated content or targeting, there is no formal process to challenge or rectify these decisions. For businesses relying heavily on AI for email marketing, this could lead to significant risks. Users should consider implementing manual checks and balances in their campaigns to ensure that AI outputs align with their brand values and ethical standards.
Practical Guidance on Settings and Features
To enhance privacy and security while using Postmark, users should actively engage with the platform's settings. Regularly review the privacy settings to ensure that data sharing preferences align with your organization's policies. Additionally, users should enable any available features that enhance data protection, such as two-factor authentication and email encryption. Familiarizing yourself with the DPA and ensuring compliance with GDPR and LGPD will also strengthen your data governance practices.
Mitigating Risks Associated with AI
Given the weaknesses in AI governance, users should take proactive steps to mitigate risks. Consider diversifying your email marketing strategies by incorporating manual oversight alongside automated processes. Regularly audit your email campaigns for compliance with ethical standards and be prepared to adjust your approach based on performance metrics and feedback. Engaging with Postmark's support team to voice concerns about AI practices can also encourage the company to improve its transparency and governance in this area.
Other Email Marketing software
Dive into in-depth research and analysis of each player

Adobe Marketo Engage
Oracle Eloqua

Brevo

Customer.io

Drip

EngageBay

Zoho Marketing Automation

Constant Contact
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Postmark:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents