Skip to main content
HubSpot logo

HubSpot

Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026

C-
AITS IA

AI Trust Summary

AI Training
Criterion not evaluated
Data Retention
Partially mentioned (no defined period)
Opt-out
Only generic controls (cookies, ads)
AIPrivacy
C-
BasePrivacy
A-
  • Regarding AI: it does not document a mechanism for contesting automated decisions, which may impact customer rights.
  • Regarding Privacy Baseline: it ensures contact channels for privacy issues, facilitating communication with the DPO and increasing transparency in data practices.

Attention Points in AI (2)

AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.

  • HubSpot
  • Does not mention human review of automated decisions, which may compromise customer rights (Art. 20 GDPR).
  • Omission of ethical AI principles may raise concerns about the responsible use of data.
  • Requiring a human review clause in contracts can mitigate risks.

AI decision contestation mechanism not available

There is no specific mention of human review of automated decisions, which may impact customer rights.

Ethical AI principles and anti-bias measures not documented

There is no mention of ethical AI principles, which may raise concerns about the responsible use of data.

Source: vendor public documents

Compliances in AI (3)

AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.

  • HubSpot
  • Documents data processing purposes by category, ensuring clarity of use.
  • Provides specific channels for privacy issues, including direct contact with the DPO.
  • These practices strengthen due diligence and trust in data management.

Automated AI decisions explained in an understandable way

The policy mentions personalization based on contact data, but does not explain how automated decisions are made.

AI features clearly identified with their purposes

The policy mentions functionalities that imply automation, but does not detail which ones use AI and for what purposes.

AI training opt-out control available

The policy offers generic controls, but there is no specific opt-out for AI model training.

Source: vendor public documents

Highlights in Privacy (3)

Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.

Data controller identity and contact clearly disclosed

HubSpot clearly identifies its data controller, facilitating contact for privacy issues.

Processing purposes clearly listed by data category

The policy connects data categories with their purposes, ensuring clarity in the use of contact data and campaign metrics.

Privacy contact channel available

HubSpot offers specific channels for privacy issues, including a DPO and a dedicated email.

Source: vendor public documents

Critical Alerts

  • Princípios de IA ética e medidas anti-viés não documentados: Crucial para garantir que a IA seja utilizada de forma ética nas campanhas de marketing..
  • Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública

Conformance analysis (20)

Premium Feature
AITS Criterion 10
Compliant

Identity and contact of the data controller clearly informed

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 12
Compliant

Processing purposes clearly listed by data category

Reference: ISO/IEC 27701 (7.3)

AITS Criterion 11
Compliant

Contact channel for privacy issues available

Reference: ISO/IEC 27701 (7.3)

Source: vendor public documents

Follow this company and access all 20 criteria

Track score changes, get alerts on policy updates, and view the full conformance analysis

Sign up free

Don't miss any update

Sign up to follow this company and track changes in privacy and AI scores

Sign up free

Why trust the AITS Index: Open Community Audit

Public transparency, peer review and open evidence trails — all verifiable by the community

Trust guarantees

Peer review

users, professionals and experts confirm or contest items online.

Public history

vendor and index changes are versioned and accessible.

Participate

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Maximize Your Marketing Automation with HubSpot: Privacy Insights and Guidance

Clear Data Processing Purposes

HubSpot excels in providing clarity regarding its data processing purposes, which is crucial for users concerned about privacy compliance. With an OPTI Base (Privacy) Score of 89%, HubSpot clearly lists the purposes for processing data by category, ensuring that users understand how their information is being utilized. This transparency is essential for compliance with regulations such as GDPR and LGPD, which mandate that users be informed about the use of their data. For businesses, this means that you can confidently communicate to your customers how their data will be handled, fostering trust and enhancing your brand reputation.

Accessible Privacy Contact Channels

Another strength of HubSpot is its provision of accessible channels for privacy-related inquiries. Users can easily reach out to the Data Protection Officer (DPO) for any privacy concerns, which is a significant advantage in maintaining compliance with privacy laws. This feature not only increases transparency but also empowers users to take an active role in managing their data privacy. Businesses should take advantage of this feature by familiarizing themselves with the contact process and encouraging their teams to utilize it whenever necessary, ensuring that any potential privacy issues are addressed promptly.

Lack of AI Decision Contestation Mechanism

Despite its strengths, HubSpot has notable weaknesses, particularly in its handling of AI-related decisions. The absence of a documented mechanism for contesting automated decisions can pose significant risks to users. This gap may affect user rights under GDPR, which emphasizes the right to contest decisions made solely based on automated processing. For businesses using HubSpot, it is crucial to be aware of this limitation and to inform customers about their rights regarding automated decision-making. Users should consider advocating for the implementation of such mechanisms to enhance their compliance posture.

Unaddressed Ethical AI Principles

Another concerning aspect is the lack of documentation regarding ethical AI principles and anti-bias measures. With an OPTI IA Score of only 42%, this shortcoming indicates that HubSpot may not adequately address potential biases in its AI systems, which can lead to unfair treatment of users. Businesses should remain vigilant and conduct their own assessments of how AI features within HubSpot may impact their operations and customer interactions. It may be beneficial to supplement HubSpot's offerings with third-party tools that provide more robust ethical AI frameworks.

Practical Settings and Precautions

To maximize the benefits of HubSpot while minimizing risks, users should actively engage with the platform's privacy settings. Review the data processing purposes listed in your account settings to ensure they align with your business practices and customer expectations. Additionally, consider enabling features that enhance transparency, such as detailed consent forms and privacy notices. Regularly audit your data handling practices in light of HubSpot's capabilities to ensure compliance with GDPR and LGPD.

Exploring Alternatives and Enhancements

If the weaknesses in HubSpot's AI governance are concerning, it may be worth exploring alternative marketing automation platforms that offer stronger compliance features, particularly in AI ethics and decision-making transparency. Alternatively, businesses can enhance their use of HubSpot by integrating it with other compliance tools that provide better oversight of AI processes. This approach can help mitigate risks while still benefiting from HubSpot's robust marketing automation capabilities.

Evidence, confirmations and contestations

participate in the collaborative validation of AITS criteria

Contact us

Scope & Limitations

TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).

The content is indicative in nature, intended for screening and comparison, not replacing internal audits.

TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.

Source: vendor public documents