Asana keeps your personal data for as long as it needs to run its service and meet legal requirements, and then securely deletes it — but the policy does not specify exact retention timeframes.
This analysis describes what Asana's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision defines the operational scope and duration of data retention by establishing multiple retention categories—service provision, legal compliance, dispute resolution, and contract enforcement—which collectively determine how long personal information remains in Asana's systems. The secure disposal mechanism establishes a procedural standard for data removal once retention purposes are satisfied.
The removal of this explicit data retention and secure deletion provision eliminates transparency about Asana's data retention practices and disposal methods.
View full change record →Asana does not disclose specific retention periods for different categories of personal data, meaning users cannot determine how long their task content, communications, or usage data is stored before deletion — a gap that creates uncertainty about compliance with GDPR's storage limitation principle.
How other platforms handle this
We collect and keep personal data only as needed or allowed for the purposes set out in this Statement, based on the reason we collected the personal data in the first instance and what is permitted under the laws that apply to the processing.
Affirm will retain your information in accordance with our Privacy Policy and any applicable state or federal law, rule or regulation.
Mistral AI shall retain the Customer Exportable Data and Assets for a period of thirty (30) days from the earlier between (a) the expiration of the Transitional Period or (b) Customer's notification under Section 2.2.2 (b) of these Additional Terms.
"We retain personal information for as long as needed to provide our Services, comply with our legal obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed, we dispose of it in a secure manner.Excerpt from Asana's Privacy Statement
REGULATORY FRAMEWORK: Implicates GDPR Art.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision defines the operational scope and duration of data retention by establishing multiple retention categories—service provision, legal compliance, dispute resolution, and contract enforcement—which collectively determine how long personal information remains in Asana's systems. The secure disposal mechanism establishes a procedural standard for data removal once retention purposes are satisfied.
Asana does not disclose specific retention periods for different categories of personal data, meaning users cannot determine how long their task content, communications, or usage data is stored before deletion — a gap that creates uncertainty about compliance with GDPR's storage limitation principle.
ConductAtlas has identified this type of provision across 274 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Asana.