toGæther.

Association data hosted in Paris

Where toGaether's data is stored, what remains outside France and why: the precise answer to the question IT departments and DPOs ask.

4 min read

Léon, in cut paper, leans at a window among the rooftops of Paris where a small server with orange cables is running.

"Where is the data hosted?" It is one of the first questions an IT department or a data protection officer (DPO) asks before opening a platform to students. The short answer: in Paris. The full answer, which also says what is not, is below.

What is hosted and processed in France

Since August 2026, toGaether has run entirely in the Google Cloud region europe-west9, in Paris:

ComponentLocation
Application (the servers that handle each request)Paris
Database (associations, members, treasury, events…)Paris
Files (receipts, documents, photos)Paris
Technical logsParis

There is only one database, in France. The former database, which was spread across several European countries, was moved to Paris and then deleted.

What is not, and why

Three services remain outside France. We prefer to say so plainly:

  • Authentication (Google Identity Platform) is operated in the United States. It handles accounts and sign-in sessions: email address, identifier, sign-in method.
  • Push notifications to phones (Firebase Cloud Messaging) go through the United States. They carry the text of the notification, not the content of the platform.
  • Automatic reading of receipts (recognising the amount and the date on a photo of a till receipt) is carried out by an AI model on Google Cloud Vertex AI, in Belgium, within the European Union.

These services have no equivalent operated in France in the infrastructure we use. Everything else — the associations' content, the financial data, the documents — does not leave Paris.

Why it matters for a school

A data protection officer and an IT director, in cut paper, go over a document in front of the rooftops of Paris; Léon gives a thumbs-up.
Knowing exactly where the data is located simplifies the record of processing activities.

For an institution, entrusting the data of its students and its associations to a third party engages its responsibility under the GDPR. Knowing precisely where each category of data is processed makes it possible to:

  • document the processing in the institution's record of processing activities;
  • answer questions from students and their families without approximation;
  • assess transfers outside the European Union, limited here to authentication and notifications.

The other safeguards

Beyond location: encryption of data in transit and at rest, role-based permissions (a member of an association does not see what the treasurer sees, a school sees only its own associations), logging of sensitive access, and rights of access and erasure for every user.

If your institution enables single sign-on (SSO), the directory password is never sent to toGaether: authentication stays with you.

A specific question from your IT department or your DPO? Write to us, and we will answer point by point.

Read next

  1. Léon, in cut paper, walks into the school while signing in on his phone, an orange badge around his neck.Product · 5 min readSSO: signing students in with their school account
  2. Léon, in cut paper, holds up his ticket at the entrance to a gala lit with string lights.Product · 5 min readTicketing for a student gala with HelloAsso
  3. At the door of an event, a volunteer scans the membership card Léon, in cut paper, shows her on his phone.Product · 4 min readOnline membership and a membership card on your phone

A question these guides leave open?

Write to us with your case: bylaws, treasury, a high-risk event. We'll answer, and show you what toGæther would do in your place.

Requesta demo

© 2026 Gaether Inc. — toGæther. All rights reserved.Société par actions simplifiée à associé unique (SASU) · 104 543 830 R.C.S. Nanterre