Legal

Privacy Policy

Last updated July 2026

Tokoaido is currently a design-partner / early-access product. This document is a good-faith template that describes our intent; it should be reviewed by your counsel and finalized in your commercial agreement before any production use.

Tokoaido is a governed operating layer designed around data minimization and neutrality: your systems of record stay in place, and we process only what is needed to discover your processes and run governed automations you approve. This policy explains what we collect, why, and the controls you have.

01Who we are

Tokoaido (“we”, “us”) provides a governed OT→IT operations platform. For customer deployments, you are the data controller and we act as your data processor under a Data Processing Agreement (DPA).

02Data we process

We process the minimum necessary to deliver the service. Depending on your deployment, this may include:

  • Operational data you connect (records from CRM/ERP/HR systems, and plant-floor telemetry over OPC UA / MQTT Sparkplug / MTConnect), processed to discover processes and run approved automations.
  • Account and workspace data (names, work email, role) for authentication and access control.
  • Product telemetry (feature usage, performance and error logs) to operate and improve the service.
  • Communications you send us (e.g., a demo or design-partner request).

03Neutral by architecture

Tokoaido reads from the systems you already own; those systems remain your system of record. In a customer deployment the platform can run in your own cloud or on-premises (Docker / Kubernetes), so your operational data does not need to move to us.

Session tokens are stored in HttpOnly cookies and are never exposed to browser JavaScript. Data is encrypted in transit and at rest, and tenants are isolated from one another.

04How we use data

  • To provide, secure, and support the service.
  • To discover processes and generate governed automation recommendations you review.
  • To maintain a tamper-evident audit trail of actions taken in the platform.
  • To improve reliability and performance. We do not sell personal data.

05AI processing & governance

AI agents operate on a read-and-propose basis and execute only within the authority they have earned and that you have approved. Consequential actions require human approval, and every action is recorded to an immutable audit trail. Where third-party model providers are used, we minimize the data shared and disclose providers in your agreement.

06Sub-processors

We maintain a current list of sub-processors (e.g., cloud hosting, model providers) and provide it on request as part of your DPA. You are notified of material changes.

07Data retention

We retain operational data only as long as needed to provide the service or as configured by you (for example, telemetry retention and audit-log retention are configurable). On termination, data is deleted or returned per your agreement.

08Your rights

Depending on your jurisdiction (including GDPR/UK GDPR and US state laws), you may have rights to access, correct, export, or delete personal data. Contact us and we will honor applicable requests, typically routed through your organization as controller.

09Security

We build to a SOC 2-ready architecture with RBAC, tenant isolation, encryption in transit and at rest, and least-privilege agent scoping. Report security concerns to security@tokoaido.com.

10Contact

Questions about this policy or your data: hello@tokoaido.com.