Data Processing Agreement
Last updated:
How Tornaly processes your clients’ personal information on your behalf, when you are a business using Tornaly.
The short version
- You control your clients’ information. We process it only to run the service for you, following your settings.
- We never sell it, use it for advertising, combine it with other businesses’ data or use it to train AI models.
- We use the providers listed below, and tell you at least 30 days before adding a new one.
- We keep it secure, tell you promptly about any breach that affects it, and help you answer your clients’ requests.
- You can export or erase any client at any time. After you close your account, we delete your data within 30 days, plus backup expiry.
This summary helps you find your way. The full text below is what applies.
1. Scope
This Data Processing Agreement (“DPA”) is part of our Terms of Service and is between you, the business, and Tornaly (“Tornaly”). It applies whenever Tornaly processes personal information on your behalf (“client data”). It is written to meet the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector (Law 25), the private-sector privacy laws of Alberta and British Columbia, and US state privacy laws where they apply. If this DPA and the Terms disagree about client data, this DPA wins.
2. Roles and instructions
You are responsible for client data and decide why and how it is used. Tornaly is your service provider: we process client data only to provide the service and only on your documented instructions. Your instructions are your settings and the way you use the service. If we think an instruction breaks the law, we will tell you.
3. What we process
- Your clients: names, phone numbers, email addresses, messaging identifiers, messages and voice-note transcripts, appointments, visit history, payment status, notes, ratings, and consent choices.
- Your team: names, email addresses, roles and working hours.
- People who visit your website or chat page: what they send you and where they came from (referring site and campaign tags).
The service is not designed for sensitive information such as detailed health records, government IDs or card numbers. Please don’t store them in Tornaly.
4. How we use client data
We use client data only to provide, secure and support the service for you, and to meet the law. We do not sell it, use it for advertising, combine it with other businesses’ data, or use it to train AI models. Our AI providers process it only to write replies and transcribe voice notes for you.
5. Your responsibilities
- Have a lawful basis, and the consent the law requires, for the client data you collect, import or message.
- Tell your clients how you use their information. Your privacy policy should mention that you use service providers such as Tornaly.
- Make sure data you import from other tools was collected lawfully.
- Keep your settings accurate and your team’s access appropriate.
6. Our people
Only people who need access to provide the service can access client data, and they are bound by confidentiality. Our staff look at a business’s data only to support it, fix a problem or keep the service secure.
7. Subprocessors
You authorize us to use the following subprocessors:
| Provider | What they do | Where |
|---|---|---|
| Render | Hosting for the app and customer websites | United States |
| Neon | Database | United States |
| Resend | Email delivery (sign-in codes, notices, reminders) | United States |
| OpenAI | AI replies and voice-note transcription | United States |
| Anthropic | AI replies, when used instead of OpenAI | United States |
| Twilio | Text messages and business phone numbers (missed-call text-back) | United States |
| Telnyx | Text messages and business phone numbers, for numbers hosted with them | United States |
| Meta Platforms | WhatsApp and Instagram messages | United States and other countries |
| Stripe | Payments into each business’s own Stripe account, and our subscription billing | United States and other countries |
| Cloudflare | Bot protection (Turnstile), DNS and content delivery | Global network |
| Sentry | Error reports, with tokens and secrets removed | United States |
8. New subprocessors
Each subprocessor is bound by a written agreement that protects client data at least as well as this DPA, and we remain responsible for their work. We will email account owners and update this page at least 30 days before a new subprocessor starts handling client data. If you have a reasonable objection, tell us. If we can’t address it, you may cancel and we will refund any prepaid fees for the unused period.
9. Transfers outside Canada
Client data is stored and processed in the United States, and some subprocessors operate in other countries too. Before client data about people in Quebec leaves the province, we assess whether it will be adequately protected, considering its sensitivity, the purpose, the safeguards in place and the laws where it goes, and we use written agreements with each subprocessor. On request, we will give you the information you need for your own assessment.
10. Security
- Encryption in transit (HTTPS) and at rest by our database provider. Access tokens for connected channels are additionally encrypted (AES-256).
- Each business’s data is kept separate, and access is checked by role on every request.
- Sign-in codes and session keys are stored only in hashed form.
- Two-step verification for our staff with platform access.
- Incoming messages from Meta, phone carriers and Stripe are checked for a valid signature.
- Automatic deletion of data we no longer need, as set out in our Privacy Policy.
11. Breaches
If we become aware of a breach of security affecting client data, we will tell you without undue delay, and no later than 72 hours after confirming it. We will explain what happened, what data was involved and what we are doing about it, and keep you updated. As the business responsible for the data, you decide whether to notify your clients and the regulator; we will help with the information you need. We keep a record of every breach.
12. Your clients’ requests
You can answer most requests yourself: from your dashboard you can export or erase any client at any time. If a client contacts us directly, we will pass the request to you and help you respond. We will not answer it ourselves unless you ask us to or the law requires it.
13. Export and deletion
Erasing a client removes their chats, contact details, notes and feedback, while keeping anonymous booking counts and a hashed record of any opt-out, so it is never forgotten.
After your account closes, you have 30 days to export your data. We then delete client data from our live systems, and backup copies are deleted as backups expire, within 30 days after that, unless the law requires us to keep something.
14. Information and audits
Once a year, or after a breach, we will answer a reasonable security questionnaire and give you the information you need to show that this DPA is being followed. We will also cooperate with a privacy regulator’s inquiry.
16. Duration
This DPA lasts for as long as we process client data for you, including the 30-day export period after your account closes.
Questions: hello@tornaly.com.
Questions about this page: hello@tornaly.com