Trust Center
Compliance
The legal and regulatory frameworks most relevant to ASUME. This page does not claim certifications ASUME does not hold. Independent assessments are listed on the Roadmap.
GDPR / Dutch UAVG
At ASUME, data protection, privacy, and security are fundamental to how we operate and design the Service. We are committed to high standards of data governance and support the objectives and legal requirements of the General Data Protection Regulation (GDPR) and the Dutch UAVG. ASUME B.V. is established in the Netherlands. That framework is reflected in Controller/Processor role allocation, a Data Processing Agreement, data-subject procedures, Subprocessor controls, international-transfer safeguards, and technical and organisational measures.
EU AI Act
ASUME actively works to align its AI systems and processes with the EU AI Act, including AI governance, risk assessment, and AI-literacy measures, in preparation for the Act's phased application through 2026 and 2027. ASUME assesses its roles and obligations based on the functionality and use case involved. A Customer's use of ASUME within a separate AI system does not by itself determine ASUME's regulatory role.
International data transfers
Transfer mechanisms ASUME uses when Personal Data leaves the EEA, including Standard Contractual Clauses and adequacy where applicable.
Controller / Processor role allocation
The Data Processing Agreement sets out when ASUME acts as a Processor for Customer Data and when ASUME acts as a Controller for its own processing.
Customer responsibility framework
Shared-responsibility and customer-configuration expectations published in Security Measures, including what Customers control in their workspace.