- What happened? HubSpot proposed adding customers' business-card-level contact details to a shared enrichment dataset, then reversed the plan after backlash and committed to a fully opt-in approach going forward.
- Why does it matter beyond HubSpot? Martech contracts rarely stay static — vendors add AI features and enrichment products that can quietly expand data use under broad "service improvement" language.
- What should customer data leaders do? Audit contract change clauses, assign clear ownership for vendor notices, and follow a structured review process — preserve, assess, decide, document — before accepting any new data use.
HubSpot’s decision earlier this month to reverse planned changes to its customer data enrichment practices demonstrated how quickly a routine vendor notification can become a customer trust crisis.
The company abandoned the plan after customers objected to a rollout they understood as automatically enrolling them in a shared enrichment dataset, but the reversal raises a broader question for businesses that entrust customer information to CRM, marketing automation and analytics providers:
Who is responsible for noticing when a vendor changes how that data may be collected, combined, used or shared?
This article examines how customer data leaders should review martech contracts, monitor changes to vendor terms and respond when new data uses threaten privacy, compliance or customer trust.
What Matters Here: What Data Did HubSpot Propose Adding To Its Shared Enrichment Dataset?
HubSpot planned to add business-card-level professional details from customer accounts into a shared enrichment dataset supporting a new prospecting feature, before reversing the change after customer backlash.
FAQ: Vendor Data Governance After HubSpot's Enrichment Reversal
Editor's note: These questions address common follow-up concerns about vendor data governance raised by HubSpot's reversed enrichment plan, and are distinct from the "What Matters Here" callouts above.
HubSpot's Data Enrichment Reversal Exposes a Broader Vendor Data Risk
HubSpot’s proposed change concerned enrichment data rather than customers’ core CRM records. The company said contacts, notes, deals, call recordings, custom fields and customer records would not be shared. Instead, business-card-level professional details would enter a shared enrichment dataset supporting a new prospecting capability.
That distinction did little to calm customers who believed their relationship with the CRM provider was changing without affirmative permission. Even seemingly minor professional details may represent valuable commercial information collected through years of sales and service interactions.
Within days of the original announcement, HubSpot chief product and technology officer Duncan Lennox said the company had made a mistake, would abandon the July 1 terms changes and make future enrichment capabilities involving customer data fully and transparently opt-in. The original HubSpot legal update described the shared dataset, the business-card-level fields involved and the settings customers could use to control enrichment. HubSpot later marked that update and its related terms as no longer in effect.
Troy Mobley, business agility consultant at Matrix Connect Group, recently wrote on LinkedIn, “Most of the businesses I speak with have spent years building their CRM database. Their team did that work. Their team paid for that time. They never once questioned who owned it.”
Mobley’s concern is indicative of why vendor terms can become a governance issue long after implementation. Businesses may treat the CRM database as an internal asset while overlooking the contractual rights a platform may retain over enrichment, derived data or secondary uses.
Related Article: HubSpot Reverses Customer Data Enrichment Plan After Customer Backlash
What Matters Here: Why Does 'Service Improvement' Language In Vendor Contracts Create Risk?
Broad language such as "service improvement" can cover uses a customer never anticipated, including training shared models or building new commercial datasets from their data.
Why Vendor Governance Must Continue Past Contract Signing
Martech relationships rarely remain static after procurement. Platforms add AI features, acquire companies, introduce enrichment services, change subprocessors and redefine what counts as product improvement, analytics or model training. A contract that was acceptable when a company purchased a CRM may not answer the questions raised when the vendor later introduces a new data product.
The governance gap often begins with ownership. Legal and privacy teams may review the original agreement, but later notices may go to an account administrator, marketing manager or generic billing inbox. The people who receive the message may not know which data is covered, while the people accountable for privacy and customer trust may never see it.
The risk changes when a vendor moves beyond processing information to provide the service a customer purchased and begins using that data for its own commercial purposes. A platform that combines customer information into a shared dataset, trains a generalized model or develops products for other customers may be assuming rights and responsibilities that were not part of the original agreement. Businesses should not assume that broad language such as “service improvement” automatically covers every later use of the data.
What Matters Here: Which Six Contract Areas Should Customer Data Leaders Audit In Martech Agreements?
Customer data leaders should examine data definitions, permitted uses, retention and deletion, subprocessors and transfers, change provisions, and audit and accountability clauses in every martech contract.
Six Contract Areas Customer Data Leaders Should Examine in Martech Agreements
The first task is to define the data in practical terms. A contract should distinguish among customer-submitted information, data generated through use of the platform and information added through enrichment. The same record may contain supplied, observed and inferred information with different ownership and usage rights. Customer data leaders should examine how a martech agreement defines data, permits secondary uses and handles changes throughout the vendor relationship.
| Contract Area | What to Examine | Why It Matters |
|---|---|---|
| Data definitions | How the agreement distinguishes customer-provided, vendor-generated, inferred and enriched data | Ownership and control may differ within the same customer record |
| Permitted uses | Whether data may be combined across accounts, used for benchmarking, added to commercial datasets or used to train AI models | Broad product-improvement language may cover uses beyond the service originally purchased |
| Retention and deletion | How long primary, derived and backup data remains after termination or opt-out | Stopping a feature may not remove data already copied or incorporated into another product |
| Subprocessors and transfers | Which third parties receive data, where it is processed and how customers are notified of changes | New vendors or processing locations can alter privacy, security and regulatory exposure |
| Change provisions | How notice is delivered, whether continued use counts as acceptance and whether customers can terminate after a material change | A business may have little time to respond before a new data use takes effect |
| Audit and accountability | What records, assessments, breach notices and compliance assistance the vendor must provide | Businesses need evidence to evaluate whether the vendor is following the agreed controls |
Scrutinize How Vendor Contracts Define 'Aggregated' and 'Product Improvement'
Customer data leaders should determine who controls each category and whether the vendor may combine it with outside information, develop a commercial dataset, train AI models, create benchmarks or offer new capabilities to other accounts.
Language such as “improving the service” deserves particular scrutiny. It could refer to fixing defects, improving a shared product or training a model used across customer accounts. Contracts should define the purposes, data types, recipients and controls rather than leaving them to later interpretation.
Channing Ferrer, chief revenue officer and Americas CEO at Brevo, said amendment clauses deserve particular attention because they can weaken other protections by allowing vendors to revise terms through a notice.
“After that, scrutinize how ‘aggregated,’ ‘de-identified’ and ‘product improvement’ are defined,” Ferrer said. “That’s where your proprietary data becomes the vendor’s asset or the training set for a product your competitor also pays for.”
How Long Does Your Martech Vendor Retain Information?
The review should also address how long the vendor retains information, what happens to primary and derived data after the contract is terminated and which subprocessors can access it. Customer data leaders should examine where information is processed, how they will be notified when third parties are added and what assistance the vendor must provide following a breach or compliance inquiry. They should also determine whether audit rights and deletion obligations extend to backups and data incorporated into other products.
The distinction between customer-provided, vendor-generated and jointly enriched data deserves particular attention. An enrichment provider may argue that its added information is part of its own dataset, while the customer may view the combined record as an extension of the CRM data it supplied. That disagreement can affect consent, deletion, portability, retention and the right to stop a secondary use.
HubSpot's current documentation also illustrates why settings matter alongside legal text. The company says accounts can turn off AI model training through an account control and that accounts using its Sensitive Data feature are opted out by default. A setting can be useful, but it does not replace a contract that explains what data is used, for which purpose and under whose authority.
Specifically, HubSpot says, "AI model training and enrichment are managed separately. Turning off AI model training doesn't turn off enrichment, and turning off enrichment doesn't turn off AI model training. Each setting controls a different use of your data and can be managed independently. Learn more about managing data enrichment settings."
What Matters Here: What Is The Difference Between Opt-In And Opt-Out Vendor Data Changes?
Opt-out places the burden on the customer to notice a change and act before a deadline, while opt-in requires the vendor to obtain affirmative agreement before a new data use begins.
Related Article: HubSpot Acquires Warmly to Boost AI Agents
Why Vendor Change Clauses Matter as Much as Data Clauses
Businesses often scrutinize how a contract describes data handling but give less attention to the provisions that allow a vendor to change the terms. Those clauses determine whether a customer receives meaningful notice, whether continued use counts as acceptance and whether the customer can terminate without penalty after a material change.
Contractual exit rights are only useful when a business can realistically exercise them.
Andy Boettcher, chief innovation officer at DoubleTrack, said customer data leaders should ask a more practical question before a dispute occurs: “Could you actually walk away if you wanted to? Not hypothetically. Actually. If the answer's no, the vendor didn't surprise you. You built that dependency years ago, and the invoice just came due.”
His point extends the contract discussion into technology architecture and procurement strategy. A business may retain the legal right to terminate, but extensive integrations, proprietary data structures and deeply embedded processes can make departure prohibitively disruptive. Vendor reviews should therefore consider not only termination language, but also data portability, migration requirements and the cost of replacing the platform.
Do You Know What a Formal Notice Is from Your Martech Vendor?
Customer data leaders should identify the communication channels that count as formal notice and the amount of time available to respond. A message posted in a legal updates center may satisfy a technical notice requirement while still failing to reach the people who manage privacy, security or data architecture.
The change process should also distinguish minor product updates from changes to data use. Adding a dashboard is not equivalent to allowing customer information to enter a shared dataset. A new AI feature may be optional, while the data contribution that improves it may be presented as a default. The contract should make those distinctions visible.
Opt-in and opt-out are not interchangeable. Opt-out places the burden on the customer to notice the change, understand the consequences and act before a deadline. Opt-in requires the vendor to obtain an affirmative decision before the new use begins. HubSpot acknowledged that its rollout failed to make the proposed opt-in clear and committed to making future enrichment capabilities involving customer data fully and transparently opt-in.
What Matters Here: Why Do Vendor Data-Use Notices Often Fail to Reach The Right Team?
Responsibility for monitoring vendor terms is often split across legal, privacy, IT and marketing, so notices can arrive without anyone confirming they own the review.
How to Build a Process for Reviewing Vendor Data-Use Notices
Stronger contract language matters, but it cannot replace a clear internal review process.
Rob Bentley, founder of CMO advisory firm Bentley Strategy, said responsibility for detecting vendor changes is often divided across privacy, legal, IT security, data and marketing teams, leaving no single group fully accountable. "In most organizations, no one is responsible,” Bentley said. “When the vendor email lands, it isn't that everyone ignored it. It's that nobody was sure they owned it.”
That ambiguity can prevent important notices from reaching the people who are qualified to evaluate them. A business may have legal, technical and marketing owners for a platform without assigning anyone direct responsibility for monitoring changes to the vendor’s terms.
Businesses should maintain an inventory connecting each martech vendor with the data it receives, enabled services, internal owner, contract, privacy and security reviews, renewal date and known subprocessors. The inventory should also identify who receives legal and product notices.
How Creating a Joint Data Governance Group Can Help Understanding Martech Vendor Changes
Stanislav Kazanov, head of GRC, cybersecurity, sustainability and data at Innowise, said the gap often develops because marketing teams adopt tools and accept updated terms faster than legal and privacy teams can evaluate them. He recommended creating a joint data governance group involving legal, marketing and IT so vendor notifications are reviewed as changes to the company’s technology and data practices rather than routine administrative messages.
The communication gap appeared in HubSpot’s own community forum. One Super Admin said they had not seen the original update despite being designated to receive important account communications and learned about the proposed change only through HubSpot’s apology. The response shows why businesses cannot assume that a vendor notice will automatically reach the people responsible for privacy, data governance or contract review.
Vendor messages should then be routed according to their potential impact. Notices involving AI training, enrichment, data sharing, retention, secondary uses or new subprocessors should reach privacy, legal, security, procurement, IT and the relevant data owner. Routine product changes may remain with the platform owner. Recording this process prevents important notices from being treated as harmless product news or discovered only after a new policy takes effect.
What Matters Here: What Six Steps Should Businesses Follow When A Vendor Changes Data Use?
Businesses should preserve the notice, identify affected data, review existing obligations, assess business risk, select a response and document the decision for follow-up.
Six Steps to Take When a Vendor Changes Data Use
A practical review can begin by preserving the vendor notice and identifying the effective date, revised contract language and product settings involved. Customer data leaders should consult the underlying documents rather than relying solely on an account representative’s summary when the change concerns customer information. A structured review process helps businesses determine whether to accept, disable, negotiate or reject a new vendor data use.
| Step | Required Action | Decision Question |
|---|---|---|
| Preserve the notice | Save the communication, revised terms, product documentation and effective date | What is changing, and when will it take effect? |
| Identify affected data | Map the customer records, content, inferred attributes and confidential business information involved | Which data and customer groups are exposed to the new use? |
| Review existing obligations | Compare the change with contracts, privacy notices, consent records and documented processing instructions | Does the existing legal and governance basis cover the new purpose? |
| Assess business risk | Evaluate privacy, security, customer trust, compliance and commercial consequences | What could happen if the business accepts or rejects the change? |
| Select a response | Enable, disable, negotiate, obtain consent, restrict data or consider another provider | Which response preserves necessary capability without surrendering inappropriate data control? |
| Record and revisit | Document the decision, owner, reasoning and follow-up date | Who is accountable for confirming that the chosen controls remain effective? |
What Matters Here: Why Must Customer Data Governance Follow Data Throughout The Vendor Relationship?
Customer trust cannot be delegated to a vendor, so procurement review, contract language, product settings and notice monitoring must stay connected as martech vendors add AI and data products.
Why You Need to Identify Affected Datasets and Customer Groups
The review should determine whether the proposed use involves personal information, confidential business data, inferred attributes or information about people who did not interact directly with the vendor. The company can then compare the new purpose with its privacy notices, consent records and documented processing instructions.
The appropriate response will depend on the findings. A business may disable the feature, update its records, conduct a privacy or security assessment, seek clarification, negotiate additional terms, obtain affirmative consent or prepare to move its data before the change takes effect. The decision, reasoning, responsible owner and follow-up date should be documented.
Ferrer said businesses should first determine whether the disputed capability can be separated from the rest of the platform. "Find what’s actually toggleable, disable the specific behavior if you can, and treat anything material that can’t be turned off as a renegotiation," he said.
Under data protection frameworks such as the GDPR, processors generally must handle personal information according to documented instructions from the controller, while contracts establish the details and responsibilities associated with that processing. Businesses must therefore determine whether a vendor’s proposed activity remains within the original instructions and agreement. Legal review may be necessary when the jurisdiction, data involved or proposed use creates material risk.