Security & trust
Who else touches your data.
The current list of sub-processors Tokoaido engages, what each one processes, and where. Published under GDPR Art. 28(3)(h) and referenced by our DPA, which grants general written authorisation for this list as it stands.
Engaged today
Processing on our infrastructure right now
These process data for every customer of the managed service. In a self-hosted deployment the hosting and email entries are yours rather than ours, and the list shortens accordingly.
| Sub-processor | Purpose | Location | Personal data it can receive |
|---|---|---|---|
Hetzner Hetzner Online GmbH | Hosting, compute, storage and backups | Helsinki, Finland | All tenant data, at rest and in transit |
Brevo Sendinblue SAS | Transactional email — password resets, invitations, approval and outage alerts | France | Recipient address, display name, organization name, message content |
MiniMax | Language model for Copilot planning and reasoning | Singapore* Transfer outside the EEA | Prompt content only. Never PHI or PCI at any setting; PII only if explicitly permitted |
Let's Encrypt Internet Security Research Group | TLS certificate issuance | United States Outside the EEA · no personal data | None — domain names only, which are public |
Namecheap | Domain registration and DNS | United States Outside the EEA · no personal data | None — DNS records only |
* Processing location stated by the provider and not yet confirmed by us in writing. We are asking as part of executing their data-processing agreement, and will correct this page if the answer differs. Affects: MiniMax.
International transfers
What leaves the EEA, and what cannot
Prompt content only. Never PHI or PCI at any setting; PII only if explicitly permitted
Transfers rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three, with a transfer impact assessment. The model boundary is enforced in code rather than promised in prose: protected health information and cardholder data are never sent to an external model at any setting available to an operator or a customer, and personal data is not sent by default. Where a request is refused it is served by the in-boundary deterministic path, and the interface says so instead of degrading silently.
Optional
Off unless you turn them on
None of these processes anything until you configure it. They are listed because you are entitled to know what the product can reach, not only what it currently does.
| Sub-processor | Purpose | Location | Personal data it can receive |
|---|---|---|---|
Resend Enabled by: EMAIL_DRIVER=resend | Alternative email transport | United States Transfer outside the EEA | Recipient address and message content |
Postmark Enabled by: EMAIL_DRIVER=postmark | Alternative email transport | United States Transfer outside the EEA | Recipient address and message content |
SendGrid Enabled by: EMAIL_DRIVER=sendgrid | Alternative email transport | United States Transfer outside the EEA | Recipient address and message content |
IntelliMento Enabled by: INTELLIMENTO_API_URL | Document intelligence (sister product) | Helsinki, Finland | Document contents the customer uploads |
Exhibit Enabled by: EXHIBIT_API_URL | Report and PDF generation (sister product) | Helsinki, Finland | Whatever the report contains |
What is not yet in place
Article 28(4) requires back-to-back data-protection terms with each sub-processor. We have not yet executed a signed DPA with Hetzner, Brevo, MiniMax. We would rather say so here than let you discover it during diligence. If this matters to your timeline, ask us where it stands before you sign.
Changes
You are told before, not after
We give 30 days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that window, and if we cannot resolve the objection you may terminate the affected services without penalty. To receive notices, write to support@tokoaido.com.