Source
Customer data protection — found from sitemap — Intercom
Checked for Intercom on 1 Oct 2026
- Page
- https://www.intercom.com/help/en/articles/1385437-how-we-comply-with-gdpr
- Checked
- 1 Oct 2026, 11:45 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:501498ee90f73e2d3900cbbe16efee5f7decfaa1aedec5a53068ef340d9c52a2
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
GDPR DPA Report an error
“The DPA (incorporating the new SCCs issued by the European Commission on June 4, 2021, is incorporated into the Terms of Service under which your Fin services are governed and no separate signature is needed.”
-
Bespoke DPA Report an error
“Our policy is that we only contract on the basis of our GDPR DPA.”
-
Data portability Report an error
“We help you meet your data portability requirements; you can easily export all of your data linked to an individual and permanently delete all data linked to an individual user.”
-
Retention Report an error
“We will automatically expire data on visitors that have not been seen in 9 months, to ensure we comply with GDPR retention requirements.”
-
US surveillance policy Report an error
“This means that Fin will only provide data in response to a court order, subpoena, warrant or other valid legal request that compels us to provide data from a customer account.”
-
International transfers Report an error
“To comply with the GDPR’s requirements for international data transfers, Fin participates in the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce.”
-
Vendor dpas Report an error
“Where appropriate, we require all of our third-party vendors to enter into data processing agreements that ensure customer data will remain protected in accordance with the GDPR and our obligations to you.”
-
Encryption Report an error
“All data sent to or from us is encrypted in transit using 256 bit encryption. Our API and application endpoints are TLS/SSL only and score an “A+” rating on Qualys SSL Labs‘ tests. This means we only use strong cipher suites and have features such as HSTS and Perfect Forward Secrecy fully enabled. We also encrypt data at rest using an industry-standard AES-256 encryption algorithm.”
-
Certifications Report an error
“We’ve built a robust security framework, achieving International Compliance standards (SOC2, ISO27001, ISO27701, ISO27018, HIPAA and HDS)”
-
Security practices Report an error
“We have regular external audits, pentests and bug bounties.”
-
Security docs Report an error
“Our audit reports, pen tests and security docs are available to customers on request.”