Skip to main content
Klaviyo logo

Klaviyo

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

D-
AITS IA

AI Trust Summary

AI Training
Not disclosed in documentation
Data Retention
Not specified in documentation
Opt-out
Criterion not evaluated
AIPrivacy
D-
BasePrivacy
D+
  • Regarding AI: it does not state whether customer data is used to train AI models, creating uncertainty about data management.
  • Regarding Basic Privacy: it does not inform about data retention periods, which may impact compliance with data protection regulations.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (3)

AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.

  • Klaviyo
  • does not state whether data is used to train AI models, creating privacy uncertainty.
  • does not mention the retention period for AI-generated data, which may compromise compliance.
  • it is advisable to require contractual clauses addressing these critical points.

Use of data for AI training is not disclosed

Klaviyo does not state whether customer data and marketing interactions are used to train AI models, creating uncertainty.

AI data retention (prompts and responses) is not disclosed

Klaviyo does not mention how long customer data and AI-generated marketing interactions are retained, creating uncertainty.

Automated AI decisions have no explanation available

Klaviyo does not provide explanations on how automated decisions are made, which may impact customer trust.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Klaviyo
  • provides a Data Processing Agreement (DPA) that ensures clear obligations regarding the processing of personal data.
  • explicitly identifies third parties involved in processing, such as AWS, promoting transparency.
  • these practices facilitate due diligence and trust in data management.

AI features clearly identified with their purposes

Klaviyo mentions functionalities that use AI, such as 'Klaviyo AI', for marketing automation and customer service.

Contestation and human review of AI decisions available

Klaviyo offers support channels to contest automated decisions, promoting transparency and customer trust.

Use of artificial intelligence clearly disclosed in policies

Klaviyo clearly states the use of artificial intelligence in its functionalities, promoting transparency.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Data retention period not stated in the policy

Klaviyo does not inform how long customer data and marketing interactions are kept, creating uncertainty.

Data Processing Agreement (DPA) available for business customers

Klaviyo provides a DPA that outlines personal data processing obligations, ensuring compliance with GDPR.

Personal data recipients clearly identified in the policy

Klaviyo explicitly identifies third parties involved in processing, such as AWS, ensuring transparency regarding data use.

Source: vendor public documents

Critical Alerts

  • Retenção de prompts e respostas de IA sem prazo definido: Importante para a gestão de dados e conformidade com regulamentos de retenção..
  • Período de retenção de dados não informado na política: Crucial para a transparência e gestão de dados.

Conformance analysis (20)

Premium Feature
AITS Criterion 20
Compliant

Data Processing Agreement (DPA) available for enterprise customers

Reference: ISO/IEC 27701 (8.2) + LGPD Art. 39 + GDPR Art. 28

AITS Criterion 14
Compliant

Recipients of personal data clearly identified in the policy

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 9
Compliant

Roles of data controller and processor clearly defined

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Klaviyo Marketing Automation: Privacy Strengths and Weaknesses Explained

Transparency in Data Processing Agreements

Klaviyo offers a Data Processing Agreement (DPA) for enterprise clients, which is a significant strength in terms of privacy. This agreement outlines the responsibilities of both parties regarding data handling, ensuring that users understand how their data will be processed. Having a DPA in place is essential for compliance with regulations like GDPR and LGPD, as it provides a legal framework for data protection. Users should review this document thoroughly to ensure that it aligns with their privacy expectations and compliance needs.

Clear Identification of Data Recipients

Another notable strength of Klaviyo is its clear identification of data recipients in its privacy policy. This transparency helps users understand who has access to their personal data, which is crucial for maintaining trust and accountability. Knowing the parties involved in data processing allows users to make informed decisions about their data sharing practices. Users are encouraged to regularly review the privacy policy to stay updated on any changes regarding data recipients.

Lack of Clarity on AI Data Usage

Despite its strengths, Klaviyo has significant weaknesses, particularly regarding its use of customer data for AI training. The platform does not declare whether customer data is utilized to train AI models, which raises concerns about data management and user consent. This lack of transparency can lead to uncertainty for users who are concerned about how their data might be used beyond the intended marketing purposes. Users should be cautious and consider reaching out to Klaviyo for clarification on this matter before fully committing to the platform.

Undefined Data Retention Periods

Another critical weakness is the absence of a defined data retention period for prompts and AI responses. Without clear guidelines on how long data is stored, users may unknowingly risk non-compliance with data protection regulations like GDPR, which mandates that personal data should not be retained longer than necessary. To mitigate this risk, users should inquire about data retention policies and consider implementing their own data management practices to ensure compliance.

Practical Guidance on Settings and Precautions

To enhance privacy while using Klaviyo, users should take proactive measures. First, review the settings related to data sharing and AI usage. If available, opt-out of any features that utilize personal data for AI training. Additionally, regularly audit your account settings to ensure that you are only sharing necessary information. Users should also consider setting up alerts for any changes in the privacy policy to stay informed about how their data is being used.

Alternatives and Compliance Strategies

For users who are concerned about Klaviyo's privacy weaknesses, exploring alternative marketing automation platforms with stronger privacy practices may be beneficial. Look for platforms that clearly outline their data usage policies, especially regarding AI, and provide defined data retention periods. Additionally, consider implementing compliance strategies such as data minimization and regular audits of your marketing practices to ensure alignment with regulations like ISO 27701. This proactive approach will help safeguard user data and maintain compliance with privacy laws.

Other Marketing Automation software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents