Tonic Privacy Policy
Last update: April 2026
- Introduction and scope
1.1. Tonic Easy Medical S.A. (“Tonic“, “we“, “us“) respects your privacy. This Privacy Policy explains how we collect, use, share, and protect Personal Data when you use the Tonic platform as an individual healthcare professional (“You“).
1.2. This Privacy Policy applies to:
- the Tonic website at tonicapp.io and its subpages;
- the Tonic web application;
- the Tonic mobile applications (iOS and Android);
- the Tonic browser extension for Google Chrome; and
- email channels through which Tonic communicates with You, (together, the “Platform“).
1.3. This Privacy Policy is the Individual Edition. It applies to direct individual use of the Platform by healthcare professionals. Where access to specific Tonic products is provided under a corporate subscription agreement (for example, Tonic AI – Enterprise Edition), the corresponding Enterprise Privacy Policy and the Subscription Agreement govern that use.
1.4. By using the Platform, You acknowledge that You have read this Privacy Policy. Specific consents, where required, are obtained separately within the Platform.
1.5. Tonic is free of charge for healthcare professionals. The Platform is funded through partnerships with life sciences companies and other organisations – in particular, sponsored communications and content, paid job listings in the jobs section, and the commercialisation of aggregated, irreversibly anonymised insights. These activities are described in clauses 9 and 10 and are designed to keep Your identifiable data protected at all times.”
- Who we are and how to contact us
2.1. Tonic Easy Medical S.A. is the data controller responsible for the processing of Your Personal Data under this Privacy Policy.
Registered office: Rua do Heroísmo 281 Arm. 1, 4300-259 Porto, Portugal
Telephone: +351 223 162 973
Data Protection Officer (DPO): dpo@tonicapp.com
General contact: support@tonicapp.com
- Definitions
3.1. In this Privacy Policy:
- “Personal Data” has the meaning given in Article 4(1) of the General Data Protection Regulation (“GDPR“) – any information relating to an identified or identifiable natural person.
- “Health Data” means Personal Data concerning health within the meaning of Article 4(15) GDPR, processed under the conditions of Article 9 GDPR.
- “AI System” means the artificial-intelligence components of the Platform, in particular Tonic AI.
- “Aggregated Data” means data that has been irreversibly anonymised so that no individual can be identified, alone or in combination with other reasonably available information.
- The Tonic Platform – what it includes
4.1. The Platform offers several features and tools for healthcare professionals, including:
- Tonic AI – a clinical AI co-pilot supporting knowledge retrieval and clinical decision-making (a CE-marked Class IIa medical device under Regulation (EU) 2017/745, “MDR“);
- Medical calculators and scales (a CE-marked Class IIa medical device under MDR);
- Clinical decision trees;
- Medical games and learning tools;
- A jobs section listing professional opportunities for doctors;
- Curated healthcare news;
- Other educational and professional content.
4.2. Tonic operates within a certified Quality Management System (ISO 13485) and a certified AI Management System (ISO 42001), and complies with applicable obligations under MDR and Regulation (EU) 2024/1689 (the “AI Act“).
- Personal Data we collect
5.1. Information You provide directly
5.1.1. Account registration data: first and last name, year of birth, email address, phone number, medical specialty, professional licence number, country of practice, educational institution, and year of conclusion of medical degree.
5.1.2. Profile photograph that You may upload.
5.1.3. Responses to medical quizzes, surveys, and other interactive content, when You voluntarily participate. Individual responses are processed by Tonic; sponsors of such content receive aggregated and non-identifiable results only, in accordance with clause 9.4.
5.1.4. Inputs You submit to AI features of the Platform (queries, prompts, content) – see clause 5.4.
5.1.5. Communications You send to us through email or in-Platform support.
5.2. Information collected automatically
5.2.1. Technical data such as IP address, device identifier, browser type, operating system, and language.
5.2.2. Usage data such as login timestamps, pages visited, features used, session duration, and approximate location derived from IP address (country and city level only – no GPS or precise location).
5.2.3. Cookies and similar technologies are addressed in our separate Cookie Policy.
5.3. Information from third parties
5.3.1. Where lawfully permitted, we may receive Personal Data from professional registries and verification providers to confirm Your professional credentials, and from partners that have collected data with Your prior consent.
5.4. AI inputs and pharmacovigilance content
5.4.1. When You use AI features such as Tonic AI, Your queries and any content You include in them are processed to operate the AI and to fulfil related regulatory obligations. You are responsible for not entering directly identifiable patient data; the Tonic Terms of Use – Individual Edition explain Your obligations.
5.4.2. Where information You submit relates to a suspected adverse drug reaction or device incident, Tonic processes the minimum necessary Personal Data to comply with pharmacovigilance and MDR vigilance obligations under clause 8.
- Why we process Your Personal Data and on what legal basis
6.1. We process Personal Data only for specific purposes and on the legal bases set out in the table below. Each purpose is grounded in one or more legal bases under Articles 6 and 9 GDPR.
| Purpose | Categories of Personal Data | Legal basis (GDPR) |
|---|---|---|
| Creating and managing Your account; providing the Platform’s core features. | Account registration data; technical and usage data. | Performance of a contract – Article 6(1)(b). |
| Operating Tonic AI and other AI features, including security monitoring and abuse detection. | Account data; AI inputs; technical and usage data. | Performance of a contract – Article 6(1)(b); legitimate interests in security and quality – Article 6(1)(f). |
| Operating Tonic AI and the medical-calculators module as CE-marked medical devices, including post-market surveillance and vigilance. | Account data; AI inputs; usage data; pharmacovigilance reports. | Compliance with a legal obligation – Article 6(1)(c); reasons of public interest in the area of public health – Article 9(2)(i). |
| Pharmacovigilance and MDR vigilance reporting to competent authorities. | Reporter contact data; minimal patient information; suspected-adverse-event details. | Legal obligation – Article 6(1)(c); public interest in public health – Article 9(2)(i). |
| Sending newsletters, healthcare news, and sponsored content from Tonic’s pharmaceutical or other partners (no third-party ad networks). | Account data; engagement metrics; specialty. | Consent – Article 6(1)(a). You may withdraw at any time. |
| Generating aggregated and irreversibly anonymised datasets to operate, evaluate, and improve the Platform and Tonic’s insights products. | AI inputs and outputs; usage data, after anonymisation. | Legitimate interests – Article 6(1)(f). Anonymised datasets are no longer Personal Data. |
| Verifying Your professional credentials. | Professional licence; specialty; educational institution. | Legitimate interests in ensuring that only qualified healthcare professionals access the Platform – Article 6(1)(f). |
| Responding to Your requests, support enquiries, and exercising data-subject rights. | Account data; correspondence content. | Performance of a contract – Article 6(1)(b); legal obligation – Article 6(1)(c) (for rights requests). |
| Conducting voluntary medical quizzes, surveys, and market research. | Quiz and survey responses; account data. | Consent – Article 6(1)(a). Participation is optional. |
| Facilitating Your application to a job listed in the Platform’s jobs section, including forwarding Your application to the employer or recruiter that posted the role. | Account data; application content; CV or other documents You attach. | Consent and performance of a contract at Your request – Articles 6(1)(a) and 6(1)(b). |
| Detecting and preventing fraud, misuse, prompt injection, and other security incidents. | Technical data; usage data; AI inputs (where misuse is suspected). | Legitimate interests in protecting the Platform and its users – Article 6(1)(f). |
| Defending legal claims and complying with court orders or supervisory-authority requests. | All categories where strictly necessary. | Legitimate interests – Article 6(1)(f); legal obligation – Article 6(1)(c). |
6.2. Where we rely on legitimate interests, we have carefully considered Your rights and concluded that they are not overridden by those interests. You have the right to object at any time – see clause 15.
6.3. Where we rely on consent, You may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawal can be done directly in Your account settings or by contacting our DPO.
6.4. If we ever wish to use Your Personal Data for a new purpose not covered by this Privacy Policy, we will inform You and, where required, obtain Your consent before doing so.
- AI-specific transparency
7.1. When You use Tonic AI or other AI-enabled features, You are interacting with an AI system. Tonic AI is a CE-marked Class IIa medical device intended to support, not replace, clinical decision-making. The medical-calculators and scales module is also a CE-marked Class IIa medical device.
7.2. Tonic operates an AI Management System certified to ISO 42001 and complies with applicable obligations under the AI Act, including transparency, technical documentation, risk management, human oversight, and post-market monitoring.
7.3. Tonic does not train foundation AI models. Tonic builds on third-party foundation models accessed through its sub-processors, and does not transfer identifiable Personal Data to those models for training purposes. Aggregated, irreversibly anonymised data may be used to evaluate and improve AI performance, prevent misuse, and ensure quality and safety.
7.4. Tonic AI may produce outputs that are inaccurate or incomplete. You retain full responsibility for clinical decisions and must independently verify and apply any AI output before relying on it in clinical practice.
7.5. Tonic does not use AI to make automated decisions producing legal or similarly significant effects on You within the meaning of Article 22 GDPR.
- Pharmacovigilance
8.1. Tonic AI and other Platform features are not pharmacovigilance reporting channels. You should report suspected adverse drug reactions or device incidents to the competent national authority through the appropriate channel.
8.2. Where information about a suspected adverse event nonetheless reaches Tonic through the Platform, Tonic processes the minimum Personal Data necessary to comply with its obligations under MDR Article 87 (vigilance) and applicable pharmacovigilance law.
8.3. Pharmacovigilance Personal Data may be disclosed to the European Medicines Agency, national competent authorities, marketing authorisation holders, and other bodies responsible for drug or device safety, solely to comply with regulatory obligations.
8.4. Identifiable pharmacovigilance Personal Data is never used for analytics, AI training, advertising, sponsored content, or any commercial purpose. It may be retained for as long as required by regulatory law, which may exceed the general retention periods of clause 13.
- How the Platform is funded – sponsored content, jobs, and aggregated insights
9.1. Tonic is free of charge for healthcare professionals. The Platform is funded by three categories of activity, each described below: sponsored communications and content, paid job listings, and aggregated insights for life sciences companies. Tonic does not display advertising from third-party advertising networks and does not sell Your identifiable Personal Data.
9.2. Sponsored communications and content
9.2.1. Tonic may send You sponsored content, newsletters, educational materials, and communications from pharmaceutical or other healthcare partners. Sponsored content is sent on the basis of Your consent, which You may withdraw at any time through Your account settings or by contacting our DPO.
9.2.2. Sponsored content selection may use account information such as Your medical specialty, country of practice, type of practice, and engagement history with previous communications. Tonic does not share Your identifiable Health Data, AI inputs, or pharmacovigilance information with sponsors for targeting purposes.
9.2.3. Tonic provides sponsors with aggregated, non-identifiable performance reports for their campaigns – for example, total reach, breakdown by specialty or country, open rates, and click-through rates. Such reports do not allow sponsors to identify individual recipients.
9.2.4. Withdrawal of consent for sponsored content does not affect transactional or service-related communications (security alerts, account notifications, Privacy Policy updates), which are necessary for the operation of the Platform.
9.3. Paid job listings
9.3.1. The jobs section displays professional opportunities posted by employers, recruiters, and other partners. Listings are paid placements; Tonic earns a fee from the entity posting the role.
9.3.2. When You browse the jobs section, no Personal Data is shared with the entity that posted a listing. Browsing is private.
9.3.3. When You actively apply to a job, the application data You submit (which may include account information, a CV, and a cover letter or message) is collected by Tonic and forwarded to the employer or recruiter that posted the listing. From the moment of forwarding, that entity acts as an independent data controller in respect of Your application data, under its own privacy policy. Tonic remains controller in respect of its own retention of the application record.
9.3.4. Tonic retains a record of Your applications submitted through the Platform for as long as necessary to operate the jobs section and to demonstrate compliance, in accordance with clause 13.
9.3.5. Tonic does not transfer Your account data, AI inputs, or any other Personal Data to employers or recruiters except where You actively apply to a specific listing.
9.4. Aggregated insights for life sciences companies
9.4.1. Tonic generates aggregated and irreversibly anonymised insights from Platform usage data – including AI inputs, content engagement, quiz and survey responses, and behavioural patterns of healthcare professionals – and commercialises these insights to life sciences companies and other organisations as part of its business model.
9.4.2. These insights describe trends, knowledge gaps, treatment-related questions, and information needs at population level. They do not identify, and cannot reasonably be used to identify, any individual healthcare professional, patient, or other person.
9.4.3. The anonymisation process applies the following minimum controls: removal of direct identifiers, transformation or generalisation of indirect identifiers, aggregation into groups meeting minimum cohort thresholds, and periodic re-identification-risk assessments.
9.4.4. Identifiable Health Data, identifiable AI inputs, and identifiable pharmacovigilance information are never used to generate or commercialise insights.
9.4.5. You may object to the inclusion of Your data in the anonymisation pipeline by contacting our DPO. Where such objection is upheld, Your data will be excluded from future anonymised datasets; previously generated anonymised datasets cannot be unwound, as they no longer contain Personal Data.
- How we share and disclose Personal Data
10.1. We share Personal Data only as described in this Privacy Policy, with the following categories of recipients:
- Service providers and sub-processors that operate parts of the Platform (hosting, infrastructure, analytics, customer support, communications), bound by data-protection obligations no less protective than those in this Privacy Policy.
- Employers, recruiters, and other entities that have posted job listings – only when You actively apply to one of their listings, and only the application data You choose to submit (see clause 9.3).
- Competent regulatory authorities (including the European Medicines Agency, national competent authorities, and supervisory authorities) where required by law.
- Pharmaceutical and other healthcare partners, only in the form of aggregated, non-identifiable data, engagement metrics, and aggregated insights (see clauses 9.2 and 9.4).
- Professional credential verification providers.
- Successors in connection with a corporate transaction (merger, acquisition, sale of assets), subject to equivalent privacy commitments.
- Courts and law-enforcement authorities, where required by valid legal process.
10.2. Tonic does not sell Your identifiable Personal Data and does not share it with third-party advertising networks.
10.3. As described in clause 9.4, Tonic commercialises aggregated and irreversibly anonymised insights as part of its business model. Such data is not Personal Data and does not allow re-identification of any individual.
- Sub-processors and international transfers
11.1. Tonic engages sub-processors to provide certain elements of the Platform. A list of sub-processors is available on written request to our DPO. Tonic will inform users of material changes to its sub-processors through updates to this Privacy Policy.
11.2. Personal Data is stored and processed within the European Economic Area (EEA).
11.3. Where a transfer outside the EEA is necessary for the operation of the Platform, such transfer is carried out under Chapter V GDPR, using appropriate safeguards (in particular, Standard Contractual Clauses adopted by the European Commission), supplemented where required by a transfer impact assessment.
- Cookies
12.1. The Platform uses cookies and similar technologies. The categories of cookies used (essential, functional, analytics, and where applicable, those linked to sponsored communications), the legal basis for each, and the means to accept, reject, or manage cookies are described in our Cookie Policy.
12.2. Non-essential cookies are placed only with Your consent, which You may grant, refuse, or withdraw through the cookie banner or Your browser settings, with no detriment to Your access to essential Platform functions.
- How long we retain Your Personal Data
13.1. We retain Personal Data for as long as necessary to provide the Platform and to comply with legal obligations, organised in the following categories:
- Account data and related Platform usage data: for the duration of Your account, plus three (3) years of inactivity (defined as no login during a continuous thirty-six-month period). At the end of this period, Personal Data is securely deleted or irreversibly anonymised.
- AI inputs: retained for the duration of Your account, with periodic anonymisation, and deleted on account deactivation, save where retention is required for security or legal purposes.
- Job application records: retained for up to twenty-four (24) months from submission, to operate the jobs section, support follow-up communications, and demonstrate compliance.
- Backups: deleted within thirty (30) days of removal from production systems.
- Pharmacovigilance and Medical Device Personal Data: retained as long as required by applicable regulatory law, which may exceed the periods above.
- Records of consent and consent withdrawal: retained as required to demonstrate GDPR compliance, typically aligned with the applicable statute of limitations.
13.2. When Personal Data is no longer required, it is securely deleted or irreversibly anonymised. Where legal obligations override (in particular, pharmacovigilance and consent records), those obligations prevail over the periods set out above.
- Security and breach notification
14.1. Tonic implements appropriate technical and organisational measures under Article 32 GDPR, including encryption at rest and in transit, access controls, multi-factor authentication for administrative access, logging and monitoring, regular security testing, and an information-security management framework.
14.2. Tonic conducts Data Protection Impact Assessments (DPIAs) for processing operations that present a high risk to data subjects, in accordance with Article 35 GDPR.
14.3. In the event of a Personal Data breach that is likely to result in a risk to Your rights and freedoms, Tonic will notify the competent supervisory authority without undue delay and within seventy-two (72) hours, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, Tonic will also notify You without undue delay, in accordance with Article 34 GDPR.
- Your rights as a data subject
15.1. Under the GDPR, You have the following rights in relation to Your Personal Data:
- Right of access (Article 15) – to obtain confirmation of, and a copy of, the Personal Data we hold about You.
- Right to rectification (Article 16) – to have inaccurate Personal Data corrected.
- Right to erasure (Article 17) – to have Personal Data deleted, subject to legal retention obligations.
- Right to restriction of processing (Article 18) – to limit how we use Your Personal Data in specific circumstances.
- Right to data portability (Article 20) – to receive Personal Data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.
- Right to object (Article 21) – in particular, to processing based on legitimate interests, including profiling for direct marketing.
- Rights related to automated decision-making and profiling (Article 22) – although Tonic does not currently take such decisions producing legal or similarly significant effects.
- Right to withdraw consent (Article 7(3)) – at any time, where processing is based on consent.
- Right to lodge a complaint with a supervisory authority (Article 77) – in particular, in the Member State of Your habitual residence, place of work, or place of the alleged infringement.
15.2. Where technically supported, You can exercise these rights directly within Your account (for example, data access, rectification, deletion, consent withdrawal, and marketing preferences). Otherwise, please contact our DPO at dpo@tonicapp.com.
15.3. We will respond to verified requests without undue delay and within one (1) month, extendable by a further two months for complex requests. We may need to verify Your identity before acting on a request.
15.4. Exercising Your rights is free of charge, except where requests are manifestly unfounded or excessive.
- Children
16.1. The Platform is intended for healthcare professionals only. We verify professional credentials at registration and do not knowingly process Personal Data of minors under the age of 18. If You believe a minor has registered, please contact our DPO at dpo@tonicapp.com.
- Sharing features
17.1. The Platform may allow You to share certain non-personal content (for example, a link to a medical game or educational resource) by generating a shareable link. The recipient is not registered with Tonic by the sharing action and no Personal Data of the recipient is collected by Tonic through this feature.
17.2. If the recipient subsequently chooses to register with the Platform, they will do so directly and become subject to this Privacy Policy in their own capacity.
- Changes to this Privacy Policy
18.1. Tonic may update this Privacy Policy from time to time.
18.2. Where changes are material – in particular, where they affect the categories of Personal Data we collect, the purposes of processing, or Your rights – we will notify You in advance by email and through the Platform, and where required by law we will obtain Your consent before the changes take effect.
18.3. Non-material changes will be notified by publishing the updated Privacy Policy on tonicapp.io with the revised “last updated” date.
- Contact
For any questions about this Privacy Policy, to exercise Your rights, or to raise a concern, please contact:
Tonic Easy Medical S.A. – Data Protection Officer
Rua do Heroísmo 281 Arm. 1, 4300-259 Porto, Portugal
Telephone: +351 223 162 973
Email: dpo@tonicapp.com