Talk legal to me
Last Modified: June 4, 2024
PLEASE READ THESE TERMS CAREFULLY
Our HubSpot Regional Data Hosting Policy ("Policy") explains where Customer Data will be hosted by HubSpot. This Policy sets out our commitment to hosting Customer Data in a specific location and the exceptions to that commitment.
In 2021, we began offering a location specific regional data hosting service (“Regional Data Hosting”) to new customers as part of their subscription. New customers who purchase the Subscription Service after July 19, 2021, and who are located in Europe (including Switzerland and the United Kingdom), Russia, the Middle East and Africa will have their Customer Data hosted in the Europe by default (based on your IP address on sign up) in accordance with this Policy. If your Order Form does not indicate a data hosting location, your Customer Data will be stored in the United States of America (“USA” or "United States").
Any terms not defined in this Policy will have the same meaning as set out in the HubSpot Customer Terms of Service. In the event of a conflict between this Policy and the Agreement, this Policy will control. We may periodically update this Policy. We will post any changes on this page and, if the changes are material, we will provide an update through the notification app in your HubSpot account.
1.1 Definitions
"Location" means the region or geographic area where your Customer Data is primarily stored within our cloud infrastructure (e.g., North America, Europe, etc.). The location will be indicated on your Order Form and in your HubSpot account. If no Location is specified in your Order Form your Customer Data is hosted in the USA.
"Exclusions" means the services and processing not covered by Regional Data Hosting Policy and which will continue outside of the Location, as described in the ‘Exclusions’ section below.
1.2 If you purchase your Subscription Service after July 19, 2021, and you are located in Europe (including Switzerland and the United Kingdom), Russia, the Middle East and Africa (based on your IP address on sign up) we will store Customer Data within the Location for the duration of your Subscription Term in accordance with the terms of this Policy. You agree that for the purposes of the DPA, this Policy constitutes your Instructions in relation to the storage of Customer Data. The Location will be indicated on your Order Form. If no Location is specified in your Order Form your Customer Data will be hosted in the USA. Your Location will also be indicated in your HubSpot account. Your Customer Data will be replicated for disaster recovery and back-up purposes to other data centers within the Location.
1.3 You understand and agree that while Customer Data will be primarily stored and processed in the Location: (i) HubSpot, Inc. is located in the USA and certain storage and processing may continue outside of the Location, including in the USA and other regions where we, our Affiliates and Sub-processors operate; (ii) we may change Sub-processors in order to provide the Subscription Service, in accordance with the DPA; (iii) Customer Data may be accessed outside of the Location if Users accessing the Subscription Service are located outside of Europe; (iv) except as otherwise agreed only Customer Data that was submitted or collected after Regional Data Hosting was included as part of your subscription will be stored in the Location; and (v) we make no warranty that Regional Data Hosting will meet your data residency requirements. Regional Data Hosting does not apply to the Exclusions, see the ‘Exclusions’ section below for further information.
1.4 This Policy does not apply if you previously agreed to the HubSpot Regional Data Hosting Beta Terms. In that case, the terms in this Policy do not apply to you and the HubSpot Regional Data Hosting Beta Terms will continue to apply until either (i) your HubSpot account is migrated to the Location, or (ii) we notify you of the end of the HubSpot Regional Data Hosting Beta Program. The HubSpot Regional Data Hosting Beta Terms will then cease to apply and this Policy will apply.
2.1 HubSpot, Inc. is located in the USA and certain storage and processing may continue outside the Location, including in the USA and other regions where HubSpot, its Affiliates and Sub-Processors operate. Customer Data may be transferred and/or accessed outside the Location for the following Exclusions:
(i) Customer and Product Development Support: In order to provide customer support and product development support, HubSpot employees from other office locations and Sub-Processors may access your HubSpot account and Customer Data. For example, we may access your HubSpot account if you call HubSpot Support and have a question about how to use a certain feature or to fix a bug.
(ii) Security and Abuse Prevention: HubSpot employees from other office locations may access your HubSpot account and Customer Data to investigate or remediate security incidents and/or product abuse.
(iii) Integrations: If you choose to use integrations that process Customer Data, those integrations may process and/or store Customer Data in locations other than the Location. Before installing integrations, you should investigate how data is being passed to these integrations and where the data will be stored and/or processed. You are responsible for any integrations you use in conjunction with your HubSpot account.
(iv) User Access: Your Users may log in to your HubSpot account from areas outside of the Location. This means that data may be accessed and transferred from the User’s location. User access is your responsibility.
(v) Usage Data: As described in the ‘Customer Data’ section of the Customer Terms of Service, we may collect data about how you use and interact with the Subscription Service. This usage data will be transferred from the Location to the USA.
(vi) Sub-Processors: HubSpot uses Sub-Processors to provide the Subscription Service and Consulting Services. These Sub-Processors may process Customer Data (which may contain Personal Data). As a HubSpot Customer, your Customer Data will be stored and processed by these Sub-Processors within the Location, except for those listed in the table below.
You can review the list of Sub-Processors in Annex 3 of the DPA. You may choose to not use certain features or integrations supported by the Sub-Processors included in the table below. If you wish to use the features or integrations supported by these Sub-Processors, you acknowledge your Customer Data will be processed and/or stored outside of the Location.
Cloudflare, Inc. |
Content delivery network |
All data entering the HubSpot platform passes through Cloudflare, and this functionality cannot be disabled. TLS connections for customer traffic will only be terminated in EU data centers. |
*Data Centers located all around the world. Traffic will be automatically routed to the nearest data center. |
Google LLC
|
Form submission spam prevention |
Use of Google reCAPTCHA is disabled by default and is an opt-in feature within the forms tool. If you do not choose to use Google reCAPTCHA, no Customer Data will be accessed by this Sub-Processor. |
United States
|
B2B Checkout spam prevention |
Use of Google reCAPTCHA is enabled by default without an opt-out feature within B2B Checkout. If you do not wish to use Google reCAPTCHA, payments should not be submitted with B2B Checkout. |
||
Litmus Software, Inc. |
Email Functionality |
Used for email previews. |
United States |
Mux, Inc. |
Video functionality |
You can choose to not use video functionality to not access Customer Data to this Sub-Processor. |
United States |
Meta Platforms, Inc. OPT-IN ONLY |
Conversation Functionality |
Use of WhatsApp is an opt-in integration. If you do not install the WhatsApp integration, no Customer Data will be accessible. |
United States |
OpenAI, LLC |
AI Products |
Used for HubSpot AI Products. If you do not choose to use AI Products, no Customer Data will be accessed by this Sub-Processor. |
United States |
Stripe, Inc. |
Payment Processor |
Used to support Commerce Hub products and services. If you do not choose to use Commerce Hub products and services, no Customer Data will be accessed by this Sub-Processor. |
United States |
Twilio, Inc. |
Calling and SMS Functionality |
You can choose to not use calling and SMS functionality to avoid this Sub-Processor having access to Customer Data. |
United States |
*see https://www.cloudflare.com/network/ for further information on Cloudflare.