Association data hosted in Paris
Where toGaether's data is stored, what remains outside France and why: the precise answer to the question IT departments and DPOs ask.

"Where is the data hosted?" It is one of the first questions an IT department or a data protection officer (DPO) asks before opening a platform to students. The short answer: in Paris. The full answer, which also says what is not, is below.
What is hosted and processed in France
Since August 2026, toGaether has run entirely in the Google Cloud region europe-west9, in Paris:
| Component | Location |
|---|---|
| Application (the servers that handle each request) | Paris |
| Database (associations, members, treasury, events…) | Paris |
| Files (receipts, documents, photos) | Paris |
| Technical logs | Paris |
There is only one database, in France. The former database, which was spread across several European countries, was moved to Paris and then deleted.
What is not, and why
Three services remain outside France. We prefer to say so plainly:
- Authentication (Google Identity Platform) is operated in the United States. It handles accounts and sign-in sessions: email address, identifier, sign-in method.
- Push notifications to phones (Firebase Cloud Messaging) go through the United States. They carry the text of the notification, not the content of the platform.
- Automatic reading of receipts (recognising the amount and the date on a photo of a till receipt) is carried out by an AI model on Google Cloud Vertex AI, in Belgium, within the European Union.
These services have no equivalent operated in France in the infrastructure we use. Everything else — the associations' content, the financial data, the documents — does not leave Paris.
Why it matters for a school

For an institution, entrusting the data of its students and its associations to a third party engages its responsibility under the GDPR. Knowing precisely where each category of data is processed makes it possible to:
- document the processing in the institution's record of processing activities;
- answer questions from students and their families without approximation;
- assess transfers outside the European Union, limited here to authentication and notifications.
The other safeguards
Beyond location: encryption of data in transit and at rest, role-based permissions (a member of an association does not see what the treasurer sees, a school sees only its own associations), logging of sensitive access, and rights of access and erasure for every user.
If your institution enables single sign-on (SSO), the directory password is never sent to toGaether: authentication stays with you.
A specific question from your IT department or your DPO? Write to us, and we will answer point by point.


