

Nutshell
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •In AI: does not mention ethical principles or measures against bias, which may compromise accountability in AI use.
- •In Core Privacy: does not document safeguards for international transfers, exposing data to significant risks.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (1)
AI criteria that require attention. Buy the Premium Analysis to see all 1 criteria.
- •Nutshell
- •Does not document ethical AI principles, which may raise concerns about responsible use.
- •Does not mention safeguards for international transfers, exposing data to risks.
- •Requires contractual clauses addressing these aspects to mitigate risks.
Ethical AI principles and anti-bias measures not documented
Nutshell does not mention ethical AI principles or measures against bias, which may raise concerns about the responsible use of AI.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •Nutshell
- •Documents data processing purposes by category, ensuring clarity of use.
- •Clearly identifies the data controller and provides multiple contact channels.
- •These practices facilitate communication and transparency, essential for due diligence.
Policy on data use for AI training clearly stated
Nutshell explicitly states that contact and interaction data are not used to train AI models, ensuring user privacy.
Use of artificial intelligence clearly disclosed in policies
Nutshell clearly informs about the use of artificial intelligence in its functionalities, promoting transparency for users.
AI features clearly identified with their purposes
Nutshell mentions functionalities that use AI, such as chatbots, although it does not detail all specific purposes.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Safeguards for international transfers are not mentioned
Nutshell does not mention specific safeguards for international transfers, which may expose data to risks.
Data controller and processor roles clearly defined
The policy clearly identifies Nutshell as the controller of contact data, sales interactions, and customer history, ensuring transparency.
Data controller identity and contact clearly disclosed
Nutshell provides clear information about its identity and contact channels, facilitating communication about contact and interaction data.
Source: vendor public documents
Critical Alerts
- •Salvaguardas para transferência internacional não são mencionadas: Importante para a proteção de dados em transferências internacionais..
- •Tratamento de dados sensíveis sem salvaguardas adicionais documentadas: Crucial para a proteção de dados sensíveis que podem ser coletados.
Conformance analysis (20)
Data controller and processor roles clearly defined
Reference: ISO/IEC 27701 (7.3)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Contact channel for privacy issues available
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Nutshell CRM: Understanding Privacy Strengths and Weaknesses
Clear Purpose of Data Processing
Nutshell excels in its transparency regarding the purposes of data processing. The software clearly lists the objectives for handling various categories of data, which is crucial for users who want to understand how their information is utilized. This clarity helps users make informed decisions about what data they share and for what purposes. A well-defined purpose can also aid in compliance with regulations like GDPR and LGPD, ensuring that users' rights are respected and upheld. By knowing the specific uses of their data, users can better assess the value and risks associated with the software.
Transparent Data Controller Information
Another strength of Nutshell is its clear communication regarding the identity and contact details of the data controller. This is vital for users who may have concerns or queries about their data. Having direct access to the data controller enhances accountability and trust, allowing users to reach out easily if they need clarification or wish to exercise their rights under privacy laws. This transparency is a positive aspect that can significantly enhance user confidence in the platform.
Lack of Ethical AI Principles
Despite its strengths, Nutshell has notable weaknesses, particularly in the realm of AI governance. The absence of documented ethical principles and anti-bias measures raises concerns about the responsible use of AI within the software. For users, this means that while the software may offer AI-driven features, there is no assurance that these features are free from bias or ethical dilemmas. Users should be cautious and consider the implications of using AI tools that lack these safeguards, especially in sensitive applications where fairness and accountability are paramount.
Risks of International Data Transfers
Another significant weakness is the lack of documented safeguards for international data transfers. This exposes users' data to potential risks, especially if the data is transferred to countries with less stringent privacy laws. Users should be aware that without these safeguards, their personal information may not be adequately protected. To mitigate this risk, users should consider reviewing their data sharing settings and limiting the information shared with the platform, especially if they are concerned about international data transfers. Additionally, users can inquire with Nutshell about their data transfer policies and any measures they plan to implement to enhance data protection.
Handling of Sensitive Data
Nutshell's approach to handling sensitive data is another area of concern. The lack of documented additional safeguards for sensitive data processing means that users may be at risk if their sensitive information is mishandled. Users should take proactive steps to protect their sensitive data by utilizing the software's privacy settings to limit the type of information shared. It may also be wise to avoid inputting highly sensitive information into the platform unless absolutely necessary. Users should also stay informed about any updates from Nutshell regarding their data handling practices.
Practical Guidance for Users
To enhance their privacy and security while using Nutshell, users should regularly review their privacy settings and familiarize themselves with the software's data handling policies. Enabling two-factor authentication can provide an additional layer of security for user accounts. Users should also consider conducting regular audits of their data within the platform to ensure that only necessary information is stored. If users have concerns about the lack of ethical AI practices or international data transfer safeguards, they may want to explore alternative CRM solutions that prioritize these aspects. Ultimately, being proactive and informed can help users navigate the privacy landscape effectively while using Nutshell.
Other Sales CRM software
Dive into in-depth research and analysis of each player

Salesforce Sales Cloud

Oracle Sales Cloud

Salesflare

Attio
Folk CRM

Capsule CRM

Agile CRM

Microsoft Dynamics 365 Sales
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of Nutshell:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents