

SugarCRM
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •Regarding AI: it does not document the retention of AI inputs and outputs, which creates uncertainties about data usage.
- •Regarding Basic Privacy: it does not provide specific data retention periods, impacting contact information management.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •SugarCRM
- •Does not mention AI data retention, which can create uncertainties about the use of sensitive data.
- •Does not document additional safeguards for sensitive data, raising concerns.
- •Requires contractual clauses that specify the retention and safeguards of sensitive data.
AI data retention (prompts and responses) is not disclosed
The policy mentions personal data retention, but does not specify the retention of AI inputs and outputs, which creates uncertainties.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •SugarCRM
- •The policy connects data categories with specific purposes, ensuring transparency in operations.
- •Clearly identifies the data controller, facilitating communication.
- •These practices are fundamental for effective due diligence and trust in data processing.
Policy on data use for AI training clearly stated
The policy mentions data usage to improve services, but does not specify AI model training, which can create uncertainties.
AI training opt-out control available
Offers generic controls for objecting to processing, but there is no specific opt-out for AI training, which may be a gap.
Use of artificial intelligence clearly disclosed in policies
The policy mentions relationship intelligence products, but does not explicitly declare the use of AI, which can cause confusion.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller and processor roles clearly defined
The policy clearly identifies the controller and defines the scope of services, essential for transparency in data management.
Data controller identity and contact clearly disclosed
The policy provides clear information about the controller, facilitating communication and accountability regarding data.
Privacy contact channel available
The policy offers a specific channel for privacy questions, ensuring that customers can clarify doubts about their data.
Source: vendor public documents
Critical Alerts
- •Período de retenção de dados claramente informado: A falta de prazos claros para retenção de dados pode impactar a confiança dos clientes na gestão de seus dados..
- •Salvaguardas adicionais documentadas para tratamento de dados sensíveis: A proteção de dados sensíveis é fundamental para garantir a conformidade e a confiança dos clientes.
Conformance analysis (20)
Data controller and processor roles clearly defined
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly provided
Reference: ISO/IEC 27701 (7.3)
Contact channel for privacy questions available
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Understanding Privacy and Security in SugarCRM: Strengths, Weaknesses, and Practical Guidance
Transparency in Data Processing
SugarCRM excels in its transparency regarding data processing practices. The platform clearly lists the purposes for which data is processed, categorized by data type. This clarity is crucial for users who want to understand how their information is being utilized. With an AITS Privacy Score of 83%, users can feel more secure knowing that their data is handled with clear intentions. This transparency helps users comply with regulations such as GDPR and LGPD, which mandate that users be informed about how their data is used.
Moreover, SugarCRM identifies the recipients of personal data in its privacy policy. This means that users can easily see who has access to their information, which is essential for maintaining trust and ensuring compliance with data protection laws. Knowing the data recipients allows users to make informed decisions about their data sharing preferences.
Clear Data Controller Information
Another strength of SugarCRM is the clear identification of the data controller's identity and contact information. This is a significant aspect of privacy governance, as it allows users to reach out directly with any concerns or inquiries regarding their data. Having this information readily available is a best practice that aligns with ISO 27701 standards, enhancing user confidence in the platform. Users should take advantage of this transparency by familiarizing themselves with the contact details and reaching out if they have any questions about data handling.
Lack of Clarity on AI Data Retention
Despite its strengths, SugarCRM has notable weaknesses, particularly concerning its handling of AI data. The platform does not provide information on the retention of AI inputs and outputs, which can lead to uncertainty about how user data is utilized in AI processes. With an AITS AI Score of only 25%, this lack of clarity is concerning for users who may be wary of how their data is being processed and stored. Users should be cautious and consider reaching out to SugarCRM for clarification on this matter to ensure their data is not being retained longer than necessary.
Undefined Data Retention Periods
Another critical weakness is the absence of clearly defined data retention periods. Users may find it challenging to manage their contact information effectively without knowing how long their data will be stored. This lack of information can hinder compliance with regulations like GDPR, which require organizations to specify data retention timelines. Users are advised to regularly audit their data within SugarCRM, ensuring that any unnecessary or outdated information is deleted to mitigate potential risks associated with indefinite data retention.
Insufficient Safeguards for Sensitive Data
Additionally, SugarCRM does not document additional safeguards for the processing of sensitive data. This is a significant shortcoming, as sensitive data requires enhanced protection measures to prevent unauthorized access or breaches. Users should be proactive in implementing their own safeguards, such as encrypting sensitive information and limiting access to only those who need it for legitimate business purposes. Regularly reviewing user permissions and access levels can also help mitigate risks associated with sensitive data handling.
Practical Steps for Enhanced Privacy Management
To enhance privacy management while using SugarCRM, users should take several practical steps. First, review the privacy settings within the platform to ensure that data sharing preferences align with personal or organizational policies. Users should also consider enabling features that allow for data minimization, ensuring that only necessary information is collected and retained.
Additionally, users should stay informed about updates to SugarCRM's privacy practices and regularly check for any changes in their data processing policies. Engaging with the support team for clarification on any ambiguous points can also help users navigate potential risks. By taking these proactive measures, users can better protect their data and ensure compliance with relevant privacy regulations.
Other Sales CRM software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of SugarCRM:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents






