Openwake · evidence pack

HubSpot

https://www.hubspot.com · record 238 · read 2026-09-06 · rules/v1 · generated 2026-09-06 04:03 UTC

Facts

Trains on customer data
no
“10.8.2 Google Workspace APIs are not used to develop, improve, or train generalized AI and/or ML models.”
privacy policy · https://legal.hubspot.com/privacy-policy · confidence 0.60
Opt-out mechanism
none described
No supporting text found in the documents read.
privacy policy · https://legal.hubspot.com/privacy-policy · confidence 0.20
AI features
present
“When you use our products and services we may process personal data to develop, support, and improve HubSpot AI features and to train our AI models and similar products and services that rely on machine learning.”
privacy policy · https://legal.hubspot.com/privacy-policy · confidence 0.55
Model providers named
Replicate
“Online replicas and backups: Where feasible, production databases are designed to replicate data between no less than 1 primary and 1 secondary instance. All databases are backed up and maintained using at least industry standard methods.”
dpa · https://legal.hubspot.com/dpa · confidence 0.60
Retention
not stated
No supporting text found in the documents read.
privacy policy · https://legal.hubspot.com/privacy-policy · confidence 0.20
Hosting regions
not stated
No supporting text found in the documents read.
privacy policy · https://legal.hubspot.com/privacy-policy · confidence 0.20
Subprocessor notice
30 days
“We will give you the opportunity to object to the engagement of new Sub-Processors on reasonable grounds relating to the protection of Customer Personal Data within 30 days of notifying you.”
dpa · https://legal.hubspot.com/dpa · confidence 0.55

Subprocessors (13)

NameCategoryLocationQuoted from
Replicatemodel providerunstated
“Online replicas and backups: Where feasible, production databases are designed to replicate data between no less than 1 primary and 1 secondary instance. All databases are backed up and maintained usi”
Oktaotherunstated
“SECURITY ADVISORY: VISHING-BASED ATTACKS TARGETING OKTA SSO ACCOUNTS”
Gainsightotherunstated
“HUBSPOT UPDATE ON GAINSIGHT INTEGRATION SECURITY INCIDENT Based on our investigation into Gainsight integration activity along with published indicators of compromise (IOCs), we have found no evidence”
Salesforceotherunstated
“HubSpot will continue to follow Gainsight’s investigation updates, and customers should continue to visit Gainsight's status page and Salesforce's status page for updated information.”
Driftotherunstated
“HUBSPOT UPDATE ON SALESLOFT DRIFT SECURITY INCIDENT SEPTEMBER 12, 2025”
Salesloftotherunstated
“HUBSPOT UPDATE ON SALESLOFT DRIFT SECURITY INCIDENT SEPTEMBER 12, 2025”
Clearbitotherunstated
“* Clearbit SOC 2 Report - Legacy * Clearbit TRUSTe Certification - Legacy”
Dropboxotherunstated
“HUBSPOT UPDATE ON DROPBOX SIGN SECURITY INCIDENT On May 2, 2024, HubSpot was notified by our service provider, Dropbox, about a security incident involving their e-signatures service. This service is ”
Stripeotherunstated
“* As of 01/15/2022, HubSpot launched a new HubSpot Payments Tool powered by Stripe. SOC 2 controls were designed/implemented/validated for Stripe prior to the public launch and are included in our new”
Amazon Web Serviceshyperscalerunstated
“* We have requested details of any potential vulnerabilities from all sub-processors of the HubSpot product, and are monitoring their responses. HubSpot’s most important sub-processors, including Amaz”
Google Cloudhyperscalerunstated
“* We have requested details of any potential vulnerabilities from all sub-processors of the HubSpot product, and are monitoring their responses. HubSpot’s most important sub-processors, including Amaz”
Snowflakeotherunstated
“* We have requested details of any potential vulnerabilities from all sub-processors of the HubSpot product, and are monitoring their responses. HubSpot’s most important sub-processors, including Amaz”
Cloudflareotherunstated
“* We have requested details of any potential vulnerabilities from all sub-processors of the HubSpot product, and are monitoring their responses. HubSpot’s most important sub-processors, including Amaz”

Sources read

DocumentURLReadContent hashLedger
privacy_policyhttps://legal.hubspot.com/privacy-policy2026-09-061e5fc31f01b4803e…seq 449
dpahttps://legal.hubspot.com/dpa2026-09-0614059695d482cb8c…seq 450
subprocessorshttps://trust.hubspot.com/legal/subprocessors2026-09-064ea7ed3ac60f57e5…seq 451
Ledger proof for this record.
seq 509 · key 2f898a895f05b7a0 · 2026-09-06T01:40:51.725Z
hash e27450e272b23c6cabcd5041db6d8390465b066264bb777bc21a900076e60d69
prev 8f9917f01bd38e67cb8e2035fb7d710f09efb3dd92979e4ed8b453b3b6e6fd5e
payload 7d8f98ede610ecace377d62fb79a15548d182e7d23887d4ac7099eec905c5273
signature 3tCJCzOo1zenPdaeao5oohcVuSsEHt7z13tsOkZwl15jFr99lTt1tqq+5zM4nO5bKI4Qaz9JhanTOo74HmPIBQ==
anchored 2026-09-06 at head seq 564 231a9dea0f93915bd7110e6786e00908325db3031635ace53c1023f850e0c49c
Fetch /v1/keys; for each ledger entry recompute sha256(prev_hash|kind|ref_id|payload_hash|created_at ISO) and verify the Ed25519 signature over that hash. Anchors are committed to git; compare the anchored head with the chain.