Data Processing Addendum
Last updated July 2026
When you use Tokoaido, you decide what data is processed and why; we process it on your behalf, only to provide the service. Our Data Processing Addendum (DPA) puts that relationship in writing and is executed as part of your commercial agreement. This page summarizes what it covers.
01What the DPA covers
The DPA governs our processing of personal data contained in the operational data you connect. You act as the data controller; Tokoaido acts as your processor (and, where relevant, engages sub-processors under equivalent obligations).
02Processing on your instructions
We process personal data only on your documented instructions and for the sole purpose of providing, securing and supporting the service — never for our own purposes, and never sold. Our neutral architecture means your systems of record stay authoritative and, in a self-hosted deployment, your data does not need to move to us at all.
03Security measures
- Encryption in transit (TLS) and at rest
- Strict multi-tenant isolation and role-based access control
- Session tokens in HttpOnly cookies, never exposed to the browser
- An immutable, hash-chained audit trail of actions taken in the platform
- Least-privilege, tool-scoped agents and human-in-the-loop approval for consequential actions
04Sub-processors
We maintain a current list of sub-processors (for example, cloud hosting and model providers), bind them to data-protection obligations no less protective than ours, and notify you of material changes so you can object. The definitive list is provided with your DPA.
05International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Regional data-residency options let you keep processing in a chosen location.
06Assisting with data-subject requests
We provide the tooling and cooperation you need to fulfill data-subject rights — access, correction, deletion, portability and restriction — typically routed through you as controller.
07Personal-data breach notification
We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own notification obligations.
08Retention, return and deletion
Data is retained only as long as needed to provide the service or as you configure. On termination, personal data is deleted or returned according to your instructions.
09Audit and information rights
We make available the information reasonably necessary to demonstrate compliance with the DPA, and support audits within a sensible, security-preserving framework.
10Requesting or executing a DPA
Email security@tokoaido.com to request our current DPA and sub-processor list. It is executed as part of your order form or master agreement.