Skip to main content
Salesforce Sales Cloud logo

Salesforce Sales Cloud

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

B-
AITS IA
Privacy Rating by TrustThis — Verified Seal

AI Trust Summary

AI Training
Training policy documented
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
B-
BasePrivacy
A-
  • Regarding AI: it does not provide information on AI data retention, which raises uncertainties about the use of sensitive information.
  • Regarding Privacy Basis: it documents the legal basis of contract performance, ensuring compliance in managing contact and lead data.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (1)

AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.

  • Salesforce Sales Cloud
  • Does not provide information on AI data retention, which raises uncertainties about the use of inputs and outputs.
  • The use of legitimate interest does not explain how customer rights are balanced.
  • It is necessary to demand contractual clauses that address these aspects.

AI data retention (prompts and responses) is not disclosed

The policy does not specify how contact and lead data used in AI are retained, creating uncertainties.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Salesforce Sales Cloud
  • The policy details data processing purposes, ensuring transparency.
  • Clearly identifies data recipients, increasing clarity on sharing.
  • These practices facilitate due diligence and trust in data management.

Automated AI decisions explained in an understandable way

The policy states that there are currently no automated decisions impacting contact and lead data, ensuring clarity.

Use of artificial intelligence clearly disclosed in policies

The policy declares the use of artificial intelligence to process contact and lead data, promoting transparency.

Policy on data use for AI training clearly stated

The policy states that contact and lead data may be used to train AI, which is relevant for service improvement.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Legitimate interest does not explain rights balancing

The policy mentions legitimate interests, but does not explain how customer rights are balanced in relation to the use of contact and lead data.

Transparency about international data transfers documented

The policy clarifies how contact and lead data are transferred internationally, ensuring adequate protection.

Adequate safeguards for international transfers documented

The policy mentions specific safeguards for international transfers, increasing the security of sales data.

Source: vendor public documents

Critical Alerts

  • Uso de legítimo interesse não explica balanceamento de direitos: Crítico para garantir que os direitos dos clientes sejam respeitados na gestão de dados..
  • Período de retenção de dados claramente informado: Importante para a transparência na gestão de dados de vendas.

Conformance analysis (20)

Premium Feature
AITS Criterion 15
Compliant

Transparency on international data transfer documented

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 16
Compliant

Adequate safeguards for international transfer documented

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 12
Compliant

Purposes of processing clearly listed by data category

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Salesforce Sales Cloud: A Comprehensive Review of Privacy and Security Features

Transparency in Data Processing

Salesforce Sales Cloud excels in its transparency regarding data processing practices. With an AITS Privacy Score of 81%, users can feel confident knowing that the purposes for which their data is processed are clearly documented by category. This means that when you input customer information or leads, you can see exactly how that data will be used. This transparency is crucial for compliance with regulations like GDPR and LGPD, which emphasize the importance of informed consent and clarity in data usage.

Moreover, the platform identifies the recipients of personal data within its privacy policy. This clarity helps users understand who has access to their information, fostering trust and ensuring that data sharing practices align with user expectations. For businesses, this means a reduced risk of non-compliance and potential fines, as the documentation supports adherence to legal frameworks.

Legal Basis for Data Processing

Another strength of Salesforce Sales Cloud is its adherence to legal requirements concerning data processing. The platform applies a legal basis of contract execution to essential data, which is a crucial aspect of GDPR compliance. This means that when you are managing contacts and leads, the data handling is grounded in a legitimate contractual relationship, reducing the risk of legal repercussions.

For users, this translates into a more secure environment for managing customer data. It is advisable to regularly review your data processing activities within the platform to ensure they remain compliant with the legal bases outlined. Utilizing Salesforce's built-in compliance tools can help maintain this alignment.

Lack of Clarity on AI Data Retention

Despite its strengths, Salesforce Sales Cloud has notable weaknesses, particularly concerning its AI data retention policies. The platform does not provide information about the retention of AI inputs and outputs, which raises concerns about how sensitive information may be used or stored. With an AITS AI Score of 63%, this lack of clarity could lead to potential risks for users who rely on AI features for customer insights or predictive analytics.

To mitigate this risk, users should be cautious when utilizing AI functionalities. It is advisable to limit the input of sensitive data into AI models and to consult Salesforce's support for guidance on best practices regarding data handling. Additionally, consider implementing internal policies that restrict the use of sensitive information in AI applications until clearer retention policies are established.

Insufficient Explanation of Legitimate Interest

Another area of concern is the platform's use of legitimate interest as a legal basis for data processing. Salesforce does not adequately explain how it balances user rights with its interests, which can create uncertainty for users regarding their data privacy. This is particularly important for businesses operating under GDPR and LGPD, where users have rights that must be respected.

To address this issue, users should proactively engage with Salesforce's privacy resources and seek clarification on how their data is being used under this legal basis. It may also be beneficial to conduct regular audits of your data processing activities to ensure that they align with user rights and expectations. Keeping an open line of communication with Salesforce regarding these concerns can also help ensure that your data practices remain compliant.

Data Retention Periods

Salesforce Sales Cloud clearly informs users about data retention periods, which is a positive aspect of its privacy practices. Knowing how long your data will be retained is essential for compliance with data protection regulations. This transparency allows users to make informed decisions about their data management strategies.

However, users should regularly review their data retention settings within the platform to ensure they align with their business needs and compliance requirements. Implementing data minimization practices, such as regularly purging unnecessary data, can help maintain compliance and reduce potential risks associated with data retention.

Practical Steps for Enhanced Privacy Management

To enhance your privacy management while using Salesforce Sales Cloud, consider the following practical steps:

1. Review Privacy Settings: Regularly check your privacy settings to ensure they align with your business's compliance needs, especially in relation to GDPR and LGPD.

2. Limit Sensitive Data Input: Be cautious about the type of data you input into the system, particularly when using AI features. Avoid entering sensitive information unless absolutely necessary.

3. Engage with Support: Utilize Salesforce's customer support for any questions regarding data retention policies and legitimate interest explanations. This can provide clarity and help you make informed decisions.

4. Conduct Regular Audits: Implement a routine audit of your data processing activities to ensure compliance with legal requirements and to identify any potential risks.

5. Educate Your Team: Ensure that your team is educated about data privacy practices and the importance of compliance with regulations like GDPR and LGPD.

6. Utilize Compliance Tools: Leverage Salesforce's built-in compliance tools to help manage your data processing activities effectively.

By following these steps, users can better navigate the complexities of data privacy and security while utilizing Salesforce Sales Cloud.

Other Sales CRM software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents