Liability Notice
What tonia's controls do, what they do not do, and the applicable limits.
- Effective date:
- 2026-07-31
- Last updated:
- 2026-07-31
tonia provides the Customer with a technical governance layer for using cloud artificial-intelligence models: an access policy, sensitive-data filtering ("DLP"), and a signed audit log. This notice explains, in plain language, what that layer does, what it does not do, and the limits of tonia's contractual liability. It supplements, without replacing, the Terms of service (notably §8, Liability) and, for customers under a signed agreement, the tonia Service Agreement (TSA).
The French notice is remitted before contract formation. The Customer may then expressly choose to be bound by English under Charter of the French language s. 55 (CQLR C-11). Checkout records delivery, selected language, and the accepted document identifier.
1. Nature of the product: a technical means, not a decision-maker
tonia is a technical means of restriction and traceability. For an organization Customer, the Customer determines the purposes of its users' prompts, outputs, and files; tonia performs the entrusted mandate under the TSA and DPA in accordance with Bill 25, s. 18.3 (CQLR P-39.1). tonia remains responsible for its own account management, billing, security, and contract-evidence purposes.
For an adult using tonia personally, tonia is responsible for content processed to provide the service, as described in the Terms and Privacy Policy.
The Privacy Policy describes the Privacy Officer's contact details, tonia's own purposes, categories, retention, communications, and rights under Bill 25, including ss. 27, 28, and 28.1 (CQLR P-39.1). The DPA and its provider schedule govern entrusted processing for an organization Customer. This notice does not claim that the Privacy Policy publishes a provider list.
2. Capabilities and limits of sensitive-data filtering
tonia's filtering reduces a specific risk. It does not eliminate it. This section describes, without euphemism, what the detection engine can catch, how tonia responds to a detection, and what remains outside its scope.
The engine recognizes certain structured identifiers through a deterministic check. That check combines a format rule with, where the format allows it, a checksum validation. Categories typically covered include, as non-exhaustive examples: Social Insurance Number, Quebec health insurance number (RAMQ), credit card number, Canadian passport, SAAQ driver's licence, Quebec or federal business number, Canadian bank account number, civic address, and court file number. The exact catalogue of enabled categories depends on the Customer's configuration and may evolve. The engine also recognizes confidential keywords that the Customer configures itself (for example project names or customer names under a non-disclosure agreement), through an exact, case-insensitive match.
This approach has known limits. An identifier or keyword that has been reworded, translated, encoded, or deliberately split across multiple fields of the same request can escape detection. The engine recognizes text patterns, not intent. Personal information expressed as narrative prose rather than in a recognizable structured form is not reliably detected either. That includes, in particular: health status, biometric or genetic data, sexual orientation, religious or political views, ethnic origin, criminal history, union membership, and most financial detail written in free text. Improving coverage of this category of information is an area of ongoing work.
By default, when a match is detected and the Customer has configured the service to block, tonia refuses the request and does not send the original content to the cloud provider. When the Customer has configured the service to issue only a warning, the request continues with the original content intact, even if redaction had been requested on that request.
The Customer may also enable an optional redaction path on an API key. Two conditions must then be met: the authorized manager authorizes redaction on the key, and the end user explicitly requests redaction on that specific request. Only when both conditions are met and the service is configured to block on detection does tonia replace detected spans with neutral placeholders within Quebec and forward the redacted version instead of refusing. If either condition is missing, tonia refuses the request as it would by default. Redaction applies only to spans the engine actually detected. Any undetected personal information may still be transmitted. The signed audit log records whether a request was refused, redacted and forwarded, or passed without intervention.
Attachments (images, scanned documents, office files) are handled separately. When text extraction is explicitly turned on by the Customer's authorized manager (it is off by default), tonia extracts the attachment's text locally, including by optical character recognition (OCR) for images and scans, before running the same detection engine used on typed text. The reliability of that extraction depends directly on the quality of the image supplied. A clean, well-lit, high-resolution printed or scanned document is generally extracted with high fidelity. A phone-camera photo, a low-resolution scan, a skewed or poorly lit page, or a handwritten document carries a materially higher recognition error rate. A single misread character in a structured identifier (for example, one digit of a Social Insurance Number) is enough to defeat detection, even when the identifier is present and the feature is turned on.
When the redaction path is enabled, how tonia reacts to a detection inside an attachment depends on where the detected identifier sits. tonia cannot guarantee that every sensitive identifier present as pixels or in an image is redacted. If the identifier sits in the file's real text — a Word, Excel, or PowerPoint document, or a born-digital PDF produced directly from text rather than scanned — tonia rewrites that one location inside the original file and forwards the modified file, rather than a separate transcript. If the identifier exists only as pixels — an image, a scanned page, or the image portion of an office file or a mixed PDF — tonia cannot yet mask that specific location; it instead forwards the original attachment completely unmodified, rather than redacting it or refusing the request, so that a model able to work with images can still read or edit it. A file that combines an identifier in its real text with one that exists only as pixels has its real-text occurrence rewritten in place; the pixel portion is still forwarded unmodified until pixel masking ships. This residual risk applies only to the redaction path: when the service is configured to block, any attachment where an identifier was detected — whether in its real text or only in pixels — is refused just like any other detection. When an in-place rewrite was attempted but could not complete safely, tonia may substitute a masked text transcript for the attachment rather than forwarding a broken file; it does not forward unmasked addressable hit bytes. If neither rewrite, transcript substitution, nor the pixel pass-through path applies, tonia refuses the request.
tonia does not, at this time, perform a visual analysis of an image's content (for example, recognizing that a photo shows a face or an ID card, as opposed to reading text off it). A second, visual-analysis layer is being explored but is not in service as of the date of this notice.
In short: tonia's filtering measurably reduces the risk that certain well-defined categories of sensitive information are inadvertently sent to a cloud provider. It does not replace staff training, the Customer's own review of its usage practices, or its own privacy factor assessment (Bill 25, s. 17, CQLR c. P-39.1) for its own transfers. The Customer remains responsible for configuring the service to fit its own regulatory and sectoral context, including how detections are handled, which categories are enabled, whether redaction is authorized on its keys, and whether attachment extraction is turned on. Compliance with Bill 25 depends on that configuration. It is not automatic.
3. Scope of tonia's contractual liability
tonia's contractual liability to the Customer for any failure related to this service is limited under the Terms of service §8. It is capped at the fees paid by the Customer in the twelve (12) months preceding the event giving rise to the claim, unless a signed master agreement between the parties (the tonia Service Agreement) provides otherwise.
This limitation applies to the fullest extent permitted by Québec law. It cannot exclude or limit tonia's liability for bodily or moral injury, nor for material injury caused by intentional or gross fault, in accordance with article 1474 of the Civil Code of Québec.
tonia carries a professional liability (errors and omissions) insurance policy. The insurer's name, coverage amount, and other policy terms are not made public.
4. What a refusal, a redaction, or uninterrupted passage is not
An HTTP 451 refusal ("Unavailable For Legal Reasons") issued by tonia is not legal advice on the lawfulness of a given prompt. It is a technical guardrail triggered by the Customer's own configuration, according to the parameters the Customer chose.
Likewise, forwarding a request after redacting detected spans is not confirmation that no personal information reaches the cloud provider. Only the spans the engine caught were replaced. The rest of the content, including undetected personal information and identifiers that exist only as pixels or in images, may still be transmitted. Block mode does not share that residual risk when a match was detected in an attachment: the request is refused.
The absence of any refusal or redaction is equally not confirmation that a prompt's content complies with Bill 25 (CQLR c. P-39.1) or any other law applicable to the Customer. See §2 above for the detection engine's known limits.
5. Governing law and forum
Quebec law governs this notice. For an organization Customer, the courts of the judicial district of Québec have jurisdiction. A consumer retains the venue provided by law. Before any proceeding, the parties attempt a good-faith written settlement within thirty (30) days under the Terms.
6. Full contractual documents
This notice is an accessible summary. It is not the controlling document where a master agreement has been signed. Where they conflict, the signed master agreement between tonia and the Customer prevails, followed by the public Terms of service. See Terms of service, Privacy policy, and, for customers under a signed agreement, the PIA applicable to their profile.
Quebec law governs this agreement. Disputes are heard in the Superior Court of Quebec, district of Montreal.