A detailed breakdown of which HubSpot objects, properties, and API scopes Cotonity requests and why each permission is necessary.
What scopes does Cotonity request?
When you connect Cotonity to HubSpot, the OAuth flow requests a carefully scoped set of permissions. Core read scopes include crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read, and crm.objects.lists.read. Write scopes include crm.objects.contacts.write, crm.objects.notes.write, and crm.objects.tasks.write. Additional scopes such as forms, marketing-email, and timeline are only requested when you enable the corresponding Cotonity features. You can review the exact scopes granted at any time from HubSpot Settings → Connected Apps.
Read vs. write permissions
Cotonity distinguishes clearly between read and write operations. Read permissions allow the platform to retrieve contact, company, and deal records to inform agent decisions — for example, enriching an inbound chat message with CRM context. Write permissions enable agents to create or update records as a result of automation rules. If you want a read-only integration for analytics or context enrichment only, you can restrict write scopes during the OAuth flow; Cotonity will automatically disable the write-dependent features and notify you which workflows are affected.
Data retention and privacy
Cotonity does not store a persistent copy of your HubSpot data. Records fetched during agent execution are held in memory for the duration of the workflow run and then discarded. The only data persisted are identifiers (contact IDs, deal IDs) stored in Cotonity's event log for audit purposes. This design minimizes data duplication and simplifies GDPR compliance. If your organization requires a Data Processing Agreement (DPA) for the HubSpot integration, contact the Cotonity legal team via the billing portal.
Scope changes and re-authorization
When Cotonity releases new features that require additional HubSpot scopes, you will see an Update Permissions banner in the integration settings. Clicking it initiates a new OAuth flow that requests only the incremental scopes. You are never required to revoke the existing connection; the new scopes are added on top of the existing grant. If you remove a feature from your Cotonity plan, the associated scopes remain granted in HubSpot but Cotonity stops exercising them. You can manually revoke individual scopes from HubSpot's Connected Apps page if desired.