ASUME

Trust Center

Data Privacy

How ASUME handles personal data: the public privacy documents, data-subject procedures, retention, and transfer safeguards. Classification and a standalone privacy-training module are still being built out.

Privacy Policy

The Privacy Policy is written for transparency. It explains how ASUME processes Personal Data where it acts as a controller, including Personal Data from public sources and Personal Data related to use of the Service.

Where ASUME processes Customer Data as a processor, the Data Processing Agreement applies. Customer Data collected through the Service is used for the purposes defined in the Terms of Service, the DPA, and the applicable customer agreement.

Data Processing Agreement

The Data Processing Agreement sets out controller and processor terms, Subprocessor controls, international-transfer safeguards, and assistance with Data Subject Requests.

The DPA is the contractual baseline for Customer Data that ASUME processes on a Customer's behalf.

Subprocessor List

The Subprocessor List identifies current Subprocessors that may Process Processor Personal Data, with processing locations and transfer safeguards.

Customers should review the list for the providers and locations applicable to the features they use.

Data subject rights

The Privacy Policy describes rights and contact paths for access, rectification, erasure, restriction, objection, and related requests. Where ASUME acts as a processor, the Customer is ordinarily the first point of contact.

Requests can be sent to privacy@asume.ai. ASUME may ask for information reasonably necessary to verify identity before fulfilling a request.

Retention and deletion

The Privacy Policy explains how long ASUME retains Personal Data, including Customer Data, public-source records, backups, and suppression records.

Deletion and backup lifecycle for Customer Data and Processor Personal Data are also described in Security Measures.

International transfer safeguards

When Personal Data leaves the EEA, ASUME uses the transfer mechanisms described in the Privacy Policy, including Standard Contractual Clauses and adequacy where applicable.

Questions about those safeguards can be sent to privacy@asume.ai.

Data Privacy contact

Privacy questions, Data Subject Requests, and concerns about how ASUME handles Personal Data can be sent to privacy@asume.ai. The same contact is published in the Privacy Policy.

Listing this contact is the published path for privacy questions. It is not a separately attested privacy-officer appointment.

Data classification

ASUME is defining how data is classified by sensitivity so that confidential and Personal Data can be encrypted and access-controlled accordingly. Current data-minimisation and development/testing expectations are described in Security Measures.

A published rule that personally identifiable information is never used in non-production environments without documented exception approval is still being formalized and is not independently verified.

Data breach notifications

ASUME investigates and contains Personal Data incidents and notifies affected Customers when a Personal Data Breach affecting Processor Personal Data occurs, as described in the DPA and Security Measures.

Standalone Personal Data Breach Management Guidelines, including a downloadable PDF, are still being formalized and are not independently verified.

Employee privacy training

Personnel with access to material systems or information receive security guidance, instructions, or awareness appropriate to their responsibilities, as described in Security Measures. That guidance includes handling Personal Data.

A mandatory online Privacy Compliance module for every employee, and dedicated data-protection awareness days, are still being formalized and are not independently verified.