Finn AI powered by Intercom
Last Reviewed: 27 Jul 2026
At a Glance
Intercom's DPA addresses the key GDPR requirements, including Data Privacy Framework certification with SCCs as fallback, detailed security measures, and a clear restriction against using Customer Personal Data (e.g. conversation data) for Intercom's own purposes. The main practical point to note is that data is stored in the US by default unless a regional hosting add-on is purchased.
Company & Product Details
HQ
United States, Ireland
Products
AI Customer Service Agent (Fin) & Customer Messaging Platform
Product description
AI-powered customer service agent and messaging platform for businesses to support, engage, and communicate with their customers.
What data is being processed?
Account Data (name, contact information, billing address) and Customer Personal Data relating to end-user activity and interactions, including conversation data (chats, messages, phone calls and recordings), username, password, email address, IP address, customer attribute data, and website page view/click data
Document Details
Date of DPA
09 Apr 2025
Additional date information
Document states "Effective April 9, 2025" directly under the title; a prior version is separately archived.
What jurisdictions are covered?
GDPR/EEA, UK GDPR, the Swiss DPA, CCPA/CPRA (US), and Australian Privacy Principles are explicitly addressed as Applicable Data Protection Legislation. SCCs (EU, UK Addendum, and Swiss-law modifications) govern international transfers as a fallback to the Data Privacy Framework; governing law for EU SCCs defaults to the data exporter's EU member state or Ireland, with UK/Swiss-governed transfers resolved before courts of England and Wales or Switzerland respectively (clauses 1, 12; Schedule 1 Annex I).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
United States, European Union, Australia By default, Customer Data is stored in the United States. Customers who purchase Intercom's regional data hosting add-on may instead have their data stored and processed in the EU or Australia, under a separate Regional Data Hosting Addendum incorporated by reference (Schedule 2).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Extensive measures are set out in Schedule 2, including TLS 1.2 in transit and 256-bit AES encryption at rest (AWS), SSO and MFA, SOC 2 Type II and ISO 27001 certification, monthly vulnerability scans, annual third-party penetration testing, and a security bug bounty program (Schedule 2).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Upon becoming aware of a Security Breach, Intercom will notify Customer without undue delay and provide information reasonably required to help Customer meet its own breach-reporting obligations; no specific fixed time limit (e.g. a number of hours) is stated (clause 9.v).
What happens to the data on termination?
Upon termination or expiry, Intercom will delete or return all Customer Personal Data at Customer's election. On Customer's written deletion request, data is deleted within a maximum of 30 days; if no request is made, data is automatically deleted 180 days after termination, with back-up copies deleted after 14 days, subject to legally required retention (clause 10).