Intempt & the GDPR
Last Modified: August 27, 2026
The GDPR sets some of the strictest privacy obligations in the world, and most of them land on you rather than on us. You decide what personal data is collected and why. Intempt processes it on your instructions, and gives you the controls to act on what your users ask for. This page covers what those controls are and what Intempt commits to.
Our role
Under the GDPR, you are the data controller and Intempt is the data processor. You determine the purposes and means of processing; we process only on your documented instructions.
Intempt is a first-party platform. The data you collect stays yours, in your project, under your access controls. We do not sell it, we do not use it to build a cross-customer profile, and we do not share it with advertising networks.
Our processing terms are set out in our Data Processing Addendum, which applies automatically to every account including free tier, with no separate signature required.
Data subject rights
Articles 15 to 22 give people rights over data held about them. Intempt implements the OpenDSR framework so you can act on those rights without building anything.
Right of access and portability. Submit an access or portability request and Intempt compiles the user's events and attributes into a file you can hand to them.
Right to erasure. Submit an erasure request and Intempt deletes the data held about that user across its active systems. A waiting period lets you cancel before it begins. Backup copies expire on their own within the backup window, and records Intempt must keep by law are retained.
Right to object. Every Intempt SDK includes opt-out methods. Calling optOut() stops collection for that user, and on mobile it discards anything already queued on the device so nothing captured before the objection is sent.
All three are available from the Privacy Center in the console and from the API, so you can wire them into your own support tooling.
Consent
Intempt records consent per user and per category, so you can show which policy a person agreed to and when. Categories processed under legitimate interest are kept separate from categories requiring active consent, and users can object to the former under Article 21.
Tracking is enabled by default once an SDK is initialized. If your lawful basis requires consent first, initialize with collection paused and enable it when your consent banner returns a decision.
International transfers
Intempt's primary hosting infrastructure is located in the United States, and Intempt does not offer data residency in the European Union or elsewhere. Certain processing activities may take place in other countries where our subprocessors operate, as set out in the DPA.
For transfers from the EEA, the United Kingdom and Switzerland, we rely on the Standard Contractual Clauses adopted by the European Commission, together with the UK Addendum issued by the Information Commissioner.
Pursuant to Article 27, Intempt Technologies LLC has appointed MB Intempt Technologies, Odminių g. 11-4, Vilnius, LT-01122, Lithuania as its EU Representative. EU data subjects and supervisory authorities may contact the EU Representative at privacy@intempt.com.
The third parties that process data on our behalf are listed at intempt.com/subprocessors.
Data minimization
Article 5 requires that you collect only what you need. Intempt is built so that is achievable rather than aspirational: you choose every event and every attribute, you can identify users by an internal identifier rather than an email address, and you can mask sensitive text so autocapture does not read it.
You choose what location data you send. The Android SDK can be configured not to derive location from a network address at all.
Our privacy documentation sets out how to design tracking that collects less in the first place.
Retention
Data is retained for a maximum of two years, after which it is deleted. Some categories are kept for shorter periods depending on the type of data and your plan. After termination, data stays in active systems for thirty days and is then deleted, and backups are kept for fourteen days. The terms are in our Data Processing Addendum and our privacy policy.
Security
All traffic to Intempt uses TLS 1.2 or higher. Access is controlled by organization and project roles, and a multi-factor authentication policy configurable per organization. Custom roles are available on the Enterprise plan. Single sign-on through SAML and OIDC, and directory provisioning through SCIM, are available on the Enterprise plan.
Enterprise organizations have an append-only audit log covering every action of consequence, retained for 730 days and exportable for review. Further detail is available at intempt.trustshare.com.
Questions
Privacy questions, data subject requests directed at Intempt, and supervisory authority enquiries all reach us at privacy@intempt.com.