Salesforce Einstein · Salesforce Trusted AI Principles · View original document ↗

Zero Data Retention Policy

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Salesforce Einstein changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Salesforce Einstein Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

This provision states that prompts sent to third-party LLMs and the generated responses are never stored by those models and are not used to train them, with the document asserting that data processed under this policy remains the customer's property.

This analysis describes what Salesforce Einstein's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a data retention and use restriction applicable to third-party LLM interactions within the Salesforce platform, which is a material term for enterprise customers assessing vendor data handling practices under GDPR, CCPA, and sector-specific data governance requirements. Compliance teams should verify whether this commitment is contractually codified in the applicable Data Processing Addendum, as the document is a policy framework rather than a binding agreement.

Interpretive note: The provision is stated as a policy commitment but the document does not specify whether it is contractually codified in the MSA or DPA, creating uncertainty about enforceability and remedies.

Consumer impact (what this means for users)

This provision establishes that customer data transmitted as prompts to third-party LLMs is not retained or used for model training, and the document asserts that such data remains exclusively the customer's property. Enterprise customers relying on this commitment for regulatory compliance purposes should confirm its codification in their specific contractual agreements with Salesforce.

Cross-platform context

See how other platforms handle Zero Data Retention Policy and similar clauses.

Compare across platforms →

Monitoring

Salesforce Einstein has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Zero data retention is a strict policy where the prompts and generated responses are never stored or used to train the underlying third-party large language models, guaranteeing the data remains exclusively the customer's property.

Excerpt from Salesforce Einstein's Salesforce Trusted AI Principles

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision engages GDPR data minimization and purpose limitation principles, CCPA restrictions on secondary use of personal information, and HIPAA requirements for covered entities and business associates regarding use of protected health information. The EU AI Act's provisions on data governance for AI systems may also apply depending on the risk classification of specific use cases. The FTC is the primary US federal enforcement authority for data use commitments made in consumer and enterprise-facing policy documents. (2) GOVERNANCE EXPOSURE: Medium. The provision makes a materially significant commitment regarding third-party LLM data handling, but its enforceability and scope depend on whether it is reflected in binding contractual instruments (MSA, DPA) and whether Salesforce's contractual arrangements with third-party LLM providers impose equivalent obligations on those providers. (3) JURISDICTION FLAGS: EU and EEA deployments create heightened exposure given GDPR requirements for documented data processing limitations and contractual safeguards with sub-processors. California deployments engage CCPA obligations regarding secondary use of personal information. Healthcare and financial services customers face additional sector-specific requirements under HIPAA and GLBA respectively. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should assess whether the zero data retention commitment is incorporated into Salesforce's standard Data Processing Addendum and whether Salesforce's agreements with third-party LLM providers include equivalent sub-processor restrictions. This provision implies a liability allocation in favor of the customer but does not specify remedies in the event of a breach of this commitment. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should update data processing inventories to reflect this commitment, verify its contractual codification, and assess whether it satisfies applicable data protection impact assessment requirements for AI processing activities. Organizations subject to HIPAA should evaluate whether this commitment, combined with other Trust Layer mechanisms, is sufficient to meet business associate agreement requirements for AI-assisted processing.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has enforcement authority over data use commitments made in corporate policy documents and may assess whether representations about zero data retention constitute material terms under unfair or deceptive practices standards.
    File a complaint →

Provision details

Document information
Document
Salesforce Trusted AI Principles
Entity
Salesforce Einstein
Document last updated
May 12, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074446
Document ID
CA-D-00818
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c9bb51f7a29871aea2e399cd45ac7de48db93c4bdcfc153b82b72422b3556af6
Analysis generated
July 12, 2026 16:47 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Salesforce Einstein
Document: Salesforce Trusted AI Principles
Record ID: CA-P-074446
Captured: 2026-07-12 16:47:16 UTC
SHA-256: c9bb51f7a29871ae…
URL: https://conductatlas.com/platform/salesforce-einstein/salesforce-trusted-ai-principles/provision/CA-P-074446/zero-data-retention-policy/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Salesforce Einstein's Zero Data Retention Policy clause do?

This provision establishes a data retention and use restriction applicable to third-party LLM interactions within the Salesforce platform, which is a material term for enterprise customers assessing vendor data handling practices under GDPR, CCPA, and sector-specific data governance requirements. Compliance teams should verify whether this commitment is contractually codified in the applicable Data Processing Addendum, as the document is a …

How does this clause affect you?

This provision establishes that customer data transmitted as prompts to third-party LLMs is not retained or used for model training, and the document asserts that such data remains exclusively the customer's property. Enterprise customers relying on this commitment for regulatory compliance purposes should confirm its codification in their specific contractual agreements with Salesforce.

Is ConductAtlas affiliated with Salesforce Einstein?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce Einstein.