Personal Information Processing Agreement

Processing Agreement

The obligations that apply when your organization entrusts information to tonia.

Effective date:
2026-07-31
Last updated:
2026-07-31

1. Parties and scope

This agreement (“DPA”) is between tonia inc. (“tonia”) and the organization identified in the order form or tonia Service Agreement (“Customer”). It governs personal information entrusted by the Customer to tonia to provide the ordered services.

The DPA is designed for organization customers. It does not characterize an adult using tonia personally as an organization responsible for processing.

2. Priority

For conflicts specifically concerning entrusted processing, this DPA prevails, followed by the order form/TSA, then the Terms. The Privacy Policy remains a statutory notice and does not silently expand the service mandate.

3. Roles

The Customer determines the purposes of information submitted by its users. tonia performs the entrusted mandate under Bill 25, s. 18.3 (CQLR P-39.1).

tonia remains responsible for its own account management, billing, security, abuse prevention, contract evidence, and operational communications.

For a personal account, tonia acts as responsible under the Privacy Policy. That account remains outside this organization DPA.

4. Instructions

Documented instructions arise from the DPA, TSA, order form, organization settings, API-key scopes, your API keys or Managed and provider choices, access/DLP policies, optional request and response storage or conversation-history settings, and compliant written requests.

tonia informs the Customer if an instruction appears inconsistent with an applicable legal obligation.

5. Bill 25, section 18.3 minimum

tonia:

  1. takes necessary confidentiality measures;
  2. uses information only to perform the mandate;
  3. does not retain entrusted information after the mandate expires, subject to documented exceptions permitted by law;
  4. notifies the Customer's Privacy Officer without delay of a breach or attempted breach of a confidentiality obligation; and
  5. allows reasonable verification by the Customer's Privacy Officer.

These commitments implement Bill 25, s. 18.3 (CQLR P-39.1). The security, audit, and transfer schedules add contractual commitments and are not all represented as the statutory minimum.

6. Purpose limitation and no training

tonia does not use entrusted content for model training, sale, commercial profiling, targeted advertising, or legally significant automated decisions. tonia may process metadata strictly needed for service security, billing, contract evidence, and operation as described in the Privacy Policy.

7. Confidentiality and security

tonia limits access to authorized persons with a need to know and confidentiality obligations. It applies the evidenced safeguards in Schedule 2. The DPA is not a certification.

8. Incidents

tonia notifies the Customer's Privacy Officer without delay of a breach or attempted breach of an obligation concerning entrusted information under Bill 25, s. 18.3 (CQLR P-39.1). The parties cooperate on mitigation, investigation, and required notices.

Where tonia must notify the Commission d'accès à l'information or affected individuals, it does so with diligence under Bill 25, s. 3.5 (CQLR P-39.1). No statutory 72-hour deadline is stated.

9. Rights and assistance

tonia reasonably assists the Customer in locating, exporting, rectifying, or deleting entrusted information where law and architecture permit; responding to Bill 25, ss. 27, 28, and 28.1; documenting the s. 17 privacy impact assessment; and responding to the Commission.

The Customer remains responsible for requestor identity, authority, and legal basis.

10. Providers and modes

Schedule 3 identifies applicable providers, roles, jurisdictions, categories, and your API keys or Managed applicability.

With your API keys, the selected provider is normally the Customer's counterparty. In Managed, the provider participates in tonia's service chain.

Amazon Bedrock remains available only with your API keys and AWS is the Customer's counterparty. The Alibaba Cloud Model Studio exception remains limited to the recorded model group and does not extend to MiniMax, StepFun, or another catalogue.

11. Provider changes

tonia gives 30 days' advance notice where a planned material change affects a Managed provider, jurisdiction, communication route, or retention posture. Notice may be shorter for a legal or security emergency.

A Customer that objects may disable the affected route, select another route or your API keys, or terminate the affected service without penalty.

12. Communications outside Quebec

Schedule 4 describes known outside-Quebec communications, categories, jurisdictions, and applicable contractual/technical measures.

The Customer remains responsible for its assessment of instructions using your API keys. tonia supplies information it holds and completes its own assessment for Managed-chain communications under Bill 25, s. 17 (CQLR P-39.1).

13. Retention, return, and destruction

Schedule 4 states retention periods. For 30 days after mandate end, the Customer retains read-only access to export its information; no new processing is permitted. tonia deletes active data by the end of that same period. Copies already present in encrypted backups expire through rotation within the following 14 days.

Any exceptional hold must be limited to what is necessary to comply with law or protect tonia's rights in an active dispute. It requires written authorization after a documented review. Audit records are retained for the customer relationship plus 90 days, subject to such an authorized hold.

tonia provides written confirmation of destruction when the Customer requests it.

14. Verification

On reasonable request, tonia provides available policies, descriptions, attestations, and evidence needed by the Customer's Privacy Officer to verify the mandate. Verification protects other customers, begins with documentary evidence, avoids unreasonable disruption, and stays within entrusted processing.

Except after an incident or material breach, verification occurs no more than once in a 12-month period with 30 days' written notice. It begins with documentary evidence. An on-site verification requires reasonable grounds, occurs during normal business hours, and is performed by an independent auditor bound by confidentiality. The Customer bears its costs unless the verification establishes tonia's material breach.

15. Liability and term

Liability follows the TSA or Terms cap and exceptions, subject to Civil Code of Québec art. 1474 and mandatory law.

The DPA remains in force while entrusted processing continues. Confidentiality, evidence, return, and destruction obligations survive as needed to be performed.

16. Schedules

  • Schedule 1 — Processing description;
  • Schedule 2 — Security safeguards;
  • Schedule 3 — Providers and modes;
  • Schedule 4 — Communications, retention, and destruction.

Schedule 1 — Processing description

ItemDescription
PurposeProvide the Portal, Chat, tonia Developer API, your API keys or Managed routing, sensitive-data filtering, audit log, and ordered services
DurationTerm of the TSA or order form, plus the limited periods in Schedule 4
IndividualsCustomer members and users; individuals whose information appears in content; Customer authorized managers and contacts
Identity and contactName, email, role, OIDC identifier, and organization
ContentRequests, outputs, files, conversations, and messages
Service informationSelected provider/model, applied rule, filter result, usage, IP address, or security event where relevant
EvidenceContent hash, authorization evidence, and accepted legal versions
Protected credentialsEncrypted provider API keys and tonia API keys
Default processingContent processed for the duration of the request; metadata and audit evidence retained as configured
Optional processingEncrypted request and response content stored for 1–90 days on request; encrypted conversation history stored for 90 days
PurposesCarry out documented instructions, apply controls, route the request, return the output, produce audit evidence, and support the service

Excluded uses

tonia does not use entrusted content to train models, sell content, deliver targeted advertising, create commercial profiles, or make legally significant automated decisions.

Personal use

This Schedule applies only to processing entrusted by an organization.


Schedule 2 — Security safeguards

AreaCurrent safeguardVerification source
SeparationData and permissions separated by customer organizationData schemas and authorization tests
IdentityOIDC identity service in Quebec; separate sessions for the Portal and ChatIdentity-service and session configuration
SessionsApproximately 8-hour duration; closed on sign-out or revocationSign-in and sign-out tests
provider API keysCredentials encrypted under tonia's key hierarchyEncryption, rotation, and revocation evidence
Retained contentRequest/response content and conversation history encryptedEncryption evidence and retention tests
Access controlRoles, API-key permissions, and authorized actionsData schemas and permission tests
Sensitive-data filteringDeterministic rules and configured modes; limits published separatelyFilter tests and Liability Notice
Audit logHashes, routing metadata, and authorization evidenceAudit schema and tests
Expiry deletionStored content and conversation history deleted automatically when their periods endExpiry and deletion tests
BackupEncrypted off-site copy stored in Quebec and retained for no more than 14 days by defaultBackup, location, encryption, and rotation evidence
RevocationMember disabled, keys revoked, and member history deletedMember-offboarding and key-revocation tests

#This Schedule makes no SOC 2 or ISO 27001 certification claim, no “zero risk” claim, and no absolute data-residency promise.


Schedule 3 — Providers and modes

This Schedule states the providers and modes the service can support.

Model providers

ProviderJurisdictionyour API keysManagedRole
OpenAIUnited StatesYesYesyour API keys: Customer counterparty; Managed: tonia chain
AnthropicUnited StatesYesYesyour API keys: Customer counterparty; Managed: tonia chain
CohereCanadaYesYesDepends on selected mode
AugureCanadaYesYesDepends on selected mode
Mistral AIFranceYesYesDepends on selected mode
xAIUnited StatesYesYesDepends on selected mode
Google GeminiUnited StatesYesYesDepends on selected mode
Alibaba Cloud Model StudioChina; service endpoint in Southeast AsiaYesYesException limited to the recorded Qwen group and routed models
Z.ai / Zhipu GLMChinaYesNoCustomer counterparty
DeepSeek directChinaYesNoCustomer counterparty; separate from Alibaba-routed models
Moonshot AI Kimi directChinaYesNoCustomer counterparty; separate from Alibaba-routed models
MiniMaxChinaYesYesSeparate provider; outside Alibaba exception
StepFunSingaporeYesYesSeparate provider; outside Alibaba exception
Amazon BedrockCustomer-selected AWS region; initial technical setting in the United StatesYesNoAWS is the Customer's counterparty; your API keys only; no additional acceptance
Custom OpenAI-compatible providerCustomer-selectedYesNoCustomer selects the endpoint and counterparty

Other provider categories

CategoryRoleLocation
OIDC identity serviceAuthentication and session managementQuebec
tonia infrastructure and databasesService hosting and storageQuebec
Off-site backupContinuity and restorationQuebec; encrypted backup
External payment providerPayment and transaction lifecycleName available on request
SupportReceiving and handling requests sent to support@tonia.caQuebec

Change notice

tonia gives 30 days' advance notice of a planned material change to a Managed provider or jurisdiction. Notice may be shorter for a legal or security emergency. The Customer may disable the route, select another route or your API keys mode, or terminate the affected service without penalty.


Schedule 4 — Communications, retention, and destruction

1. Quebec base

The current fact matrix places tonia's main application, OIDC identity service, audit log, optional request and response storage, and conversation history in Quebec.

This is not an absolute Canada-only promise. A request may leave Quebec when the Customer enables an eligible provider that processes information elsewhere.

2. Communications

ModeInstruction and counterpartyRequired assessmentInformation communicated
your API keysCustomer selects the provider, credentials, and regionCustomer completes its PIA; tonia supplies technical information it holdsRequest, attachments, information needed by the provider, and returned output
Managedtonia uses a provider allowed by the Customer's policytonia assesses its Managed chain; Customer assesses its purposes and categoriesSame content needed to provide the service
Amazon Bedrock your API keysCustomer-selected AWS account and regionCustomer completes its assessmentSame content; AWS is the Customer's counterparty
Custom providerCustomer-defined endpoint and locationCustomer completes its assessmentSame content

Before communicating personal information outside Quebec, the responsible person must complete the PIA and written agreement required by Bill 25, s. 17 (CQLR P-39.1).

3. Retention

CategoryPeriod or ruleDeletionDetails
Transient request and outputNo plaintext content retained by default after executionReleased after executionProvider handling depends on applicable terms
Request and response content stored on request1–90 days; 30 days by default when enabledDeleted at expiry or within 30 days after an approved requestBackup copies expire within 14 days
Conversation historyRolling 90 daysDeleted at expiry, member offboarding, or within 30 days after an approved requestBackup copies expire within 14 days
Portal or Chat sessionApproximately 8 hoursExpiry or sign-outProduction settings
Member invitation72 hoursExpiry
Contract acceptance7 years after the customer relationship ends; old values are not rewrittenDeleted at expiry unless an authorized hold appliesLimited to applicable legal obligations
Audit hashes and metadataCustomer relationship plus 90 daysDeleted at expiry unless an authorized hold appliesLimited to applicable legal obligations
Off-site backupNo more than 14 days by default; encrypted and stored in QuebecRotation expiry; deleted data is not restored to active systemsDocumented technical controls
Payment references7 years after the relevant fiscal yearDeleted at expiry, subject to provider rulesLimited to applicable legal obligations
SupportActive request, then 2 years after closureDeleted at expiry

4. Contract end

For 30 days after contract end, the Customer retains read-only access to export its data; no new processing is permitted. tonia deletes active data by the end of that same 30-day period. Copies already present in encrypted backups expire through rotation within the following 14 days.

An exceptional hold requires written authorization after a documented review. The hold must be limited to what is necessary to comply with law or protect tonia's rights in an active dispute.

tonia provides written confirmation of destruction when the Customer requests it.

Quebec law governs this agreement. Disputes are heard in the Superior Court of Quebec, district of Montreal.