Skip to main content
Platform Review
PricingSign in
Asana AI assessment

Asana AI procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Asana AI
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow Asana offers global data residency options with data centers in Europe, Australia, Japan, and US so customers have more control over where their data is stored.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law in the United States that requires the creation of national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. Businesses that are subject to HIPAA can use Asana to support HIPAA-compliant work management. HIPAA compliance for Asana is governed by Asana’s Business Associate Addendum (BAA) . For additional detail on HIPAA and Asana, please refer to the HIPAA Data Sheet .Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Learn more about how Asana earns trust through security, reliability, privacy, and compliance at our Trust Center and Asana's Privacy Statement . For more information, please visit our AI Product Page and our AI & Admin Console Help Center Article .Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The DPA is incorporated by reference in a customer entity's Subscriber Terms with Asana.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Asana relies on applicable Data Privacy Frameworks to facilitate international transfers of data. If the applicable Data Privacy Framework is invalidated, Asana relies on applicable standard contractual clauses incorporated by reference in the DPA.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow To demonstrate our commitment to global privacy standards, Asana has certifications of compliance with ISO 27018:2019 (Protecting Personal Data in the Cloud)​​ and ISO 27701:2019 (Privacy Information Management).  We also work to ensure our agreements with our customers are up to date–our Data Processing Addendum incorporates the latest data privacy frameworks between the US and EU, United Kingdom, and Switzerland as well as the EU and UK Standard Contractual Clauses, which outlines our contractual privacy obligations and facilitates the transfer of data globally.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow How we will assist our customers with their obligations under the APPI; and Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Asana has self-certified to the EU-US Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-US Data Privacy Framework as set forth by the US Department of Commerce regarding the transfer of personal information from the European Economic Area (EEA), the United Kingdom, and Switzerland to the United States. For more information about Asana’s certification, please visit the Data Privacy Framework Program .  Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Yes. Asana’s DPA is applied globally.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Asana’s DPA is meant to cover customers globally and sets out relevant legal obligations and commitments related to Asana’s processing of Customer Personal Data.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The provisions of Asana’s DPA reflect Asana’s services and multi-tenant infrastructure. For example, Asana's DPA is tailored to our processes around privacy related notifications, audits, certifications, security measures, and sub-processing activities. Asana’s DPA also seamlessly interoperates with other agreements and relevant Documentation.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The CCPA (as amended by CPRA) is a law that provides California consumers certain rights with respect to their personal information. Specifically, the law requires that businesses subject to the statute grant consumers the ability to request access to and deletion of their data, and the ability to opt out of certain types of disclosures of their personal information. The law also restricts how service providers that process personal information on behalf of a business may use that information. Where a business subject to the CCPA has entered into a service or subscription agreement with Asana, Asana will act as a service provider to that business. Specifically, Asana will process such customers’ personal information only for the purposes set forth in the applicable agreement and will cooperate with customers to fulfill their obligations with respect to deletion or access requests. Asana's Data Processing Addendum specifically references our obligations under the CCPA. If your organization is a customer of Asana and requires an addendum, please reach out to dpa@asana.com .Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Asana’s technical and organizational security and privacy measures have been reviewed by independent third-party auditors and have achieved ISO 27018 : 2019 and ISO 27701 : 2019 certifications. We have also undergone SOC 2 Type 1 + HIPAA and SOC 2 Type 2 + Privacy audits. For more information on Asana’s security and data protection practices, please see our Trust Center . Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Family Educational Rights and Privacy Act (FERPA) is a federal law that requires academic institutions like colleges and universities to protect the privacy of student educational records. Asana enables our customers to comply with FERPA by ensuring personal data is kept secure and only used to provide our services as described in our Terms of Service and Privacy Statement . Asana contractually commits to not disclosing customer data except as directed by the contracting academic institution, as allowed by our terms, or as required by law. As laws, regulations, and guidance from data protection authorities and regulators continue to evolve and more countries are passing new data protection laws and regulations, we will continue to follow these developments closely and evaluate our program for any changes or enhancements as needed.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Asana has established a comprehensive GDPR/UK GDPR compliance program and is committed to partnering with customers and vendors on our compliance efforts. Some significant steps Asana takes to align its practices with the GDPR/UK GDPR include: Revising our policies and contracts with our partners, vendors, and users to reflect legislative developments;Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Gramm-Leach-Bliley Act (GLBA) requires financial institutions—companies that offer consumers financial products or services like loans, financial or investment advice, or insurance—to explain their information-sharing practices to their customers and to safeguard sensitive data. Service providers who are permitted by the financial institutions to access their consumers' nonpublic personal information (NPI) are also required to comply with GLBA. Asana is GLBA-ready and aligns our practices in accordance with GLBA's Privacy Rule and Safeguards Rule. In addition to implementing security safeguards, we only use customer work content to provide our services, and not for any other purpose. Customers should not store sensitive personal data (including financial account numbers and social security numbers) in Asana.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The Act on the Protection of Personal Information (APPI) is the primary data protection law in Japan that regulates the protection of personal information. It applies to business operators handling personal information of individuals in Japan. The APPI has been amended since it was originally enacted in 2003, with the most recent amendments coming into effect April 1, 2022. Similarly to the distinction between “data controllers” and “data processors” under the GDPR, the APPI makes a distinction between “business operators”—or entities with the authority to control and make decisions about retained personal information (i.e., Asana’s customers) and third-party service providers handling personal information on behalf of a business operator (i.e., Asana). The APPI also imposes restrictions on cross-border transfers of personal information outside of Japan. Personal information may be transferred to overseas recipients if there are contractual agreements in place that ensure compliance with data protection standards in Japan. Asana is committed to processing and safeguarding personal information as required by the APPI and its amendments. Asana’s Data Processing Addendum covers Our data protection commitments to ensure that we comply with the APPI; Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium Asana offers our Starter, Advanced, Enterprise, and Enterprise+ customers a Data Processing Addendum that incorporates Data Privacy Frameworks between the EU, UK, Switzerland, and the US, as well as applicable standard contractual clauses.Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Asana is a global company and data will be transferred to regions where our subprocessors and affiliates are located. For more information, please see Asana Subprocessors . Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Every request we receive is carefully reviewed by our privacy team to determine the validity of the legal process, assess the proportionality of the request, and ensure compliance with the commitments we’ve made to our users. For more information, please see Asana's Law Enforcement Guidelines .Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Learn how Asana engages third-party subprocessors and Asana affiliates to help us provide services to our customers.Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Asana will respond to government access requests in accordance with Asana’s Law Enforcement Guidelines . Asana only responds to law enforcement requests that adhere to established legal process and applicable law.Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Yes, Asana does use subprocessors. More information can be found at Asana Subprocessors . Captured 2026-06-08Open source →Finding permalink →
Tier differencesAll applicable tierslow “ Managed Users ” use the Service as part of any paid Asana subscription plan purchased by a person or entity (the “ Customer ”) who has separately entered into a written agreement with Asana (the “ Customer Agreement ”) governing access and use of the Service and permitting such Customer to create and configure Asana so that Managed Users may join.Captured 2026-06-08Open source →Finding permalink →
Tier differencesAll applicable tiersunknown To the extent you are a Managed User, only the following sections of these Terms will apply to you: Section 1 (Introduction); Section 2 (How These Terms Apply); and Section 6 (Acceptable Use Policy). As a Managed User, you gain access to the Service through a Customer of Asana.  For example, if you are joining your employer’s organization, Customer is your employer.  If you are joining a workspace created by your friend using a personal email address, your friend is the Asana Customer and is authorizing you to join his or her workspace.  The Customer Agreement governs our relationship and commitment to deliver the Service to that Customer, who may then invite Managed Users to join their Asana instance.  When you or another Managed User submit content or information to the Service, such as messages or files (“ Customer Data ”), you acknowledge and agree that, as between Asana and Customer, the Customer Data is controlled by Customer and the Customer Agreement provides Customer with choices and control over that Customer Data.  For example, Customer may manage permissions, enable or disable third party integrations, or take steps to expand, consolidate or share the contents of Asana portfolios, projects, tasks and subtasks, and these choices and instructions may result in the access, use, disclosure, modification or deletion of certain or all Customer Data. AS BETWEEN ASANA AND CUSTOMER, YOU ACKNOWLEDGE AND AGREE THAT IT IS SOLELY CUSTOMER’S RESPONSIBILITY TO (A) INFORM YOU AND ANY OTHER MANAGED USERS OF ANY RELEVANT CUSTOMER POLICIES, PRACTICES AND SETTINGS THAT MAY IMPACT THE PROCESSING OF CUSTOMER DATA; (B) OBTAIN ANY RIGHTS, PERMISSIONS OR CONSENTS FROM YOU AND ANY OTHER MANAGED USERS THAT ARE NECESSARY FOR THE LAWFUL USE OF CUSTOMER DATA AND THE OPERATION OF THECaptured 2026-07-19Open source →Finding permalink →
Tier differencesAll applicable tierslow Yes. Asana AI features use artificial intelligence (AI) to sort, filter, categorize, or otherwise analyze data and/or content to help users in your organization optimize their work. Asana AI features are available on Asana Starter, Advanced, Enterprise, and Enterprise+ tiers, as well as legacy tiers Premium, Business, and Legacy Enterprise. For details and updates to tiers and pricing, see Asana's pricing page.Captured 2026-06-08Open source →Finding permalink →
Tier differencesAll applicable tierslow “ Free Users ” use the free/basic version of the Service.  Free Users have access to a more limited set of Service features and functionality than Managed Users.  Free Users may have their own individual workspaces and/or take part in a free multi-user Asana domain.Captured 2026-06-08Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.