

HubSpot
Based exclusively on public evidence • 20 criteria (Privacy + AI)
Last review: 21 Feb 2026
AI Trust Summary
- •Regarding AI: it does not document a mechanism for contesting automated decisions, which may impact customer rights.
- •Regarding Privacy Baseline: it ensures contact channels for privacy issues, facilitating communication with the DPO and increasing transparency in data practices.
Safer Alternatives
Higher-rated software in the same category
Attention Points in AI (2)
AI criteria that require attention. Buy the Premium Analysis to see all 2 criteria.
- •HubSpot
- •Does not mention human review of automated decisions, which may compromise customer rights (Art. 20 GDPR).
- •Omission of ethical AI principles may raise concerns about the responsible use of data.
- •Requiring a human review clause in contracts can mitigate risks.
AI decision contestation mechanism not available
There is no specific mention of human review of automated decisions, which may impact customer rights.
Ethical AI principles and anti-bias measures not documented
There is no mention of ethical AI principles, which may raise concerns about the responsible use of data.
Source: vendor public documents
Compliances in AI (3)
AI criteria the company meets. Buy the Premium Analysis to see all 3 criteria.
- •HubSpot
- •Documents data processing purposes by category, ensuring clarity of use.
- •Provides specific channels for privacy issues, including direct contact with the DPO.
- •These practices strengthen due diligence and trust in data management.
Automated AI decisions explained in an understandable way
The policy mentions personalization based on contact data, but does not explain how automated decisions are made.
AI features clearly identified with their purposes
The policy mentions functionalities that imply automation, but does not detail which ones use AI and for what purposes.
AI training opt-out control available
The policy offers generic controls, but there is no specific opt-out for AI model training.
Source: vendor public documents
Highlights in Privacy (3)
Most relevant criteria for this category. Buy the Premium Analysis to see all 3 criteria.
Data controller identity and contact clearly disclosed
HubSpot clearly identifies its data controller, facilitating contact for privacy issues.
Processing purposes clearly listed by data category
The policy connects data categories with their purposes, ensuring clarity in the use of contact data and campaign metrics.
Privacy contact channel available
HubSpot offers specific channels for privacy issues, including a DPO and a dedicated email.
Source: vendor public documents
Critical Alerts
- •Princípios de IA ética e medidas anti-viés não documentados: Crucial para garantir que a IA seja utilizada de forma ética nas campanhas de marketing..
- •Aspecto de privacidade não mencionado na documentação do fornecedor: Ausência de informação pública
Conformance analysis (20)
Identity and contact of the data controller clearly informed
Reference: ISO/IEC 27701 (7.3)
Processing purposes clearly listed by data category
Reference: ISO/IEC 27701 (7.3)
Contact channel for privacy issues available
Reference: ISO/IEC 27701 (7.3)
Source: vendor public documents
Follow this company and access all 20 criteria
Track score changes, get alerts on policy updates, and view the full conformance analysis
Don't miss any update
Sign up to follow this company and track changes in privacy and AI scores
Why trust the AITS Index: Open Community Audit
Public transparency, peer review and open evidence trails — all verifiable by the community
Trust guarantees
Peer review
users, professionals and experts confirm or contest items online.
Public history
vendor and index changes are versioned and accessible.
Participate
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Maximize Your Marketing Automation with HubSpot: Privacy Insights and Guidance
Clear Data Processing Purposes
HubSpot excels in providing clarity regarding its data processing purposes, which is crucial for users concerned about privacy compliance. With an OPTI Base (Privacy) Score of 89%, HubSpot clearly lists the purposes for processing data by category, ensuring that users understand how their information is being utilized. This transparency is essential for compliance with regulations such as GDPR and LGPD, which mandate that users be informed about the use of their data. For businesses, this means that you can confidently communicate to your customers how their data will be handled, fostering trust and enhancing your brand reputation.
Accessible Privacy Contact Channels
Another strength of HubSpot is its provision of accessible channels for privacy-related inquiries. Users can easily reach out to the Data Protection Officer (DPO) for any privacy concerns, which is a significant advantage in maintaining compliance with privacy laws. This feature not only increases transparency but also empowers users to take an active role in managing their data privacy. Businesses should take advantage of this feature by familiarizing themselves with the contact process and encouraging their teams to utilize it whenever necessary, ensuring that any potential privacy issues are addressed promptly.
Lack of AI Decision Contestation Mechanism
Despite its strengths, HubSpot has notable weaknesses, particularly in its handling of AI-related decisions. The absence of a documented mechanism for contesting automated decisions can pose significant risks to users. This gap may affect user rights under GDPR, which emphasizes the right to contest decisions made solely based on automated processing. For businesses using HubSpot, it is crucial to be aware of this limitation and to inform customers about their rights regarding automated decision-making. Users should consider advocating for the implementation of such mechanisms to enhance their compliance posture.
Unaddressed Ethical AI Principles
Another concerning aspect is the lack of documentation regarding ethical AI principles and anti-bias measures. With an OPTI IA Score of only 42%, this shortcoming indicates that HubSpot may not adequately address potential biases in its AI systems, which can lead to unfair treatment of users. Businesses should remain vigilant and conduct their own assessments of how AI features within HubSpot may impact their operations and customer interactions. It may be beneficial to supplement HubSpot's offerings with third-party tools that provide more robust ethical AI frameworks.
Practical Settings and Precautions
To maximize the benefits of HubSpot while minimizing risks, users should actively engage with the platform's privacy settings. Review the data processing purposes listed in your account settings to ensure they align with your business practices and customer expectations. Additionally, consider enabling features that enhance transparency, such as detailed consent forms and privacy notices. Regularly audit your data handling practices in light of HubSpot's capabilities to ensure compliance with GDPR and LGPD.
Exploring Alternatives and Enhancements
If the weaknesses in HubSpot's AI governance are concerning, it may be worth exploring alternative marketing automation platforms that offer stronger compliance features, particularly in AI ethics and decision-making transparency. Alternatively, businesses can enhance their use of HubSpot by integrating it with other compliance tools that provide better oversight of AI processes. This approach can help mitigate risks while still benefiting from HubSpot's robust marketing automation capabilities.
Other Marketing Automation software
Dive into in-depth research and analysis of each player
Source: vendor public documents
Analyzed Sources
Public documents used in the audit of HubSpot:
Evidence, confirmations and contestations
participate in the collaborative validation of AITS criteria
Scope & Limitations
TrustThis/AITS assessments are based exclusively on publicly available information, duly cited with date and URL, following the AITS methodology (privacy & AI transparency).
The content is indicative in nature, intended for screening and comparison, not replacing internal audits.
TrustThis/AITS does not perform invasive tests, does not access vendor technology environments and does not process customer personal data. Conclusions reflect only the vendor's public communication at the date of collection.
Source: vendor public documents





