Is it safe to connect Claude to Xero and HubSpot? A UK GDPR view

Yes, with conditions, and the conditions are ordinary ones. Xero's connector for Claude is read-only, so Claude can answer questions about profit, cash, receivables and invoices but cannot change a figure in your books. HubSpot's connector can read, create and update CRM records but cannot delete them, has to be approved by a HubSpot Super Admin who chooses what it may see, and works inside each user's existing HubSpot permissions. On the Claude side, on a Team or Enterprise plan, an Owner enables each connector for the organisation, every person authenticates individually, and write actions can be set to need approval or be blocked. Neither business plan trains on your content by default. What remains is your own work as a UK data controller: a lawful basis, a data protection screen, a record of what is connected and at what scope, and a rule that a person approves anything that changes a record.
This article sets out what each connector can and cannot do as of 15 September 2026, read from Xero's and HubSpot's own documentation rather than from forum threads; how the permission model works on the Claude side; what happens to the data on Team and Enterprise; the concerns people raise; and a checklist for the person who has to sign it off. It is a companion to our longer guide to Claude Code and Cowork for non-technical UK teams, which covers plan choice, seat costs and governance in the round.
What the Xero connector for Claude can and cannot do
Xero's connector for Claude is a read-only connection between one Xero organisation and one Claude account. Xero's UK product page and its Xero Central setup article both describe it the same way: Claude can view and retrieve data from Xero, answer in plain English with visual summaries, and link back to the report, invoice or contact it drew on, but it cannot make changes to the Xero organisation. Xero's own words are that the connector is read-only at launch, that Claude has no write actions, and that the books stay exactly as they are.
The questions it is built to answer fall into four areas. Revenue and profit: whether the business is making money, how much, and whether performance is improving. Receivables and payables: who owes you, who you owe, how much and how old. Financial and cash position: assets, liabilities and cash balance, with prior-year comparisons. Invoices: what is invoiced, outstanding and paid, top customers, and the detail of individual invoices. Xero Central gives worked example prompts for each and notes that Claude defaults to the current month for profit questions and the last twelve months for contact and receivables questions unless the prompt names a period.
Four practical limits matter for a UK firm. The connector links one Xero organisation at a time, so a group with several entities disconnects and reconnects to switch. It is available on any Xero business plan and needs a Claude account on a free or paid plan; Xero does not charge for it. The data comes through Xero Analytics, so a figure can lag until Analytics refreshes, and Xero's article tells you how to refresh and re-ask. And it is not the Xero MCP server. Xero also publishes an open-source Model Context Protocol server for developers building custom workflows and automations, tested by Xero with Claude Desktop and Cursor; that is a developer tool with a broader API surface and a different risk profile, and it is not what a finance manager should be handed. Most of the disappointment that circulates online about "Xero plus Claude" attaches to the developer route or to questions the read-only connector was never built to answer.
On data, Xero states that Xero data is never used to train AI models, that the connection is read-only and session-only, and that Xero remains the source of truth. Anthropic's side of that position is covered below.
What the HubSpot connector for Claude can and cannot do
HubSpot's connector is more capable, which is why it has more controls. HubSpot's Knowledge Base article, last updated on 11 September 2026, says the connector can read, create and update CRM records, log activities, and analyse engagement history, and it publishes the permission matrix object by object. Read, create and update: contacts, leads, companies, deals, tickets, custom objects, line items, products, landing pages, website pages, blog posts, marketing emails, and the engagement types calls, meetings, notes, tasks and emails. Read and create only: campaigns and marketing events. Read only: invoices, orders, carts, payments, payment links, subscriptions, lists, campaign attribution, users, teams, the partner client object and inbox conversations. Delete: nothing. HubSpot's own summary is that the connector supports view, create and update but not delete, and that you keep full control to delete anything, including data added through the connector, inside HubSpot.
The approval chain is the part IT will want to hear. A HubSpot Super Admin must approve the HubSpot connector for Claude before anyone in the account can connect it, and at approval chooses which optional data permissions the connector may have and who in the account may install it. When a Super Admin later widens those permissions, each user has to reconnect to gain the new access. Every user then sees only what their own HubSpot permissions allow: a sales rep who can only view their own deals sees only those deals through Claude. Bulk operations are capped at ten records per create or update. Conditional property rules and pipeline stage validations configured in HubSpot are applied to writes made through Claude.
Three protections are specific and worth quoting in a policy. The connector cannot access custom Sensitive Data properties, including personal health information, and if a HubSpot account has Sensitive Data turned on the connector gets no engagement data at all. Every create and update made through the connector is written to HubSpot's audit log against both the user and the Claude connector, so a Super Admin can see who connected, when, and what changed. And HubSpot recommends, twice in the same article, that the connector's write tools be set to Needs approval in Claude so that edits do not occur without a person confirming them; on the default setting Claude may show the proposed change and ask before acting, and on Always allow it may not.
Two more facts for the record. A paid Claude plan (Pro, Max, Team or Enterprise) is required. And on data location, HubSpot says requests are routed through the data centre your HubSpot account lives in, so an EU-hosted account is served from HubSpot's EU data centre, and that once the data reaches Anthropic your Anthropic terms govern where and how it is processed. HubSpot also publishes a separate remote MCP server for developers building their own agents against a HubSpot account; like Xero's, that is a builder's tool rather than the connector a non-technical team uses.
How the permission model works on the Claude side
Anthropic's Help Center describes one model for every connector, and it is the same whether the other end is Xero, HubSpot, Google Drive or Microsoft 365. Connectors inherit each person's permissions from the connected service: if someone cannot access a file, channel or record in the source system, the connector cannot reach it from Claude either. On Team and Enterprise, an Owner or Primary Owner has to enable a connector for the organisation before any member can use it, and enabling it grants nobody access; each person still authenticates with the third-party service, typically through a one-time OAuth consent, before they can use it.
Owners can then narrow what a connected service is allowed to do across the whole organisation. Anthropic's examples are the ones a finance or sales lead would choose: let Claude search and summarise email but not send it; let it read files in Drive but not create or edit documents; let it view issues but not create them. Each category of tool, read-only or write and delete, can be set to Always allow, Needs approval or Blocked, individual users cannot override the setting, and restricting an action in Claude never grants more than the source system permits. In Claude Cowork there is a further organisation-level switch that controls whether members may skip per-task approval for write-capable connector tools; it is off by default, so on a fresh Team or Enterprise organisation every write through Cowork is approved per task until an Owner decides otherwise. Two smaller points from the same documentation belong in a policy: on Team and Enterprise, connectors are only available in private projects, and chats containing synced content cannot be shared.
The honest caveat is also Anthropic's. Connected services process data on their own infrastructure, under their own terms, which may be located outside the United Kingdom, and Anthropic's own settings for where inference runs do not change where a third-party service operates. Xero and HubSpot are therefore processors in their own right, on their own terms, and belong in your records as such.
What happens to the data on Team and Enterprise
Model training first, because it is the question people ask. Anthropic's pricing page lists model training as none by default on Team and Enterprise, and its Privacy Center article for commercial products states that data from those products is not used to train its models. On the individual plans, Free, Pro and Max, a model-improvement setting in each account decides; Anthropic's consumer article says that when the setting is on it may use chats and coding sessions to improve its models and retain them in de-identified form for up to five years, and that even then raw content from connectors, including remote and local MCP servers, is not included unless it is copied into the conversation. That exclusion is useful but it is not a reason to run a business on personal accounts; the sensible control is a company-owned Team or Enterprise tenancy where the default is no training and nobody has to check five settings.
Retention second. On the commercial plans Anthropic retains chats and sessions in the product so that conversations can be continued, deletes a conversation from back-end storage within 30 days of the user deleting it, and offers custom retention controls on Enterprise only. Chats flagged as usage-policy violations are retained for up to two years. Anthropic's Covered Models, the Mythos-class tier, carry a 30-day retention requirement as part of its safety work regardless of plan. Our guide to whether Claude is GDPR compliant for UK business sets these positions out plan by plan, and Claude data residency for UK organisations covers where processing happens.
Visibility third. On Team, Owners and Primary Owners get the usage analytics dashboard, which includes a connectors view with the number of users and counts of read and write actions, and Cowork events can be streamed to a SIEM through OpenTelemetry. Audit logs and the Compliance API are Enterprise features. Add HubSpot's own audit log, which records every connector write regardless of the Claude plan, and a Team-plan firm has a reasonable evidence trail for CRM changes even without Enterprise; for Xero there is nothing to audit on the write side because there are no writes.
The concerns people actually raise
The questions that circulate on the Xero and HubSpot user forums are worth answering directly, paraphrased rather than quoted.
It looks good on paper and will not work in practice. The most-shared Xero thread makes this argument, and a follow-up complains that the MCP route is limited. Both are about the developer server and about expectations the read-only connector was not built to meet. If the need is to post journals or reconcile bank feeds from Claude, the connector will not do it and Xero says so. If the need is a plain-English answer to what is overdue, what cash looks like and how this quarter compares, that is exactly the four areas Xero built it for, with a link back to the source record so the figure can be checked.
The figures might be wrong or out of date. Two real risks, with two real controls. The connector draws on Xero Analytics, which can lag, so Xero shows a timestamp on each summary and explains how to refresh; and Claude can misread a question, so the answer links to the underlying report. HubSpot's article makes the same point for CRM data: have a person review, ask for citations, and never rely on an AI answer alone for an important decision. Neither vendor claims otherwise.
Can the whole organisation be given access, and should it? On HubSpot, yes, through a Super Admin's approval and each user's own permissions, which is the right mechanism because it means nobody sees more through Claude than they already see in HubSpot. Whether they should depends on the workflow. Sales teams updating deal stages and logging notes from a call are the use HubSpot itself lists; a marketing team bulk-editing records is where the ten-record cap and the Needs approval setting earn their keep.
Management wants to use Claude as the CRM. It is not one. The connector gives Claude a governed way to read and, with approval, write to HubSpot; HubSpot remains the system of record with its own permissions, audit log and validations, and Claude cannot delete anything in it. The same is true of Xero: it stays the source of truth and the connector reads from it.
Are there privacy concerns in connecting Claude to Google Workspace, or to anything? The concern is legitimate and the answer is the scope. A connector that can read a person's Drive and Calendar and draft but not send email, on a plan that does not train on the content, under a policy that names the data that must never go in, is a defensible position for a UK SME. A connector with write access, on a personal account with the model-improvement setting on, with no record of what was connected, is not.
The UK GDPR view
UK GDPR regulates your processing of personal data, not the software, so no connector can be compliant or non-compliant on its own; compliance is a property of how your organisation uses it. Xero holds personal data about customers, suppliers and sometimes staff; HubSpot holds it about contacts, leads and the people at your customer accounts. Reading that data into a Claude conversation is processing, and so is writing a note back. That gives the firm, as controller, five things to have in order.
A lawful basis for each use. Answering a finance question from your own books and updating your own CRM after a call are ordinary business processing that most firms will run on legitimate interests, but the assessment should be written down per use case rather than assumed.
Processor arrangements. Anthropic acts as processor on its commercial plans under its commercial terms and Data Processing Addendum; Xero and HubSpot each process on their own infrastructure under their own terms, and HubSpot's article points to its Data Processing Agreement. Each belongs in your Article 30 record of processing as a recipient, with the categories of data and the purpose.
A data protection impact assessment screen. The Information Commissioner's Office lists new technologies and new processing of personal data among the triggers for a DPIA. Connecting a large language model to your finance and customer systems is likely to meet a screening trigger even where the full assessment concludes the risk is low. Record the screening decision either way; our DPIA screening test for AI assistant rollouts is written for this decision.
Data minimisation through scope. The permission controls described above are how a controller demonstrates minimisation: read-only where read-only will do, write actions set to need approval where they will not, Sensitive Data excluded on the HubSpot side, and one named person responsible for each connection. Reviewing scopes at the 30-day mark and retiring connections nobody uses is part of the same duty.
International transfers. Anthropic's processing for Claude runs on its own infrastructure and its Help Center is explicit that its inference-location settings do not change where Xero or HubSpot operate. Your transfer assessment should name all three and rely on the mechanisms each offers rather than on the assumption that a UK-hosted CRM keeps everything in the UK.
None of that is unusual. It is the same list a firm works through when it adds any new system that touches customer data, and the controls the two connectors expose make most of it straightforward to evidence.
A checklist before you connect
- Confirm the Claude plan is Team or Enterprise and that the organisation is company-owned; retire personal accounts for work use.
- Check the plan's model-training position and record the date you checked it. On Team and Enterprise it is none by default.
- Name the workflow each connection serves and write a one-line lawful basis for it.
- Screen for a DPIA and record the decision.
- In HubSpot, have a Super Admin approve the connector, select the narrowest data permissions that serve the workflow, and restrict who may install it. Confirm whether Sensitive Data is on and what that excludes.
- In Claude, have an Owner enable the connector for the organisation, then set write tools to Needs approval, or Blocked where the workflow is read-only. In Cowork, leave the always-allow option for write tools off.
- For Xero, choose the one organisation to connect and note that switching requires a disconnect; for groups, decide which entity the finance questions concern.
- Write the banned-data list: what staff must not paste into a conversation regardless of what the connector can see.
- Add Anthropic, Xero and HubSpot to the Article 30 record with the categories of data and the purpose, and note the transfer position for each.
- Keep a connector inventory: system, scope, write permission, approval setting, who signed it off, and the review date.
- Tell staff to check figures against the linked source record before acting on them, and to treat a Claude answer as a draft.
- Review at 30 days using the usage analytics your plan provides and HubSpot's audit log, and retire any connection nobody used.
Where this fits
The controls above are what our Claude Enablement install configures as standard: Xero, HubSpot and Google Workspace connectors enabled at organisation level on least-privilege scopes, write actions set to need approval, every scope recorded in a connector inventory with the sponsor's sign-off, and a 30-day adoption window in which the scopes are reviewed against real use. For the wider decisions, plan choice, seat costs, Cowork versus Claude Code and the handover pack, see the companion guide to Claude Code and Cowork for non-technical UK teams. For bespoke connectors and deeper integration, see Claude Implementation, and for the underlying protocol, our briefing on connecting Claude to your business data through MCP.
Sources
- Xero, "Get clear answers on your Xero finances from Claude", xero.com/uk/ai-in-accounting/claude, accessed 15 September 2026.
- Xero Central, "Connect Xero using the Xero connector in Claude", accessed 15 September 2026.
- Xero Developer, "Xero's AI Toolkit" and developer FAQ on the Xero MCP server, accessed 15 September 2026.
- HubSpot Knowledge Base, "Set up and use the HubSpot connector for Claude", last updated 11 September 2026, accessed 15 September 2026.
- HubSpot Developers, "HubSpot MCP server", accessed 15 September 2026.
- Claude Help Center, "Use connectors to extend Claude's capabilities" and "Use Claude Cowork on Team and Enterprise plans", accessed 15 September 2026.
- Claude Help Center, "View usage analytics for Team and Enterprise plans", accessed 15 September 2026.
- Anthropic Privacy Center, "Is my data used for model training?" (consumer and commercial), "How long do you store my data?" and "How long do you store my organization's data?", accessed 15 September 2026.
- claude.com/pricing, UK render, model training row, accessed 15 September 2026.
- Information Commissioner's Office, guidance on data protection impact assessments and on controllers and processors.
- Community discussion on r/xero, r/hubspot, r/CRM and r/ClaudeAI, read in September 2026 and paraphrased; no thread is quoted.
This article is general information for UK businesses, not legal or data protection advice. Connector capabilities are Xero's, HubSpot's and Anthropic's as published on the dates stated and change without notice; confirm the current position before relying on it.
Frequently asked questions
- Can Claude change my Xero accounts?
- No. Xero states that its connector for Claude is read-only at launch: Claude can read live Xero data to answer a question and link back to the report, invoice or contact it used, but cannot edit invoices, post transactions or change anything in your books. If you want to act on what you learn, you follow the link into Xero and make the change yourself. The separate Xero MCP server for developers is a different product with a different risk profile and is not what a non-technical team should be given.
- Can Claude update or delete HubSpot records?
- It can create and update, and it cannot delete. HubSpot's Knowledge Base lists read, create and update access for contacts, leads, companies, deals, tickets, custom objects, line items, products, marketing emails, pages, blog posts and engagements, read-only access for invoices, orders, payments, campaigns attribution, users and teams, and no delete access for anything. Claude may show the proposed change and ask for confirmation, and HubSpot recommends setting the connector's write tools to Needs approval so nothing changes without a person confirming it.
- Who has to approve the connection?
- Two admins, one on each side. In HubSpot a Super Admin must approve the HubSpot connector for Claude, choose which data permissions it may have and decide who in the account may install it. In Claude, on Team and Enterprise, an Owner or Primary Owner must enable the connector for the organisation before any member can use it. Each person then authenticates individually, and Claude inherits only what that person can already see. For Xero, the person connecting signs in with their own Xero login and chooses one organisation.
- Is our Xero or HubSpot data used to train Claude?
- Not on a business plan. Anthropic's pricing page lists model training as none by default on Team and Enterprise, and its Privacy Center says data from its commercial products is not used to train its models. Xero states that Xero data is not used to train AI models, and HubSpot's Knowledge Base says Anthropic does not use data shared through HubSpot for training except where a customer provides feedback or opts in. On the individual plans a model-improvement setting decides; even then Anthropic excludes raw connector content from training data unless it is copied into the chat.
- Do we need a DPIA before connecting?
- Screen for one. Both systems hold personal data about customers, suppliers and staff, and connecting them to a new processor changes how that data is processed. The Information Commissioner's Office lists innovative technology and new processing of personal data among the triggers for a data protection impact assessment. Record the screening decision either way. Our guide to whether you need a DPIA before rolling out Claude gives a screening test built on UK GDPR Article 35.
- Is a read-only connection still processing under UK GDPR?
- Yes. Reading personal data from Xero or HubSpot into a Claude conversation is processing, so the firm needs a lawful basis for it, transparency to the people concerned, and a retention position. Read-only limits what can go wrong, which is why it is the right starting scope, but it does not remove the controller's obligations.
Get new briefings by email
The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.