Privacy Policy
Information processed, its use and retention, and your rights.
- Effective date:
- 2026-07-31
- Last updated:
- 2026-07-31
1. Who we are
tonia inc. operates tonia.ca and the tonia services.
Office: 20 boul. Charest O., Québec, Québec, G1K 1X2 Email: privacy@tonia.ca and vieprivee@tonia.ca
These details are published under Bill 25, s. 3.1 (CQLR P-39.1).
2. Scope
This policy covers personal information processed through tonia.ca, the customer Portal, tonia Chat, the tonia Developer API, the OIDC identity service, billing and payment, support and operational communications, optional request and response storage, conversation history, professional services, and the on-prem framework when activated by an order form.
The on-prem framework is not represented as generally available.
3. Our roles
tonia is responsible for its own account management, authentication, billing, service security, abuse prevention, contract evidence, support, legal compliance, and operational communications.
Where an organization determines the purposes of prompts, outputs, files, conversations, and other content submitted by its users, tonia performs the service entrusted by that organization. The TSA and DPA govern that mandate under Bill 25, s. 18.3 (CQLR P-39.1).
An adult may also contract personally.
For personal use, tonia is responsible for prompts, outputs, files, and history it processes to provide the service. It processes them to perform the contract and, where consent is required, according to the choice presented at collection. Optional storage can be disabled. The organization DPA does not apply to personal use.
4. Information we process
| Category | Examples | Source |
|---|---|---|
| Identity and contact | name, email, organization, role | you, your organization, OIDC identity service |
| Organization profile | legal name, address, industry, phone, required tax details | authorized authorized manager |
| Authentication and security | OIDC subject, session, IP address, sign-in and revocation events | browser, identity service, security logs |
| Contract and billing | tier, your API keys or Managed mode, accepted legal versions, payment references | you, Portal, payment provider |
| Service credentials | tonia API keys and encrypted provider selected with your API keys credentials | authorized authorized manager |
| Routing and audit | provider/model, policy result, usage metadata, content hash, authorization evidence | tonia service |
| Transient content | prompts, outputs, and attachments needed to perform a request | you and authorized users |
| Instructed retained content | encrypted request and response content; encrypted conversations and messages | authorized activation/configuration |
| Support | messages, diagnostics, and attachments sent to support | requester |
| Browser state | sessions, demo counter, known-user marker, consent choice if analytics is enabled | browser |
5. Purposes and necessity
We process information needed to provide the requested service, perform the contract, manage accounts, protect tonia and its customers, respond to requests, and comply with law.
provider API keys, request and response storage, conversation history, and analytics cookies are optional. Refusing an optional function prevents that function without removing unrelated essential account features. Identity, contract, security, and payment information may be required to open or maintain a paid account.
Collection-time notices identify purposes, means of collection, access/rectification rights, consent withdrawal, recipient categories, and the possibility of communication outside Quebec as required by Bill 25, s. 8 (CQLR P-39.1).
6. Recipients
Depending on enabled functions, information may be accessible to authorized organization users, authorized tonia personnel, the Quebec-based OIDC identity service, an external payment provider, a provider selected with your API keys selected by the customer, Managed model providers, required infrastructure/backup/support providers, and public authorities where required by law.
The factual provider list for entrusted processing is delivered to organization customers with the DPA provider schedule.
7. your API keys and Managed
With your API keys, you select and contract with the provider and use your own credentials. In Managed, the provider participates in tonia's service chain and is identified in the customer provider schedule.
Amazon Bedrock remains available only with your API keys and AWS is the customer's counterparty. The Alibaba Cloud Model Studio exception remains limited to tonia's recorded model group.
8. Communications outside Quebec
tonia's main infrastructure, OIDC identity service, and current audit/content stores are located in Quebec. A request may nevertheless be communicated outside Quebec when you enable a provider that processes elsewhere.
Before personal information is communicated outside Quebec, the person responsible must complete the privacy impact assessment and written safeguards required by Bill 25, s. 17 (CQLR P-39.1). For an organization customer, the TSA and DPA allocate the parties' responsibilities.
DLP controls reduce risk. They do not guarantee that every item of personal information is detected or that an authorized route remains in Canada.
9. Retention
| Information | Current rule |
|---|---|
| Portal/Chat session | approximately 8 hours; cleared on sign-out |
| Member invitation | 72 hours |
| Request and response content stored on request | 1–90 days by instruction; 30 days by default when enabled |
| Conversation history | rolling 90 days |
| Off-site backups | encrypted and stored in Quebec; no more than 14 days by default |
| Contract acceptances | 7 years after the customer relationship ends; old versions are not rewritten |
| Audit log/metadata | customer relationship plus 90 days |
| Payment references | 7 years after the relevant fiscal year |
| Support | active request, then 2 years after closure |
When purposes are fulfilled, tonia destroys or anonymizes information under Bill 25, s. 23 (CQLR P-39.1), subject to lawful retention.
10. Safeguards
Depending on the information and feature, safeguards include encrypted your API keys secrets and retained content, organization/role access controls, separate OIDC sessions by surface, logging of policy and authorized actions, key/access revocation, limited-retention purge jobs, and encrypted backups stored in Quebec.
This list is not a certification or a promise that any control removes all risk.
11. Confidentiality incidents
Where tonia has reason to believe a confidentiality incident has occurred, it assesses and mitigates the incident. If the incident presents a risk of serious injury, tonia notifies the Commission d'accès à l'information and affected individuals with diligence under Bill 25, s. 3.5 (CQLR P-39.1).
tonia keeps the register required by Bill 25, s. 3.8 (CQLR P-39.1). For information entrusted by an organization, tonia notifies its Privacy Officer without delay of a breach or attempted breach of a confidentiality obligation under Bill 25, s. 18.3 (CQLR P-39.1).
12. Your rights
Subject to applicable conditions, you may request:
- access and a copy, plus limited portability of computerized information collected from you — Bill 25, s. 27 (CQLR P-39.1);
- rectification of inaccurate, incomplete, or equivocal information, or information collected, disclosed, or retained without authorization — Bill 25, s. 28 (CQLR P-39.1);
- cessation of dissemination or de-indexing of a hyperlink in the cases provided by law — Bill 25, s. 28.1 (CQLR P-39.1);
- withdrawal of consent, subject to the consequences explained when requested — Bill 25, ss. 8 and 14 (CQLR P-39.1); and
- handling of a privacy complaint.
Section 28.1 is not described as a general deletion right.
A written request must allow identity and authority verification. tonia responds within 30 days under Bill 25, ss. 30 and 32 (CQLR P-39.1). A refusal states reasons and available recourse.
13. Privacy Officer
The Privacy Officer oversees tonia's privacy practices. The role receives rights requests and complaints, approves governance policies, and coordinates incident response.
Contact and complaints
Mailing address:
Privacy Officer tonia inc. 20 boul. Charest O. Québec, Québec, G1K 1X2
Write to privacy@tonia.ca or vieprivee@tonia.ca.
You may also contact Quebec's Commission d'accès à l'information: https://www.cai.gouv.qc.ca/
14. Changes
We publish an effective date and notice of material changes under Bill 25, s. 8.2 (CQLR P-39.1). A material contractual change incorporated into the Terms or DPA follows the new-version and re-acknowledgment process. A Privacy Policy update normally uses prospective notice.
Quebec law governs this agreement. Disputes are heard in the Superior Court of Quebec, district of Montreal.