Finn AI powered by Intercom

Last Reviewed: 27 Jul 2026

GDPR Addressed

At a Glance

Intercom's DPA addresses the key GDPR requirements, including Data Privacy Framework certification with SCCs as fallback, detailed security measures, and a clear restriction against using Customer Personal Data (e.g. conversation data) for Intercom's own purposes. The main practical point to note is that data is stored in the US by default unless a regional hosting add-on is purchased.

Company & Product Details

HQ

United States, Ireland

Products

AI Customer Service Agent (Fin) & Customer Messaging Platform

Product description

AI-powered customer service agent and messaging platform for businesses to support, engage, and communicate with their customers.

What data is being processed?

Account Data (name, contact information, billing address) and Customer Personal Data relating to end-user activity and interactions, including conversation data (chats, messages, phone calls and recordings), username, password, email address, IP address, customer attribute data, and website page view/click data

Document Details

Date of DPA

09 Apr 2025

Additional date information

Document states "Effective April 9, 2025" directly under the title; a prior version is separately archived.

What jurisdictions are covered?

GDPR/EEA, UK GDPR, the Swiss DPA, CCPA/CPRA (US), and Australian Privacy Principles are explicitly addressed as Applicable Data Protection Legislation. SCCs (EU, UK Addendum, and Swiss-law modifications) govern international transfers as a fallback to the Data Privacy Framework; governing law for EU SCCs defaults to the data exporter's EU member state or Ireland, with UK/Swiss-governed transfers resolved before courts of England and Wales or Switzerland respectively (clauses 1, 12; Schedule 1 Annex I).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA is made pursuant to and forms part of the Master SaaS Subscription Agreement, Intercom's Terms of Service, or other written/electronic agreement between the parties, and automatically applies once such an Agreement is in place (Preamble; Schedule 1 Annex I).

Location & Transfers

Where is data held or processed?

United States, European Union, Australia By default, Customer Data is stored in the United States. Customers who purchase Intercom's regional data hosting add-on may instead have their data stored and processed in the EU or Australia, under a separate Regional Data Hosting Addendum incorporated by reference (Schedule 2).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
Intercom primarily relies on its certification under the EU-US, Swiss-US, and UK-US Data Privacy Frameworks for Restricted Transfers. If the DPF is invalidated or ceases to be valid, the appropriate SCCs (EU SCCs Module One for Account Data, Module Two/Three for Customer Personal Data) are deemed incorporated, together with a UK Addendum and Swiss-law modifications, with governing law defaulting to the data exporter's EU member state or Ireland (clause 12).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Extensive measures are set out in Schedule 2, including TLS 1.2 in transit and 256-bit AES encryption at rest (AWS), SSO and MFA, SOC 2 Type II and ISO 27001 certification, monthly vulnerability scans, annual third-party penetration testing, and a security bug bounty program (Schedule 2).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
Section 2.iv confirms Intercom acts as an independent controller only in respect of Account Data (name, contact information, billing address) for account management, core business operations, fraud/security detection, identity verification and legal compliance — this is User/Account Data and does not affect this assessment. For Customer Personal Data (the end-user/conversation data Intercom processes as Processor), clause 14 additionally restricts Intercom from selling it, combining it with data from other sources, or using/disclosing it outside the direct business relationship or specified business purposes. No controller rights or independent-use provisions over Processor/Customer Data were identified (clauses 2.iv, 3.i, 14).

Subprocessing

General authorization

General
Customer provides general authorization for Intercom to engage sub-processors listed on its published Sub-processor Page, subject to Intercom restricting their access to what is necessary, imposing equivalent contractual obligations, and remaining liable for their acts. Intercom gives at least 20 days' notice of new sub-processors (via an opt-in distribution list); Customer may object within 20 days on reasonable data-protection grounds, triggering good-faith discussions, with Customer's termination right as the fallback if unresolved (clauses 7.i–7.ii).

Do all the DPA terms flow down to sub-processors?

Yes
Intercom imposes contractual data protection obligations on each sub-processor equivalent to the standard required by Applicable Data Protection Legislation, and remains liable and accountable for any breach of the DPA caused by a sub-processor's act or omission (clause 7.i(b)-(c)).

Is data only processed on the instruction of the controller?

Yes
Intercom processes Customer Personal Data on behalf of Customer and in accordance with Customer's instructions as set out in the Agreement and this DPA (Permitted Purposes); additional instructions outside this scope must be mutually agreed in writing (clause 3).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Intercom provides self-service features enabling Customer to delete, obtain a copy of, or restrict use of Customer Personal Data, and will provide reasonable assistance (at Customer's cost) to help Customer respond to data subject rights requests where these tools are insufficient (clause 13.i).

Does the contract include staff confidentiality clauses?

Yes
Intercom requires all employees to sign a confidentiality statement at hire and adhere to its security policies, ensures anyone authorized to process Customer Personal Data is subject to a duty of confidentiality, and conducts criminal background checks where legally permitted (clause 6.i).

Are there audit rights for the data?

Structured
Intercom primarily provides documentation of its audits/certifications (e.g. SOC 2) via trust.intercom.com at no cost. Customer or a qualified third-party auditor may also conduct a full audit, at Customer's cost, limited to once annually and subject to mutually agreed scope, timing, and confidentiality terms; Intercom may object to an auditor it reasonably considers unqualified or a competitor (clause 11).

Is there assistance with DPIA requests?

Yes
Intercom will provide reasonable assistance, at Customer's cost, with data protection impact assessments or prior consultations with data protection authorities that Customer is required to carry out (clause 8).

How much notice is provided for data breaches?

Upon becoming aware of a Security Breach, Intercom will notify Customer without undue delay and provide information reasonably required to help Customer meet its own breach-reporting obligations; no specific fixed time limit (e.g. a number of hours) is stated (clause 9.v).

What happens to the data on termination?

Upon termination or expiry, Intercom will delete or return all Customer Personal Data at Customer's election. On Customer's written deletion request, data is deleted within a maximum of 30 days; if no request is made, data is automatically deleted 180 days after termination, with back-up copies deleted after 14 days, subject to legally required retention (clause 10).