If your employer pays for Asana, your employer controls your data — not Asana. You need to ask your employer, not Asana, about your privacy rights.
This analysis describes what Asana's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision clarifies the allocation of data responsibility in business deployments, designating the employing or sponsoring organization—rather than Asana—as the entity responsible for determining how user data is collected, used, and disclosed. This structure establishes the contractual relationship between Asana and the organization as the primary data governance arrangement.
This foundational provision explaining the data controller-processor relationship was removed, though its content appears partially replaced by the new 'Controller-Processor Distinction' provision with less detailed explanation.
View full change record →Employees using Asana through a company account cannot directly request data deletion or access from Asana — those rights must be exercised through the employing organization, which has contractual control over the workspace data.
How other platforms handle this
We use your personal information to send you newsletters and other promotional communications, including information about MyFitnessPal's new offerings, features, offers, events, webinars, and other information.
We may infer certain information from your interactions with the Lyft Platform and other personal information available to us. For example, if you frequently ride to or from airports, we may infer you are a frequent traveler.
we may use this information to make it easier for you to find the people you want to send payments to, for account and identity verification and fraud prevention purposes, to reduce the risk you will send payments to the wrong person, or to provide other personalized services.
"Asana's customers ('Customers') are organizations that use Asana to manage their work. When a Customer provides access to Asana to their users, those users' data ('Customer Data') is controlled by the Customer. Asana processes Customer Data on behalf of the Customer and in accordance with the Customer's instructions. If you are a user of an Asana Customer's workspace, please refer to the privacy policy of the organization that has provided you access to Asana for information about their privacy practices.Excerpt from Asana's Privacy Statement
REGULATORY FRAMEWORK: This provision implicates GDPR Art.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
We read the privacy policies and terms of service of 38 AI platforms. Here is what they say about training, retention, arbitration, and liability.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision clarifies the allocation of data responsibility in business deployments, designating the employing or sponsoring organization—rather than Asana—as the entity responsible for determining how user data is collected, used, and disclosed. This structure establishes the contractual relationship between Asana and the organization as the primary data governance arrangement.
Employees using Asana through a company account cannot directly request data deletion or access from Asana — those rights must be exercised through the employing organization, which has contractual control over the workspace data.
ConductAtlas has identified this type of provision across 279 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Asana.