Skip to content

Subprocessors

Last updated: 2026-08-05

This is the current list of subprocessors engaged to process customer personal data in the Taiga platform. It is the list referred to by the data processing agreement annexed to the services agreement. Subprocessors used for our own business operations rather than for the platform are not listed here.

Who we are

Taiga AI Oy Business ID: 3607851-2 Lapinlahdenkatu 16 00180 Helsinki, Finland Email: hello@tai.ga

Notice and your right to object

Customers grant general written authorization to engage sub-processors. We inform customers of any intended addition or replacement before it takes effect, and a customer may object on reasonable grounds within the notice period set by its data processing agreement. If a customer objects, we negotiate in good faith to find a solution; the agreement sets out what follows if none is found. The notice period, the objection right, and the consequences are governed by that agreement, not by this page.

Notifications go to the contact named in the agreement. To add or change a recipient, or to be told about changes to this page, write to hello@tai.ga.

Current subprocessors

Subprocessors
SubprocessorPurposeData processedLocation
Amazon Web Services EMEA SARLInfrastructure, database, storage, identity, model inference, emailAll platform dataEU, eu-central-1 Frankfurt
Anthropic, accessed through Amazon BedrockFoundation model inferencePrompts and responses, never used for trainingEU regions, through Amazon Bedrock
GitHubSource-code access through a GitHub App the customer installsCustomer repositories, scope set and revocable by the customerCustomer's own GitHub instance
GoogleOptional SSO identity provider; documentation lookups by the design and security agentsSSO identity claims if enabled; agent documentation queriesEU
MicrosoftOptional Microsoft Entra ID single sign-onSign-in claims in transit only, not stored by Taiga's Entra tenantCustomer's own Entra tenant

What we require of them

Each subprocessor is bound by contract to data protection obligations equivalent to those in our own data processing agreement, and has to provide sufficient guarantees of appropriate technical and organizational measures. We remain fully liable to the customer for the performance of a subprocessor's obligations.

Data residency

Personal data is processed inside the EU or EEA. We do not transfer customer personal data outside the EU or EEA without the customer's prior written consent and appropriate safeguards under Chapter V of the GDPR. EU-only operation is enforced at the infrastructure boundary by AWS Control Tower guardrails that deny non-EU regions.

Contact

Questions about this list go to hello@tai.ga

How platform data is handled