Security & trust

Who else touches your data.

The current list of sub-processors Tokoaido engages, what each one processes, and where. Published under GDPR Art. 28(3)(h) and referenced by our DPA, which grants general written authorisation for this list as it stands.

5 engaged today1 transfer outside the EEA5 optional, off unless you enable them

Engaged today

Processing on our infrastructure right now

These process data for every customer of the managed service. In a self-hosted deployment the hosting and email entries are yours rather than ours, and the list shortens accordingly.

Sub-processorPurposeLocationPersonal data it can receive
Hetzner
Hetzner Online GmbH
Hosting, compute, storage and backups
Helsinki, Finland
All tenant data, at rest and in transit
Brevo
Sendinblue SAS
Transactional email — password resets, invitations, approval and outage alerts
France
Recipient address, display name, organization name, message content
MiniMax
Language model for Copilot planning and reasoning
Singapore*
Transfer outside the EEA
Prompt content only. Never PHI or PCI at any setting; PII only if explicitly permitted
Let's Encrypt
Internet Security Research Group
TLS certificate issuance
United States
Outside the EEA · no personal data
None — domain names only, which are public
Namecheap
Domain registration and DNS
United States
Outside the EEA · no personal data
None — DNS records only

* Processing location stated by the provider and not yet confirmed by us in writing. We are asking as part of executing their data-processing agreement, and will correct this page if the answer differs. Affects: MiniMax.

International transfers

What leaves the EEA, and what cannot

MiniMax· Singapore

Prompt content only. Never PHI or PCI at any setting; PII only if explicitly permitted

Transfers rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three, with a transfer impact assessment. The model boundary is enforced in code rather than promised in prose: protected health information and cardholder data are never sent to an external model at any setting available to an operator or a customer, and personal data is not sent by default. Where a request is refused it is served by the in-boundary deterministic path, and the interface says so instead of degrading silently.

Optional

Off unless you turn them on

None of these processes anything until you configure it. They are listed because you are entitled to know what the product can reach, not only what it currently does.

Sub-processorPurposeLocationPersonal data it can receive
Resend
Enabled by: EMAIL_DRIVER=resend
Alternative email transport
United States
Transfer outside the EEA
Recipient address and message content
Postmark
Enabled by: EMAIL_DRIVER=postmark
Alternative email transport
United States
Transfer outside the EEA
Recipient address and message content
SendGrid
Enabled by: EMAIL_DRIVER=sendgrid
Alternative email transport
United States
Transfer outside the EEA
Recipient address and message content
IntelliMento
Enabled by: INTELLIMENTO_API_URL
Document intelligence (sister product)
Helsinki, Finland
Document contents the customer uploads
Exhibit
Enabled by: EXHIBIT_API_URL
Report and PDF generation (sister product)
Helsinki, Finland
Whatever the report contains

What is not yet in place

Article 28(4) requires back-to-back data-protection terms with each sub-processor. We have not yet executed a signed DPA with Hetzner, Brevo, MiniMax. We would rather say so here than let you discover it during diligence. If this matters to your timeline, ask us where it stands before you sign.

Changes

You are told before, not after

We give 30 days' notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that window, and if we cannot resolve the objection you may terminate the affected services without penalty. To receive notices, write to support@tokoaido.com.