Effective date: 24 July 2026
This Data Security and Privacy Statement describes how Power BI Connector for HubSpot (the “Connector”) handles personal data. It applies to Metrica Software Inc.’s (“Metrica”) processing of data on behalf of customers who install the Connector into their HubSpot account. For the legal contract governing personal-data processing, see the Data Processing Agreement.
The Connector at a glance #
Power BI Connector for HubSpot is a live-passthrough connector. It exposes an OData endpoint that Power BI queries. When Power BI refreshes, the Connector calls the HubSpot CRM API on the user’s behalf and streams the result to Power BI without persisting the rows.
Metrica does not use HubSpot business data, or any customer personal data, to train, fine-tune, or improve any artificial-intelligence or machine-learning model.
What we collect and store #
The Connector persists a small amount of configuration and identity data — not the HubSpot business data itself.
- Configuration data — data source names and descriptions, selected HubSpot objects and fields, filter expressions, sharing-list entries (HubSpot user and team identifiers).
- Identity and account data — HubSpot user identifiers for the owner, creator, and editor of each data source; per-user role assignments in the Connector; and a one-row install record containing the HubSpot portal id (
hub_id), HubSpot domain, installing user’s email, installing user id, and install date. - Access token records — the SHA-256 hash of each Power BI access token, plus token name, status, expiry, and owner user id. The plaintext token is generated in the user’s browser, hashed there, and only the hash is sent to the backend. The plaintext is shown once at creation and cannot be retrieved afterward — not by users, not by Metrica staff, not from any backup.
- HubSpot OAuth tokens — per-user HubSpot access and refresh tokens, stored encrypted at rest, used only to query HubSpot live on that user’s behalf.
- History and audit records — data-source activity, token activity, and export events. Export events capture the actor, user email, data-source label, object name, status, row count, and duration — never the exported records themselves.
HubSpot business data is not stored. Every Power BI refresh re-queries HubSpot live and streams the result to Power BI. Object rows, field values, and associations are never copied, cached, or persisted by the Connector.
Where data is hosted #
The Connector runs in Metrica’s own Amazon Web Services (AWS) account, region us-east-1 (United States):
- Application logic runs on AWS Lambda behind Amazon API Gateway.
- The user interface runs inside HubSpot as a HubSpot UI Extension.
- Persistent storage is Amazon DynamoDB in
us-east-1, partitioned per HubSpot account byhub_id.
Non-production data is held in separate DynamoDB tables from production.
Encryption #
In transit. All traffic between the HubSpot UI, Power BI, and the Connector backend uses HTTPS/TLS, terminated at Amazon API Gateway. Calls from the backend to HubSpot (api.hubapi.com) use HTTPS. Traffic between AWS Lambda and DynamoDB uses AWS’s TLS-encrypted service endpoints.
At rest. DynamoDB encryption at rest is enabled on every table. The access-token table is additionally protected with a customer-managed AWS KMS key with annual key rotation.
HubSpot scopes we request #
At install, the Connector requests OAuth scopes for read-only access to the HubSpot objects you choose to expose. The Connector does not have write access to HubSpot data. A subset of scopes is optional at authorization time, so the default permission footprint stays as narrow as possible — you only grant what you need.
Isolation between accounts #
Every backend query is scoped by HubSpot portal identifier (hub_id) at the data layer. The Power BI authentication path rejects a token presented against a portal it does not belong to, so one HubSpot account’s data cannot be read using another account’s token.
Exports run under the token owner’s own HubSpot OAuth grants, so the Connector cannot return data the user could not read directly in HubSpot.
Who can see what #
- You — see every data source you own and every data source someone has shared with you in your HubSpot account.
- Other users in your HubSpot account — see only what you explicitly share with them (individual users or HubSpot teams). Sharing is read-only.
- Metrica staff — can access audit and diagnostic records for support purposes. Cannot view HubSpot business data (never stored). Cannot recover plaintext access tokens (only hashes are stored, and the hash cannot be reversed).
Retention #
- Configuration, install, token, and OAuth records — retained for the term of the subscription. On termination, deleted within 60 days.
- Export-session data — automatically deleted on completion, or within 24 hours by a DynamoDB time-to-live.
- History and audit records — retained indefinitely for compliance and security-review purposes.
If your account is removed and you exercise your right to erasure, we anonymise the actor identifiers in history records rather than deleting the history rows themselves — the audit trail must remain intact for compliance, but your personal identifiers are removed from it.
Sub-processors #
The Connector uses one sub-processor: Amazon Web Services, Inc. — hosting and storage in AWS us-east-1.
Your HubSpot Subscription Service and Microsoft Power BI are your own environments and are not sub-processors of Metrica.
We will notify you of any addition or replacement of a sub-processor with reasonable advance notice.
International data transfers #
Persistent data is hosted in the United States (AWS us-east-1). Where our processing involves a transfer of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the EU Standard Contractual Clauses (Module Two, Controller-to-Processor), as incorporated into our Data Processing Agreement. For UK transfers, the UK International Data Transfer Addendum applies; for Swiss transfers, the SCCs apply with the adaptations required by Swiss law.
Personal data breach notification #
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 72 hours. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
To report a suspected security issue, contact security@metricasoftware.com.
Your rights #
Individuals whose personal data is processed through the Connector have rights under applicable data-protection laws — access, correction, deletion, portability, and objection. Because Metrica processes personal data on behalf of the customer (as a processor), most of these rights are exercised through the customer’s own privacy contact. Where a request comes directly to Metrica, we route it to the customer or handle it under the Data Processing Agreement.
Compliance #
The Connector’s underlying infrastructure (AWS) holds third-party certifications including SOC 2 and ISO 27001. Metrica reviews each release against its internal security policy prior to publication. For audit reports, control mappings, and compliance documentation, see the Metrica Trust Center.
Contact #
- Privacy questions and data subject requests: legal@metricasoftware.com
- Security incidents: security@metricasoftware.com
- Product support: Contact Support
Metrica Software Inc., 9353 Tangerine Coast Dr, Boca Raton, FL 33434-5919, USA.
Updates to this statement #
We may update this Data Security and Privacy Statement from time to time. Material changes are called out in the Release Notes. The “Effective date” at the top of this page reflects the most recent update.