The statement discloses that Salesforce uses AI to process Personal Data in its controller capacity, including for developing and deploying AI systems, subject to legal permissibility and consistency with its privacy commitments. This provision explicitly excludes Personal Data submitted by users of Salesforce customer platforms, where Salesforce acts as a processor.
This analysis describes what Salesforce's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that controller-side Personal Data may be used as input for AI system development and deployment, which creates compliance exposure under emerging AI regulations, including the EU AI Act, and may interact with GDPR requirements regarding automated processing and profiling under applicable law.
Interpretive note: The provision does not specify which AI systems, model types, or categories of Personal Data are used for AI development, leaving the operational scope of this processing uncertain.
Under this provision, Personal Data collected by Salesforce in its controller capacity may be processed using AI systems, including for the purpose of developing those systems. The agreement states this applies to individuals interacting with Salesforce's own websites, events, and marketing, not to data submitted within customer-controlled Salesforce deployments.
Cross-platform context
See how other platforms handle AI Processing of Personal Data and similar clauses.
Compare across platforms →"Salesforce may use artificial intelligence to process your Personal Data, including to develop and deploy AI systems. Where artificial intelligence is leveraged, it will only be used where legally permissible, in compliance with this Privacy Statement, and in a manner which is consistent with our commitments and values. More information on Salesforce's responsible AI practices can be found here. For the avoidance of doubt, this applies where Salesforce processes your Personal Data as a controller. It does not apply to Personal Data you voluntarily submit to our services as an authorised user of a Salesforce customer for which Salesforce always acts as a processor.Excerpt from Salesforce's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 22 regarding automated decision-making and profiling, GDPR Article 6 legal basis requirements, and the EU AI Act as its obligations phase in.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that controller-side Personal Data may be used as input for AI system development and deployment, which creates compliance exposure under emerging AI regulations, including the EU AI Act, and may interact with GDPR requirements regarding automated processing and profiling under applicable law.
Under this provision, Personal Data collected by Salesforce in its controller capacity may be processed using AI systems, including for the purpose of developing those systems. The agreement states this applies to individuals interacting with Salesforce's own websites, events, and marketing, not to data submitted within customer-controlled Salesforce deployments.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce.