This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The dual-role structure defines HubSpot's legal responsibilities and regulatory obligations under data protection frameworks. When operating as a controller, HubSpot bears primary responsibility for processing decisions; when operating as a processor, responsibility for lawfulness and data subject rights transfers to the customer as controller, while HubSpot assumes data handling obligations specified in processing agreements.
The updated policy now explicitly discloses that HubSpot collects Email Engagement Data (such as open, delivery, bounce, and click statuses) from emails sent through its Subscription Services using embedded tracking technologies. This represents formalization of a data collection practice into explicit policy language. However, the policy simultaneously removed a previously stated sentence directing users to a form for removing their personal data from HubSpot's commercial dataset. The updated terms do not indicate an alternative removal mechanism.
View change record →For individuals whose data HubSpot collects directly (website visitors), HubSpot functions as the accountable party for processing decisions and privacy obligations. For individuals whose data customers upload to HubSpot Services, the customer assumes controller responsibility while HubSpot operates under the customer's processing instructions, meaning data subject requests and compliance obligations flow through the customer rather than directly to HubSpot.
How other platforms handle this
Amplitude acts as a data controller when we collect and use Personal Information for our own purposes, such as providing and improving our Services, marketing, and other business operations. When Amplitude processes Personal Information on behalf of our customers (for example, event data that our cu...
Mixpanel acts as a data processor on behalf of its customers (the controllers) when processing end user data through the Mixpanel analytics platform, and as a data controller with respect to data it collects about its own website visitors and account holders.
When our business customers use certain Services, we generally process and store limited personal information on their behalf as a data processor. For certain products such as Docusign's Contract Lifecycle Management (CLM) and Identity products, we may act as a processor and as a controller in certa...
Monitoring
HubSpot has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"HubSpot acts as a data controller when we collect and process personal information about visitors to our Websites and for our own business purposes. HubSpot acts as a data processor when we process personal information on behalf of our customers using our Services. In those cases, our customers are the data controllers and are responsible for the personal information they upload to our Services.— Excerpt from HubSpot's HubSpot Privacy Policy
We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and liability.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The dual-role structure defines HubSpot's legal responsibilities and regulatory obligations under data protection frameworks. When operating as a controller, HubSpot bears primary responsibility for processing decisions; when operating as a processor, responsibility for lawfulness and data subject rights transfers to the customer as controller, while HubSpot assumes data handling obligations specified in processing agreements.
For individuals whose data HubSpot collects directly (website visitors), HubSpot functions as the accountable party for processing decisions and privacy obligations. For individuals whose data customers upload to HubSpot Services, the customer assumes controller responsibility while HubSpot operates under the customer's processing instructions, meaning data subject requests and compliance obligations flow through the customer rather than directly to HubSpot.
ConductAtlas has identified this type of provision across 1 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.