

Salesflare
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •In AI: it does not document ethical AI principles, which may raise concerns about bias in automated decisions.
- •In Basic Privacy: it does not provide a Data Processing Agreement, increasing legal risks for users.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •Salesflare
- •The absence of a Data Processing Agreement may limit the protection of contact data.
- •It does not document ethical AI principles, increasing the risk of bias in automated decisions.
- •It is recommended to require a DPA and clear commitments to AI ethics.
Ethical AI principles and anti-bias measures not documented
The lack of clear commitments to AI ethics may raise concerns about bias and discrimination in automated decisions.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Salesflare
- •Clearly identifies the data controller, facilitating understanding of legal responsibilities.
- •Details data processing purposes, allowing users to understand how their information is used.
- •These practices strengthen due diligence regarding data privacy.
Contestation and human review of AI decisions available
Users can request review of automated decisions that impact their profiles, ensuring greater control over their data.
AI data retention policy clearly documented
The policy mentions the retention of interaction data but does not specify deadlines, which may create uncertainties for users.
Policy on data use for AI training clearly stated
The policy mentions the use of data to improve services but does not specify if it is used for AI training, which raises questions.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data Processing Agreement (DPA) not available for customers
The absence of an explicit DPA may limit the protection of contact data and sales interactions, increasing legal risks.
Data controller and processor roles clearly defined
Clear identification of the data controller helps to understand responsibilities and legal obligations in managing contact data.
Data controller identity and contact clearly disclosed
Clear information about the data controller facilitates contact for privacy issues, increasing user trust.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: Crucial para a responsabilidade e a justiça no uso de IA..
- •Política de retenção de dados de IA claramente documentada: Importante para a gestão de dados e para a conformidade com a LGPD.
Conformance analysis (20)
Human review and contestation of AI decisions available
Reference: ISO/IEC 42001 (8.3)
Clearly defined data controller and processor roles
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Salesflare CRM: Understanding Privacy and AI Governance Strengths and Weaknesses
Clear Definition of Data Roles
Salesflare excels in defining the roles of data controllers and processors, which is crucial for compliance with regulations like GDPR and LGPD. This clarity helps users understand who is responsible for data management, thereby reducing the risk of data mishandling. With an AITS Privacy Score of 75%, users can feel more secure knowing that their data handling processes are transparent. This transparency is essential for building trust with customers and ensuring that data is processed in accordance with legal requirements. Users should regularly review these roles to ensure they align with their organizational practices and compliance needs.
Explicit Purposes for Data Processing
Another strength of Salesflare is its clear listing of data processing purposes by category. This means that users can easily identify why their data is being collected and how it will be used. Such explicitness is vital for compliance with privacy regulations, as it empowers users to make informed decisions about their data. By knowing the specific purposes, users can better manage their data and ensure that it is only used for intended functions. Regular audits of data categories and their purposes can help maintain compliance and enhance user trust.
Lack of Data Processing Agreement (DPA)
Despite its strengths, Salesflare has a significant weakness: it does not provide a Data Processing Agreement (DPA) for its clients. This absence raises legal risks, as a DPA is essential for outlining the responsibilities and liabilities of both parties in data processing. Without this agreement, users may find themselves vulnerable to legal challenges, especially under stringent regulations like GDPR and LGPD. Users should consider reaching out to Salesflare for clarification on this issue and advocate for the implementation of a DPA to safeguard their interests.
Absence of Ethical AI Principles
Another area of concern is the lack of documented ethical AI principles and anti-bias measures. With an AITS AI Score of only 38%, this shortcoming indicates that Salesflare may not adequately address potential biases in automated decisions. For users relying on AI-driven insights, this could lead to skewed data interpretations and unfair outcomes. To mitigate this risk, users should critically evaluate the AI features they use and consider implementing additional checks or balances to ensure fairness in decision-making processes.
Documented Data Retention Policy
Salesflare does have a clearly documented data retention policy for its AI features, which is a positive aspect. This policy outlines how long data will be retained and under what circumstances it will be deleted. For users, this means they can have a clearer understanding of their data lifecycle, which is essential for compliance with privacy laws. Users should regularly review this policy to ensure it meets their organizational needs and aligns with legal requirements. Additionally, they should consider setting reminders for data audits to ensure compliance with retention schedules.
Practical Steps for Users
To navigate the strengths and weaknesses of Salesflare effectively, users should take proactive steps. First, ensure that the roles of data controllers and processors are well-defined within your organization. Regularly review the purposes for data processing to maintain transparency. Secondly, advocate for a Data Processing Agreement with Salesflare to mitigate legal risks. Lastly, consider implementing additional measures to address potential biases in AI-driven features. By taking these steps, users can enhance their privacy and AI governance while using Salesflare, ensuring that they remain compliant and secure.
Other Sales CRM software
Dive into in-depth research and analysis of each player

Salesforce Sales Cloud

Oracle Sales Cloud

Nutshell

Attio
Folk CRM

Capsule CRM

Agile CRM

Microsoft Dynamics 365 Sales
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Salesflare:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents