Tonic AI Privacy Policy - Enterprise Edition
Version 1.0 – June 2026
This Enterprise Privacy Policy explains how Tonic Easy Medical S.A. (“Tonic”, “we”, “us”) processes Personal Data when you access Tonic AI as a Licensed User under a corporate Subscription Agreement between Tonic and your employer or contracting organisation (the “Client”).
This policy applies exclusively to Enterprise access. The Tonic Privacy Policy – Individual Edition, published on Tonic’s website, applies to direct individual use of the Tonic platform, including Tonic AI, outside any corporate subscription. Where you hold both contexts, this Enterprise Privacy Policy governs your Enterprise activity.
- Data-protection roles
1.1. In connection with your Enterprise use of Tonic AI, the Client acts as Controller in respect of: (a) your account information and authentication data; (b) usage logs attributable to you as a Licensed User; and (c) any Personal Data that may be inadvertently included in Inputs.
1.2. Tonic acts as Processor on behalf of the Client for the purposes set out in this policy and in the Subscription Agreement.
1.3. Tonic acts as Controller exclusively for: (a) generating aggregated and irreversibly anonymised datasets. Once anonymisation is complete, the resulting datasets fall outside the scope of GDPR and do not constitute Personal Data within the meaning of Article 4(1) GDPR; and (b) limited Personal Data Tonic must retain to comply with its own legal obligations (including MDR vigilance and pharmacovigilance retention duties, on the basis of Article 6(1)(c) GDPR).
1.4 Tonic may also act as independent Controller for processing activities related to regulatory compliance, security incidents, anonymised analytics and platform integrity (Article 6(1)(f) GDPR – legitimate interest in maintaining a secure and reliable service).
- Personal Data we process
2.1. When you access Tonic AI under the Enterprise Edition, the following categories of Personal Data are processed:
- Identification and professional data: name, professional email address, professional ID, professional specialty, country of practice, and the legal entity through which you are authorised.
- Authentication data: authentication identifiers, multi-factor authentication tokens.
- Technical and usage data: IP address, device identifier, browser type, operating system, login timestamps, session duration, and access logs.
- Inputs: queries and prompts you submit to Tonic AI during clinical decision support, which may incidentally contain Personal Data despite the prohibition in clause 4 of the Enterprise Terms of Use.
2.2. Tonic does not collect from Licensed Users: date of birth, home address, personal phone number, marital status, financial information, or any sensitive Personal Data not necessary for Enterprise authentication and use.
- Purposes and legal bases
3.1. Tonic processes Personal Data for the following purposes and on the following legal bases:
- Service provision and account management – performance of the Subscription Agreement (Article 6(1)(b) GDPR for the Client; Article 28 GDPR for Tonic as Processor).
- Security, monitoring, and misuse detection – legitimate interest of Tonic and the Client (Article 6(1)(f) GDPR) in maintaining a secure platform.
- Compliance with MDR (Class IIa medical device obligations), the EU AI Act, and pharmacovigilance law – legal obligation (Article 6(1)(c) GDPR).
- Generation of aggregated, irreversibly anonymised datasets to operate and improve Tonic AI and Tonic’s insights products – legitimate interest (Article 6(1)(f) GDPR), with anonymisation taking the resulting datasets outside the scope of GDPR.
- Pharmacovigilance and adverse-event data
4.1. Tonic AI is not a pharmacovigilance reporting channel. You should report adverse drug reactions or device incidents to the competent national authority through the appropriate channel (e.g. in Italy, AIFA; in Portugal, Infarmed; in other jurisdictions, the relevant competent authority).
4.2. Where information about a suspected adverse event is nonetheless included in an Input, Tonic processes it solely to comply with its legal obligations under MDR Article 87 (vigilance) and applicable pharmacovigilance law, based on Article 6(1)(c) GDPR.
4.3. Identifiable pharmacovigilance Personal Data is never used for analytics, AI training, or commercial purposes. Retention of such Personal Data may exceed the standard retention periods of this policy where required by regulatory law.
- Aggregated and anonymised data
5.1. Tonic generates aggregated and irreversibly anonymised datasets (Article 6(1)(f) GDPR – legitimate interest in operating and improving the platform and Tonic’s insights products) from Inputs, Outputs, and platform usage data. The anonymisation process applies the following minimum controls:
- Removal of direct identifiers.
- Transformation or generalisation of indirect identifiers.
- Aggregation into groups meeting minimum cohort thresholds.
- Periodic re-identification-risk assessments.
5.2. Tonic may use such anonymised datasets to operate and commercialise Tonic’s insights products (including Tonic BI). Anonymised datasets are not Personal Data and do not allow re-identification of any healthcare professional, patient, or other individual.
Aggregation and anonymisation measures are designed to prevent the identification or singling out of individual healthcare professionals.
Tonic shall not use anonymised datasets derived predominantly from Client activity to generate Client-specific competitive intelligence or to train foundation models without Client’s prior written consent.
- Disclosure and sharing
6.1. Tonic does not sell, rent, or otherwise commercialise your identifiable Personal Data.
6.2. Tonic may share Personal Data with: (a) sub-processors providing infrastructure, hosting, security, or analytics services, each bound by data-protection obligations no less protective than those owed to the Client, in accordance with Article 28(4) GDPR; (b) competent regulatory authorities where required by law (including in connection with MDR vigilance (Article 87) and pharmacovigilance); and (c) the Client, in the form of administrative dashboards and audit logs reflecting your authorised use.
6.3. Tonic does not disclose the content of Inputs to other Licensed Users, to other clients, or to any third party not authorised under the Subscription Agreement.
- Data residency and international transfers
7.1. Personal Data is stored and processed within the European Economic Area (EEA).
7.2. Where a transfer outside the EEA is necessary for the operation of Tonic AI, such transfer is subject to: (a) appropriate safeguards under Chapter V GDPR (including Standard Contractual Clauses); and (b) the consent and data-residency requirements set out in the Subscription Agreement, which may be stricter than the safeguards available under GDPR alone.
- Retention
8.1. Personal Data is retained for the duration of the Subscription Agreement and for the deletion period set out therein following termination, save where: (a) longer retention is required by law (including MDR vigilance and pharmacovigilance retention obligations); or (b) Personal Data has been irreversibly anonymised, in which case the resulting datasets are not Personal Data and may be retained by Tonic.
8.2. On termination of the Subscription Agreement, Inputs are deleted in accordance with the timeline and process set out in that agreement, including the issuance, on request, of a deletion certificate signed by Tonic’s Data Protection Officer.
- Your rights as a data subject
9.1. You have the rights set out in Chapter III GDPR, including: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and objection (Article 21). Where applicable, you may also withdraw consent at any time, without affecting the lawfulness of prior processing.
9.2. Because your employer or contracting organisation is the Controller for most processing under this policy, you should exercise these rights primarily through your employer or contracting organisation . Where you contact Tonic directly, Tonic will forward your request to your employer or contracting organisation and assist in responding.
9.3. You may lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement, in accordance with Article 77 GDPR. For example, in Italy: Garante per la protezione dei dati personali (www.garanteprivacy.it); in Portugal: Comissão Nacional de Proteção de Dados (www.cnpd.pt).
- Security
10.1. Tonic implements appropriate technical and organisational measures under Article 32 GDPR, including: encryption at rest and in transit, access controls in accordance with the principle of least privilege, authentication mechanisms, logging and monitoring, regular security testing, and an information-security management system aligned with ISO 27001.
10.2. Tonic notifies the Client without undue delay and in any event within seventy-two (72) hours, of any Personal Data breach affecting Client data, in accordance with the Subscription Agreement and Article 33 GDPR.
- Sub-processors
11.1. Tonic engages sub-processors to provide certain elements of the Tonic AI service. The Client provides general written authorisation under the Subscription Agreement for such engagement. A list of sub-processors is available to the Client on written request. Tonic notifies the Client of any addition or replacement of a sub-processor at least thirty (30) days before the change takes effect, allowing the Client an opportunity to object on specific and documented data-protection grounds in accordance with the Subscription Agreement.
11.2. All sub-processors are bound by data-protection obligations no less protective than those Tonic owes to the Client, in accordance with Article 28(4) GDPR, and are reviewed for security and data-protection compliance prior to engagement.
- AI-specific transparency
12.1. You are interacting with an AI system. Tonic AI incorporates a CE-marked Class IIa medical device whose intended purpose is to support clinical decision-making, not to replace it.
12.2. Tonic complies with applicable obligations under Regulation (EU) 2024/1689 (the AI Act), including transparency, technical documentation, risk management, human oversight, and post-market monitoring.
12.3. Identifiable Personal Data is not used to train Tonic’s foundation models. Aggregated, irreversibly anonymised data may be used for model evaluation and improvement.
- Changes to this Enterprise Privacy Policy
13.1. Tonic may update this policy from time to time. Non-material changes will be notified through the platform or by email.
13.2. Material changes that adversely affect Licensed Users’ rights, or that affect the Client’s rights under the Subscription Agreement, shall not take effect without the Client’s prior written consent.
- Contact and Data Protection Officer
For questions about this Enterprise Privacy Policy or to exercise your data-subject rights:
Tonic Easy Medical S.A. – Data Protection Officer
Rua do Heroísmo 283 Arm. 1, 4300-259 Porto, Portugal
Phone: +351 223 162 973 | Email: dpo@tonicapp.com