Trains on customer data
unclear
Not stated in the documents we could read. An absence here is an unknown, not a no.
Opt-out mechanism
* You have the right to opt-out of marketing communications we send you at any time.
“* You have the right to opt-out of marketing communications we send you at any time.”
AI features
present
“* Artificial intelligence: We, our service providers and the third parties we work with may use artificial intelligence (AI) and machine learning technologies, including generative AI, to facilitate the processing of personal information described in this Privacy Policy.”
Model providers named
none named
Not stated in the documents we could read. An absence here is an unknown, not a no.
Retention
30 days
“Customer may request to Intercom to delete all Customer Personal Data, and Intercom will proceed to delete the data as soon as reasonably practicable and within a maximum period of 30 days from Customer’s written request.”
Hosting regions
United States
“6.1The Intercom Services and Sites, and our messenger domains are provided and hosted in the United States.”
Subprocessor notice
20 days
“If Customer reasonably objects to the appointment of a new Sub-processor within twenty (20) days of receiving such notice, on reasonable grounds relating to the protection of the Customer Personal Data, then Intercom will work in good faith with Customer to find an alternative solution.”
Downstream
Who's behind Intercom, as listed in its own subprocessor documents. 1 listed.
Model providers
- none listed
Hyperscalers
- Amazon Web Servicesunstated
Other subprocessors
- none listed
Reviewer notes
Extracted by deterministic rules (rules/v1), no language model. Coverage is limited to recognisable clauses and a gazetteer of common subprocessors; absent values mean 'not matched', not 'not present'. no training clause matched
Documents read
- privacy policy https://www.intercom.com/legal/privacyHTTP 200 · 2026-09-05
- dpa https://www.intercom.com/legal/data-processing-agreementHTTP 200 · 2026-09-06
Document changes
- high 2026-09-06 · dpa +3 / −3 lines
show diff
+ * https://www.intercom.+ * Customer Personal Data is encrypted at rest using 256-bit encryption, leveraging AWS’ encryption framework’s model C as described in https://d0.awsstatic..pdf+ * See https://www.intercom..− * https://www.intercom.com/help/en/articles/1385437-how-intercom-complies-with-gdpr− * Customer Personal Data is encrypted at rest using 256-bit encryption, leveraging AWS’ encryption framework’s model C as described in https://d0.awsstatic.com/whitepapers/aws-securing-data-at-rest-with-encryption.pdf− * See https://www.intercom.com/help/en/articles/4667982-review-actions-taken-in-your-workspace-with-teammate-activity-logs.
Fact changes
- medium 2026-09-05 · 1 field change(s), +1/−0 subprocessors, +0 model providers
Corrections
No correction requests. Anyone may dispute a fact with a source; requests and resolutions are public and ledger-entered.
Facts are as stated in Intercom's public documents on the date read. This is a record, not legal advice. Work for Intercom? Claim this profile · Something wrong? Request a correction.