Summary
-
300+ web pages assessed
-
40 pages deemed as possibly relevant documents
-
5 binding documents identified for a standard use case (Customer ToS, DPA, AUP, Privacy Policy, Product Specific Terms)
-
-
Scored against a 65-point in-house counsel playbook: 25 aligned, 32 flagged for review, 8 conflicts
-
183 clauses matched to playbook requirements, every one cited to its source section
-
Silent on 2 playbook points (silence is a finding too, see below)
Key Findings from HubSpot’s Terms
Rights to Custom Deliverables
Playbook requirement: Custom deliverables produced for the customer are owned by the customer.
“We retain all intellectual property rights to the HubSpot Content, the Subscription Service, the Consulting Services, and any other products or services provided under this Agreement.”
Source: Customer Terms of Service, §6.1 (Ownership)
Consulting Services covers professional services such as training, installation, and integration work, the engagement type that produces custom deliverables. The Product Specific Terms mention deliverables (§8.1.2) but govern only delivery timing, with no IP assignment to the customer. The customer's ownership carve-outs are limited to Customer Materials and Customer Data (§5.1) and AI Output (§7.4), neither of which covers work product HubSpot creates. Scope note: this mainly matters if you purchase consulting or custom work; subscription-only use is unaffected.
Conflict
Breach Indemnification
Conflict
Playbook requirement: the vendor indemnifies the customer for its own breaches and for breaches by its subprocessors.
“We will indemnify, defend and hold you harmless, at our expense, against any Action brought against you (and your officers, directors, employees, agents, service providers, licensors, and Affiliates) by a third party not affiliated with you to the extent that such Action is based upon or arises out of an allegation that the Subscription Service infringes a valid patent in a member state of th Patent Cooperation Treaty, registered trademark, or registered copyright ("IP Indemnification").”
Source: Customer Terms of Service, §9.2 (HubSpot Indemnification)
This is the only indemnity in HubSpot's terms that runs in the customer's favor, and it covers IP infringement claims only. There is no indemnification for HubSpot's own security incidents or contractual breaches, and none for its subprocessors'. DPA §5 makes HubSpot "remain responsible" for subprocessor compliance failures, which prevents deflection, but it is not indemnification: the customer still brings and proves the claim, and recovery stays under the liability cap. One point in HubSpot's favor: DPA §12.3 lifts the cap for claims involving an individual's data protection rights, and the DPA's precedence clause makes that control over the General Terms.
Vendor Liability for a Data Incident
Playbook requirement: The vendor retains meaningful liability for data breaches, uncapped preferred.
“...the aggregate liability of a party and its affiliates will be limited to a sum equal to the total amounts paid or payable for the Subscription Service in the twelve month period preceding the event giving rise to a claim...”
Source: Customer Terms of Service, §10.4 (Limitation of Liability)
The carve-outs from this cap do not include HubSpot's general breach liability, so a data incident claim sits under the 12-month fee cap. Separately, §10.3 (No Indirect Damages) excludes indirect, incidental, and consequential damages for both parties, which is where much of a breach's real cost tends to land.
Needs Review
Customer Data and AI Output Ownership
Aligned
Playbook requirement: The customer retains all rights to its materials, data, and outputs.
“You own and retain all rights to the Customer Materials and Customer Data. You grant permission to us and our licensors to use the Customer Materials and Customer Data as necessary to provide the Subscription Service and Consulting Services to you, as permitted by this Agreement, and as permitted by applicable law.”
Source: Customer Terms of Service, §5.1
“Between you and HubSpot, you retain all rights you may have to use and exploit your AI Output. This means you can use your AI Output for any lawful purpose, including commercial purposes such as sale or publication, in accordance with the Customer Terms of Service (including these Product Specific Terms).
Source: Product Specific Terms, §7.4
Data ownership and AI output rights both sit with the customer, including commercial use of AI output. This is a clean pass against the playbook.
The full analysis below covers all 65 playbook points with 183 cited clauses.
What HubSpot’s Terms Don’t Say
The terms were silent on 2 of the 65 playbook points:
-
Exclusivity: nothing restricts the customer from using competing tools. Silence here is acceptable.
-
Non-solicitation of employees: no restriction on either side recruiting the other's people. Silence here is acceptable.
Both were graded acceptable despite the silence. Knowing what a vendor's terms don't say is half the review.
How TermTrax Produced This Analysis
TermTrax assembles the vendor's complete binding document set (here, 5 documents found across 300+ pages), compares every clause against each requirement in your playbook, and drafts a graded first pass. Every finding cites the exact source clause. You review, edit, and decide.
Your policies at a glance

Every finding cites the exact clause

AI analyzes, you decide

-
Output quality confirmed by in-house legal counsel
-
No implementation, no migration. Paste a URL and go
-
Every finding cites the exact source clause
-
AI analyzes, you decide. All findings can be edited and overwritten
This analysis was generated by TermTrax using a standard general-terms playbook in June 2026. It is not legal advice. Vendor terms may have been updated since this analysis. Your team's playbook will produce findings specific to your organization's policies and risk tolerances.