StackLégal

Support and CRM

GDPR Intercom

In an indie stack, Intercom is used for Support chat and messaging. Entity cited: Intercom, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA Intercom

Yes. Public Data Processing Agreement.

Read the DPA

Stated role

For Customer Personal Data, the customer may be controller or processor and Intercom is processor. For Account Data, Intercom is an independent controller.

Personal data

Account data (name, contact details, billing address), conversations (chats, messages, calls, and recordings), identifier, password, email, IP address, customer attributes, pages viewed, and clicks.

Sub-processors of Intercom

Public list, which also specifies the default hosting and the EU option.

List published by the vendor

Transfers outside the EU

Hosting / location

By default, the primary facilities are in the United States. Customers who choose EU hosting have AWS hosting in Dublin (region eu-west-1).

EU–United States Data Privacy Framework

Intercom, Inc. is registered. EU-U.S. Data Privacy Framework status: Active.

Data Privacy Framework sheet

Cookies

The Messenger help (stated update: 10 August 2026) publishes first-party cookies on the customer's domain: intercom-id-[app_id] (anonymous identifier), intercom-session-[app_id] (session, 1 week by default), and intercom-device-id-[app_id] (device, 270 days). Names of cookies on the intercom.com site: not disclosed.

Typical use, written by StackLégal and not by the vendor: Support chat and messaging.

History

Last update: October 4, 2026.

  1. Cookies: Messenger names taken from the Intercom help, in place of "not disclosed".

  2. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is Intercom a processor within the meaning of the GDPR?

For Customer Personal Data, the customer may be controller or processor and Intercom is processor. For Account Data, Intercom is an independent controller.

What DPA does Intercom publish?

Yes. Public Data Processing Agreement. https://www.intercom.com/legal/data-processing-agreement

Which further sub-processors does Intercom publish?

Public list, which also specifies the default hosting and the EU option. https://www.intercom.com/legal/subprocessors-list

Where does Intercom state that it processes data, including outside the EU?

By default, the primary facilities are in the United States. Customers who choose EU hosting have AWS hosting in Dublin (region eu-west-1).

Is Intercom registered under the EU–United States Data Privacy Framework?

Intercom, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. https://www.dataprivacyframework.gov/participant/5893

Which personal data does Intercom mention?

Account data (name, contact details, billing address), conversations (chats, messages, calls, and recordings), identifier, password, email, IP address, customer attributes, pages viewed, and clicks.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets support and crm

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.