Privacy facts at a glance
- Jurisdictions
- US · EU · Belgium · Netherlands · Spain · Indonesia · Malaysia
- Subprocessors
- 26
- Retention
- AI subprocessors do not store Customer Content longer than necessary to provide the output, and automatically clear cache within two hours; general customer data retention period is not stated.
- Breach notification
- Figma must notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of a security breach affecting Customer Content.
- Transfer mechanism
- Transfer impact assessments and appropriate transfer mechanisms are in place for cross-border transfers, but specific mechanism (e.g., SCCs) is not named in the excerpts.
- DPA available
- Yes
- Certifications
- SOC 2 Type 2 · SOC 3 · ISO 27001 · ISO 27017 · ISO 27018 · ISO 27701 · EU Cloud Code of Conduct · C5 · TISAX · CSA CAIQ · FedRAMP
- GDPR addressed
- Yes
Named subprocessors
Amazon Web Services, Inc.
Cloudflare, Ltd.
Datadog, Inc.
Functional Software, Inc. (Sentry)
Agora, Inc.
Modal Labs, Inc.
Snowflake, Inc.
Twilio, Inc. (Segment)
Twilio, Inc.
Anthropic PBC
Cerebras Systems, Inc.
OpenAI, LLC
Tracked documents
Recent changes
Public summary; per-account review history visible to subscribers tracking this vendor.
Track Figma in your workspace.
Get notified when Figma adds a subprocessor, changes retention, updates their DPA, or quietly amends their privacy posture.
Start tracking — 14-day trialNo card required.