Support and CRM
GDPR Intercom
In an indie stack, Intercom is used for Support chat and messaging. Entity cited: Intercom, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Intercom
Yes. Public Data Processing Agreement.
Stated role
For Customer Personal Data, the customer may be controller or processor and Intercom is processor. For Account Data, Intercom is an independent controller.
Personal data
Account data (name, contact details, billing address), conversations (chats, messages, calls, and recordings), identifier, password, email, IP address, customer attributes, pages viewed, and clicks.
Sub-processors of Intercom
Public list, which also specifies the default hosting and the EU option.
Transfers outside the EU
Hosting / location
By default, the primary facilities are in the United States. Customers who choose EU hosting have AWS hosting in Dublin (region eu-west-1).
EU–United States Data Privacy Framework
Intercom, Inc. is registered. EU-U.S. Data Privacy Framework status: Active.
Cookies
The Messenger help (stated update: 10 August 2026) publishes first-party cookies on the customer's domain: intercom-id-[app_id] (anonymous identifier), intercom-session-[app_id] (session, 1 week by default), and intercom-device-id-[app_id] (device, 270 days). Names of cookies on the intercom.com site: not disclosed.
Typical use, written by StackLégal and not by the vendor: Support chat and messaging.
History
Last update: October 4, 2026.
Cookies: Messenger names taken from the Intercom help, in place of "not disclosed".
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Intercom a processor within the meaning of the GDPR?
For Customer Personal Data, the customer may be controller or processor and Intercom is processor. For Account Data, Intercom is an independent controller.
What DPA does Intercom publish?
Yes. Public Data Processing Agreement. https://www.intercom.com/legal/data-processing-agreement
Which further sub-processors does Intercom publish?
Public list, which also specifies the default hosting and the EU option. https://www.intercom.com/legal/subprocessors-list
Where does Intercom state that it processes data, including outside the EU?
By default, the primary facilities are in the United States. Customers who choose EU hosting have AWS hosting in Dublin (region eu-west-1).
Is Intercom registered under the EU–United States Data Privacy Framework?
Intercom, Inc. is registered. EU-U.S. Data Privacy Framework status: Active. https://www.dataprivacyframework.gov/participant/5893
Which personal data does Intercom mention?
Account data (name, contact details, billing address), conversations (chats, messages, calls, and recordings), identifier, password, email, IP address, customer attributes, pages viewed, and clicks.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.