Subprocessors
Subprocessors
Last updated: 2026-08-24
This is the current list of subprocessors engaged to process customer personal data in the Taiga platform. It is the list referred to by the data processing agreement annexed to the services agreement. Subprocessors used for our own business operations rather than for the platform are not listed here.
Who we are
Taiga AI Oy Business ID: 3607851-2 Lapinlahdenkatu 16 00180 Helsinki, Finland Email: hello@tai.ga
Notice and your right to object
Customers grant general written authorization to engage sub-processors. We inform customers of any intended addition or replacement before it takes effect, and a customer may object on reasonable grounds within the notice period set by its data processing agreement. If a customer objects, we negotiate in good faith to find a solution; the agreement sets out what follows if none is found. The notice period, the objection right, and the consequences are governed by that agreement, not by this page.
Notifications go to the contact named in the agreement. Changes are also posted, dated, on our trust center updates page, which carries an Atom feed you can watch without giving us an address. To add or change a recipient, write to hello@tai.ga.
Current subprocessors
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Infrastructure, database, storage, identity, model inference, email | All platform data | EU, eu-central-1 Frankfurt |
| Anthropic, accessed through Amazon Bedrock | Foundation model inference | None. The model runs in an AWS-operated deployment account; the provider receives no prompts, responses, or service logs. | Model runs in EU regions, in AWS-operated accounts |
| GitHub | Source-code access through a GitHub App the customer installs | Customer repositories, scope set and revocable by the customer | Customer's own GitHub instance |
| Optional SSO identity provider; developer-documentation lookups by agents in the design and planning stage | SSO identity claims if enabled; agent documentation queries | EU | |
| Microsoft | Optional Microsoft Entra ID single sign-on | Sign-in claims in transit only, not stored by Taiga's Entra tenant | Customer's own Entra tenant |
Anthropic is listed even though no customer data reaches it. Amazon Bedrock deploys each provider's model into an account AWS owns and operates, one per provider in each region, and the provider has no access to that account, to the prompts and responses passing through it, or to the service logs. A few models on Bedrock can only be used if you opt in to sharing retained traffic with their provider, and we run none of them. The party processing your prompts is AWS, on the row above, and AWS is who the flow-down obligations below bind: Anthropic is named here as the model supplier rather than as a processor, and we hold no contract with it. We name the model supplier anyway, because a register that left it out would have you discover the dependency somewhere else.
What we require of them
Each subprocessor is bound by contract to data protection obligations equivalent to those in our own data processing agreement, and has to provide sufficient guarantees of appropriate technical and organizational measures. We remain fully liable to the customer for the performance of a subprocessor's obligations.
Data residency
Personal data is processed inside the EU or EEA. We do not transfer customer personal data outside the EU or EEA without the customer's prior written consent and appropriate safeguards under Chapter V of the GDPR. EU-only operation is enforced at the infrastructure boundary by AWS Control Tower guardrails that deny non-EU regions.
Contact
Questions about this list go to hello@tai.ga
Verified 2026-08-24. Changes to this register are notified on the updates page and to the contact named in your agreement.