Montro

HubSpot CRM Access & GDPR Governance

HubSpot holds your customers' contact records, email history, and deal data - and not everyone with access to it should still have it. Connect HubSpot to Montro to see exactly who can reach your CRM and govern that access against your GDPR and compliance obligations.

01GDPR

GDPR

HubSpot and GDPR - your CRM is a repository of customer personal data

HubSpot processes personal data belonging to your customers, prospects, and contacts - not just your employees. Every contact record, email interaction, and deal note is personal data under GDPR. Your organisation is the controller; HubSpot is the processor. A Data Processing Agreement must be in place, and HubSpot must appear in your Article 30 record of processing activities. Montro surfaces who holds CRM access so your data inventory reflects reality.

Learn more →
02EU AI Act

EU AI Act

HubSpot AI features and the EU AI Act - lead scoring and content AI in scope

HubSpot's AI features include predictive lead scoring, content generation, and conversation intelligence. Predictive scoring used in financial services contexts - prioritising which customers to contact for products or services - may attract a high-risk classification under EU AI Act Annex III. If your organisation has HubSpot AI features enabled, deployer obligations apply. Montro surfaces HubSpot in your governed inventory so AI feature usage does not go undocumented.

Learn more →
03DORA

DORA

HubSpot and DORA - CRM tools supporting financial services operations belong in your ICT register

Financial entities using HubSpot for customer acquisition, relationship management, or sales operations are using it as an ICT service that supports their business. Under DORA Article 28.3, it belongs in the ICT Third-Party Register alongside other operational tools. Montro surfaces HubSpot in your ICT inventory, supporting register completeness and the third-party risk visibility DORA demands.

Learn more →
04NIS2

NIS2

HubSpot and NIS2 - CRM platforms are business-critical ICT supply chain

A CRM holding customer data and supporting commercial operations qualifies as a business-critical ICT service under NIS2 Article 21(3)(d). Organisations must document and assess the cybersecurity of suppliers in this position. Connecting HubSpot to Montro brings it into your governed application inventory, supporting supply chain security obligations and ensuring CRM access is visible in any NIS2 compliance review.

Learn more →
05ISO 27001

ISO 27001

HubSpot and ISO 27001 - access to customer data systems requires documented controls

ISO 27001 requires documented access control policies (A.5.15, A.5.16) and a complete asset inventory (A.5.9). HubSpot, as a system holding customer personal data, warrants particular attention in access control evidence. Montro imports HubSpot user data into your governed inventory, giving auditors a consolidated record of who holds CRM access and supporting the evidence requirements ISO 27001 demands for customer data systems.

Learn more →

Discovery

What Montro discovers from HubSpot

HubSpot user access is a GDPR exposure in waiting. Sales reps leave, agencies rotate, contractors move on - and their CRM access often stays. Montro imports HubSpot user records into your governed inventory so you know who can reach your customer data, and when that list last changed.

CRM user access visibility

Montro imports every HubSpot user account in your organisation - including sales contractors, marketing agency staff, and customer success team members whose access may pre-date your current governance processes. CRM access is often the last thing reviewed in an offboarding checklist and the most consequential when it is missed.

Customer data access governance

HubSpot contains personal data belonging to your customers - contact records, communication history, deal information. Montro surfaces who holds access to that data, supporting your GDPR Article 30 record of processing activities and giving your DPO a current view of who processes customer data on the organisation's behalf.

Offboarding and access lifecycle

When a sales rep leaves or an agency engagement ends, HubSpot access rarely gets revoked at the same time. Montro keeps HubSpot user records current in your governed inventory, making it straightforward to identify stale accounts and act on them before they become a GDPR enforcement question or a data breach notification scenario.

Subscription and licence tracking

HubSpot subscription and seat records are imported into Montro's Subscriptions module alongside every other application in your estate. Understand how CRM licences are allocated across sales, marketing, and customer success functions - and whether your seat count reflects your actual active user base rather than accumulated historical growth.

Technical details

Authentication Method


HubSpot authenticates using a Private App Access Token. Administrators create a Private App in their HubSpot account, generate an access token, and provide it to Montro to authorise read-only access to user and account data. 


How to Connect:


  1. Open the Integrations page in Montro.
  2. Select HubSpot from the available integrations.
  3. Enter your HubSpot Private App Access Token in the field provided.
  4. Click Connect to authorise the integration.
  5. Montro validates the token and begins synchronisation.
  6. HubSpot user records are imported automatically.
  7. Review synchronised HubSpot users within the Users module in Montro.


Data Synced

Users Module

HubSpot user identities, including email addresses, account status, and role information.


Data Residency


HubSpot data imported into Montro is stored on AWS Frankfurt (eu-central-1), within the European Union. No customer data is transferred outside the EU. Data residency terms are specified in Montro's Data Processing Agreement.


Sync Frequency


Data can be synchronised manually at any time after the initial connection, with no limit on the number of manual syncs. Montro also provides an automatic sync option - when enabled, the platform synchronises data once every night to keep information current.


Permission Scope


Montro requests read-only access to HubSpot using a Private App Access Token scoped to user and account information. The integration does not access HubSpot contact records, deal data, email content, marketing lists, or CRM pipeline data. No changes are made to your HubSpot environment. Access is limited to the minimum required for user and account governance visibility.


EU Data Storage


Montro's infrastructure runs exclusively on AWS eu-central-1 (Frankfurt), governed by Irish and EU law. There is no FISA 702 exposure and no Schrems II ambiguity. Your data is never replicated outside the EU without your explicit, documented consent. EU data residency is not a configuration option - it is the architecture.

Related

Apps commonly used with HubSpot

Discover compliance profiles for tools in your stack.

Identity & Access Management

Identity & Access Governance for Microsoft Entra ID

Microsoft Entra ID is the identity backbone of your Microsoft environment. Connect it to Montro and bring your entire directory - users, roles, licences, MFA status, and application access - into a single governed view alongside your wider SaaS and AI estate.

Learn more →

AI Platforms

OpenAI Governance & Compliance Discovery

Most organisations using OpenAI have no visibility into who holds access, how many seats are active, or whether usage is documented against EU AI Act obligations. Montro surfaces all of it.

Learn more →

Microsoft Teams Collaboration Governance

Microsoft Teams is central to how your organisation communicates - and often overlooked in access reviews. Montro imports Teams users and licences so your collaboration platform is as governed as everything else in your estate.

Learn more →

Okta Identity Governance & Compliance

Okta controls who gets into everything else. Without it in your governed inventory, your compliance picture has a gap at the foundation. Montro connects Okta identity data to your full application estate.

Learn more →

Collaboration & Messaging

Zoom Governance & Compliance Discovery

Zoom accounts grow quietly - provisioned outside your identity provider, renewed without IT review, and rarely audited. Montro discovers every user and licence in your Zoom environment and maps it against your EU compliance obligations.

Learn more →
Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.