Last updated: 2026-04-14
Version: 2.0
This is an informational translation. The binding text is the Spanish original — in the event of any discrepancy, the Spanish version prevails.
This is an informational English translation of revision 2.0. The binding text is the Spanish original, available at app.toniagent.com/legal/terms-of-services; in the event of any discrepancy, the Spanish version prevails.
These Terms of Service ("Terms") govern access to and use of the ToniAgent service, offered by Productivity Agents SL, with registered address at Carrer Santa Eulalia 5, 08195, Sant Cugat del Vallès (Spain) ("the Company").
By registering on the platform and activating the service, the Client accepts these Terms and confirms having read and accepted the Data Processing Agreement (DPA).
ToniAgent is a virtual voice agent that can:
The service is provided on a SaaS basis.
The Client acknowledges and accepts that ToniAgent acts as virtual administrative staff, following instructions defined by the Client.
The Company does not provide healthcare services and does not deliberately access medical records, diagnoses or clinical processes. Any health data processed will be processed on behalf of the Client in accordance with the DPA.
Using ToniAgent requires:
The Client is responsible for keeping their credentials confidential.
4.1 Billing model: Monthly fees according to the contracted package. Discount for annual payment. Overage charges for additional call minutes.
4.2 Trial period: The Client has a 1-month free trial. On expiry, unless cancelled, the paid plan starts automatically.
4.3 Automatic renewal: Plans renew automatically unless cancelled beforehand.
4.4 Cancellation: Monthly cancellation with no minimum term. For annual plans already paid, no refunds are issued; cancellation affects the renewal only.
The Client undertakes to:
The Client authorises the Company to:
The Client expressly acknowledges and authorises that:
The Company guarantees 99.9% annual service availability.
Excluded are: failures arising from third parties (AWS, Twilio, ElevenLabs or equivalent providers), scheduled maintenance announced in advance, and failures arising from the Client's own configuration.
All ToniAgent software, models, content and documentation are the exclusive property of the Company. The Client retains the rights to their own data and content.
The Client authorises the Company to display their name and logo as a ToniAgent client and to use it in commercial presentations, client listings and on the website. The Client may revoke this permission in writing.
To the maximum extent permitted by law: the Company will not be liable for indirect damages, loss of Client data or loss of profit. The Company's total aggregate liability is limited to an amount equivalent to one (1) month of the contracted service.
The Client accepts the use of the providers detailed in the Subprocessor List . International transfers are carried out under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework, always prioritising European Union regions where possible.
The processing of personal data carried out by ToniAgent is governed by the Data Processing Agreement (DPA), which forms an integral part of these Terms.
These Terms remain in force for as long as the Client uses the service. The Client may cancel at any time from the control panel.
The Company may update these Terms and will give notice of changes at least 15 days in advance.
These Terms are governed by Spanish law. Any dispute will be submitted to the courts of Barcelona, unless the law requires another jurisdiction.
This Privacy Policy describes how Productivity Agents SL ("the Company", "ToniAgent", "we") collects, uses, stores and shares personal information when you use our ToniAgent platform, particularly in relation to third-party integrations such as Google Calendar.
If you choose to connect your Google Calendar account to ToniAgent, we access the following Google user data through the Google Calendar API:
1. Google Account Information:
Your Google email address (used to identify and associate your Google Calendar with your ToniAgent account).
2. Calendar Metadata:
Calendar IDs and names, calendar descriptions, time zone settings, calendar colours (background and foreground), primary calendar indicator.
3. Calendar Events:
Event titles (summary), event descriptions, event locations, start and end times (including all-day event indicators), event status (confirmed, tentative, cancelled), organiser email addresses, attendee information (email addresses and response status), recurrence rules (for recurring events), links to events in Google Calendar.
When you interact with the ToniAgent AI assistant for calendar management, the AI agent processes:
This data is processed in order to carry out your calendar management requests and is subject to the same security and privacy protections as other Google Calendar data.
We use your Google Calendar data for the following purposes:
1. Displaying Calendar Events:
Showing your calendar events within the ToniAgent application interface so that you can see your schedule alongside your other tasks and activities.
2. Local Synchronisation:
Synchronising and storing your calendar events locally in our database for faster access and better performance. This lets you view your calendar without repeated calls to the Google API.
3. Event Notifications (Optional):
If enabled, we configure webhook notifications from Google Calendar to receive real-time updates when your events change, keeping your synchronised events up to date.
4. Calendar Management by the AI Agent:
When you interact with the ToniAgent AI assistant, the agent may carry out the following actions in your Google Calendar on your behalf and with your explicit authorisation:
How AI Agent Modifications Work:
Important Safeguards:
Your Google Calendar data is stored in a PostgreSQL database hosted on Amazon Web Services (AWS) in the Ireland region (eu-west-1). We store three types of data:
We use Amazon Web Services (AWS) as our hosting and database provider. Your Google Calendar data is stored on AWS servers located in the Ireland region (eu-west-1) within the European Economic Area (EEA). AWS acts as a data processor under our Data Processing Agreement (DPA) and is subject to AWS's GDPR-compliant terms.
We do not share your Google Calendar data with any other third-party service, including: analytics providers, advertising networks, marketing platforms, or other integrations (e.g. voice synthesis, telephony services).
Your Google Calendar data is used exclusively within ToniAgent for the purposes described in this policy.
When you authorise ToniAgent to access your Google Calendar, our AI assistant can perform calendar management tasks on your behalf, including:
You have full control over your Google Calendar integration:
Revoke Access at Any Time:
You may disconnect your Google Calendar account from ToniAgent at any time through the Integrations page in your account settings. Disconnecting will immediately delete all OAuth tokens, calendar metadata and synchronised events from our database.
Granular Control:
You may choose which specific calendars to synchronise with ToniAgent. You may disconnect individual calendars while keeping other calendars connected.
Google Account Settings:
You may also revoke ToniAgent's access to your Google Calendar directly through your Google Account settings at myaccount.google.com/permissions . Revoking access through Google will prevent ToniAgent from accessing your calendar data, but you should also disconnect the integration within ToniAgent to delete the locally stored data.
Data Portability:
Your calendar events remain in your Google Calendar at all times. You may export your calendar data directly from Google Calendar using Google Takeout ( takeout.google.com ).
GDPR Rights (EEA Users):
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal or regulatory reasons. We will notify you of any material change by publishing the new policy on this page and updating the "Last updated" date at the top.
If you have questions about this Privacy Policy or about how we handle your Google Calendar data, please contact us at:
Productivity Agents SL Carrer Santa Eulalia 5 08195 Sant Cugat del Vallès, Spain Email: support@toniagent.com
This Data Processing Agreement ("DPA") forms part of the Terms of Service accepted by the Client when registering on the ToniAgent platform, offered by Productivity Agents SL, with registered address at Carrer Santa Eulalia 5, 08195, Sant Cugat del Vallès (Spain) ("the Processor").
The Client ("the Controller") accepts this DPA on activating the service.
This DPA governs the processing of personal data carried out by the Processor on behalf of the Controller through the use of ToniAgent. Processing takes place for as long as the Controller keeps their account active.
ToniAgent processes personal data for the following purposes:
The processing does not include the provision of healthcare services. Any health data processed is processed exclusively on an administrative basis and under the Controller's instructions.
Patient / end-user data: name and contact details, reason for the visit or enquiry, national ID or other identifiers (if provided by the end user), the full content of the conversation (voice and/or text), call transcripts and recordings, information derived from conversational analysis (sentiment, urgency, context).
Controller's staff data: name, email, role and availability for scheduling appointments.
Technical data: usage logs, call metadata, timestamps, access IP addresses.
ToniAgent may incidentally process health data expressed by the patient during a call or interaction. The processing is for administrative (not clinical) purposes, is carried out exclusively under the Controller's instructions, and is covered by Article 9(2)(h) GDPR (management of healthcare services) and by the healthcare professional–patient relationship.
Important: It is the Controller who must ensure the appropriate legal basis for processing these special categories, including giving patients prior notice about the recording and transcription of the call.
The Processor will process personal data only in accordance with the Controller's documented instructions, for the purposes described in this DPA, and may not use it for its own purposes under any circumstances. If an instruction is contrary to the law, the Processor will notify the Controller immediately.
5bis.1. The Processor represents and warrants that it does not use, and does not permit its subprocessors to use, the personal data processed under this DPA to train, fine-tune, improve or develop artificial intelligence models, neural networks, machine learning algorithms, or any other automated decision-making system.
5bis.2. This warranty extends expressly to: voice recordings and their content, generated transcripts, the content of text conversations, calendar and appointment data, and any data derived from conversational analysis.
5bis.3. The Processor contractually requires the same no-training warranty from each subprocessor (see Subprocessor List ). In particular:
5bis.4. Should a subprocessor change its terms of service in a way that may affect this warranty, the Processor will notify the Controller within a maximum of 15 days and, if the warranty cannot be maintained, will replace the subprocessor within a reasonable period.
The Controller expressly authorises the use of the subprocessors detailed in the [Subprocessor List](/legal/subprocessors) .
6.1. Procedure for adding or changing subprocessors:
6.2. The up-to-date subprocessor list is available at app.toniagent.com/legal/subprocessors .
Technical measures: encryption in transit (TLS 1.2+), encryption at rest (AES-256) for recordings, transcripts and OAuth tokens, logical segmentation per client (multi-tenant isolation), role-based access control with mandatory MFA, immutable audit logs, anomaly detection on the API and on calls, and encrypted backups with limited retention.
Organisational measures: least-privilege access policy, all personnel bound by confidentiality agreements, periodic security reviews (at least every six months), documented deletion and incident management procedures, and mandatory data protection training for all personnel.
ISO 27001 certification: The Processor plans to obtain ISO 27001 certification (Information Security Management System) during the fourth quarter of 2026. This certification will evidence the implementation of an internationally recognised security framework, audited by an independent body.
A detailed technical annex can be provided at the Controller's request.
All of the Processor's personnel are bound by confidentiality obligations, which survive even after the end of their employment or contractual relationship with the Processor.
9.1. Standard policy (default):
| Data type | Standard retention | Configurable options |
| Voice recordings | 12 months | Can be reduced to < 24h (deleted after transcription) / 7/30/90/180/365 days |
| Transcripts | 12 months | Can be reduced to < 24h / 30/90/180/365 days |
| Metadata and logs | 12 months | 6/12/24 months |
| Analytics data | Anonymised at 30 days | Immediate anonymisation / 7/30/90 days |
| Google Calendar (tokens/events) | While the integration is active | Deleted immediately on disconnection |
9.2. The Controller may request a retention configuration different from the standard one by writing to privacy@toniagent.com . The Processor will implement the requested configuration within a maximum of 10 business days.
9.3. Standard retention for voice recordings and transcripts is 12 months. The Controller may disable call recording from the control panel, in which case recordings are deleted after transcription (< 24 hours). This setting is available from the "Legal i Compliment" section of each agent's panel.
9.4. On termination of the contract, all data will be deleted within a maximum of 30 days, unless there is a legal obligation to retain it. The Controller may request a copy before deletion.
On termination of the contract or at the Controller's request: data will be deleted or returned (at the Controller's choice), the Processor will issue a certificate of destruction if the Controller requests one, and only data strictly necessary under a legal obligation will be retained, duly identified and with restricted access.
The Processor will notify the Controller without undue delay and within a maximum of 36 hours of becoming aware of the incident. The notification will include: the nature of the breach, the categories of data affected, the approximate number of data subjects, the likely consequences and the measures adopted or proposed. The Processor will cooperate with the Controller in managing the incident and in notifying the AEPD where applicable. It is the Controller who must notify the supervisory authority or the affected data subjects where required.
The Controller may: request detailed information about the security measures implemented, carry out reasonable audits (a maximum of one per year, with 30 days' notice), and require cooperation on DPIAs where ToniAgent is used in high-risk processes.
The Processor makes available to the Controller a baseline DPIA template covering the standard use of ToniAgent in medical clinics (available on request at privacy@toniagent.com ). The Controller must adapt it to their specific context.
The Controller warrants: a valid legal basis for the processing (Arts. 6 and 9 GDPR), prior and adequate notice to patients about the recording, transcription and AI processing of their calls, correct configuration of the service (including the chosen retention policy), that the data provided is accurate and relevant, and the handling of data subjects' rights (access, rectification, erasure, etc.) with the Processor's cooperation where necessary.
The Processor is responsible for complying with its obligations under the GDPR. Financial liability is limited to what is established in the Terms of Service: a maximum limit equivalent to one (1) month of service.
This DPA is in force for as long as the Controller uses ToniAgent. On termination, clauses 9 and 10 apply.
This DPA is governed by Spanish law, the GDPR and the LOPDGDD. Any dispute will be resolved in the courts of Barcelona.
Supplementary documents: