SPRINKLR SECURITY & PRIVACY
A relentless commitment to security and privacy.
At Sprinklr, security, compliance, and privacy are foundational to our customer and investor trust. We are fiercely dedicated to safeguarding information assets and continuously enhancing the security and privacy of our customers' data.Security & Data Privacy
Explore Sprinklr’s certifications, assessments, and industry compliance status and dive deeper into the processes and features behind our platform and product security and privacy features. Discover how Sprinklr processes and safeguards information provided to us by our customers and get more details on our data transfer mechanisms, subprocessors, and find answers to frequently asked questions.
Sprinklr Platform Security
Safeguarding our customer information is of the utmost importance to Sprinklr. To demonstrate that commitment — and reduce customer exposure to risk — we’ve implemented the most comprehensive security standards, including web applications, optimized infrastructure, governance across all modern channels, network security, and more.
Product Security Features
We offer a number of features and support industry-standard controls in order to help protect your brand. Security features include role-based access permissions, access controls, single sign-on, two-factor authentication, IP restricted access, and more.
Secure Development Lifecycle Process
Our platform is developed internally by Sprinklr employees who receive regular training on secure coding practices. When we create a product, our security team works closely with engineering to inject security throughout every step of the development process – and the job is never “finished.” Sprinklr follows the Open Web Application Security Project (OWASP) standard security controls and other industry-standard control systems for application security.
Detection & Response
Sprinklr’s dedicated Detection & Response team is focused on threat detection engineering, vulnerability management, incident response and crisis communication management in order to support our customers in security incidents and beyond. Within scope are product operations, business system, and all corporate assets.
Infrastructure Security
Sprinklr’s production environment is completely virtual, running in an Infrastructure-as-a-Service (IaaS) third-party cloud environment. We also leverage additional IaaS providers’ security controls. Sprinklr partners with AWS, Microsoft, and Google data centers in the United States and Europe for data hosting.
Network Security
Sprinklr has implemented both reactive and proactive network security controls. We monitor network activity for anomalies 24/7 and respond to security events within minutes. Proactive controls such as firewalls, cloud security posture management, and network penetration tests ensure a very high degree of protection. All sensitive data is encrypted during transit.
Security Awareness & Training
At Sprinklr, we believe our employees are our first and strongest defense against cyber threats. Our employees are trained annually and regularly presented with security education and best practices in order to drive awareness, reduce risk and remain vigilant against potential threats. Annual tabletop exercises are also conducted to test our incident response plans.
Vulnerability Disclosure Program
Sprinklr utilizes a third-party Vulnerability Disclosure Program (VDP) for managing security vulnerabilities reported by the security community. For more information, please visit Sprinklr’s Vulnerability Disclosure Program
For more information and to request access to view compliance reports and more, visit and subscribe to the Sprinklr Trust Portal.
Security Governance
Sprinklr has aligned configuration, policies, procedures, and processes in place, which are reviewed annually, to help our organization achieve business objectives, address uncertainty, and act with integrity.
Security Certifications & Assessments
Sprinklr is regularly audited by third-party assessments, evaluating internal controls that protect the security, confidentiality, integrity, availability, and privacy of the information entrusted to us by our customers. Sprinklr maintains SOC1 Type II, SOC2 Type II, PCI-DSS, and ISO 27001 certifications as well as FedRAMP authorization.
For high-level Sprinklr availability information and any known issues affecting Sprinklr products, please visit the Sprinklr Status page. Potential service interruptions may vary from customer to customer, depending on the systems or services impacted.
Security FAQs
Visit our Security & Privacy Trust Portal at trust.sprinklr.com
Sprinklr has a dedicated Security Team chartered to define, supervise implementation, and monitor all relevant security and privacy policies, standards, and controls. We have a dedicated detection and response team who is tasked with 24/7 monitoring of our platform, and we abide by industry best practices, compliance regulations and all applicable laws. Periodic tests by independent third parties (such as third-party auditors, assessors, penetration testers, etc.) are organized and conducted under the guidance of the Security Team. Remediation of any material findings is tracked and validated. These tests include the validation of administrative, procedural, and technical controls.
While we continue to invest significant resources in order to ensure the continued security of our Sprinklr services and our user’s data, we also believe it’s important that Sprinklr users better understand not only the security options we offer, but also how they can best protect their devices from malware and other threats. Combined with our efforts securing Sprinklr, and users following online best practices, users can ensure the security of their information. Please see our recommended best practices here.
At Sprinklr, we recognize the importance of safeguarding the personal information we handle, including the information provided to us by customers, personal information we leverage from various sources to provide our products, as well as customer information. We are committed to protecting this data and not using it for any reason beyond what was initially agreed upon.
We use appropriate technical, organizational and administrative security measures to protect any information we hold in our records from loss, misuse, and unauthorized access. Our engineering teams proactively incorporate privacy into Sprinklr products and ensure the collection, use, retention, and disclosure of data is tailored and limited to the purposes necessary to provide our products to customers. We also take all reasonable precautions to ensure that our employees who have access to personal data about customers are limited and receive adequate training.
Build stronger customer trust on a foundation of robust data privacy measures
Sprinklr prioritizes safeguarding the personal information we handle — information provided to us by customers, the personal information we leverage from various sources to power our products, and the information we gather about consumers. We’re committed to protecting this data and using it solely to provide our services. Our Data Processing Addendum and Privacy Policy provide additional information.
Our compliance with privacy laws
At Sprinklr, data protection and information security are integral to our culture and values, fostering strong customer relationships. As a service provider and data processor, we view privacy as fundamental and support our customers in meeting data protection requirements. Our legal and compliance team, alongside security and product teams, closely monitors evolving data privacy regulations to ensure ongoing compliance with laws such as GDPR, CCPA, CPRA, and LGPD.
Sprinklr’s Data Protection Principles
Proportionality and Accountability
As a processor and service provider for our customers, Sprinklr processes customer data only as needed to provide our services. Sprinklr has internal policies, processes, and controls to manage data processing activities in accordance with applicable global data protection laws. You can read more about Sprinklr’s approach to data protection here.
Contractual Commitments
Sprinklr’s Data Processing Addendum (DPA) governs how we process data on behalf of our customers. It defines Sprinklr’s role as a processor, incorporates data transfer mechanisms, and outlines the technical & organizational measures in place to protect data from unauthorized access or loss.
Privacy Training
Sprinklr is committed to ensuring all of our employees understand their obligations under applicable data privacy laws. All new hires that join Sprinklr are trained on privacy and security during onboarding, and Sprinklr conducts annual refresher training, as well as tailored training for specific teams throughout the year.
Data Transfer Mechanisms
Sprinklr is committed to securing data transferred across geographic borders and leverages Standard Contractual Clauses, as well as additional technical and organizational measures, for such transfers. For more details, please refer to our White Paper on Data Transfers, available here, which you can use to inform your Data Transfer Impact Assessment.
Sharing Data
Sprinklr conducts careful due diligence on the privacy and security practices of third parties we engage to help us provide our services. All of our sub-processors must agree to and sign data protection agreements that include terms that are at least as protective as those that Sprinklr commits to with its customers. You can find our list of subprocessors here.
Data Subject Rights
Sprinklr puts customers in control through our in-product Privacy Center, which is available in the Sprinklr platform. Through the Privacy Center, customers can manage their data subject requests, such as access, deletion, and rectification, in real-time. Sprinklr also provides a privacy request form to assist with data subject requests directed at Sprinklr.
Privacy Resources
For more information and to view documentation related to Sprinklr’s privacy program, visit and subscribe to the Sprinklr Trust Portal.
Review our Privacy Policy
Sprinklr’s Privacy Policy provides details on how Sprinklr collects, uses, and shares information when you use our products, services, and website.
Access Sprinklr’s Data Processing Addendum
The DPA governs how Sprinklr processes data on behalf of our customers.
Contact Us
If you have any questions about Sprinklr’s approach to privacy, please submit your question.
For more information and to request access to view compliance reports and more, visit and subscribe to the Sprinklr Trust Portal.
Data Privacy FAQs
Yes. Sprinklr’s Data Processing Addendum (DPA) is available here. Our DPA governs how Sprinklr processes and safeguards the data we process to provide you with our services. During contract negotiations, the DPA will be referenced in your Master Services Agreement (MSA) with Sprinklr and will become an addendum to the MSA. Sprinklr’s DPA is global and covers all processing activities between Sprinklr and our customers. We make regular updates to our DPA, as needed, to ensure ongoing compliance with data protection requirements.
Sprinklr is the processor of our customer data and processes data to provide customers with the Sprinklr services. The customer is either the Controller or Processor, depending on whether the customer or a customer affiliate is signing the contract with Sprinklr. This is outlined in Section 2.1 of Sprinklr’s Data Processing Addendum.
The GDPR has a broad territorial scope and applies to the processing of EU personal data, even if the processing activity happens outside of the EU. Given the global nature of social media channels, Sprinklr will likely process customer data, especially social data, which would be subject to the GDPR. Because Sprinklr is a processor, we do not have control over the type of data our customers collect from their consumers or users, where those individuals are located, or when customers expand their business to new markets. We ask that all customers enter into a Data Processing Addendum (DPA) which complies with GDPR requirements, such as Standard Contractual Clauses.
Sprinklr generally processes three categories of data:
- Account Information, which we collect from users of our platform in order to create and authenticate their Sprinklr accounts;
- Customer Content, which can include any kind of data our customers choose to process through, or upload into, the Sprinklr platform; and
- Social Content, which includes any interactions social media users may have with customer’s social channels, as well as other publicly available webs sources such as blogs, forums, reviews, etc.
For more information on the type of personal data processed by Sprinklr, please review our Data Protection Addendum.
Sprinklr does not request or require special categories of data in order to provide its services to our customers. Whether or not such data may be processed by Sprinklr depends on the type of data customers choose to store or load into the Sprinklr platform, or the types of content social media users choose to make publicly available on social media channels or the web.
Sprinklr requires that all employees undergo security awareness and privacy training upon hire, and annually thereafter, and we require additional role-specific training on an ad-hoc basis across the company, as needed. Sprinklr has privacy and security policies that provide internal guidance on employee obligations related to safeguarding the security and privacy of all data we process. Our Code of Conduct also requires that our employees treat all information as confidential.
Sprinklr hosts data in data centers located in the United States and Europe, and where each customer will be hosted is determined during the contracting and implementation process. Please note that even with a specific hosting location selected, Sprinklr may still need to leverage affiliates or vendors in other regions to provide the Sprinklr services, such as trouble ticketing or engineering support. For such transfers, we rely on Standard Contractual Clauses and contractual, technical, and organizational measures. You can find a full list of data hosting locations, as well as the locations of our subprocessors here.
Following the Schrems II decision, Sprinklr relies on the Standard Contractual Clauses (SCCs) published by the European Court of Justice on June 4, 2021, to safeguard data transfers out of the EU/EEA. Standard Contractual Clauses are legal contracts entered into between parties transferring data to third countries. The 2021 SCCs include four transfer scenarios and Sprinklr leverages Module 2 (controller to processor) and Module 3 (processor to processor) with its customers. Following the ICO’s publication of UK cross-border transfer mechanisms on March 21, 2022, Sprinklr also relies upon the UK International Data Transfer Addendum to safeguard data transfers out of the United Kingdom. Both are part of our standard Data Processing Addendum.
Sprinklr complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit dataprivacyframework.gov.
Following the Schrems II decision in the EU, Sprinklr is committed to helping our customers understand national legislation that may impact data transfers out of the European Economic Area. Please review Sprinklr’s White Paper on International Data Transfers, which provides customers with all information needed to complete internal data transfer impact assessments. If you still need further assistance, please work with your Sprinklr account or sales representative, or reach out to privacy@sprinklr.com.
Yes. Sprinklr engages certain third-party service providers to perform limited and specific services to support our customers on the Sprinklr platform. Sprinklr sub-processors include Sprinklr affiliates who provide customers with services such as consulting, customer success management, maintenance, technical troubleshooting, and other technical support, as well as third parties who provide data hosting solutions, enhanced consulting or implementation services, and additional product features.
Sprinklr’s list of sub-processors is available here. Sprinklr’s data protection and security teams conduct due diligence on all sub-processors and their security and privacy programs. All sub-processors must enter into security, privacy, and confidentiality terms that are at least as restrictive as what Sprinklr has committed to with its customers, including appropriate SCCs to facilitate data transfers. Contracts with sub-processors limit their access to customers’ data only as needed to perform the services they are contracted for, and Sprinklr assesses sub-processors periodically to ensure ongoing compliance.
Sprinklr’s list of subprocessors is available here here and information about the services provided by each sub-processor and their geographic location. Customers should use the subscription tools on that site to subscribe for updates to the sub-processor list.
Sprinklr offers an in-product Privacy Center to customers, which is a module embedded in the Sprinklr platform that enables customers to handle data subject requests for access, deletion, correction, or opt-out. Sprinklr also offers a Privacy API to help customers automate GDPR requests on their end. You can find more information about this API on our Developer Portal. For data subject requests directed at Sprinklr, you can visit sprinklr.com/privacy-request.