This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The incorporation by reference establishes a separate contractual framework governing data processing obligations, liability allocation, and compliance responsibilities under European data protection law. This mechanism ensures that data processing activities are subject to statutorily-mandated terms rather than remaining within the general service agreement, affecting the regulatory compliance posture of both parties.
The updated terms now explicitly state that AI is embedded throughout HubSpot's platform and is foundational to how subscription services operate. The agreement permits HubSpot to use customer data to train AI models, subject to contractual obligations. You can opt out of having your data used to train AI models by updating your settings in your HubSpot account.
View change record →Customers processing personal data subject to GDPR or similar legislation become bound by the terms of the separate DPA without requiring a separate signature or affirmative acceptance beyond continued service use. The customer's obligations and HubSpot's responsibilities regarding data security, transfers, sub-processing, and regulatory compliance are specified in the referenced DPA rather than the primary service agreement.
How other platforms handle this
If you are using our Services pursuant to a separate agreement with Figma that includes data processing terms, such as an enterprise agreement, those terms will govern the processing of personal data to the extent they conflict with this Privacy Policy.
Signal can optionally discover which contacts in your address book are Signal users, using a service designed to protect the privacy of your contacts. Information from the contacts on your device may be cryptographically hashed and transmitted to the server in order to determine which of your contac...
We collect information about you when you shop in our stores, including through store cameras, loyalty programs, payment processing systems, and other in-store technologies. This information is used to improve store operations, loss prevention, and marketing.
Monitoring
HubSpot has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"To the extent Customer uses the Services to process personal data subject to GDPR, the UK GDPR, or other applicable data protection legislation, the parties agree to be bound by HubSpot's Data Processing Agreement ('DPA'), which is incorporated herein by reference and available at legal.hubspot.com/dpa. Customer's use of the Services to process such personal data constitutes Customer's agreement to the DPA.— Excerpt from HubSpot's HubSpot Terms of Service
We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and liability.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The incorporation by reference establishes a separate contractual framework governing data processing obligations, liability allocation, and compliance responsibilities under European data protection law. This mechanism ensures that data processing activities are subject to statutorily-mandated terms rather than remaining within the general service agreement, affecting the regulatory compliance posture of both parties.
Customers processing personal data subject to GDPR or similar legislation become bound by the terms of the separate DPA without requiring a separate signature or affirmative acceptance beyond continued service use. The customer's obligations and HubSpot's responsibilities regarding data security, transfers, sub-processing, and regulatory compliance are specified in the referenced DPA rather than the primary service agreement.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.