HubSpot (Breeze AI)
medium riskEmbedded SaaS AIhubspot.comverified 2026-06-27profile 85% complete
Data-handling profile
- Trains on input
- Yes, on the consumer tier (enterprise tier excluded)
- Retention
- Third-party AI providers are contractually barred from training on HubSpot customer data (zero data retention). Separately, HubSpot may use customer data to train its own Breeze/AI models unless the account-level 'AI model training' setting is turned off; when off, data is excluded and not shared with other customers.
- Data region
- US
- Certifications
- SOC 2 Type IIISO 27001
- DPA available
- Yes
- Breach history
- 2022 breach: a compromised employee account was used to access data of ~30 HubSpot customer accounts via an internal support tool.
- EU AI Act
- Embedded CRM AI (lead scoring, content generation); lead/customer-scoring agent features warrant review for high-risk classification under EU AI Act depending on downstream use (e.g., credit or employment-adjacent decisions).
Sources
- https://www.hubspot.com/products/artificial-intelligence/ai-trust
- https://knowledge.hubspot.com/hubspot-ai-cloud-infrastructure-frequently-asked-questions
- https://vantagepoint.io/blog/hs/hubspot-ai-model-training-customer-data-opt-out-guide
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Control mapping
Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.
- EU AI Act Art. 50 — Transparency obligations for AI systemsattention
trains_on_input = consumer_tier. Inputs may be reused for model training — users interacting with this system need to be informed accordingly.
- EU AI Act Art. 26 — Obligations of deployers of high-risk AI systemsapplies
Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).
- ISO/IEC 27001 A.5.19 — Information security in supplier relationshipsapplies
HubSpot (Breeze AI) processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.
- ISO/IEC 27001 A.5.20 — Addressing information security within supplier agreementsok
dpa_available = true. A data processing agreement is available and should be executed.
- ISO/IEC 27001 A.5.22 — Monitoring, review and change management of supplier servicesattention
breach_history: 2022 breach: a compromised employee account was used to access data of ~30 HubSpot customer accounts via an internal support tool. Prior incident on record — justify continued use and monitor.
- ISO/IEC 27001 A.5.23 — Information security for use of cloud servicesattention
Cloud AI service; trains_on_input = consumer_tier. Data submitted to this cloud service may be retained or reused — define acceptable-use rules for it.
- ISO/IEC 42001 A.10.3 — Suppliers of AI systems and servicesapplies
certifications: SOC 2 Type II, ISO 27001 No AI-management certification identified; assurance must come from your own supplier assessment.
- GDPR Art. 44–49 — International transfers of personal dataattention
data_region = US. Processing occurs outside the EU/EEA — a transfer mechanism (SCCs or adequacy) must be in place.
- NIS2 Art. 21(2)(d) — Supply chain securityapplies
AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.
- DORA Art. 28 — General principles for ICT third-party riskapplies
AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.
Change history
No material changes recorded since monitoring began.