Allow attachments received in emails to log to CRM

We’ve been voicing the same concern. This is not just a bad design decision on Hubspot’s part, it is a viloation of several data privacy statues. Please see my direct note to Nicholas Knoop, thier Data Privacy Officer. Given that this has been over 3 months ago, we can only surmise that complying with such rules is not a priority. If you feel the same, please email privacy@hubspot.com.

***

I’m writing this out of last resort, to notify you of a long-standing data privacy concern and GDPR violation. I’ve tried in good faith to work this through your support team over the last 3 months but have been underwhelmed with their handling of this.

Here are the facts (please referenced support ticket xxxxx):

  • Sometime around October of this Hubspot enabled a feature to start logging attachments from emails as part of the CRM record. You did not notify your users, and thus did so without specific opt-in permission, a clear violation of user trust and data privacy laws. You also did not provide the requisite controls to allow us to disable this feature or permanently delete such information.
  • Our business deals in confidential information (CVs, M&A, Data Rooms) and we were put into risk as many of these files were not available to our full team and your support team.
  • I notified your support team on October 20th, 2019 requesting to disable that feature. We were told simply not to BCC such documents, which is near impossible given our team being trained to BCC almost everything.
  • I subsequently notified your support over ten times requesting the status of the ticket. I was asked to speak with your EU legal counsel which I declined as this GDPR violation was clear. I even provided industry examples of how your peer companies have provided such features right from the beginning. Domencia Paccione, our account representative finally sent me a direct message asking me not to post this concern any longer.
  • On or about Jan 1, I noted that your development team added a check box on the attachment file delete screen that allowed for permanent deletion of the file.
  • On Jan 23rd, Hubspot released a privacy policy update that made it my responsibility to not upload Sensitive Information.

We’ve worked in good faith to resolve this issue. At the very least, we would have expected you to roll back this feature until it could be legally and properly rolled-out with notification and opt-in. Unfortunately, such data privacy does not seem to be a concern for Hubspot. I do not want to escalate this to data privacy regulators, but we also can’t be put at continued risk from your lack of response.

Therefore, I request the following:

  1. This collection of attachment data be rolled back until you have legally allowed for opt.in.
  2. You perpetually and permanently delete all our attachments, at least weekly. We expressly forbid you from sharing this information with any third-party or anyone internally at Hubspot without our express permission.

If this is not complete by the end of January, I’ll start a formal complaint with the Swiss authorities and under California law as we are present in both.

Regards,

*****