

Toucan
By Toucan Toco
Toucan typical implementation process:
Discovery and use-case scoping: Define target embedded analytics use cases, data sources (warehouses, databases, APIs), key KPIs, audience, and branding requirements for the host product.
Data connection and modeling: Connect Toucan to sources such as BigQuery, Snowflake, PostgreSQL, MySQL, Google Sheets, or REST APIs using native connectors; configure built-in storage, refresh schedules, and any hybrid live/cached setup.
Data preparation in YouPrep/DataHub: Use YouPrep to join, filter, and aggregate data with no code (or SQL where needed), then organize datasets in the DataHub (create, tag, duplicate, and govern them for each app or tenant).
Dashboard and story design: Build branded dashboards with the drag-and-drop builder, choose visualizations, apply white-label styling, and add data storytelling elements (text, tips, glossaries, media, multilingual content).
Security and access configuration: Set up row-level security, roles, personalized views, and token-based multi-tenant access so each user or customer only sees their own data.
Embedding and integration: Use the Embed SDK or iframe/API options to embed dashboards into the SaaS product, web portal, or mobile app, wiring navigation, filters, and SSO or token exchange.
Toucan is designed to be highly customizable at the branding, data, architecture, and UX levels so it can fit very specific business and multi-tenant SaaS needs.
Toucan supports full white-labeling of the analytics experience: customers can remove all Toucan branding and fully align colors, fonts, logos, layout, and even custom CSS so embedded dashboards look and behave like a native part of the host product. This includes deep chart and dashboard customization via theming and custom CSS, allowing different visual styles (e.g., dark modes, minimalist charts) per application or client.
Multi-tenant and security architecture are also configurable. Toucan can run single-tenant or multi-tenant, with dynamic database connection parameters and user-token–based templating so each customer tenant can connect to its own data without separate app instances. The HADES multi-tenant service and dataset/vault components allow per-tenant caching in dedicated S3 buckets and isolation of credentials, while row-level security, role-based access, and token-based personalization ensure users only see authorized data slices.
Toucan provides structured onboarding, extensive documentation, and multiple live support channels to help new users get productive quickly.
Toucan’s onboarding for customer projects typically combines a short self-paced online module with about a month of guided coaching, where a Customer Success Manager helps define scope, design data stories, and train internal “champions” who will build and deploy apps. New customers receive best‑practice sessions on data visualisation, design workshops to craft the narrative of their dashboards, and project-methodology guidance so teams can become autonomous on the tool.
For ongoing enablement, Toucan maintains comprehensive product documentation (installation, data management, embedding tutorials, administration, and FAQs) plus a dedicated “Getting Started with Embedded Analytics” guide that walks product managers, analysts, and developers through connecting data, building datasets and charts, and embedding them securely. There is also a rich library of video tutorials and webinars on YouTube and Livestorm covering embedded workflows, self-service features, and product deep dives, which new users can follow at their own pace.
Toucan secures data with fine-grained access controls, row-level security, and token-based embedded authentication, complemented by a modern privacy framework:
Toucan uses a continuous SaaS-style release model with frequent, incremental updates rather than rare big-bang versions. Public documentation refers to major product generations (such as Toucan 3.0) but also to regular feature enhancements and improvements released throughout the year. For self-hosted or on-premise deployments, Toucan provides packaged versions that administrators can upgrade to when ready, while the vendor’s cloud instances are updated centrally by Toucan’s team.
Toucan’s contracts state that the customer retains full ownership of all data loaded into the platform, while Toucan owns the software and only processes customer data as needed to deliver the service. For portability, Toucan offers a reversibility mechanism: on termination, you can formally request export of all your data in a standard readable electronic format within a defined timeframe, after which Toucan will delete it if no export is requested.
The contract explicitly says that the customer owns all the Data, and is solely responsible for its quality, lawfulness, relevance, and for holding all necessary rights and consents to use it in Toucan.
Toucan (the Service Provider) keeps all intellectual property rights in the “Solution” and “Application Service”; the customer only receives a right of use and does not gain any ownership in the software itself.
Toucan undertakes to preserve the integrity and confidentiality of customer data, implementing technical and organizational measures to prevent unauthorized access, loss, alteration, or destruction, as described in the security annexes to the contract.
Toucan may process some personal data of customer users (identifiers, logs, incident data) for contract execution, access control, and service improvement, but this is framed as processing on behalf of or in relation to the customer, under applicable data‑protection law.
The SaaS terms include a Reversibility clause: at the customer’s request (sent by registered letter with acknowledgment of receipt no later than the effective date of termination/expiry), Toucan must return all customer data in a standard readable electronic format in an environment equivalent to Toucan’s.
Toucan can also provide additional technical assistance for data export or migration (reversibility assistance) for a fee, and the customer and its chosen third‑party provider are expected to collaborate actively to complete the data transfer.
If the customer does not request reversibility, Toucan’s policy is to completely delete the data at the end of the contract, with no obligation to store it beyond that point.
During the contract and for six months after termination, Toucan may request information and records from the customer to verify proper use of the service and respect of Toucan’s IP rights, but this is separate from the data‑export option.
Toucan also offers a self‑hosted deployment option for organizations that want “full control, customization, and data ownership,” indicating a model where data stays entirely within the customer’s own infrastructure while still using Toucan’s software.
Toucan’s standard SaaS and OEM contracts auto‑renew for the same duration as the initial term unless you give formal written notice several months before expiry, and early cancellation is penalized by requiring payment of all fees for the remaining term. Pricing is billed annually in advance, non‑refundable, and Toucan can revise subscription fees at renewal subject to conditions stated in the agreement or purchase order.
The contract starts on the “Effective Date” defined in the purchase order and runs for an “Initial Term” (e.g., one or more years) agreed in that order form.
At the end of the Initial Term, the contract renews automatically (“tacit renewal”) for successive periods equal to the Initial Term (“Additional Terms”), unless special conditions in the purchase order override this.
Either party can prevent auto‑renewal by sending a written termination notice (typically by registered letter with acknowledgment of receipt) at least three months before the end of the Initial Term or any Additional Term, unless the purchase order specifies a different notice period.
Toucan reserves the right to modify annual subscription and other prices before each renewal; any such revision follows the conditions and formulas described in the pricing section of the SaaS or OEM agreement and/or the purchase order.
On signing, the customer must pay the full setup fees (if any) and the full annual subscription fee for the first year; on each anniversary, the full annual subscription fee for the next year is due, in line with the “Annual Billing” article of the purchase order.
Invoices are payable within 30 days after issuance, prices are firm and non‑refundable, and amounts are typically stated in USD, excluding taxes, which remain payable by the customer.
If the customer terminates early (before the end of the current Initial or Additional Term), all remaining annual subscription fees for the rest of that term become immediately due and payable to Toucan.
On termination or expiry, all rights of access and use cease, and the customer must stop using the software and related credentials; this is in addition to any other remedies Toucan may have for breach or non‑payment.
Non‑payment can lead to late‑payment interest (up to 1.5% per month or the maximum rate allowed by law) and may result in delay or suspension of access to the software.
Toucan may also terminate the contract if the customer enters dissolution, reorganization, or liquidation proceedings, without prejudice to other contractual or legal remedies.
For OEM / embedded deals, the OEM agreement mirrors the SaaS model: basic subscription fees are due at the Effective Date, and full subscription fees are payable on each anniversary if the agreement auto‑renews.
GDPR & CNIL (France)
Toucan states that it complies with the General Data Protection Regulation and has filed a data‑processing declaration with the French CNIL (Declaration No. 2129004 v0), indicating formal registration of its processing activities.
Its privacy and security communication emphasises GDPR readiness and ongoing adjustment of processes to GDPR requirements (security investment, contractual safeguards, data‑protection measures).
NIST Cybersecurity Framework
Toucan describes its security and privacy management as “implementing the industry‑leading NIST practices,” and documents how its controls map to the NIST framework’s Identify–Protect–Detect–Respond–Recover functions.
Product security pages explicitly state that practices “adhere to the NIST framework,” tying platform security governance and technical controls to this model.
ISO and SOC on the hosting layer
Toucan’s SaaS infrastructure documentation explains that the underlying Azure cloud environment is certified for SOC 2, ISO 27001, ISO 27018 and ISO 9001, and refers customers to Microsoft’s documentation for details.
These attestations apply to the cloud infrastructure and managed services on which Toucan runs, not necessarily as Toucan’s own audited certificates, so they are usually framed as “leveraging Azure’s compliance posture” in security reviews.
Transport and platform security (SSL/TLS)
Toucan states that its private cloud uses “the latest security certifications (SSL Grade A…)” and elsewhere highlights “Certified SSL Grade A+,” indicating hardened TLS configurations validated by third‑party scanners.
Customers are offered isolated instances (separate network, volumes, and databases) in Toucan’s private cloud, which supports stricter segmentation for regulated environments, though this is an architectural rather than a formal standard.
You can accurately state that:
The Toucan platform is designed to be GDPR‑compliant, with CNIL registration and privacy processes aligned to EU data‑protection law.
Toucan’s security program follows the NIST Cybersecurity Framework, with controls mapped to the NIST functions for governance and technical safeguards.
Toucan is hosted on Microsoft Azure, which is certified for SOC 2, ISO 27001, ISO 27018, ISO 9001 and other cloud compliance programs; Toucan inherits these controls at the infrastructure level.