This is HubSpot's Customer Terms of Service — the legal contract that governs how businesses can use HubSpot's CRM, marketing, and sales tools. The most important thing to know is that your company (not HubSpot) is legally responsible for how your employees and contacts' data is used within the platform, and HubSpot's liability to you is capped at only the fees you paid in the past 12 months no matter what goes wrong. If you handle personal data of EU or UK residents through HubSpot, you must sign a separate Data Processing Agreement with HubSpot to stay legally compliant with GDPR.
This document is HubSpot's Customer Terms of Service governing the contractual relationship between HubSpot, Inc. and its business customers ('Customers') who purchase or use HubSpot's subscription-based CRM, marketing, sales, and service software platforms, with the agreement forming a binding contract upon Customer's acceptance or use of the services. The most significant obligations include Customer's duty to pay all fees, comply with Acceptable Use Policies, ensure their own end-users' compliance, and HubSpot's obligation to provide the contracted services while maintaining security safeguards and processing Customer Data only under documented instructions. Notably, the agreement includes a mutual limitation of liability capped at fees paid in the prior twelve months, broad indemnification obligations on the Customer side for third-party claims arising from Customer Data or violations of the AUP, and HubSpot's reserved right to modify pricing and features with notice. The document engages GDPR (via a Data Processing Agreement incorporated by reference), CCPA, and standard SaaS contractual frameworks enforced primarily by the FTC and applicable state attorneys general; material compliance considerations include the Customer's classification as a data controller and the requirement to execute HubSpot's DPA separately for lawful cross-border data transfers. EU and UK customers are subject to jurisdiction-specific addenda, and the governing law defaults to Massachusetts for US customers and Ireland for EU/UK customers.
🔒 Institutional analysis locked
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Upgrade to Professional — $149/mo3 changes analyzed since monitoring began.
Cross-platform context
See how other platforms handle Customer Data Ownership and Controller Responsibility and similar clauses.
Compare across platforms →