Processing Agreement
The obligations that apply when your organization entrusts information to tonia.
- Effective date:
- 2026-07-31
- Last updated:
- 2026-07-31
1. Parties and scope
This agreement (“DPA”) is between tonia inc. (“tonia”) and the organization identified in the order form or tonia Service Agreement (“Customer”). It governs personal information entrusted by the Customer to tonia to provide the ordered services.
The DPA is designed for organization customers. It does not characterize an adult using tonia personally as an organization responsible for processing.
2. Priority
For conflicts specifically concerning entrusted processing, this DPA prevails, followed by the order form/TSA, then the Terms. The Privacy Policy remains a statutory notice and does not silently expand the service mandate.
3. Roles
The Customer determines the purposes of information submitted by its users. tonia performs the entrusted mandate under Bill 25, s. 18.3 (CQLR P-39.1).
tonia remains responsible for its own account management, billing, security, abuse prevention, contract evidence, and operational communications.
For a personal account, tonia acts as responsible under the Privacy Policy. That account remains outside this organization DPA.
4. Instructions
Documented instructions arise from the DPA, TSA, order form, organization settings, API-key scopes, your API keys or Managed and provider choices, access/DLP policies, optional request and response storage or conversation-history settings, and compliant written requests.
tonia informs the Customer if an instruction appears inconsistent with an applicable legal obligation.
5. Bill 25, section 18.3 minimum
tonia:
- takes necessary confidentiality measures;
- uses information only to perform the mandate;
- does not retain entrusted information after the mandate expires, subject to documented exceptions permitted by law;
- notifies the Customer's Privacy Officer without delay of a breach or attempted breach of a confidentiality obligation; and
- allows reasonable verification by the Customer's Privacy Officer.
These commitments implement Bill 25, s. 18.3 (CQLR P-39.1). The security, audit, and transfer schedules add contractual commitments and are not all represented as the statutory minimum.
6. Purpose limitation and no training
tonia does not use entrusted content for model training, sale, commercial profiling, targeted advertising, or legally significant automated decisions. tonia may process metadata strictly needed for service security, billing, contract evidence, and operation as described in the Privacy Policy.
7. Confidentiality and security
tonia limits access to authorized persons with a need to know and confidentiality obligations. It applies the evidenced safeguards in Schedule 2. The DPA is not a certification.
8. Incidents
tonia notifies the Customer's Privacy Officer without delay of a breach or attempted breach of an obligation concerning entrusted information under Bill 25, s. 18.3 (CQLR P-39.1). The parties cooperate on mitigation, investigation, and required notices.
Where tonia must notify the Commission d'accès à l'information or affected individuals, it does so with diligence under Bill 25, s. 3.5 (CQLR P-39.1). No statutory 72-hour deadline is stated.
9. Rights and assistance
tonia reasonably assists the Customer in locating, exporting, rectifying, or deleting entrusted information where law and architecture permit; responding to Bill 25, ss. 27, 28, and 28.1; documenting the s. 17 privacy impact assessment; and responding to the Commission.
The Customer remains responsible for requestor identity, authority, and legal basis.
10. Providers and modes
Schedule 3 identifies applicable providers, roles, jurisdictions, categories, and your API keys or Managed applicability.
With your API keys, the selected provider is normally the Customer's counterparty. In Managed, the provider participates in tonia's service chain.
Amazon Bedrock remains available only with your API keys and AWS is the Customer's counterparty. The Alibaba Cloud Model Studio exception remains limited to the recorded model group and does not extend to MiniMax, StepFun, or another catalogue.
11. Provider changes
tonia gives 30 days' advance notice where a planned material change affects a Managed provider, jurisdiction, communication route, or retention posture. Notice may be shorter for a legal or security emergency.
A Customer that objects may disable the affected route, select another route or your API keys, or terminate the affected service without penalty.
12. Communications outside Quebec
Schedule 4 describes known outside-Quebec communications, categories, jurisdictions, and applicable contractual/technical measures.
The Customer remains responsible for its assessment of instructions using your API keys. tonia supplies information it holds and completes its own assessment for Managed-chain communications under Bill 25, s. 17 (CQLR P-39.1).
13. Retention, return, and destruction
Schedule 4 states retention periods. For 30 days after mandate end, the Customer retains read-only access to export its information; no new processing is permitted. tonia deletes active data by the end of that same period. Copies already present in encrypted backups expire through rotation within the following 14 days.
Any exceptional hold must be limited to what is necessary to comply with law or protect tonia's rights in an active dispute. It requires written authorization after a documented review. Audit records are retained for the customer relationship plus 90 days, subject to such an authorized hold.
tonia provides written confirmation of destruction when the Customer requests it.
14. Verification
On reasonable request, tonia provides available policies, descriptions, attestations, and evidence needed by the Customer's Privacy Officer to verify the mandate. Verification protects other customers, begins with documentary evidence, avoids unreasonable disruption, and stays within entrusted processing.
Except after an incident or material breach, verification occurs no more than once in a 12-month period with 30 days' written notice. It begins with documentary evidence. An on-site verification requires reasonable grounds, occurs during normal business hours, and is performed by an independent auditor bound by confidentiality. The Customer bears its costs unless the verification establishes tonia's material breach.
15. Liability and term
Liability follows the TSA or Terms cap and exceptions, subject to Civil Code of Québec art. 1474 and mandatory law.
The DPA remains in force while entrusted processing continues. Confidentiality, evidence, return, and destruction obligations survive as needed to be performed.
16. Schedules
- Schedule 1 — Processing description;
- Schedule 2 — Security safeguards;
- Schedule 3 — Providers and modes;
- Schedule 4 — Communications, retention, and destruction.
Schedule 1 — Processing description
| Item | Description |
|---|---|
| Purpose | Provide the Portal, Chat, tonia Developer API, your API keys or Managed routing, sensitive-data filtering, audit log, and ordered services |
| Duration | Term of the TSA or order form, plus the limited periods in Schedule 4 |
| Individuals | Customer members and users; individuals whose information appears in content; Customer authorized managers and contacts |
| Identity and contact | Name, email, role, OIDC identifier, and organization |
| Content | Requests, outputs, files, conversations, and messages |
| Service information | Selected provider/model, applied rule, filter result, usage, IP address, or security event where relevant |
| Evidence | Content hash, authorization evidence, and accepted legal versions |
| Protected credentials | Encrypted provider API keys and tonia API keys |
| Default processing | Content processed for the duration of the request; metadata and audit evidence retained as configured |
| Optional processing | Encrypted request and response content stored for 1–90 days on request; encrypted conversation history stored for 90 days |
| Purposes | Carry out documented instructions, apply controls, route the request, return the output, produce audit evidence, and support the service |
Excluded uses
tonia does not use entrusted content to train models, sell content, deliver targeted advertising, create commercial profiles, or make legally significant automated decisions.
Personal use
This Schedule applies only to processing entrusted by an organization.
Schedule 2 — Security safeguards
| Area | Current safeguard | Verification source |
|---|---|---|
| Separation | Data and permissions separated by customer organization | Data schemas and authorization tests |
| Identity | OIDC identity service in Quebec; separate sessions for the Portal and Chat | Identity-service and session configuration |
| Sessions | Approximately 8-hour duration; closed on sign-out or revocation | Sign-in and sign-out tests |
| provider API keys | Credentials encrypted under tonia's key hierarchy | Encryption, rotation, and revocation evidence |
| Retained content | Request/response content and conversation history encrypted | Encryption evidence and retention tests |
| Access control | Roles, API-key permissions, and authorized actions | Data schemas and permission tests |
| Sensitive-data filtering | Deterministic rules and configured modes; limits published separately | Filter tests and Liability Notice |
| Audit log | Hashes, routing metadata, and authorization evidence | Audit schema and tests |
| Expiry deletion | Stored content and conversation history deleted automatically when their periods end | Expiry and deletion tests |
| Backup | Encrypted off-site copy stored in Quebec and retained for no more than 14 days by default | Backup, location, encryption, and rotation evidence |
| Revocation | Member disabled, keys revoked, and member history deleted | Member-offboarding and key-revocation tests |
#This Schedule makes no SOC 2 or ISO 27001 certification claim, no “zero risk” claim, and no absolute data-residency promise.
Schedule 3 — Providers and modes
This Schedule states the providers and modes the service can support.
Model providers
| Provider | Jurisdiction | your API keys | Managed | Role |
|---|---|---|---|---|
| OpenAI | United States | Yes | Yes | your API keys: Customer counterparty; Managed: tonia chain |
| Anthropic | United States | Yes | Yes | your API keys: Customer counterparty; Managed: tonia chain |
| Cohere | Canada | Yes | Yes | Depends on selected mode |
| Augure | Canada | Yes | Yes | Depends on selected mode |
| Mistral AI | France | Yes | Yes | Depends on selected mode |
| xAI | United States | Yes | Yes | Depends on selected mode |
| Google Gemini | United States | Yes | Yes | Depends on selected mode |
| Alibaba Cloud Model Studio | China; service endpoint in Southeast Asia | Yes | Yes | Exception limited to the recorded Qwen group and routed models |
| Z.ai / Zhipu GLM | China | Yes | No | Customer counterparty |
| DeepSeek direct | China | Yes | No | Customer counterparty; separate from Alibaba-routed models |
| Moonshot AI Kimi direct | China | Yes | No | Customer counterparty; separate from Alibaba-routed models |
| MiniMax | China | Yes | Yes | Separate provider; outside Alibaba exception |
| StepFun | Singapore | Yes | Yes | Separate provider; outside Alibaba exception |
| Amazon Bedrock | Customer-selected AWS region; initial technical setting in the United States | Yes | No | AWS is the Customer's counterparty; your API keys only; no additional acceptance |
| Custom OpenAI-compatible provider | Customer-selected | Yes | No | Customer selects the endpoint and counterparty |
Other provider categories
| Category | Role | Location |
|---|---|---|
| OIDC identity service | Authentication and session management | Quebec |
| tonia infrastructure and databases | Service hosting and storage | Quebec |
| Off-site backup | Continuity and restoration | Quebec; encrypted backup |
| External payment provider | Payment and transaction lifecycle | Name available on request |
| Support | Receiving and handling requests sent to support@tonia.ca | Quebec |
Change notice
tonia gives 30 days' advance notice of a planned material change to a Managed provider or jurisdiction. Notice may be shorter for a legal or security emergency. The Customer may disable the route, select another route or your API keys mode, or terminate the affected service without penalty.
Schedule 4 — Communications, retention, and destruction
1. Quebec base
The current fact matrix places tonia's main application, OIDC identity service, audit log, optional request and response storage, and conversation history in Quebec.
This is not an absolute Canada-only promise. A request may leave Quebec when the Customer enables an eligible provider that processes information elsewhere.
2. Communications
| Mode | Instruction and counterparty | Required assessment | Information communicated |
|---|---|---|---|
| your API keys | Customer selects the provider, credentials, and region | Customer completes its PIA; tonia supplies technical information it holds | Request, attachments, information needed by the provider, and returned output |
| Managed | tonia uses a provider allowed by the Customer's policy | tonia assesses its Managed chain; Customer assesses its purposes and categories | Same content needed to provide the service |
| Amazon Bedrock your API keys | Customer-selected AWS account and region | Customer completes its assessment | Same content; AWS is the Customer's counterparty |
| Custom provider | Customer-defined endpoint and location | Customer completes its assessment | Same content |
Before communicating personal information outside Quebec, the responsible person must complete the PIA and written agreement required by Bill 25, s. 17 (CQLR P-39.1).
3. Retention
| Category | Period or rule | Deletion | Details |
|---|---|---|---|
| Transient request and output | No plaintext content retained by default after execution | Released after execution | Provider handling depends on applicable terms |
| Request and response content stored on request | 1–90 days; 30 days by default when enabled | Deleted at expiry or within 30 days after an approved request | Backup copies expire within 14 days |
| Conversation history | Rolling 90 days | Deleted at expiry, member offboarding, or within 30 days after an approved request | Backup copies expire within 14 days |
| Portal or Chat session | Approximately 8 hours | Expiry or sign-out | Production settings |
| Member invitation | 72 hours | Expiry | — |
| Contract acceptance | 7 years after the customer relationship ends; old values are not rewritten | Deleted at expiry unless an authorized hold applies | Limited to applicable legal obligations |
| Audit hashes and metadata | Customer relationship plus 90 days | Deleted at expiry unless an authorized hold applies | Limited to applicable legal obligations |
| Off-site backup | No more than 14 days by default; encrypted and stored in Quebec | Rotation expiry; deleted data is not restored to active systems | Documented technical controls |
| Payment references | 7 years after the relevant fiscal year | Deleted at expiry, subject to provider rules | Limited to applicable legal obligations |
| Support | Active request, then 2 years after closure | Deleted at expiry | — |
4. Contract end
For 30 days after contract end, the Customer retains read-only access to export its data; no new processing is permitted. tonia deletes active data by the end of that same 30-day period. Copies already present in encrypted backups expire through rotation within the following 14 days.
An exceptional hold requires written authorization after a documented review. The hold must be limited to what is necessary to comply with law or protect tonia's rights in an active dispute.
tonia provides written confirmation of destruction when the Customer requests it.
Quebec law governs this agreement. Disputes are heard in the Superior Court of Quebec, district of Montreal.