Data Processing Addendum
Last updated July 2026
When you use Tokoaido, you decide what data is processed and why; we process it on your behalf, only to provide the service. Our Data Processing Addendum (DPA) puts that relationship in writing and is executed as part of your commercial agreement. This page summarizes what it covers.
01What the DPA covers
The DPA governs our processing of personal data contained in the operational data you connect. You act as the data controller; Tokoaido acts as your processor (and, where relevant, engages sub-processors under equivalent obligations).
02Processing on your instructions
We process personal data only on your documented instructions and for the sole purpose of providing, securing and supporting the service — never for our own purposes, and never sold. Our neutral architecture means your systems of record stay authoritative and, in a self-hosted deployment, your data does not need to move to us at all.
03Security measures
- Encryption in transit (TLS) and at rest
- Strict multi-tenant isolation and role-based access control
- Session tokens in HttpOnly cookies, never exposed to the browser
- An immutable, hash-chained audit trail of actions taken in the platform
- Least-privilege, tool-scoped agents and human-in-the-loop approval for consequential actions
04Sub-processors
We publish the current list of sub-processors — named, with what each one processes and where — at /security/subprocessors, and give 30 days' notice before adding or replacing one so you can object. The DPA grants general written authorisation for that list as it stands when you sign.
05International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Residency follows your deployment: the managed service processes and stores in the EU (Helsinki, Finland) for every tenant, and self-hosted or private-cloud deployments process wherever you run them. We do not offer per-tenant residency within the managed service.
06Assisting with data-subject requests
We provide the tooling and cooperation you need to fulfill data-subject rights — access, correction, deletion, portability and restriction — typically routed through you as controller.
07Personal-data breach notification
We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own notification obligations.
08Retention, return and deletion
Data is retained only as long as needed to provide the service or as you configure. On termination, personal data is deleted or returned according to your instructions.
09Audit and information rights
We make available the information reasonably necessary to demonstrate compliance with the DPA, and support audits within a sensible, security-preserving framework.
10Requesting or executing a DPA
Email security@tokoaido.com to request our current DPA and sub-processor list. It is executed as part of your order form or master agreement.