Asgard supports regulated, high-stakes innovation — including clinical and healthcare contexts. Data protection is designed in, GDPR-first, not bolted on afterwards. Here's how we handle the personal data you trust to the platform.
Concrete, GDPR-aligned measures that govern how personal data moves through Asgard.
Personal data you put into Asgard is stored and processed within the EU/EEA. Where a transfer outside the EEA is ever required, it is governed by Standard Contractual Clauses.
Traffic to and from Asgard is encrypted with TLS, and stored data is encrypted at rest. Access is restricted on a least-privilege basis.
A GDPR Article 28 DPA is available to every customer. Under it, Fivation processes personal data only on your documented instructions.
DPA available on requestWe keep a Data Protection Impact Assessment for Asgard, and support yours where your use involves high-risk processing such as health data or profiling.
GDPR Art. 35Asgard collects only the personal data it needs to deliver the service, for clearly defined purposes, and retains it no longer than necessary.
We use a small, vetted set of sub-processors, each bound by GDPR-compliant terms. The current list is available on request, with notice of material changes.
Access, rectification, erasure, restriction, and portability — we help you honour data-subject requests within the statutory timeframes.
A documented incident process. If a personal-data breach occurs, we notify you without undue delay — and within 72 hours where the GDPR requires it.
GDPR splits responsibility between the party that decides why data is processed and the party that processes it on their behalf.
For the personal data you put into Asgard, you (or your organisation) are the data controller. You determine the purposes and means of processing, and you remain responsible for the lawful basis of the data you upload.
For that same data, Fivation acts as your processor — handling it only on your documented instructions under our DPA. For the Fivation website and direct enquiries, Fivation is the controller of the limited data you choose to share.
You control retention. On request, or on termination of your use of Asgard, we delete or return the personal data we process on your behalf within the period set out in the DPA — except where law requires us to retain it.
To exercise a data-subject right — access, rectification, erasure, restriction, or portability — contact our data protection point of contact and we'll respond within the statutory timeframes.
This page is a plain-language summary, provided for transparency. It is not legal advice and does not itself create contractual obligations. The binding terms — including the exact Data Processing Agreement text and the current sub-processor list — live on Asgard itself (linked below), since those are versioned alongside the product and this page has no way to stay in sync with them.
Asgard's own legal pages are the authoritative source — versioned, dated, and kept current as the platform evolves. This page is a plain-language summary, not a substitute.
Our GDPR Article 28 DPA, setting out how Fivation processes personal data on your behalf as your processor — current version, on Asgard.
Read the DPAThe current, named list of providers Asgard relies on, each bound by GDPR-compliant terms, with advance notice of material changes.
See the sub-processor listHow Asgard handles the personal data your organisation puts into the platform — separate from Fivation's own website privacy policy.
Read Asgard's Privacy PolicyHow Fivation handles personal data across the website and direct enquiries, where we act as the controller.
Read the Privacy Policy