HubSpot

Last Reviewed: 03 Jun 2026

Data Use Review

At a Glance

HubSpot's DPA covers the required processor obligations in respect of customer provided personal data. HubSpot explicitly claims independent controller status over website tracking data and professional enrichment data, using it to build and improve its own commercial dataset — not solely to deliver the contracted service. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United States

Products

CRM & Marketing Platform

Product description

Provides integrated CRM, marketing automation, sales, and customer service software.

What data is being processed?

Contact information (names, email addresses, phone numbers), professional data (business email, employer, role, title), usage data, IP addresses, online identifiers, website tracking data

Document Details

Date of DPA

14 Apr 2026

Additional date information

Document states "Last Modified: April 14, 2026" in the page header.

What jurisdictions are covered?

GDPR (EU/EEA), UK GDPR, Swiss DPA, CCPA/CPRA (California), and other applicable US federal and state privacy laws, plus Australia, Canada, Singapore, India, and Japan. Governing law for SCCs defaults to Republic of Ireland unless the Agreement specifies another EU Member State (clauses 11.2A, 11.2B). Supervisory authority defaults to the Irish Data Protection Commission for Controller Personal Data (clause 11.2B).

Is the DPA incorporated into service or customer agreements?

Yes
DPA is incorporated into and forms part of the HubSpot Customer Terms of Service. In case of conflict, the DPA takes precedence. The term of the DPA follows the term of the Agreement (preamble).

Location & Transfers

Where is data held or processed?

United States Customer Personal Data may be transferred to and processed by HubSpot, Inc. in the United States and to other jurisdictions where HubSpot Affiliates and Sub-Processors have operations. Data location is not customer-selectable; it follows HubSpot's global infrastructure needs (clause 6).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU SCCs (Commission Decision 2021/914) incorporated by reference: Module 2 (Controller-to-Processor) where Customer is a Controller; Module 3 (Processor-to-Processor) where Customer is a Processor. Module 1 (Controller-to-Controller) applies for Controller Personal Data (enrichment products and HubSpot Tracking Code). UK Addendum incorporated for UK GDPR transfers; Swiss DPA modifications applied for Swiss transfers. Clause 9 Option 2 (general sub-processor authorisation) applies. Annexes 1A/1B and Annex 2 complete the SCC Annexes. Governing law defaults to Republic of Ireland (clause 11.2).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Detailed security measures set out in Annex 2: (1) Information Security Policy — written internal policy maintained; (2) Access Control — outsourced cloud infrastructure, uniform password policy, role-based authorisation, JITA privileged access controls, logical/physical separation of production from corporate systems; (3) Transmission Control — HTTPS/TLS encryption in transit, layered at-rest encryption for Customer Data; (4) Incident Management — written Incident Response Plan, extensive logging and monitoring, incident tracking and playbooks; (5) Availability Control — 99.95% uptime target, N+1 redundancy, multi-AZ data replication, disaster recovery plans; (6) Vulnerability Management — daily vulnerability scanning, annual penetration testing by independent firms, bug bounty programme; (7) Personnel Management — background checks (where permitted), security training for all employees. Hosting sub-processors independently validated to SOC 2 Type II and ISO 27001 (clause 3.3, Annex 2).

Non Processor Data Use

Does the company process data solely as a processor?

No
HubSpot claims independent Controller status over "Controller Personal Data" — being Website Data (IP addresses and other online identifiers) and Professional Enrichment Data (business email addresses) — in connection with the HubSpot Tracking Code and enrichment products (clause 10.2, Annex 1B). Section 10.2 explicitly states: "nothing in the Agreement or this Controller-to-Controller Terms section shall restrict HubSpot in any way from collecting, using, or sharing data that HubSpot would otherwise Process independently of Customer's use of the Subscription Services, including our enrichment products." Annex 1B further states this data is processed "to provide, maintain, append, improve, and develop HubSpot's commercial dataset." This constitutes HubSpot acting as an independent controller and using personal data for its own commercial purposes.

Subprocessing

General authorization

General
General authorisation to engage sub-processors for hosting/infrastructure, product features/integrations, and HubSpot Affiliate service/support. Sub-processor list maintained in Annex 3 and at legal.hubspot.com/sub-processors-page. Customers may opt-in to receive email notifications at least 30 days prior to any change. Customers may object on reasonable grounds relating to Customer Personal Data protection within 30 days; if unresolved, HubSpot may decline the new sub-processor or permit suspension/termination of the affected service without liability (clause 5).

Do all the DPA terms flow down to sub-processors?

Yes
HubSpot imposes data protection terms on sub-processors that provide at least the same level of protection as this DPA, to the extent applicable to the services provided. HubSpot remains responsible for each sub-processor's compliance and for any acts or omissions causing HubSpot to breach its DPA obligations (clause 5).

Is data only processed on the instruction of the controller?

Yes
HubSpot will only Process Customer Personal Data for purposes described in the DPA or as agreed within the scope of Customer's lawful Instructions. The Agreement and DPA, together with Customer's use of the Subscription Service, constitute complete Instructions. Additional instructions consistent with the Agreement may be given during the Subscription Term (clauses 3.1, 2.2).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Subscription Service includes built-in controls for Customer to retrieve, correct, delete, or restrict Customer Personal Data to assist with Data Subject Requests. Where self-service is insufficient, HubSpot will provide reasonable assistance upon written request for DSRs or requests from data protection authorities, at commercially reasonable cost to be notified in advance (clause 4).

Does the contract include staff confidentiality clauses?

Yes
HubSpot ensures all authorised personnel who Process Customer Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory (clause 3.4).

Are there audit rights for the data?

Structured
Audit rights exist but are channelled through defined compliance measures. Customers must exercise audit rights by instructing HubSpot to comply with the "Demonstration of Compliance" measures, rather than conducting direct on-site inspections. HubSpot provides SOC 2 reports and penetration test summaries on request (on a confidential basis), and written responses to all reasonable compliance questions. Frequency is limited to once per calendar year unless Customer has reasonable grounds to suspect noncompliance. Hosting sub-processors independently validated to SOC 2 Type II and ISO 27001 (clause 7).

Is there assistance with DPIA requests?

Yes
HubSpot will provide reasonable assistance with DPIAs and prior consultations with supervisory authorities (e.g., CNIL, BlnBDI, ICO) to the extent required by European Data Protection Laws and where the required information is reasonably available to HubSpot (clause 8.4).

How much notice is provided for data breaches?

HubSpot will notify Customer without undue delay, but no later than 72 hours, after becoming aware of a Customer Personal Data Breach. Timely information will be provided as it becomes known or is reasonably requested. Upon request, HubSpot will provide reasonable assistance to notify competent authorities and/or affected Data Subjects where required under Data Protection Laws (clause 3.5).

What happens to the data on termination?

Customer Personal Data deleted or returned on termination or expiration of Subscription Service in accordance with the procedures in the Product Specific Terms. Exceptions apply where legally required retention is mandated and for archived backup copies, which are securely isolated and protected from further Processing until deleted per HubSpot's deletion practices (clause 3.6).