Personal information governance

Personal information governance

Lifecycle, responsibilities, complaints, and annual review.

Effective date:
2026-07-31
Last updated:
2026-07-31

This publication summarizes tonia's governance policies and practices under Bill 25, s. 3.2 (CQLR P-39.1).

Lifecycle

tonia limits collection to information needed for declared purposes. Access follows roles and service needs. The Privacy Policy states retention periods; DPA Schedule 4 states periods for entrusted processing.

At expiry, information is destroyed or anonymized under law. Active data is deleted no later than 30 days after contract end. Copies already present in encrypted backups expire through rotation within the following 14 days.

Responsibilities

  • The Privacy Officer approves policies, receives requests and complaints, and coordinates incidents.
  • Engineering applies access controls, security, retention, and deletion.
  • Product owners document purposes and collection notices.
  • Authorized personnel maintain confidentiality and report incidents without delay.

Complaints

Write to privacy@tonia.ca or vieprivee@tonia.ca. tonia acknowledges receipt, verifies identity where needed, examines the facts, and responds in writing. A refusal states reasons and available recourse.

You may also contact Quebec's Commission d'accès à l'information.

Review

The Privacy Officer reviews these practices at least annually and whenever a material change affects purposes, providers, processing locations, retention, or safeguards.

Quebec law governs this agreement. Disputes are heard in the Superior Court of Quebec, district of Montreal.