View Categories

Data Processing Agreement

14 min read

Metrica Power BI Connector for HubSpot

Metrica Software Inc.

Last Updated: 10th June, 2026

This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the End User License Agreement between Metrica Software Inc. (“Metrica”, “we”, or “us”) and the customer (“Customer”, “you”) governing the Power BI Connector for HubSpot (the “App” or “Connector”). This DPA applies to the extent Metrica processes Customer Personal Data on Customer’s behalf in connection with the Connector. Capitalized terms not defined here have the meanings given in the EULA.

In the event of a conflict between this DPA and the EULA regarding the processing of Customer Personal Data, this DPA controls.

1. DEFINITIONS #

“Customer Personal Data” means Personal Data that Metrica processes on Customer’s behalf in connection with the Connector, as described in Annex I.

“Data Protection Laws” means all laws and regulations applicable to the processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws.

“Personal Data”, “Controller”, “Processor”, “Data Subject”, “process/processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in the GDPR (or the equivalent terms under other applicable Data Protection Laws).

“HubSpot Business Data” means the Customer’s CRM records, business data, and other content residing in the Customer’s HubSpot Subscription Service.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries approved by the European Commission (Decision 2021/914), Module Two (Controller to Processor).

“Sub-processor” means any third party engaged by Metrica to process Customer Personal Data.

“License Data” has the meaning given in the EULA (name and email of the license holder and associated license metadata).

2. ROLES AND SCOPE #

2.1 Roles. For Customer Personal Data processed in connection with the Connector, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Metrica is the Processor. Where Customer is itself a Processor, Metrica is a sub-processor and the instructions referenced in this DPA are those of Customer’s own controller.

2.2 License Data. Metrica processes License Data as an independent Controller for licensing, billing, and support purposes, as described in Metrica’s Privacy Policy. License Data is outside the scope of Metrica’s Processor obligations under this DPA, except that Metrica will process it in accordance with applicable Data Protection Laws.

2.3 Scope of Processing. The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects are described in Annex I.

3. PROCESSING OF CUSTOMER PERSONAL DATA #

3.1 Documented Instructions. Metrica will process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Metrica will, where legally permitted, inform Customer of that requirement before processing). Customer’s instructions are set out in this DPA, the EULA, and Customer’s configuration and use of the Connector. Customer’s instructions will comply with Data Protection Laws.

3.2 HubSpot Business Data Is Not Stored. Metrica does not copy, cache, or persist HubSpot Business Data. The OData feed exposed to Power BI is a live passthrough: every Power BI refresh re-queries HubSpot through the HubSpot CRM API under the individual user’s own OAuth grants and streams the result back without storing the rows. Object and association relationships are read live on each request and are not cached. The only by-product recorded from an export is aggregate metadata (for example, row counts per object and duration) for the export-history view, not the exported records themselves. Metrica does not use HubSpot Business Data, or any Customer Personal Data, to train, fine-tune, or improve any artificial intelligence or machine-learning model, or for any purpose other than providing and supporting the Connector and as instructed by Customer.

3.3 Confidentiality. Metrica will ensure that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.

3.4 Customer Responsibilities. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data, for establishing a lawful basis for the processing, and for its configuration choices (including which HubSpot objects, fields, and recipients it exposes through the Connector, and which users it authorizes).

4. SECURITY #

4.1 Security Measures. Metrica will implement and maintain the technical and organizational measures set out in Annex II, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.

4.2 Hosting and Data Residency. The Connector’s backend runs in Metrica’s own Amazon Web Services (“AWS”) account in the United States (region `us-east-1`), using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB; the Connector’s user interface runs inside HubSpot as a HubSpot UI-Extension. All persistent Customer Personal Data is stored in Amazon DynamoDB in `us-east-1`, partitioned per HubSpot portal by portal identifier (`hub_id`) and separated from non-production data by table. Customer acknowledges that persistent data is hosted in the United States.

5. SUB-PROCESSING #

5.1 Authorized Sub-processors. Customer provides general authorization for Metrica to engage the Sub-processors listed in Annex III. Metrica’s Sub-processor for hosting and storage is Amazon Web Services, Inc.

5.2 Sub-processor Obligations. Metrica will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains responsible for each Sub-processor’s performance of its obligations.

5.3 Changes. Metrica will inform Customer of any intended addition or replacement of a Sub-processor with reasonable advance notice, giving Customer the opportunity to object on reasonable data-protection grounds. If Customer reasonably objects and the parties cannot agree on a resolution, Customer may terminate the Connector subscription as its exclusive remedy.

6. ASSISTANCE TO CUSTOMER #

6.1 Data Subject Requests. Taking into account the nature of the processing, Metrica will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Laws. If Metrica receives such a request directly, it will, unless legally prohibited, promptly inform the Data Subject to direct the request to Customer and notify Customer.

6.2 DPIAs and Consultation. Metrica will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the processing and the information available to Metrica.

7. PERSONAL DATA BREACH #

Metrica will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it. Metrica will provide reasonable cooperation and information to assist Customer in meeting its breach-notification obligations.

8. INTERNATIONAL TRANSFERS #

8.1 Transfer Mechanism. Persistent Customer Personal Data is hosted in the United States (Section 4.2). To the extent Metrica’s processing involves a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, the SCCs are incorporated into this DPA by reference, with Metrica as data importer and Customer as data exporter, completed as follows:

– Module Two (Controller to Processor) applies (or Module Three, Processor to Processor, where Customer acts as a Processor);

– the optional docking clause applies;

– for Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.3;

– for Clause 17, the governing law is the law of Ireland;

– for Clause 18, the courts of Ireland have jurisdiction;

– Annexes I, II, and III to this DPA populate the corresponding Annexes of the SCCs.

8.2 UK and Swiss Transfers. For UK transfers, the UK International Data Transfer Addendum to the SCCs applies; for Swiss transfers, the SCCs apply with the adaptations required by Swiss law.

9. AUDITS #

Metrica will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, primarily through current third-party certifications or audit reports for the underlying AWS infrastructure (such as SOC 2 or ISO 27001) and Metrica’s responses to a reasonable written data-protection questionnaire no more than once per twelve (12) months. The parties agree that provision of this documentation will ordinarily satisfy Customer’s audit rights. An on-site inspection may be conducted only (a) where required by a Supervisory Authority, (b) following a confirmed Personal Data Breach affecting Customer Personal Data, or (c) where Metrica fails to provide the documentation described above; and then only by an independent third-party auditor mandated by Customer and bound by confidentiality, on at least thirty (30) days’ prior written notice, during business hours, at Customer’s expense, subject to Metrica’s security and confidentiality requirements, limited to information relevant to Customer, and without access to other customers’ data or to any data center operated by a Sub-processor.

10. DELETION AND RETURN #

10.1 On Termination. Upon termination or expiration of the Connector subscription, and at Customer’s choice, Metrica will delete or return Customer Personal Data within sixty (60) days, and delete existing copies, unless applicable law requires continued storage. Deletion covers the persisted categories described in Annex I, including configuration data, the install record, Power BI access-token records, and HubSpot OAuth tokens. Because HubSpot Business Data is never stored (Section 3.2), no business records require deletion.

10.2 Credentials. On deletion, stored HubSpot OAuth tokens are revoked and removed, and Power BI access-token records (hash only) are deleted. The plaintext Power BI access token is never stored by Metrica (Annex II), and the HubSpot app’s own OAuth client credentials are held only in environment configuration, not in any data table.

11. LIABILITY #

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the EULA, and any reference to a party’s aggregate liability includes liability under this DPA and the EULA combined. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws.

12. GENERAL #

12.1 Term. This DPA takes effect when the EULA takes effect and continues for as long as Metrica processes Customer Personal Data, after which the deletion and return obligations apply.

12.2 Precedence. This DPA supplements the EULA. In case of conflict regarding Customer Personal Data, this DPA controls; where the SCCs apply, the SCCs control over this DPA to the extent of any conflict.

12.3 Governing Law. Except where the SCCs or Data Protection Laws require otherwise, this DPA is governed by the governing law of the EULA.

ANNEX I — DESCRIPTION OF PROCESSING

A. List of Parties

Data Exporter (Controller): Customer, as identified in the EULA / order.

Data Importer (Processor): Metrica Software Inc., 9353 Tangerine Coast Dr, Boca Raton, FL 33434-5919, USA. Contact: legal@metricasoftware.com

B. Description of Processing

*Categories of Data Subjects:* Customer’s authorized users of the Connector and of Power BI (including HubSpot users and the installing user); individuals identified in the HubSpot records the Customer elects to expose through the Connector; and individuals named in Customer’s sharing/recipient lists.

Categories of Personal Data — persisted by Metrica (in Amazon DynamoDB, `us-east-1`, keyed by `hub_id`):

1. Configuration data — data-source name and description, selected HubSpot objects and fields, and filter expressions (the Customer’s choices about what to expose to Power BI).

2. Identity and sharing data — HubSpot user identifiers for the owner/creator/editor of a data source; sharing-list entries (HubSpot user and team identifiers); per-user role assignments in app settings; and a one-row install record containing `hub_id`, HubSpot domain, installing user’s email, installing user id, and install date.

3. Power BI access-token records — the SHA-256 hash of each Power BI access token together with token name, status, expiry, owner user id, and timestamps. The plaintext token is generated and hashed in the browser, shown to the user once at creation, and is never transmitted to or stored by the backend.

4. HubSpot OAuth tokens — per-user HubSpot access and refresh tokens and expiry, stored encrypted at rest and used solely to query HubSpot live on that user’s behalf.

5. History / audit records — data-source activity events, access-token activity events, and export events. Export events include the actor, user email, data-source label, object name, status, row count, and duration. These records capture how much was exported, never the exported records themselves.

6. Transient export-session data — per-refresh counters, automatically deleted on completion or otherwise expired by a 24-hour DynamoDB time-to-live.

*Categories of Personal Data — processed transiently only (not stored):* Personal Data contained in HubSpot Business Data returned in response to a Power BI refresh. This data is streamed live from HubSpot to Power BI under the user’s own OAuth grants and is never copied, cached, or persisted by Metrica.

*HubSpot authentication credentials:* The HubSpot app’s own OAuth `client_id` and `client_secret` are held only in backend environment configuration (per deployment stage), never in a data table.

*Special categories of data:* None intended. Customer is responsible for not exposing special-category data through the Connector except as permitted by the HubSpot Terms and Data Protection Laws.

*Nature and purpose of processing:* Provision of the Connector — enabling the Customer to query its HubSpot Subscription Service live and load the resulting data into Microsoft Power BI for analytics and reporting, and to manage configuration, authentication, sharing, and audit.

Duration / Retention:* Configuration, install, token, and OAuth records are retained for the term of the subscription and deleted under Section 10. Export-session data auto-expires within 24 hours. **History/audit records are currently retained indefinitely.**

C. Competent Supervisory Authority

The Supervisory Authority of the EEA member state of the Customer’s establishment, or the lead Supervisory Authority where applicable; for SCC purposes, the Irish Data Protection Commission where the data exporter is not established in the EEA.

ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES

Hosting and infrastructure. The Connector backend runs in Metrica’s own AWS account in region `us-east-1` (AWS Lambda, Amazon API Gateway, Amazon DynamoDB); the user interface runs inside HubSpot as a HubSpot UI-Extension. All persistent Customer Personal Data is stored in Amazon DynamoDB in `us-east-1`.

Encryption in transit. All traffic from the HubSpot UI and from Power BI to the backend is HTTPS/TLS, terminated at Amazon API Gateway. Calls from the backend to HubSpot (`api.hubapi.com`) use HTTPS. Traffic between AWS Lambda and DynamoDB uses AWS’s TLS-encrypted service endpoints.

Encryption at rest. DynamoDB encryption at rest is enabled on every table. The access-token table is additionally configured with a customer-managed AWS KMS key (CMK) with annual key rotation, protecting backups and snapshots even though the stored token value is only a non-reversible hash.

Per-portal (tenant) isolation. Every query is scoped by HubSpot portal identifier (`hub_id`) at the data layer, and the Power BI authentication path rejects a token presented against a portal it does not belong to, so one portal’s data cannot be read using another portal’s token. Non-production data is held in separate tables.

Authentication and authorization. Power BI authenticates with a per-user access token, validated by SHA-256 hash lookup. Exports run under the token owner’s own HubSpot OAuth grants, so the Connector can never read data the user could not read directly in HubSpot. Within the management UI, role checks (app user, app admin, HubSpot Super Admin) gate who may create, edit, share, or administer data sources and tokens.

Token handling. Power BI access tokens are generated client-side (256-bit random value) and hashed in the browser with SHA-256; only the hash is sent to and stored by the backend, and the plaintext is shown once and never retrievable thereafter. A SHA-256 hash of a 256-bit random value is non-reversible. HubSpot OAuth tokens are stored encrypted at rest and refreshed automatically shortly before expiry. The HubSpot app’s OAuth client credentials are held only in environment configuration, never in a data table.

Inbound request-signature verification. Requests reaching the backend from HubSpot are verified using HubSpot’s request signature (`x-hubspot-signature-v3`, an HMAC-SHA256 over the request method, URL, body, and timestamp) before any action is taken.

Data minimization by design. HubSpot Business Data is never copied, cached, or persisted; each Power BI refresh re-queries HubSpot live and streams the result without storing the rows.

Logging and auditability. Data-source, token, and export events are recorded in dedicated DynamoDB tables for security and usage auditing.

ANNEX III — SUB-PROCESSORS

HubSpot (the Customer’s HubSpot Subscription Service) and Microsoft Power BI are the Customer’s own environments and are not Sub-processors of Metrica.