Skip to main content
Ontraport logo

Ontraport

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

D-
AITS IA

AI Trust Summary

AI Training
Possibly (generic mention of service improvement)
Data Retention
Not specified in documentation
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
D-
BasePrivacy
C+
  • Regarding AI: it does not document ethical principles or anti-bias measures, which may lead to distrust in automated decisions.
  • Regarding Core Privacy: it does not mention the retention period for AI data, creating uncertainties about the management of sensitive information.

Safer Alternatives

Higher-rated software in the same category

See Full Alternative Comparison

Attention Points in AI (3)

AI criteria that require attention. Buy the Premium Analysis to see all 3 criteria.

  • Ontraport
  • does not inform the retention period for AI data, creating uncertainties about information management.
  • does not document commitments to ethical AI, raising concerns about bias.
  • it is advisable to require contractual clauses addressing these aspects to mitigate risks.

AI data retention (prompts and responses) is not disclosed

Ontraport does not clearly state how long it retains contact data and AI-generated interactions, which may create uncertainties.

Ethical AI principles and anti-bias measures not documented

Ontraport does not mention commitments to the ethical use of AI, which may raise concerns about bias and discrimination.

Features using AI are not identified in the policy

Ontraport does not specify which features use AI, which may make it difficult to understand the use of contact data.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • Ontraport
  • clearly identifies its roles as a data processor, ensuring transparency in responsibilities.
  • provides detailed contact information, facilitating data-related communication.
  • these practices strengthen due diligence and customer trust in data management.

Use of artificial intelligence clearly disclosed in policies

Ontraport informs about the use of artificial intelligence, allowing customers to understand how their interactions are processed.

Policy on data use for AI training clearly stated

Ontraport mentions the use of contact data to improve services, demonstrating an initial effort in transparency regarding data use.

AI training opt-out control available

Ontraport offers opt-out options, allowing customers some control over the use of their data for improvements.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Data retention period not stated in the policy

Ontraport does not specify how long it retains contact data, which may create uncertainties about privacy.

Data controller and processor roles clearly defined

Ontraport is clearly identified as a data processor, ensuring transparency in responsibilities regarding contact data and interactions.

Data controller identity and contact clearly disclosed

Ontraport provides clear contact information, facilitating communication about customer contact data and interactions.

Source: vendor public documents

Critical Alerts

  • Princípios de IA ética e medidas anti-viés não documentados: Importante para garantir que a automação de marketing não perpetue discriminações..
  • Decisões automatizadas por IA não têm explicação disponível: Crucial para a transparência nas decisões que afetam os clientes.

Conformance analysis (20)

Premium Feature
AITS Criterion 9
Compliant

Clearly defined data controller and processor roles

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 10
Compliant

Data controller's identity and contact clearly informed

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 12
Compliant

Purposes of processing clearly listed by data category

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Ontraport Marketing Automation: Privacy and AI Governance Insights

Strengths of Ontraport in Privacy and Data Management

Ontraport demonstrates commendable practices in defining the roles of data controllers and processors. This clarity is crucial for users, as it ensures that responsibilities regarding data handling are well understood. Users can feel more secure knowing who is accountable for their data, which is especially important in light of regulations like GDPR and LGPD. Furthermore, the platform provides clear contact information for the data controller, allowing users to easily reach out with any inquiries regarding their data. This transparency can foster trust and confidence among users, as they know their concerns will be addressed promptly.

Additionally, Ontraport offers a Data Processing Agreement (DPA) for enterprise clients. This agreement outlines the terms under which data is processed, providing an extra layer of security and compliance. For businesses that handle sensitive information, having a DPA in place is essential for meeting legal obligations and ensuring that data is managed responsibly. Users should take advantage of this feature by reviewing the DPA to understand their rights and the measures in place to protect their data.

Understanding Ontraport's Privacy Weaknesses

Despite its strengths, Ontraport has notable weaknesses that users should be aware of. One significant concern is the lack of a defined retention period for AI prompts and responses. Without this information, users may face uncertainty regarding how long their data is stored and when it might be deleted. This ambiguity can be problematic, especially for organizations that must comply with strict data retention policies under regulations like GDPR and ISO 27701.

Another critical weakness is the absence of documented ethical principles and anti-bias measures in Ontraport's AI functionalities. This lack of transparency can lead to distrust in automated decisions made by the software. Users should be cautious about relying on AI-driven insights without understanding the underlying principles guiding those decisions. It is advisable to monitor AI outputs closely and consider implementing manual checks to ensure that decisions align with ethical standards.

Practical Guidance: Enhancing Privacy Settings

To mitigate some of the risks associated with Ontraport's weaknesses, users should actively manage their privacy settings. First, review the data retention policies within the platform. If there is an option to limit the retention period for AI-generated data, enable it to ensure that sensitive information is not kept longer than necessary. Additionally, users should regularly audit the data stored within their accounts and delete any unnecessary information to minimize exposure.

Furthermore, consider disabling AI features that do not align with your organization's ethical standards. If Ontraport allows for customization of AI functionalities, tailor these settings to ensure that they reflect your values and compliance requirements. Regularly check for updates from Ontraport regarding their AI governance practices, as improvements in this area could enhance user trust.

Exploring Alternatives for Data Management

Given the privacy concerns associated with Ontraport, users may want to explore alternative marketing automation platforms that prioritize transparency and ethical AI practices. Research competitors that have higher AITS Privacy and AI Scores, as these platforms may offer more robust data governance features. Look for solutions that provide clear documentation on data retention, ethical AI principles, and user rights under GDPR and LGPD.

When considering alternatives, evaluate how well these platforms align with your organization's specific needs and compliance requirements. Conduct thorough audits of potential software to ensure they meet your privacy standards before making a switch.

Staying Informed on Compliance and Best Practices

As a user of Ontraport or any marketing automation software, it is essential to stay informed about compliance requirements and best practices in data management. Regularly review updates from regulatory bodies regarding GDPR, LGPD, and ISO 27701 to ensure your organization remains compliant. Attend webinars, read industry publications, and participate in forums to keep abreast of the latest developments in privacy and AI governance.

Additionally, consider implementing a regular training program for your team on data privacy and ethical AI use. This proactive approach will help cultivate a culture of compliance within your organization and empower employees to make informed decisions regarding data handling and automation tools. By staying informed and proactive, you can better navigate the complexities of marketing automation while safeguarding your users' data.

Other Marketing Automation software

Dive into in-depth research and analysis of each player

Source: vendor public documents

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents