Back to home

Terms of Service, Privacy Policy and DPA

Last updated: 2026-04-14

Version: 2.0

This is an informational translation. The binding text is the Spanish original — in the event of any discrepancy, the Spanish version prevails.

This is an informational English translation of revision 2.0. The binding text is the Spanish original, available at app.toniagent.com/legal/terms-of-services; in the event of any discrepancy, the Spanish version prevails.

TERMS OF SERVICE

These Terms of Service ("Terms") govern access to and use of the ToniAgent service, offered by Productivity Agents SL, with registered address at Carrer Santa Eulalia 5, 08195, Sant Cugat del Vallès (Spain) ("the Company").

By registering on the platform and activating the service, the Client accepts these Terms and confirms having read and accepted the Data Processing Agreement (DPA).

1. Purpose of the Service

ToniAgent is a virtual voice agent that can:

  • Answer and handle incoming calls.
  • Redirect calls according to rules configured by the Client.
  • Record, transcribe and analyse conversations.
  • Schedule, modify and cancel appointments on behalf of the Client.
  • Integrate with calendars (including Google Calendar), CRMs and other external systems.
  • Synchronise calendar events to improve management of the Client's schedule.
  • Allow the AI agent to create, modify and cancel events in the Client's calendar through voice or text instructions.
  • Send reminders and automated communications.
  • Handle written conversations with patients or end users.

The service is provided on a SaaS basis.

2. Nature of the Service

The Client acknowledges and accepts that ToniAgent acts as virtual administrative staff, following instructions defined by the Client.

The Company does not provide healthcare services and does not deliberately access medical records, diagnoses or clinical processes. Any health data processed will be processed on behalf of the Client in accordance with the DPA.

3. Registration and Account

Using ToniAgent requires:

  • Creating an account with a name, email address and password.
  • Accepting these Terms and the DPA.
  • Providing billing details to activate the contracted plan.
  • Redirecting the Client's calls to the ToniAgent telephone number.

The Client is responsible for keeping their credentials confidential.

4. Plans, Pricing and Billing

4.1 Billing model: Monthly fees according to the contracted package. Discount for annual payment. Overage charges for additional call minutes.

4.2 Trial period: The Client has a 1-month free trial. On expiry, unless cancelled, the paid plan starts automatically.

4.3 Automatic renewal: Plans renew automatically unless cancelled beforehand.

4.4 Cancellation: Monthly cancellation with no minimum term. For annual plans already paid, no refunds are issued; cancellation affects the renewal only.

5. Permitted Use of the Service

The Client undertakes to:

  • Use ToniAgent in accordance with the law and these Terms.
  • Not use the service for unlawful, deceptive or harmful activities.
  • Not attempt to access the source code or carry out reverse engineering.

6. Integrations and Actions on Behalf of the Client

The Client authorises the Company to:

  • Connect ToniAgent with calendars, CRMs and external systems configured by the Client.
  • Access Google Calendar calendars via OAuth 2.0 to synchronise events, read calendar information and manage events.
  • Securely store Google authorisation tokens (encrypted with AES-256) to keep the connection active.
  • Synchronise and store calendar events in our database to improve performance and enable offline functionality.
  • Carry out administrative actions in Google Calendar through the AI agent, including creating, cancelling and modifying events when the Client requests it.
  • Carry out other administrative actions (scheduling, reminders, basic management) on behalf of the Client.
  • Record and transcribe calls in order to provide the service and improve its operation.

The Client expressly acknowledges and authorises that:

  • The Google Calendar integration requires granting read and write permissions through Google OAuth.
  • The ToniAgent AI agent will act on their behalf to manage calendar events according to their instructions.
  • Google Calendar data is stored on AWS servers in Ireland (eu-west-1).
  • All modifications made by the AI agent in Google Calendar will be reflected immediately in their Google Calendar account.
  • The Client may revoke access to Google Calendar at any time from the integrations settings or from their Google account settings.

7. Service Availability (SLA)

The Company guarantees 99.9% annual service availability.

Excluded are: failures arising from third parties (AWS, Twilio, ElevenLabs or equivalent providers), scheduled maintenance announced in advance, and failures arising from the Client's own configuration.

8. Support Levels

  • Level 1 – Critical (service inoperative): Initial response within 1–2 hours.
  • Level 2 – Partial degradation: Response within 1 business day.
  • Level 3 – General enquiries: Response within 72 business hours.

9. Intellectual Property

All ToniAgent software, models, content and documentation are the exclusive property of the Company. The Client retains the rights to their own data and content.

10. Commercial Use of the Client's Name and Brand

The Client authorises the Company to display their name and logo as a ToniAgent client and to use it in commercial presentations, client listings and on the website. The Client may revoke this permission in writing.

11. Limitation of Liability

To the maximum extent permitted by law: the Company will not be liable for indirect damages, loss of Client data or loss of profit. The Company's total aggregate liability is limited to an amount equivalent to one (1) month of the contracted service.

12. Subprocessors and Technology Providers

The Client accepts the use of the providers detailed in the Subprocessor List . International transfers are carried out under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework, always prioritising European Union regions where possible.

13. Data Protection

The processing of personal data carried out by ToniAgent is governed by the Data Processing Agreement (DPA), which forms an integral part of these Terms.

14. Term and Termination

These Terms remain in force for as long as the Client uses the service. The Client may cancel at any time from the control panel.

15. Modifications

The Company may update these Terms and will give notice of changes at least 15 days in advance.

16. Governing Law

These Terms are governed by Spanish law. Any dispute will be submitted to the courts of Barcelona, unless the law requires another jurisdiction.

PRIVACY POLICY

This Privacy Policy describes how Productivity Agents SL ("the Company", "ToniAgent", "we") collects, uses, stores and shares personal information when you use our ToniAgent platform, particularly in relation to third-party integrations such as Google Calendar.

1. Google Calendar Integration

If you choose to connect your Google Calendar account to ToniAgent, we access the following Google user data through the Google Calendar API:

OAuth Scopes Requested:

  • calendar.readonly: Read-only access to your list of calendars and events.
  • calendar.events: Read/write access to calendar events (used to read events and for the AI agent to book and cancel appointments on your behalf).
  • userinfo.email: Your Google account email address.

Specific Data Collected:

1. Google Account Information:

Your Google email address (used to identify and associate your Google Calendar with your ToniAgent account).

2. Calendar Metadata:

Calendar IDs and names, calendar descriptions, time zone settings, calendar colours (background and foreground), primary calendar indicator.

3. Calendar Events:

Event titles (summary), event descriptions, event locations, start and end times (including all-day event indicators), event status (confirmed, tentative, cancelled), organiser email addresses, attendee information (email addresses and response status), recurrence rules (for recurring events), links to events in Google Calendar.

Data Accessed by the AI Agent:

When you interact with the ToniAgent AI assistant for calendar management, the AI agent processes:

  • Your voice or text instructions about calendar operations (e.g. "Book a meeting with Juan tomorrow at 3 PM").
  • Your existing calendar events, to check availability and avoid scheduling conflicts.
  • Event details you provide (meeting titles, attendee names/emails, locations, descriptions).
  • Confirmation responses for calendar operations.

This data is processed in order to carry out your calendar management requests and is subject to the same security and privacy protections as other Google Calendar data.

2. How We Use Your Google Calendar Data

We use your Google Calendar data for the following purposes:

1. Displaying Calendar Events:

Showing your calendar events within the ToniAgent application interface so that you can see your schedule alongside your other tasks and activities.

2. Local Synchronisation:

Synchronising and storing your calendar events locally in our database for faster access and better performance. This lets you view your calendar without repeated calls to the Google API.

3. Event Notifications (Optional):

If enabled, we configure webhook notifications from Google Calendar to receive real-time updates when your events change, keeping your synchronised events up to date.

4. Calendar Management by the AI Agent:

When you interact with the ToniAgent AI assistant, the agent may carry out the following actions in your Google Calendar on your behalf and with your explicit authorisation:

  • Create new calendar events (book appointments): When you ask the AI agent to schedule a meeting or appointment, it will create a new event in your connected Google Calendar with the details specified (title, date, time, attendees, location, description).
  • Cancel existing events: When you ask the AI agent to cancel an appointment, it will update the event status to "cancelled" or delete the event from your Google Calendar.
  • Modify event details: When you request changes to an existing event (time, location, attendees), the AI agent will update the event in your Google Calendar.

How AI Agent Modifications Work:

  • The AI agent only makes changes when you explicitly instruct it to (e.g. "Book a meeting with Juan tomorrow at 3 PM" or "Cancel my 2 PM appointment").
  • All AI agent actions are performed using your authenticated OAuth tokens, which means changes are made as if you had made them yourself.
  • You will receive confirmation of calendar modifications through the ToniAgent interface.
  • All events created, modified or cancelled are reflected immediately in your Google Calendar and in any other application connected to it.

Important Safeguards:

  • Your Google Calendar data is never shared with third-party services beyond our infrastructure provider (AWS).
  • Your calendar data is isolated to your account and cannot be accessed by other ToniAgent users.
  • The AI agent can only access calendars that you have explicitly connected to ToniAgent.
  • We do not use your Google Calendar data for advertising, marketing or any purpose beyond the core calendar integration and AI assistant functionality.
  • You retain full control and may revoke ToniAgent's access to your Google Calendar at any time.

3. How We Store Your Google Calendar Data

Database Storage:

Your Google Calendar data is stored in a PostgreSQL database hosted on Amazon Web Services (AWS) in the Ireland region (eu-west-1). We store three types of data:

  • Google Account Information: Your Google email address and OAuth tokens (encrypted).
  • Calendar Metadata: Calendar names, settings and synchronisation status.
  • Calendar Events: Event details, times, attendees and descriptions.

Encryption and Security:

  • OAuth tokens (access tokens and refresh tokens) are encrypted at rest using Fernet encryption with AES-256 before being stored in our database.
  • Encryption keys are stored securely in AWS Secrets Manager and are never exposed in application code or logs.
  • Calendar event data (titles, descriptions, attendees) is stored unencrypted for performance reasons, but access is restricted to authenticated users only.
  • All data transmission between your browser, our servers and Google's servers uses HTTPS/TLS 1.2 or higher.

Data Isolation:

  • Your Google Calendar data is associated exclusively with your user account.
  • Our application enforces strict authorisation controls to ensure that users can only access their own Google Calendar data.
  • Administrative users cannot override these controls to access other users' Google Calendar data.

Data Retention:

  • Your Google Calendar data is retained for as long as your calendar integration is active.
  • When you disconnect your Google Calendar account, we immediately and permanently delete all associated data, including: OAuth tokens, calendar metadata, and all synchronised events (both events created by you and events created by the AI agent on your behalf).
  • This deletion is automatic and cascades throughout our database schema.

Important Note About AI-Created Events:

  • Events created by the AI agent in your Google Calendar remain in your Google Calendar even after you disconnect ToniAgent. These are your calendar events.
  • To remove AI-created events from Google Calendar, you must delete them directly in Google Calendar (either before or after disconnecting ToniAgent).
  • Disconnecting ToniAgent only deletes our local copy of the synchronised event data, not the events themselves in Google Calendar.

4. Sharing Your Google Calendar Data

Infrastructure Provider:

We use Amazon Web Services (AWS) as our hosting and database provider. Your Google Calendar data is stored on AWS servers located in the Ireland region (eu-west-1) within the European Economic Area (EEA). AWS acts as a data processor under our Data Processing Agreement (DPA) and is subject to AWS's GDPR-compliant terms.

No Sharing With Other Third Parties:

We do not share your Google Calendar data with any other third-party service, including: analytics providers, advertising networks, marketing platforms, or other integrations (e.g. voice synthesis, telephony services).

Your Google Calendar data is used exclusively within ToniAgent for the purposes described in this policy.

Google as a Data Source:

  • When you connect your Google Calendar, you grant ToniAgent permission to access your Google Calendar data through Google's OAuth 2.0 authorisation.
  • We access your Google Calendar data using Google's official Calendar API.
  • Your relationship with Google and their use of your data is governed by Google's Privacy Policy, available at policies.google.com/privacy .

5. How the AI Agent Accesses Your Google Calendar

AI Agent Capabilities:

When you authorise ToniAgent to access your Google Calendar, our AI assistant can perform calendar management tasks on your behalf, including:

  • Reading Your Schedule: The AI agent can view your calendar events to check your availability when scheduling appointments or answering questions about your schedule.
  • Creating Events: When you instruct the AI agent (e.g. "Schedule a meeting with Juan on Friday at 2 PM"), it will create a new event in your connected Google Calendar, set the event title, date, time, location and description according to your instructions, add attendees if specified, and send calendar invitations through Google Calendar.
  • Cancelling Events: When you instruct the AI agent (e.g. "Cancel my 3 PM meeting tomorrow"), it will find the corresponding event in your calendar, update the event status to "cancelled" or delete the event, and Google Calendar will notify attendees of the cancellation.
  • Modifying Events: When you instruct the AI agent (e.g. "Move my meeting to 4 PM"), it will update the event details in your Google Calendar and Google Calendar will notify attendees of the changes.

Important Safeguards:

  • The AI agent only acts on your explicit instructions — it will not create, modify or cancel events autonomously without your direction.
  • All calendar operations are performed using your authenticated OAuth credentials, which means changes appear as if you had made them yourself in Google Calendar.
  • The AI agent can only access calendars that you have explicitly connected to ToniAgent.
  • You will receive confirmation of any calendar change through the ToniAgent interface.
  • All modifications are synchronised immediately with your Google Calendar and are visible across all your devices and applications.

User Control:

  • You may disconnect Google Calendar at any time to revoke the AI agent's access.
  • You may select which specific calendars to share with ToniAgent (e.g. share your work calendar but not your personal calendar).
  • You may review and manually modify any event created by the AI agent directly in Google Calendar.

6. Your Rights Regarding Google Calendar Data

You have full control over your Google Calendar integration:

Revoke Access at Any Time:

You may disconnect your Google Calendar account from ToniAgent at any time through the Integrations page in your account settings. Disconnecting will immediately delete all OAuth tokens, calendar metadata and synchronised events from our database.

Granular Control:

You may choose which specific calendars to synchronise with ToniAgent. You may disconnect individual calendars while keeping other calendars connected.

Google Account Settings:

You may also revoke ToniAgent's access to your Google Calendar directly through your Google Account settings at myaccount.google.com/permissions . Revoking access through Google will prevent ToniAgent from accessing your calendar data, but you should also disconnect the integration within ToniAgent to delete the locally stored data.

Data Portability:

Your calendar events remain in your Google Calendar at all times. You may export your calendar data directly from Google Calendar using Google Takeout ( takeout.google.com ).

GDPR Rights (EEA Users):

  • Right of Access: View all connected Google accounts and synchronised calendar data through your ToniAgent account.
  • Right to Erasure: Delete all Google Calendar data by disconnecting your Google account.
  • Right to Data Portability: Export your calendar data from Google Calendar directly.
  • Right to Restriction: Disconnect individual calendars to stop synchronising specific calendar data.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal or regulatory reasons. We will notify you of any material change by publishing the new policy on this page and updating the "Last updated" date at the top.

8. Contact

If you have questions about this Privacy Policy or about how we handle your Google Calendar data, please contact us at:

Productivity Agents SL Carrer Santa Eulalia 5 08195 Sant Cugat del Vallès, Spain Email: support@toniagent.com

DATA PROCESSING AGREEMENT (DPA)

This Data Processing Agreement ("DPA") forms part of the Terms of Service accepted by the Client when registering on the ToniAgent platform, offered by Productivity Agents SL, with registered address at Carrer Santa Eulalia 5, 08195, Sant Cugat del Vallès (Spain) ("the Processor").

The Client ("the Controller") accepts this DPA on activating the service.

1. Purpose and Duration

This DPA governs the processing of personal data carried out by the Processor on behalf of the Controller through the use of ToniAgent. Processing takes place for as long as the Controller keeps their account active.

2. Nature and Purpose of the Processing

ToniAgent processes personal data for the following purposes:

  • Answering and handling incoming calls.
  • Redirecting calls or handling interactions according to the Controller's configuration.
  • Recording and transcribing telephone conversations.
  • Scheduling, modifying or cancelling appointments.
  • Integrating with calendars, CRMs or other systems configured by the Controller.
  • Synchronising Google Calendar events (title, description, location, dates, attendees).
  • Creating, modifying and cancelling events in Google Calendar through the AI agent when the user requests it.
  • Sending reminders and communications.
  • Analysing conversations to optimise service quality (without identifying the patient outside the context of the call).

The processing does not include the provision of healthcare services. Any health data processed is processed exclusively on an administrative basis and under the Controller's instructions.

3. Categories of Personal Data

Patient / end-user data: name and contact details, reason for the visit or enquiry, national ID or other identifiers (if provided by the end user), the full content of the conversation (voice and/or text), call transcripts and recordings, information derived from conversational analysis (sentiment, urgency, context).

Controller's staff data: name, email, role and availability for scheduling appointments.

Technical data: usage logs, call metadata, timestamps, access IP addresses.

4. Special Categories of Data (Art. 9 GDPR)

ToniAgent may incidentally process health data expressed by the patient during a call or interaction. The processing is for administrative (not clinical) purposes, is carried out exclusively under the Controller's instructions, and is covered by Article 9(2)(h) GDPR (management of healthcare services) and by the healthcare professional–patient relationship.

Important: It is the Controller who must ensure the appropriate legal basis for processing these special categories, including giving patients prior notice about the recording and transcription of the call.

5. Controller's Instructions

The Processor will process personal data only in accordance with the Controller's documented instructions, for the purposes described in this DPA, and may not use it for its own purposes under any circumstances. If an instruction is contrary to the law, the Processor will notify the Controller immediately.

5bis. Commitment Not to Train AI Models

5bis.1. The Processor represents and warrants that it does not use, and does not permit its subprocessors to use, the personal data processed under this DPA to train, fine-tune, improve or develop artificial intelligence models, neural networks, machine learning algorithms, or any other automated decision-making system.

5bis.2. This warranty extends expressly to: voice recordings and their content, generated transcripts, the content of text conversations, calendar and appointment data, and any data derived from conversational analysis.

5bis.3. The Processor contractually requires the same no-training warranty from each subprocessor (see Subprocessor List ). In particular:

  • ElevenLabs: Model-training opt-out enabled ("Improve models for everyone" = OFF). Conversation retention configured to the operational minimum. ElevenLabs is certified under the EU-US Data Privacy Framework (DPF). The Processor plans to migrate to the ElevenLabs Enterprise plan with an isolated EU environment (eu.elevenlabs.io) during Q3 2026, which will include a formal DPA, European data residency and Zero Retention Mode.
  • Twilio: Recordings are stored solely on infrastructure controlled by the Processor (AWS eu-west-1). Twilio does not retain copies beyond real-time processing.
  • AWS: Acts as infrastructure (IaaS). It has no logical access to the stored data.

5bis.4. Should a subprocessor change its terms of service in a way that may affect this warranty, the Processor will notify the Controller within a maximum of 15 days and, if the warranty cannot be maintained, will replace the subprocessor within a reasonable period.

6. Authorised Subprocessors

The Controller expressly authorises the use of the subprocessors detailed in the [Subprocessor List](/legal/subprocessors) .

6.1. Procedure for adding or changing subprocessors:

  • The Processor will notify the Controller at least 30 days before adding a new subprocessor or replacing an existing one.
  • The notification will include: the subprocessor's identity, the processing location, the purpose, and data protection safeguards.
  • The Controller will have 15 days from the notification to raise a reasoned objection.
  • In the event of a reasoned objection, the Processor will not proceed with the change or will seek an alternative. If that is not possible, either party may terminate the contract without penalty.

6.2. The up-to-date subprocessor list is available at app.toniagent.com/legal/subprocessors .

7. Security and Technical and Organisational Measures

Technical measures: encryption in transit (TLS 1.2+), encryption at rest (AES-256) for recordings, transcripts and OAuth tokens, logical segmentation per client (multi-tenant isolation), role-based access control with mandatory MFA, immutable audit logs, anomaly detection on the API and on calls, and encrypted backups with limited retention.

Organisational measures: least-privilege access policy, all personnel bound by confidentiality agreements, periodic security reviews (at least every six months), documented deletion and incident management procedures, and mandatory data protection training for all personnel.

ISO 27001 certification: The Processor plans to obtain ISO 27001 certification (Information Security Management System) during the fourth quarter of 2026. This certification will evidence the implementation of an internationally recognised security framework, audited by an independent body.

A detailed technical annex can be provided at the Controller's request.

8. Confidentiality

All of the Processor's personnel are bound by confidentiality obligations, which survive even after the end of their employment or contractual relationship with the Processor.

9. Data Retention — Configurable Retention Policy

9.1. Standard policy (default):

Data typeStandard retentionConfigurable options
Voice recordings12 monthsCan be reduced to < 24h (deleted after transcription) / 7/30/90/180/365 days
Transcripts12 monthsCan be reduced to < 24h / 30/90/180/365 days
Metadata and logs12 months6/12/24 months
Analytics dataAnonymised at 30 daysImmediate anonymisation / 7/30/90 days
Google Calendar (tokens/events)While the integration is activeDeleted immediately on disconnection

9.2. The Controller may request a retention configuration different from the standard one by writing to privacy@toniagent.com . The Processor will implement the requested configuration within a maximum of 10 business days.

9.3. Standard retention for voice recordings and transcripts is 12 months. The Controller may disable call recording from the control panel, in which case recordings are deleted after transcription (< 24 hours). This setting is available from the "Legal i Compliment" section of each agent's panel.

9.4. On termination of the contract, all data will be deleted within a maximum of 30 days, unless there is a legal obligation to retain it. The Controller may request a copy before deletion.

10. Data Deletion

On termination of the contract or at the Controller's request: data will be deleted or returned (at the Controller's choice), the Processor will issue a certificate of destruction if the Controller requests one, and only data strictly necessary under a legal obligation will be retained, duly identified and with restricted access.

11. Data Breaches

The Processor will notify the Controller without undue delay and within a maximum of 36 hours of becoming aware of the incident. The notification will include: the nature of the breach, the categories of data affected, the approximate number of data subjects, the likely consequences and the measures adopted or proposed. The Processor will cooperate with the Controller in managing the incident and in notifying the AEPD where applicable. It is the Controller who must notify the supervisory authority or the affected data subjects where required.

12. Assessments, Audits and DPIAs

The Controller may: request detailed information about the security measures implemented, carry out reasonable audits (a maximum of one per year, with 30 days' notice), and require cooperation on DPIAs where ToniAgent is used in high-risk processes.

The Processor makes available to the Controller a baseline DPIA template covering the standard use of ToniAgent in medical clinics (available on request at privacy@toniagent.com ). The Controller must adapt it to their specific context.

13. Controller's Obligations

The Controller warrants: a valid legal basis for the processing (Arts. 6 and 9 GDPR), prior and adequate notice to patients about the recording, transcription and AI processing of their calls, correct configuration of the service (including the chosen retention policy), that the data provided is accurate and relevant, and the handling of data subjects' rights (access, rectification, erasure, etc.) with the Processor's cooperation where necessary.

14. Liability

The Processor is responsible for complying with its obligations under the GDPR. Financial liability is limited to what is established in the Terms of Service: a maximum limit equivalent to one (1) month of service.

15. Term and Termination

This DPA is in force for as long as the Controller uses ToniAgent. On termination, clauses 9 and 10 apply.

16. Governing Law

This DPA is governed by Spanish law, the GDPR and the LOPDGDD. Any dispute will be resolved in the courts of Barcelona.

Supplementary documents: