Privacy facts at a glance
- Jurisdictions
- US · EU · DE · IE · AU · JP
- Subprocessors
- 13
- Breach notification
- Asana's Trust Center FAQ references a defined SLA or timeframe for notifying customers in the event of a data breach, but the specific timeframe is not stated in the excerpts provided.
- Transfer mechanism
- EU-US Data Privacy Framework, UK-US and Swiss-US Data Privacy Frameworks, and EU/UK Standard Contractual Clauses
- DPA available
- Yes
- Certifications
- ISO 27001:2022 · ISO/IEC 27017:2015 · ISO/IEC 27018:2019 · ISO/IEC 27701:2019 · SOC 2 Type 1 · SOC 2 Type 2 · SOC 3 · CSA STAR · TX-RAMP · HIPAA
- GDPR addressed
- Yes
- CCPA addressed
- Yes
Named subprocessors
Amazon Web Services, Inc.
Google, LLC (Google Cloud)
Amplitude, Inc.
Anthropic, PBC
Databricks, Inc.
OpenAI, Inc.
Segment (Twilio, Inc.)
Tableau Software, LLC (Salesforce, Inc.)
Intercom, Inc
OpenAI, LLC
Service Cloud (Salesforce, Inc.)
Tracked documents
Recent changes
Public summary; per-account review history visible to subscribers tracking this vendor.
Track Asana in your workspace.
Get notified when Asana adds a subprocessor, changes retention, updates their DPA, or quietly amends their privacy posture.
Start tracking — 14-day trialNo card required.