HubSpot
Last Reviewed: 03 Jun 2026
At a Glance
HubSpot's DPA covers the required processor obligations in respect of customer provided personal data. HubSpot explicitly claims independent controller status over website tracking data and professional enrichment data, using it to build and improve its own commercial dataset — not solely to deliver the contracted service. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Company & Product Details
HQ
United States
Products
CRM & Marketing Platform
Product description
Provides integrated CRM, marketing automation, sales, and customer service software.
What data is being processed?
Contact information (names, email addresses, phone numbers), professional data (business email, employer, role, title), usage data, IP addresses, online identifiers, website tracking data
Document Details
Date of DPA
14 Apr 2026
Additional date information
Document states "Last Modified: April 14, 2026" in the page header.
What jurisdictions are covered?
GDPR (EU/EEA), UK GDPR, Swiss DPA, CCPA/CPRA (California), and other applicable US federal and state privacy laws, plus Australia, Canada, Singapore, India, and Japan. Governing law for SCCs defaults to Republic of Ireland unless the Agreement specifies another EU Member State (clauses 11.2A, 11.2B). Supervisory authority defaults to the Irish Data Protection Commission for Controller Personal Data (clause 11.2B).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
United States Customer Personal Data may be transferred to and processed by HubSpot, Inc. in the United States and to other jurisdictions where HubSpot Affiliates and Sub-Processors have operations. Data location is not customer-selectable; it follows HubSpot's global infrastructure needs (clause 6).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Detailed security measures set out in Annex 2: (1) Information Security Policy — written internal policy maintained; (2) Access Control — outsourced cloud infrastructure, uniform password policy, role-based authorisation, JITA privileged access controls, logical/physical separation of production from corporate systems; (3) Transmission Control — HTTPS/TLS encryption in transit, layered at-rest encryption for Customer Data; (4) Incident Management — written Incident Response Plan, extensive logging and monitoring, incident tracking and playbooks; (5) Availability Control — 99.95% uptime target, N+1 redundancy, multi-AZ data replication, disaster recovery plans; (6) Vulnerability Management — daily vulnerability scanning, annual penetration testing by independent firms, bug bounty programme; (7) Personnel Management — background checks (where permitted), security training for all employees. Hosting sub-processors independently validated to SOC 2 Type II and ISO 27001 (clause 3.3, Annex 2).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
HubSpot will notify Customer without undue delay, but no later than 72 hours, after becoming aware of a Customer Personal Data Breach. Timely information will be provided as it becomes known or is reasonably requested. Upon request, HubSpot will provide reasonable assistance to notify competent authorities and/or affected Data Subjects where required under Data Protection Laws (clause 3.5).
What happens to the data on termination?
Customer Personal Data deleted or returned on termination or expiration of Subscription Service in accordance with the procedures in the Product Specific Terms. Exceptions apply where legally required retention is mandated and for archived backup copies, which are securely isolated and protected from further Processing until deleted per HubSpot's deletion practices (clause 3.6).