Data Processing Agreement

Last updated:

How Tornaly processes your clients’ personal information on your behalf, when you are a business using Tornaly.

The short version

  • You control your clients’ information. We process it only to run the service for you, following your settings.
  • We never sell it, use it for advertising, combine it with other businesses’ data or use it to train AI models.
  • We use the providers listed below, and tell you at least 30 days before adding a new one.
  • We keep it secure, tell you promptly about any breach that affects it, and help you answer your clients’ requests.
  • You can export or erase any client at any time. After you close your account, we delete your data within 30 days, plus backup expiry.

This summary helps you find your way. The full text below is what applies.

1. Scope

This Data Processing Agreement (“DPA”) is part of our Terms of Service and is between you, the business, and Tornaly (“Tornaly”). It applies whenever Tornaly processes personal information on your behalf (“client data”). It is written to meet the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector (Law 25), the private-sector privacy laws of Alberta and British Columbia, and US state privacy laws where they apply. If this DPA and the Terms disagree about client data, this DPA wins.

2. Roles and instructions

You are responsible for client data and decide why and how it is used. Tornaly is your service provider: we process client data only to provide the service and only on your documented instructions. Your instructions are your settings and the way you use the service. If we think an instruction breaks the law, we will tell you.

3. What we process

  • Your clients: names, phone numbers, email addresses, messaging identifiers, messages and voice-note transcripts, appointments, visit history, payment status, notes, ratings, and consent choices.
  • Your team: names, email addresses, roles and working hours.
  • People who visit your website or chat page: what they send you and where they came from (referring site and campaign tags).

The service is not designed for sensitive information such as detailed health records, government IDs or card numbers. Please don’t store them in Tornaly.

4. How we use client data

We use client data only to provide, secure and support the service for you, and to meet the law. We do not sell it, use it for advertising, combine it with other businesses’ data, or use it to train AI models. Our AI providers process it only to write replies and transcribe voice notes for you.

5. Your responsibilities

  • Have a lawful basis, and the consent the law requires, for the client data you collect, import or message.
  • Tell your clients how you use their information. Your privacy policy should mention that you use service providers such as Tornaly.
  • Make sure data you import from other tools was collected lawfully.
  • Keep your settings accurate and your team’s access appropriate.

6. Our people

Only people who need access to provide the service can access client data, and they are bound by confidentiality. Our staff look at a business’s data only to support it, fix a problem or keep the service secure.

7. Subprocessors

You authorize us to use the following subprocessors:

ProviderWhat they doWhere
RenderHosting for the app and customer websitesUnited States
NeonDatabaseUnited States
ResendEmail delivery (sign-in codes, notices, reminders)United States
OpenAIAI replies and voice-note transcriptionUnited States
AnthropicAI replies, when used instead of OpenAIUnited States
TwilioText messages and business phone numbers (missed-call text-back)United States
TelnyxText messages and business phone numbers, for numbers hosted with themUnited States
Meta PlatformsWhatsApp and Instagram messagesUnited States and other countries
StripePayments into each business’s own Stripe account, and our subscription billingUnited States and other countries
CloudflareBot protection (Turnstile), DNS and content deliveryGlobal network
SentryError reports, with tokens and secrets removedUnited States

8. New subprocessors

Each subprocessor is bound by a written agreement that protects client data at least as well as this DPA, and we remain responsible for their work. We will email account owners and update this page at least 30 days before a new subprocessor starts handling client data. If you have a reasonable objection, tell us. If we can’t address it, you may cancel and we will refund any prepaid fees for the unused period.

9. Transfers outside Canada

Client data is stored and processed in the United States, and some subprocessors operate in other countries too. Before client data about people in Quebec leaves the province, we assess whether it will be adequately protected, considering its sensitivity, the purpose, the safeguards in place and the laws where it goes, and we use written agreements with each subprocessor. On request, we will give you the information you need for your own assessment.

10. Security

  • Encryption in transit (HTTPS) and at rest by our database provider. Access tokens for connected channels are additionally encrypted (AES-256).
  • Each business’s data is kept separate, and access is checked by role on every request.
  • Sign-in codes and session keys are stored only in hashed form.
  • Two-step verification for our staff with platform access.
  • Incoming messages from Meta, phone carriers and Stripe are checked for a valid signature.
  • Automatic deletion of data we no longer need, as set out in our Privacy Policy.

11. Breaches

If we become aware of a breach of security affecting client data, we will tell you without undue delay, and no later than 72 hours after confirming it. We will explain what happened, what data was involved and what we are doing about it, and keep you updated. As the business responsible for the data, you decide whether to notify your clients and the regulator; we will help with the information you need. We keep a record of every breach.

12. Your clients’ requests

You can answer most requests yourself: from your dashboard you can export or erase any client at any time. If a client contacts us directly, we will pass the request to you and help you respond. We will not answer it ourselves unless you ask us to or the law requires it.

13. Export and deletion

Erasing a client removes their chats, contact details, notes and feedback, while keeping anonymous booking counts and a hashed record of any opt-out, so it is never forgotten.

After your account closes, you have 30 days to export your data. We then delete client data from our live systems, and backup copies are deleted as backups expire, within 30 days after that, unless the law requires us to keep something.

14. Information and audits

Once a year, or after a breach, we will answer a reasonable security questionnaire and give you the information you need to show that this DPA is being followed. We will also cooperate with a privacy regulator’s inquiry.

15. Requests from authorities

If an authority asks us for client data, we will try to redirect it to you, and tell you about the request unless the law forbids it. We disclose only what we are legally required to.

16. Duration

This DPA lasts for as long as we process client data for you, including the 30-day export period after your account closes.

Questions: hello@tornaly.com.

Questions about this page: hello@tornaly.com