ASUME

Trust Center

Privacy Policy

Last updated: 8 September 2026

Introduction

ASUME B.V. (“ASUME,” “we,” “us,” or “our”) respects your privacy and is committed to protecting Personal Data.

This Privacy Policy explains how we collect, obtain, use, disclose, store, and protect Personal Data when you visit our websites, request access, book a demo, create or use an ASUME account, join a Workspace, connect integrations or data sources, communicate with us, interact with the Service, or otherwise engage with ASUME. It also explains how ASUME processes professional Personal Data obtained from publicly accessible sources and the rights available to individuals under applicable data-protection law.

ASUME B.V. is established in the Netherlands. Where applicable, our processing is governed by Regulation (EU) 2016/679 (the “GDPR”), the Dutch Uitvoeringswet Algemene verordening gegevensbescherming (“UAVG”), and other applicable privacy and data-protection laws.

The Service is designed for business and professional use and is not intended for consumers or children.

This Privacy Policy applies where ASUME acts as a controller of Personal Data. Where ASUME processes Personal Data solely on behalf of a Customer as a processor, that processing is governed by the applicable customer agreement and our Data Processing Agreement (“DPA”). In those circumstances, the relevant Customer generally determines the purposes and means of the processing and should normally be contacted first in relation to Data Subject Requests.

This Privacy Policy should be read together with our Terms of Service, Cookie Policy, DPA, Subprocessor List, Security Measures, Acceptable Use Policy, Service and Technical Parameters, and Legal Notice.

Full company and registered details for ASUME B.V. are available in our Legal Notice.

1. Personal Data We Collect

1.1. Account and Workspace Information

When you create or use an ASUME account, we may collect information including your name, business email address, employer, job title or role, profile information, Workspace membership, account settings, authentication information, permissions, and other information necessary to administer your account and access to the Service.

1.2. Contact, Sales, and Customer Relationship Information

If you contact us, request access, book a demo, participate in customer discovery, join a waitlist, attend an event, or otherwise interact with ASUME in a business context, we may collect your name, business contact information, employer, professional role, country or region, professional profile information, communications, meeting information, product feedback, research notes, and relationship history.

1.3. Billing and Contract Information

Where you represent a Customer or prospective Customer, we may collect billing contact information, billing address, VAT information, company registration information, Order Form details, subscription information, invoices, payment status, purchase history, and records relating to our contractual relationship.

1.4. Payment Information

Payments may be processed by third-party payment providers. ASUME generally does not need to receive or store complete payment-card credentials. We may receive limited information such as payment status, payment method type, last four digits of a payment card, expiry information, billing details, and transaction identifiers.

1.5. Support and Communications

If you communicate with ASUME for support or another purpose, we may process the content of your request, emails, messages, troubleshooting information, technical information, attachments, feedback, and other information you choose to provide.

1.6. Inputs and Requests

The Service allows Users to submit prompts, queries, objectives, configuration choices, files, notes, company lists, and other information. Where those materials contain Personal Data, that Personal Data may be processed to provide the requested functionality.

1.7. Usage and Technical Information

When you use the Service, we may automatically collect information concerning Workspace activity, feature usage, API activity, integration events, exports, authentication activity, error logs, performance information, security events, IP addresses, device and browser information, operating system, approximate location derived from IP address, timestamps, session information, and other technical or diagnostic information.

1.8. Cookies and Similar Technologies

We use cookies and similar technologies to operate and secure our websites and Service, remember preferences, analyse usage and performance, and, where permitted, support marketing activities. More information about the technologies we use and your choices is provided in our Cookie Policy.

1.9. Customer Data

Customers may upload, connect, submit, or otherwise make information available to ASUME. Depending on the Customer's configuration, Customer Data may include CRM information, company and account lists, business contacts, sales notes, communications, meeting or call information, transcripts, internal documents, reports, feedback, and data obtained through Customer-enabled integrations. Where ASUME acts as processor in relation to such Personal Data, the DPA applies.

1.10. Integration Data

Where a Customer enables an integration, we may receive and process information from the connected service within the permissions and access scopes configured by the Customer or its authorised Users.

1.11. Information from Third Parties

We may receive Personal Data from employers, Customers, Customer-authorised integrations, authentication providers, service providers, event organisers, referrals, business partners, and publicly accessible sources.

1.12. Authentication Providers

If you authenticate using a third-party provider, we may receive information such as your name, business email address, profile image, organisation, authentication metadata, and login status, depending on the provider and your configuration.

2. Personal Data from Public Sources

2.1. Public-Source Professional Information

ASUME may obtain Personal Data from sources other than the individual where that information is publicly accessible and relevant to understanding a company or other business organisation. Such information may include a person's name, employer, professional role, business contact information, professional profile, employment information, publicly made professional statements, authorship or participation in company materials, and other information published in a professional or business context.

2.2. Sources

Public-source Personal Data may be obtained from company websites, product and documentation sites, professional profiles, public registers, job postings, corporate announcements, press releases, case studies, investor or regulatory materials, public business directories, public articles and reports, public social-media pages, and other sources accessible to the public.

2.3. Provenance Information

ASUME may retain information concerning where information was obtained, including source URL, publisher or source identity, retrieval time, publication date where available, and limited supporting source material. We use provenance information to support accuracy, evidence traceability, source refresh, rights management, suppression, correction, and compliance.

2.4. Company-First Processing

ASUME is designed primarily to understand companies rather than to construct comprehensive profiles of individuals. Where professional Personal Data provides evidence about a company, we seek where appropriate to transform that evidence into company-level facts, features, relationships, or inferences and to minimise retention or presentation of person-level information that is not necessary for the relevant business purpose.

2.5. Sensitive Information

ASUME is not designed to collect or infer special-category Personal Data, criminal-offence information, children's information, biometric information, health information, or other highly sensitive attributes from public sources. Where we identify such information and it is not necessary and legally justified for processing, we may exclude, suppress, minimise, or delete it.

2.6. Article 14 Transparency

Where ASUME obtains Personal Data from a source other than the individual and Article 14 GDPR applies, we assess the applicable transparency requirements, including whether individual notice is required and whether an exception recognised by applicable law applies. Where ASUME relies on an exception to individual notice, we document the basis for doing so and apply appropriate safeguards. This Privacy Policy is also intended to provide publicly accessible information about ASUME's public-source processing.

4. Customer-Controlled Sources

4.1. Customer-Controlled Sources

A Customer may identify or verify a website, domain, database, documentation portal, API, repository, knowledge base, or other source that the Customer owns, controls, or is otherwise authorised to make available to ASUME as described in our Terms of Service.

4.2. Personal Data in Customer-Controlled Sources

A Customer's contractual authorisation for ASUME to access and process a Customer-Controlled Source does not remove the rights of individuals whose Personal Data appears in that source. Where ASUME processes such Personal Data as an independent controller, we process it only where we have an applicable lawful basis and in accordance with this Privacy Policy and applicable law.

4.3. Customer Responsibility

Customers are responsible for ensuring that they possess the necessary rights and authority to make Customer-Controlled Sources available to ASUME. Where a Customer determines the purposes and means of Personal Data processing and ASUME acts solely on the Customer's behalf, the DPA applies.

5. AI, Derived Data, and Model Training

5.1. AI-Assisted Processing

ASUME uses automated systems, machine learning, and AI-assisted methods to analyse information, structure company evidence, generate facts and features, maintain company understanding, identify business signals, create classifications and relationships, and generate evidence-linked Outputs. These systems may process Personal Data where Personal Data appears in Customer Data, Public Source Data, integrations, Customer-Controlled Sources, requests, or other information processed by the Service.

5.2. Customer Data Training

ASUME does not use Customer Data, Customer prompts, private integration content, or Customer-specific Outputs to train or fine-tune generally reusable ASUME or third-party AI models unless the Customer expressly opts in or otherwise agrees in writing. Processing Customer Data for model inference, retrieval, temporary context processing, support, debugging, security, fraud or abuse detection, or evaluation necessary to provide the Service does not constitute model Training solely because an AI system is involved.

5.3. Third-Party Model Training

ASUME does not authorise third-party foundation-model providers to train their generally available models on Customer Data unless the Customer expressly enables or agrees to such use. Providers may process limited information where reasonably necessary for security, fraud prevention, abuse detection, policy enforcement, or other purposes permitted under ASUME's contractual arrangements and applicable law.

5.4. Customer-Controlled Source Training

Subject to applicable law, content obtained from a Customer-Controlled Source may be used by ASUME to train, fine-tune, evaluate, benchmark, test, develop, and improve ASUME models and related systems unless the Customer opts out through available Workspace settings or by written notice to ASUME. An opt-out under the Customer agreement generally applies prospectively. Where such content contains Personal Data, any continued processing remains subject to applicable data-protection law and applicable Data Subject rights.

5.5. Public Source Data

Subject to applicable law, third-party rights, applicable rights reservations, and ASUME's legal and compliance controls, ASUME may use Public Source Data to develop, train, test, evaluate, benchmark, and improve ASUME models and systems. Where Public Source Data used for such purposes contains Personal Data, ASUME applies the lawful-basis, minimisation, transparency, retention, and rights requirements applicable to that processing.

5.6. Derived Data

ASUME may generate structured facts, features, classifications, embeddings, representations, relationships, signals, evaluations, and other information derived from information processed by the Service (“Derived Data”). Derived Data may itself constitute Personal Data where it relates to an identified or identifiable individual. We treat such information as Personal Data for as long as applicable data-protection law requires.

5.7. Aggregated, De-Identified, and Anonymous Information

ASUME may create aggregated, de-identified, or anonymous information where the resulting information no longer identifies an individual, Customer, specific Workspace, or Customer record. We may use such information for analytics, research, benchmarking, security, evaluation, product development, and other lawful purposes. Where information has been anonymised within the meaning of applicable law, we do not intentionally re-identify it.

5.8. Automated Decisions

ASUME is designed to support human review and business decision-making. ASUME does not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects on an individual. Customers are prohibited from using the Service as the sole determinative basis for such decisions where prohibited by our Terms or applicable law.

6. How We Share Personal Data

6.1. Service Providers and Subprocessors

We may disclose Personal Data to service providers that support hosting, infrastructure, storage, databases, authentication, analytics, communications, billing, payment processing, security, logging, monitoring, support, AI systems, search, retrieval, and other operations. Where ASUME acts as processor, subprocessors are governed by our DPA and are identified in our Subprocessor List where required.

6.2. AI, Search, Retrieval, and Infrastructure Providers

Information may be transmitted to AI model providers, cloud providers, search providers, retrieval providers, database or vector infrastructure providers, and other technical providers where reasonably necessary to provide or operate the Service. We apply contractual and technical safeguards appropriate to the processing involved.

6.3. ASUME Customers

Where relevant to a Customer's authorised use of the Service, publicly available professional Personal Data may be included in, referenced by, or used to support company-related Outputs provided to authorised Customers. Customers are responsible for establishing their own lawful basis and satisfying their own privacy obligations when they independently process such Personal Data for their own purposes.

6.4. Workspace Administrators

If you use ASUME through an organisation or Customer Workspace, authorised administrators of that organisation may be able to access or manage information relating to your Account, Workspace membership, permissions, activity, connected sources, Inputs, Outputs, and other Workspace information depending on the Service configuration.

6.5. Integrations and Third-Party Services

Where you or your organisation enables a third-party integration, Personal Data may be disclosed to or received from that integration in accordance with the permissions configured by the Customer. Third-party services are independently governed by their own privacy policies and terms.

6.6. Affiliates

ASUME may share Personal Data with entities that control, are controlled by, or are under common control with ASUME where necessary for legitimate business operations and where such processing is consistent with this Privacy Policy.

6.7. Professional Advisers

We may disclose Personal Data to lawyers, auditors, accountants, insurers, banks, consultants, and other professional advisers where reasonably necessary.

6.8. Legal and Regulatory Disclosures

We may disclose Personal Data to courts, regulators, supervisory authorities, tax authorities, law-enforcement bodies, government agencies, or other appropriate recipients where required by law or reasonably necessary to protect legal rights, security, safety, systems, or property.

6.9. Corporate Transactions

Personal Data may be disclosed in connection with an actual or prospective merger, acquisition, investment, financing, restructuring, due-diligence process, asset transfer, or similar corporate transaction, subject to appropriate confidentiality and data-protection safeguards.

6.10. At Your Direction

We may disclose Personal Data where you or the relevant Customer instructs, enables, or consents to the disclosure through the Service.

7. Customer Processing and Downstream Use

7.1. Customer Responsibility

Where a Customer independently exports, stores, enriches, combines, contacts, profiles, or otherwise processes Personal Data contained in an Output for its own purposes, that Customer is responsible for its subsequent processing and the obligations applicable to it as controller or other regulated actor.

7.2. No Downstream Legal Clearance

ASUME's inclusion of publicly available professional information in an Output does not constitute a representation that a Customer may lawfully contact, market to, profile, monitor, publish information about, or otherwise process that person for every purpose.

7.3. Customer Notices and Consents

Unless expressly agreed otherwise, ASUME does not provide privacy notices, obtain consents, conduct legitimate-interest assessments, perform direct-marketing compliance analysis, or satisfy other Customer-specific privacy obligations on behalf of Customers.

8. Retention

8.1. General Principle

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy or as otherwise required or permitted by applicable law. Retention depends on the nature and sensitivity of the Personal Data, the purposes of processing, the relationship with the relevant individual or Customer, security requirements, dispute and enforcement needs, statutory obligations, and whether the purpose can reasonably be achieved using less or no Personal Data.

8.2. Account and Customer Relationship Information

We generally retain Account, Customer relationship, support, and business-contact information for the duration of the relevant relationship and for a reasonable period thereafter where necessary for administration, legal compliance, dispute resolution, fraud prevention, or legitimate business records.

8.3. Billing and Contract Records

Contract, billing, tax, accounting, and transaction records may be retained for periods required by Dutch and other applicable accounting, tax, and corporate laws.

8.4. Customer Data

Where ASUME acts as processor, Customer Data is retained and deleted in accordance with the applicable Customer agreement, DPA, Workspace settings, and backup practices.

8.5. Public Source Data

Public-source Personal Data and associated provenance information may be retained while reasonably necessary to maintain and revise company understanding, support evidence traceability, assess accuracy and freshness, prevent duplicate or stale information, manage rights and suppression requests, and provide the Service. We may periodically refresh, correct, minimise, suppress, or remove such information.

8.6. Security and Compliance Records

Security, authentication, fraud-prevention, audit, and compliance records may be retained for periods reasonably necessary to investigate incidents, protect the Service, demonstrate compliance, or establish, exercise, or defend legal claims.

8.7. Suppression Records

Where appropriate, ASUME may retain a minimal identifier or suppression record after complying with an objection, deletion, or similar request where retaining that limited information is necessary to ensure that information is not unintentionally recollected, republished, or processed again. Such records are used only for suppression, compliance, security, or related legal purposes.

8.8. Backups

Personal Data may remain in backups, disaster-recovery systems, or immutable logs for a limited period after deletion from active systems. Such data remains subject to appropriate safeguards and is not ordinarily restored or processed except for disaster recovery, security, or legal requirements.

9. Security

9.1. Security Measures

We maintain technical and organisational measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, alteration, or disclosure. Measures may include access controls, authentication, encryption in transit and, where appropriate, at rest, logging and monitoring, vulnerability management, secure development practices, incident response, vendor-management controls, backups, and resilience measures.

9.2. Security Information

Additional information about our security practices is available in our Security Measures.

9.3. No Absolute Security

No network, software, AI model, storage system, integration, or transmission mechanism can be guaranteed to be completely secure. You should therefore use appropriate care when deciding what information to submit to the Service.

9.4. Security Contact

If you believe an Account or information handled by ASUME has been compromised, please contact security@asume.ai.

10. Your Rights and Choices

10.1. GDPR Rights

Where the GDPR applies, you may have the right to request access to Personal Data about you, correction of inaccurate information, deletion, restriction of processing, portability where applicable, and information about our processing. You may also have the right to object to processing based on legitimate interests and to withdraw consent where processing is based on consent.

10.2. Right to Object

Where we rely on legitimate interests, you have the right to object to processing on grounds relating to your particular situation. Where required by applicable law, we will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms or the processing is necessary for the establishment, exercise, or defence of legal claims.

10.3. Direct Marketing

You may object to processing for direct-marketing purposes at any time. Where you do so, we will stop processing your Personal Data for that purpose.

10.4. Public-Source Correction and Suppression

If ASUME maintains publicly sourced professional information about you, you may contact us to request access, correction, deletion where applicable, restriction, or objection to further processing. Depending on the circumstances and applicable law, we may correct the information, suppress it from relevant Outputs or future refresh, delete it, or retain a minimal suppression record to prevent re-collection.

10.5. Identity Verification

We may request information reasonably necessary to verify your identity and protect Personal Data before fulfilling a privacy request.

10.6. Customer-Controlled Personal Data

If your request concerns Personal Data that ASUME processes solely on behalf of a Customer, we may refer you to that Customer or forward your request to the Customer where appropriate. We assist Customers with applicable requests in accordance with the DPA and applicable law.

10.7. Withdrawal of Consent

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing undertaken before withdrawal.

10.8. Automated Decision-Making

ASUME does not intend to make solely automated decisions that produce legal effects or similarly significant effects on individuals. If applicable law provides rights relating to automated decision-making in a particular context, those rights remain available.

10.9. Complaints

You have the right to lodge a complaint with a competent supervisory authority. Because ASUME B.V. is established in the Netherlands, our lead supervisory authority may, where applicable, be the Autoriteit Persoonsgegevens. You may also have the right to contact the supervisory authority in the EEA country of your habitual residence, place of work, or alleged infringement.

You can find information about the Dutch supervisory authority at autoriteitpersoonsgegevens.nl.

11. International Transfers

11.1. Processing Locations

ASUME is established in the Netherlands and may process Personal Data in the European Economic Area and in other countries where our service providers, subprocessors, or infrastructure operate.

11.2. Transfer Safeguards

Where Personal Data protected by the GDPR is transferred outside the EEA to a country that is not recognised as providing an adequate level of data protection, we use an appropriate transfer mechanism where required, such as European Commission Standard Contractual Clauses, together with transfer assessments and supplementary technical, organisational, or contractual safeguards where appropriate.

11.3. Adequacy Decisions

Where the European Commission has recognised a jurisdiction or applicable transfer framework as providing adequate protection, we may rely on that adequacy decision.

11.4. Other Jurisdictions

Where UK, Swiss, or other privacy laws apply, we use applicable transfer safeguards required under those laws.

11.5. Information About Transfers

You may contact us at privacy@asume.ai for additional information concerning the safeguards applicable to relevant international transfers.

12. Cookies and Similar Technologies

12.1. Website Technologies

We use cookies and similar technologies for purposes such as essential website functionality, authentication, preferences, security, analytics, performance, and, where permitted, marketing.

12.2. Consent

Where Dutch or other applicable electronic-communications or privacy law requires consent for a cookie or similar technology, we seek that consent before using the relevant technology.

12.3. Choices

Additional details concerning the technologies we use, their providers and purposes, retention periods, and how to manage your choices are available in our Cookie Policy and cookie-preference interface.

13. Children

13.1. Business Service

ASUME is designed for business and professional use and is not directed to individuals under the age of 18.

13.2. Unintended Collection

We do not knowingly seek to collect Personal Data from children. If we become aware that we have unintentionally obtained Personal Data concerning a child in circumstances where we do not have an appropriate legal basis to process it, we may delete, suppress, restrict, or otherwise appropriately handle that information.

14. Jurisdiction-Specific Disclosures

14.1. Additional Rights

Individuals in certain jurisdictions may have privacy rights or disclosures in addition to those described in this Privacy Policy. Where such laws apply to ASUME, we will provide any additional notices and mechanisms required by applicable law.

14.2. United States

Certain U.S. state privacy laws use specific definitions of terms including “sale,” “sharing,” “targeted advertising,” “consumer,” and “sensitive data.” Where ASUME becomes subject to such laws in relation to a particular activity, we will provide the disclosures and opt-out mechanisms required by those laws.

14.3. Customer Data

ASUME does not sell Customer Data. ASUME does not disclose Customer Data for cross-context behavioural advertising.

Nothing in this Section limits disclosures of Public Source Data or professional information through legitimate company-intelligence functionality where such processing is otherwise permitted by applicable law and described in this Privacy Policy.

15. Changes to This Privacy Policy

15.1. Updates

We may update this Privacy Policy to reflect changes in the Service, technology, law, regulatory guidance, our processing practices, or other circumstances.

15.2. Notice

When we update this Privacy Policy, we will publish the revised version and update the “Last updated” date. Where required by applicable law or appropriate given the nature of the change, we will provide additional notice.

Changes to this Privacy Policy do not retroactively create a lawful basis for processing that previously lacked one.

16. Contacting Us

16.1. Controller

The controller responsible for the independent processing described in this Privacy Policy is:

ASUME B.V. The Netherlands

Full registered company information is available in our Legal Notice.

16.2. Privacy Requests

If you have questions concerning this Privacy Policy, want to exercise a Data Subject right, want to object to or request suppression of publicly sourced professional information, or otherwise want to contact us about our processing of Personal Data, contact:

privacy@asume.ai

16.3. Security

For suspected security incidents, Account compromise, or security-related concerns, contact:

security@asume.ai

16.4. Rights and Source Matters

Matters concerning copyright, database rights, source restrictions, confidentiality, or other non-privacy source rights may be submitted to:

legal@asume.ai

© 2026 ASUME B.V.