HubSpot · HubSpot Terms of Service · View original document ↗

Sensitive Data Terms

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time HubSpot changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity HubSpot recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for HubSpot Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement prohibits use of the Subscription Service for regulated sensitive data categories including HIPAA, COPPA, GLBA, and FISMA-governed data unless the customer separately enables Sensitive Data functionality and accepts the HubSpot Sensitive Data Terms.

This analysis describes what HubSpot's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Organizations in healthcare, financial services, or those processing children's data must separately enable and accept the Sensitive Data Terms before using HubSpot to process regulated data categories; use of the standard Subscription Service for such data without enabling these additional terms is prohibited under the agreement.

Recent Activity

This document changed recently

Medium Jul 2, 2026

The updated terms now explicitly state that AI is embedded throughout HubSpot's platform and is foundational to how subscription services operate. The agreement permits HubSpot to use customer data to train AI models, subject to contractual obligations. You can opt out of having your data used to train AI models by updating your settings in your HubSpot account.

View change record →

Clause Stability Stable

0
Changes
3
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

The agreement prohibits processing of HIPAA-covered health information, COPPA-governed children's data, GLBA-regulated financial information, and FISMA-governed data through the standard Subscription Service. Customers who require such processing must enable the Sensitive Data functionality in their account, which triggers the Sensitive Data Terms as an additional contractual obligation.

Cross-platform context

See how other platforms handle Sensitive Data Terms and similar clauses.

Compare across platforms →

Monitoring

HubSpot has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
The HubSpot Sensitive Data Terms available at https://legal.hubspot.com/sensitive-data-terms are incorporated into this Agreement if you enable the Sensitive Data functionality in your HubSpot Account. To the extent specifically permitted under the HubSpot Sensitive Data Terms and subject to those additional terms, you may use the Subscription Services to collect, store, manage, or otherwise process information considered sensitive information under various regulations. You may not use the Subscription Service in a way that would violate local or industry-specific regulations (for example, the Children's Online Privacy Protection Rule consistent with the requirements of the Children's Online Privacy Protection Act (COPPA), the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act (GLBA), the Federal Information Security Management Act (FISMA), etc.).

Excerpt from HubSpot's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly implicates HIPAA (covered health information and business associate obligations), COPPA (children's online privacy), GLBA (financial institution data), and FISMA (federal information security requirements). HHS OCR enforces HIPAA, the FTC enforces COPPA and GLBA with respect to non-bank financial institutions, and FISMA compliance is overseen by federal agency inspectors general and OMB. Customers processing data subject to these regulations must assess whether the Sensitive Data Terms satisfy their specific regulatory obligations, including whether HubSpot qualifies as a business associate under HIPAA when processing PHI. 2. GOVERNANCE EXPOSURE: High for regulated industry customers. Use of the Subscription Service to process HIPAA-covered, COPPA-regulated, or GLBA-governed data without enabling the Sensitive Data Terms is a contractual violation and may create independent regulatory liability for the customer. The provision places the responsibility on the customer to identify applicable regulations and enable the appropriate functionality. 3. JURISDICTION FLAGS: Healthcare organizations subject to HIPAA, financial institutions subject to GLBA, education platforms subject to FERPA, and any organization processing data about minors under COPPA face heightened exposure. State-level data protection laws in California, Illinois, New York, and others may impose additional sensitive data category obligations beyond those named in this provision. 4. CONTRACT AND VENDOR IMPLICATIONS: Legal and compliance teams must review the Sensitive Data Terms at legal.hubspot.com/sensitive-data-terms in full before enabling the functionality. For HIPAA-covered entities, the Sensitive Data Terms or DPA must function as a Business Associate Agreement; legal review should confirm this. Procurement teams should incorporate a review of the Sensitive Data Terms into vendor risk assessments for any HubSpot deployment in regulated contexts. 5. COMPLIANCE CONSIDERATIONS: Organizations should conduct a data classification review to identify whether any data processed through HubSpot falls within regulated sensitive categories before deploying the Subscription Service. The Sensitive Data functionality must be explicitly enabled in the account before regulated data is uploaded or processed. Ongoing compliance monitoring should verify that account settings and data flows remain consistent with the applicable Sensitive Data Terms.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • Hhs Ocr
    HHS OCR enforces HIPAA and is relevant where customers process health information through HubSpot without appropriate safeguards or business associate agreements.
    File a complaint →
  • FTC
    The FTC enforces COPPA and GLBA requirements for non-bank financial institutions and may be relevant where customers process children's data or financial information in violation of applicable law.
    File a complaint →

Provision details

Document information
Document
HubSpot Terms of Service
Entity
HubSpot
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014229
Document ID
CA-D-00207
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9354d9ea33aa6c19b10e820d5e10f058f214c5b5203163751de0d75b91477b43
Analysis generated
July 9, 2026 05:04 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: HubSpot
Document: HubSpot Terms of Service
Record ID: CA-P-014229
Captured: 2026-07-09 05:04:00 UTC
SHA-256: 9354d9ea33aa6c19…
URL: https://conductatlas.com/platform/hubspot/hubspot-terms-of-service/provision/CA-P-014229/sensitive-data-terms/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does HubSpot's Sensitive Data Terms clause do?

Organizations in healthcare, financial services, or those processing children's data must separately enable and accept the Sensitive Data Terms before using HubSpot to process regulated data categories; use of the standard Subscription Service for such data without enabling these additional terms is prohibited under the agreement.

How does this clause affect you?

The agreement prohibits processing of HIPAA-covered health information, COPPA-governed children's data, GLBA-regulated financial information, and FISMA-governed data through the standard Subscription Service. Customers who require such processing must enable the Sensitive Data functionality in their account, which triggers the Sensitive Data Terms as an additional contractual obligation.

Is ConductAtlas affiliated with HubSpot?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by HubSpot.