Skip to main content
GetResponse logo

GetResponse

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 26 Feb 2026

E+
AITS IA

AI Trust Summary

AI Training
Not disclosed in documentation
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
E+
BasePrivacy
A-
  • Regarding AI: it does not document the use of data for AI training, which raises uncertainties about the privacy of the data used.
  • Regarding Core Privacy: it does not specify data retention periods, which can impact the management of sensitive information for contractors.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (3)

AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.

  • GetResponse
  • Does not specify AI data retention periods, leading to uncertainties about information management.
  • Omission regarding the use of data for AI training may compromise privacy.
  • It is recommended to require contractual clauses that define data retention periods and uses.

AI data retention (prompts and responses) is not disclosed

GetResponse does not specify how long it retains email campaign data and user interactions, which can create uncertainties for clients.

Use of data for AI training is not disclosed

GetResponse does not clarify whether email campaign data is used to train AI models, which can raise privacy concerns.

Ethical AI principles and anti-bias measures not documented

GetResponse does not mention commitments to ethical AI practices, which may raise questions about accountability in its operations.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • GetResponse
  • The policy details data processing purposes, ensuring transparency.
  • Clearly identifies its roles as data controller and processor, promoting clarity in operations.
  • These practices facilitate due diligence and trust in data management.

AI training opt-out control available

GetResponse offers opt-out options for personalized ads, but not for the use of data in AI training, limiting client control.

Use of artificial intelligence clearly disclosed in policies

GetResponse mentions the use of automated systems but does not clarify if it uses AI, which can create uncertainties about its practices.

AI features clearly identified with their purposes

GetResponse mentions functionalities that imply automation but does not detail how AI is used, which can create uncertainties.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Sensitive data processing without additional documented safeguards

GetResponse does not document additional safeguards for the processing of sensitive data, which may create risks for client privacy.

Privacy contact channel available

GetResponse provides a DPO and multiple contact channels to clarify privacy questions, ensuring customer support.

Processing purposes clearly listed by data category

GetResponse's policy details how email campaign data and user interactions are used, ensuring transparency in purposes.

Source: vendor public documents

Critical Alerts

  • Uso de dados para treinamento de IA não é declarado: A falta de transparência pode afetar a percepção de responsabilidade da empresa em relação aos dados dos clientes..
  • Mecanismo de contestação de decisões de IA não disponível: A falta de um mecanismo de contestação pode afetar a confiança dos clientes nas decisões automatizadas.

Conformance analysis (20)

Premium Feature
AITS Criterion 11
Compliant

Contact channel for privacy issues available

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 12
Compliant

Processing purposes clearly listed by data category

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 14
Compliant

Recipients of personal data clearly identified in the policy

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

GetResponse Email Marketing: Privacy and Security Insights

Transparency in Data Processing

GetResponse excels in transparency regarding its data processing practices, which is crucial for users concerned about privacy. The platform clearly lists the purposes of data processing categorized by data type, contributing to an OPTI Base Privacy Score of 86%. This means that users can easily understand how their data is being used, allowing for informed consent. For businesses, this clarity can help ensure compliance with regulations such as GDPR and LGPD, which require explicit communication about data usage. Users should regularly review these purposes in their settings to ensure they align with their privacy expectations.

Defined Roles in Data Management

Another strength of GetResponse is the clear definition of data controller and processor roles. This clarity is essential for users, especially businesses that must comply with data protection laws. Knowing who is responsible for data management helps users understand their rights and obligations under frameworks like ISO 27701. Users are encouraged to review their Data Processing Agreement (DPA), which is available for enterprise clients, to ensure that it meets their needs and legal requirements. This proactive approach can mitigate potential compliance risks.

Undefined Data Retention Policies

Despite its strengths, GetResponse has notable weaknesses that users should be aware of. One significant concern is the lack of a defined data retention policy for AI prompts and responses. This absence can lead to uncertainty about how long sensitive information is stored, potentially exposing users to risks if data is retained longer than necessary. Users should regularly audit their data retention settings and consider implementing internal policies to manage their data lifecycle effectively.

Lack of AI Data Usage Disclosure

Another critical weakness is the platform's failure to disclose how user data is used for AI training. This lack of transparency raises concerns about the privacy of data utilized in machine learning processes. Users should be cautious and inquire directly with GetResponse about their data usage policies. Additionally, if users are uncomfortable with this ambiguity, they might consider disabling AI-related features until clearer guidelines are established. This precaution can help mitigate risks associated with data privacy.

Absence of AI Decision Contestation Mechanism

GetResponse also lacks a mechanism for contesting AI-driven decisions, which can be a significant drawback for users relying on automated features. This absence means that if a user receives an unfavorable outcome from an AI decision, they have no formal recourse to challenge it. Users should remain vigilant and document any AI interactions that seem erroneous or unfair, as this information could be valuable in discussions with GetResponse support. Furthermore, users might explore alternative platforms that offer more robust AI governance features.

Practical Steps for Enhanced Privacy

To enhance their privacy while using GetResponse, users should take several practical steps. First, they should review their account settings to ensure that data processing purposes align with their expectations. Additionally, users should consider enabling two-factor authentication for added security and regularly update their passwords. For those concerned about AI data usage, disabling AI features until more transparency is provided can be a wise precaution. Lastly, staying informed about updates to GetResponse’s privacy policies and engaging with customer support for clarification can help users navigate their privacy landscape effectively.

Other Email Marketing software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents