Third Party Index

Snapshot 48650

Document
Security page
URL
https://impulsecreative.com/company/legal/security
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
100601 bytes
SHA-256 (raw)
67adc486212dff44ebd2796d558c8674fb33027b1dfc03c432dd75fa7bfe2528
SHA-256 (normalized text)
f0f195b559448e2c847f38b4d52004aa55df4d6e1376a3b9fe331b29e1f47bd0

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security posture.
Written for the security reviewer. Where client data lives, how sub-processors are handled, and how we complete your questionnaire.
Key takeaways
Client CRM data stays in the client's HubSpot portal under the client's auth.
Our products are portal-installed; there is no vendor-side copy of your CRM.
Sub-processor changes carry 14-day advance notice.
We complete security questionnaires directly on request.
Where does client data live?
Client CRM data lives in the client's own HubSpot portal. Our products install into that portal and operate under its authentication and permission model. We do not maintain a separate database of client CRM records.
Access during service engagements runs through named user accounts in the client's portal, granted and revocable by the client. When an engagement ends, the client removes the access. There is no residual copy to request deletion of, because the architecture never created one.
How are sub-processors handled?
Sub-processor additions and changes are announced 14 days in advance to DPA holders.
Statements on this page are updated when the underlying facts change, with the reviewed date below as the record.
How do we complete your security questionnaire?
We complete questionnaires directly rather than pointing reviewers at a portal. Standing answers for common frameworks exist and shorten the turnaround.
For questions this page and the standing documents don't cover, the contact page reaches the people who can answer in writing.
REVIEWED · AUG 2026CITE · impulsecreative.com/company/legal/security
Privacy & DPAThe policy and the data processing agreement.→AI PolicyWhat never goes into a model, in writing.→ExtendStackThe architecture behind the portal-native claims above.→