HubSpot Breeze Compliance Starts With the CRM Fields the Agents Can Read
HubSpot documents Breeze Assistant alongside a set of Breeze agents for customer conversations, record analysis, prospecting research, content generation and project automation, each consuming HubSpot Credits. A compliance assessment has to work out which CRM records those agents can read, which outputs reach customers and what evidence exists per interaction. This article sets out the scoping questions and where the evidence has to come from.

HubSpot's product and services catalog documents Breeze Assistant alongside several Breeze agents. The catalog names a customer agent that holds text conversations, a data agent for record analysis and a prospecting agent that researches leads. It also lists content generation, custom agents in beta and work agents for project automation, all metered through HubSpot Credits. HubSpot Breeze compliance work has to start from that functional list, because the compliance exposure follows what each agent reads and what it emits.
A CRM is where personal data concentrates. Contact records, email threads, call notes, support tickets and deal history sit in one tenant, and an agent with read access to that tenant has read access to all of it unless the configuration says otherwise.
TL;DR
- HubSpot documents Breeze Assistant and several Breeze agents that read CRM records and generate customer-facing output, each metered through HubSpot Credits.
- Scope the assessment by data read and output destination per agent rather than by the product name.
- The catalog page does not name the underlying model providers, so ask for the subprocessor list in writing and file the response.
- Customer-facing generated output needs a human review rule and a record of who approved what.
Scope by agent, not by product
A single compliance statement about "Breeze" is too coarse to act on. The HubSpot product and services catalog describes agents with materially different exposure. An agent that holds text conversations with customers produces outbound communication. A data agent that analyses records reads whatever the record scope allows. A prospecting agent researches leads, which can involve data the contact never knowingly provided to you.
Write one row per agent with four entries: the CRM objects it reads, whether its output reaches a customer, who reviews that output and which retention rule applies to the generated text. The exercise usually surfaces at least one agent nobody had assigned an owner to.
AI governance framework covers the ownership structure these rows attach to.
Record scope is the real access control
Marketing and sales teams configure CRM permissions for human workflows, where practical friction limits how much a person reads. An agent has no such limit. It will read every field it is permitted to read, on every record it touches, at machine speed.
That makes field-level sensitivity worth a second pass before any agent is enabled. Payment details in a custom property, health information pasted into a support note and employment data in a recruiting pipeline are the usual finds. Restricting the agent's record scope is cheaper than redacting after the fact.
My view is that the most useful hour in a Breeze rollout is spent reading the custom property list rather than the model documentation, because a property named "notes" can hold anything a rep typed into it.
Named subprocessors or no file
A compliance file that cannot name the processors handling personal data is incomplete under GDPR Article 28, which requires processors to engage sub-processors only under contract and with authorization. The catalog page describing the Breeze agents does not name the underlying model providers.
Ask HubSpot in writing for the current subprocessor list covering the Breeze features you have enabled, the processing locations and the retention applied to prompts and generated output. File the dated response with the vendor assessment. If a data protection impact assessment is required, that response is an input to it rather than an optional attachment.
Vendor attestations cover vendor behavior. Which of your records were sent, by which user and under which rule, remains yours to evidence.
Customer-facing output needs a review rule
An agent that drafts an email for a human to send and an agent that sends it are different risk categories. Decide which mode each agent runs in, write it down and make the setting auditable.
For autonomous customer-facing output, three records matter: the input the agent read, the text it produced and the decision that released it. Without the third, a complaint about an inaccurate statement has no accountable approver, and the organization is left arguing about what the system probably did.
The NIST AI Risk Management Framework places this under MANAGE, which asks for documented response to identified risk, and under MEASURE, which asks for dated evidence that the control operated.
The shadow path around the CRM
Sales and marketing teams that find a managed agent restrictive will paste the same records into a consumer chat tool. That traffic leaves no trace in the CRM, so a Breeze compliance file can look complete while the actual exposure sits elsewhere.
Covering it means seeing AI-bound HTTP traffic from managed devices and applying policy to the content, not only configuring the sanctioned product. AI policy enforcement at the HTTP layer describes that control surface, and HubSpot Breeze security covers the platform-side settings.
What to retain and for how long
Generated content counts as a record in its own right. A drafted email that was never sent, an agent's summary of a support thread and a prospecting note about an individual all sit inside the personal data the tenant holds.
Set a retention rule for each category and confirm that a data subject access request can return generated content as well as source records. HubSpot Breeze audit logs covers what the platform records, and AI audit trail requirements by regulation covers the fields regulators name.
DeepInspect
DeepInspect is a stateless proxy for authenticated HTTP traffic between enterprise users or agents and LLM endpoints. It evaluates application-supplied identity, request classification, approved destination and policy before forwarding, and writes a signed per-decision record outside the calling application's write path.
For a HubSpot estate, that covers the traffic your own applications and users generate toward model endpoints, including the shadow path around the sanctioned product. Inference that runs inside HubSpot's own platform is vendor-native and stays outside the proxy's boundary, so it needs HubSpot's attestations, the subprocessor list and contractual terms as its evidence. Book a demo today.
Frequently asked questions
- Which HubSpot Breeze features need a data protection impact assessment?
Any agent whose processing is likely to result in high risk to individuals, which in practice means agents that read special category data, make or materially support decisions about people, or communicate with customers without human review. Document the assessment per agent rather than once for the product, because the agents differ in what they read and what they emit.
- Does HubSpot name the model providers behind Breeze?
The product and services catalog describes the Breeze agents and their credit consumption without naming the underlying model providers. Request the current subprocessor list for your enabled features in writing, together with processing locations and retention for prompts and generated output, and keep the dated response in the vendor file.
- How do we evidence that an agent only read permitted records?
Export the agent's configured record scope and property-level permissions with an export date, then test it. Create a record containing a marker value outside the intended scope and confirm the agent cannot retrieve it. A tested negative result is stronger evidence than a permissions screenshot.
- What stops a sales rep pasting CRM data into a consumer chat tool?
A control that sees AI-bound traffic from the managed device and applies policy to the content, combined with a published rule the team has been trained on. Platform configuration inside HubSpot has no visibility into a browser session with an unrelated provider, so that path needs its own enforcement point and its own evidence.