Privacy facts at a glance
- Jurisdictions
- US · DE · IE · AU · JP · EU
- Subprocessors
- 14
- Breach notification
- Asana's Trust Center FAQ references a defined SLA or timeframe for notifying customers in the event of a data breach, but the specific timeframe is not stated in the excerpts provided.
- Transfer mechanism
- EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the EU-U.S. DPF, and EU/UK Standard Contractual Clauses
- DPA available
- Yes
- Certifications
- ISO/IEC 27001 · ISO/IEC 27017:2015 · ISO/IEC 27018:2019 · ISO/IEC 27701:2019 · SOC 2 Type 1 · SOC 2 Type 2 · SOC 3 · CSA STAR · TX-RAMP · HIPAA
- GDPR addressed
- Yes
- CCPA addressed
- Yes
Named subprocessors
Amazon Web Services, Inc.
Amplitude, Inc.
Anthropic, PBC
Databricks, Inc.
OpenAI, Inc.
Segment (Twilio, Inc.)
Tableau Software, LLC (Salesforce, Inc.)
Intercom, Inc
Service Cloud (Salesforce, Inc.)
Amazon Web Services Inc (AWS Bedrock)
OpenAI, LLC
Tracked documents
Recent changes
Public summary; per-account review history visible to subscribers tracking this vendor.
Track Asana in your workspace.
Get notified when Asana adds a subprocessor, changes retention, updates their DPA, or quietly amends their privacy posture.
Start tracking — 14-day trialNo card required.