StackLégal

Support and CRM

GDPR Crisp

In an indie stack, Crisp is used for Support chat. Entity cited: Crisp IM SAS. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Crisp

Yes. The PDF is downloaded from the account. The official help page describes where to find it. Direct URL of the PDF: not disclosed.

Read the DPA

Stated role

Crisp acts as processor of the personal data of the customer's end users. The customer remains the controller. French company, SIREN 833 085 806, 2 boulevard de Launay, 44100 Nantes.

Personal data

Customer profile (first name, last name, photo), billing data (card numbers are stored by Stripe), system logs (IP address, user agent, login time), and on the end-user side: email, phone, exchanges, last activity, and profile information.

Sub-processors of Crisp

Public list (stated update: 15 July 2026): DigitalOcean (data in the EU, the Netherlands and Germany), Vultr (email relay, no data retained), AWS (encrypted backups in Ireland), Cloudflare, Stripe Payments Europe, PayPal, Scaleway (France), and optional providers (Firebase Cloud Messaging, Azure, OpenAI, Gemini, Anthropic, Mistral).

List published by the vendor

Transfers outside the EU

Hosting / location

Messaging data is stored in the Netherlands and plugin data in Germany, on DigitalOcean servers in the EU. Relay servers that store only connection logs are in the United States, the United Kingdom, and Singapore.

EU–United States Data Privacy Framework

Official search for “Crisp IM” and “crisp.chat”: no participant. A “Crisp, Inc.” entry (Springdale, Arkansas) concerns another company. Crisp IM SAS: not registered.

Cookies

The cookies policy (stated update: 15 July 2026) lists, on crisp.chat, in particular crisp_cookie_consent, crisp-client-session-*, crisp-client-*, i18n_redirected, g_state, shared_profile, ph_phc_, _gcl_au, _fbc, _fbp, and LinkedIn cookies. On a customer's site, the chatbox sets cookies of the same pattern (crisp-client-session-*, crisp-client-*), limited to the widget's domain, with a default expiration of six months.

Typical use, written by StackLégal and not by the vendor: Support chat.

History

Last update: October 4, 2026.

  1. Sub-processors and cookies: public list and cookie policy of 15 July 2026, in place of the previous wording.

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Crisp a processor within the meaning of the GDPR?

Crisp acts as processor of the personal data of the customer's end users. The customer remains the controller. French company, SIREN 833 085 806, 2 boulevard de Launay, 44100 Nantes.

What DPA does Crisp publish?

Yes. The PDF is downloaded from the account. The official help page describes where to find it. Direct URL of the PDF: not disclosed. https://help.crisp.chat/en/article/where-do-i-find-my-gdpr-data-processing-agreement-dpa-1wfmngo/

Which further sub-processors does Crisp publish?

Public list (stated update: 15 July 2026): DigitalOcean (data in the EU, the Netherlands and Germany), Vultr (email relay, no data retained), AWS (encrypted backups in Ireland), Cloudflare, Stripe Payments Europe, PayPal, Scaleway (France), and optional providers (Firebase Cloud Messaging, Azure, OpenAI, Gemini, Anthropic, Mistral). https://crisp.chat/en/sub-processors/

Where does Crisp state that it processes data, including outside the EU?

Messaging data is stored in the Netherlands and plugin data in Germany, on DigitalOcean servers in the EU. Relay servers that store only connection logs are in the United States, the United Kingdom, and Singapore.

Is Crisp registered under the EU–United States Data Privacy Framework?

Official search for “Crisp IM” and “crisp.chat”: no participant. A “Crisp, Inc.” entry (Springdale, Arkansas) concerns another company. Crisp IM SAS: not registered.

Which personal data does Crisp mention?

Customer profile (first name, last name, photo), billing data (card numbers are stored by Stripe), system logs (IP address, user agent, login time), and on the end-user side: email, phone, exchanges, last activity, and profile information.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets support and crm

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.