Talk legal to me
Last Modified: September 18, 2024
PLEASE READ THESE TERMS CAREFULLY
Our HubSpot Regional Data Hosting Policy ("Policy") explains where Customer Data will be hosted by HubSpot and is incorporated into the HubSpot Terms of Service. This Policy sets out our commitment to hosting Customer Data in a specific location and the exceptions to that commitment.
HubSpot offers location specific regional data hosting (“Regional Data Hosting”) to customers as part of their subscription. Any terms not defined in this Policy will have the same meaning as set out in the HubSpot Customer Terms of Service. In the event of a conflict between this Policy and other terms in the Agreement, this Policy will control. We may periodically update this Policy.
1.1 Hosting Location Information
1.1.1 "Hosting Location" means the region or geographic area where your Customer Data is primarily stored within our cloud infrastructure (e.g., North America, Europe, etc.).
1.1.2 At sign up, customers who purchase the Subscription Service can select to either host their Customer Data in the European Union Hosting Location (“Europe”) or the United States of America Hosting Location (“USA” or "United States"). Where a customer has not purchased a Subscription Service and has not selected a Hosting Location, HubSpot makes no commitments on the hosting location of Customer Data. Where customers have purchased the Subscription Service and Customer Data is hosted in the United States, they can choose to migrate their data to Europe, subject to some limitations.
In cases where a customer has not selected a Hosting Location or for customers using Free Services only, you agree HubSpot will make a Hosting Location selection to support your access to the Subscription Services.
1.1.3 Where a Customer has purchased the Subscription Service and selected a Hosting Location, we will store Customer Data within the Hosting Location for the duration of your Subscription Term in accordance with the terms of this Policy. Your Customer Data will be replicated for disaster recovery and back-up purposes to other data centers within the regional Hosting Location.
1.1.4 Scope. Except where otherwise agreed, the Regional Data Hosting Services do not apply to or cover other services or types of data including (i) Add-Ons and Third Party Products (ii) Consulting Services; (iii) HubSpot Content; or (iv) analytics or usage data generated in connection with the Subscription Service.
1.2 Hosting Location Acknowledgments
1.2.1 You agree that for the purposes of the DPA, this Policy constitutes your Instructions in relation to the storage of Customer Data.
1.2.2 Although Customer Data will be primarily stored and processed in the Hosting Location, you also understand:
(i) HubSpot, Inc. is located in the USA and, certain storage and processing may continue outside of the Hosting Location, including in the USA and other regions where we, our Affiliates and Sub-processors operate;
(ii) we may add or change Sub-processors in order to provide the Subscription Service, in accordance with the DPA;
(iii) Customer Data may be processed outside of the Hosting Location if Users and your end users accessing the Subscription Service are located outside of Hosting Location;
(iv) Regional Data Hosting does not apply to the Exclusions, see the ‘Exclusions’ section below for further information; and
(v) WE MAKE NO WARRANTY THAT REGIONAL DATA HOSTING WILL MEET YOUR DATA RESIDENCY REQUIREMENTS.
2.1 Data Migration is a programmatic migration of your HubSpot account from one Hosting Location to another. You will lose access to your HubSpot portal prior to and during the Data Migration (included in Downtime as defined in the Product Specific Terms and excluded from any Service Uptime Commitment). For more information on Data Migration, please see the HubSpot knowledge base article Migrate your account data to HubSpot’s EU data center.
2.2 You acknowledge the limitations and risks associated with data migration, including migration cancellation at the reasonable determination of HubSpot, and possible migration failure. In the event of cancellation or failure, Customer Data will remain in the original data Hosting Location.
2.3 Post Migration Data Retention. After a reasonable period of time, we will either delete or anonymize your Customer Data or, if this is not possible, then we will securely store your Customer Data and isolate it from any further use until deletion is possible. We will only retain your Customer Data on an ongoing legitimate business need to do so in accordance with this policy and in accordance with the DPA.
3.1 "Exclusions" means the services and processing not covered by Regional Data Hosting Policy and which will continue outside of the Hosting Location, as described in the ‘Exclusions’ section below.
3.2 HubSpot, Inc. is located in the USA, and certain storage and processing may continue outside the Hosting Location, including in the USA and other regions where HubSpot, its Affiliates and Sub-Processors operate. Customer Data may be transferred and/or accessed outside the Hosting Location for the following Exclusions:
(i) Customer Support and Product Development. In order to provide customer support and product development, HubSpot employees from other office locations may access your HubSpot account and Customer Data. For example, we may access your HubSpot account if you call HubSpot Support and have a question about how to use a certain feature or to fix a bug. We may also use your data pursuant to section 5.3 of HubSpot’s Customer Terms of Service.
(ii) Security and Abuse Prevention. HubSpot employees from other office locations may access your HubSpot account and Customer Data to investigate or remediate security incidents and/or product abuse.
(iii) Integrations. If you choose to use integrations that process Customer Data, those integrations may process and/or store Customer Data in Hosting Locations other than the Hosting Location. Before installing integrations, you should investigate how data is being passed to these integrations and where the data will be stored and/or processed. You are responsible for any integrations you use in conjunction with your HubSpot account.
(iv) User Access. Your Users may log in to your HubSpot account from areas outside of the Hosting Location. This means that data may be accessed and transferred from the User’s Hosting Location. User access is your responsibility.
(v) Usage Data. As described in Terms of Service, we may collect data about how you use and interact with the Subscription Service. This usage data will be transferred from the Hosting Location to the USA.
(vi) Sub-Processors. HubSpot uses Sub-Processors to provide the Subscription Service and Consulting Services. These Sub-Processors may process Customer Data (which may contain Personal Data). As a HubSpot Customer, your Customer Data will be stored and processed by these Sub-Processors within the Hosting Location, except for those listed in the table below.
You can review the list of Sub-Processors on HubSpot’s Sub-Processors Page available at https://legal.hubspot.com/sub-processors-page or in Annex 3 of the DPA. You may choose to not use certain features or integrations supported by the Sub-Processors included in the table below. If you wish to use the features or integrations supported by these Sub-Processors, you acknowledge your Customer Data will be processed and/or stored outside of the Hosting Location.
Cloudflare, Inc. |
Content Delivery network |
All data entering the HubSpot platform passes through Cloudflare, and this functionality cannot be disabled. TLS connections for customer traffic will only be terminated in EU data centers. |
*Data Centers located all around the world. Traffic will be automatically routed to the nearest data center. |
Google LLC
|
Form submission spam prevention |
Use of Google reCAPTCHA is disabled by default and is an opt-in feature within the forms tool. If you do not choose to use Google reCAPTCHA, no Customer Data will be accessed by this Sub-Processor. |
United States
|
B2B Checkout spam prevention |
Use of Google reCAPTCHA is enabled by default without an opt-out feature within B2B Checkout. If you do not wish to use Google reCAPTCHA, payments should not be submitted with B2B Checkout. |
||
Litmus Software, Inc. |
Email Functionality |
Used for email previews. |
United States |
Mux, Inc. |
Video functionality |
You can choose to not use video functionality to not access Customer Data to this Sub-Processor. |
United States |
Meta Platforms, Inc. OPT-IN ONLY |
Conversation Functionality |
Use of WhatsApp is an opt-in integration. If you do not install the WhatsApp integration, no Customer Data will be accessible. |
United States |
OpenAI, LLC |
AI Products |
Used for HubSpot AI Products. If you do not choose to use AI Products, no Customer Data will be accessed by this Sub-Processor. |
United States |
Stripe, Inc. |
Payment Processor |
Used to support Commerce Hub products and services. If you do not choose to use Commerce Hub products and services, no Customer Data will be accessed by this Sub-Processor. |
United States |
Twilio, Inc. |
Calling and SMS Functionality |
You can choose to not use calling and SMS functionality to avoid this Sub-Processor having access to Customer Data. |
United States |
*see https://www.cloudflare.com/network/ for further information on Cloudflare.