Work line
Thalovant Data Processing Agreement
How Thalovant processes personal information on behalf of organisations, under GDPR Article 28, Quebec Law 25, PIPEDA and US state privacy laws.
1. Definitions and roles
1.1 Terms. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the EU General Data Protection Regulation (GDPR). For Canadian law, "personal data" includes "personal information". "Data Protection Laws" means all laws that apply to the processing under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the Personal Information Protection and Electronic Documents Act (PIPEDA), the Quebec Act respecting the protection of personal information in the private sector (as amended by Law 25), and US state privacy laws such as the California Consumer Privacy Act (CCPA).
1.2 Roles. The Customer is the controller (under Quebec law, the person carrying on an enterprise that communicates personal information to a mandatary). Thalovant is the processor (under Quebec law, a mandatary or service provider; under the CCPA, a service provider). Where the Customer acts as a processor for another controller, Thalovant is a subprocessor and the Customer is responsible for passing on the relevant obligations.
1.3 Outside this DPA. Thalovant processes some information as an independent controller, as described in the Privacy Notice: account and billing administration, security and abuse prevention, and compliance with law. Where Stripe acts as merchant of record, it processes payment information as an independent controller.
2. Instructions
2.1 Documented instructions. Thalovant processes Customer personal data only on the Customer's documented instructions. The Business Terms, this DPA, the Customer's configuration of the Services (for example, its hubs, skills, ACL policies and retention settings) and any written instructions agreed later are the Customer's complete instructions.
2.2 Unlawful instructions. Thalovant informs the Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is confirmed or changed.
2.3 Legal requirements. If the law requires Thalovant to process personal data other than on the Customer's instructions, Thalovant informs the Customer before processing, unless the law prohibits it.
2.4 Customer responsibilities. The Customer is responsible for the lawfulness of its instructions, for providing notices to and obtaining any consents from data subjects (including through the venue signage required by section 8 of the Business Terms), and for the accuracy of the personal data it submits.
3. Details of the processing
| Item | Description |
|---|---|
| Subject matter | Providing the Thalovant Services under the Business Terms. |
| Duration | The term of the Business Terms, plus the export and deletion periods in section 10. |
| Nature and purpose | Converting speech to text, generating answers with AI models, executing skills, storing hub configuration, memory items and utterance text, routing connections from clients, authentication, logging for security and troubleshooting, and support. |
| Data subjects | The Customer's Authorised Users (employees, contractors, officials); End Users who talk to the Customer's hubs (for example visitors, patrons, residents, clients); people whose information the Customer puts in memory items or skills. |
| Categories of personal data | Account identifiers and contact details of Authorised Users; utterance text and hub answers; memory items; hub, client and device identifiers; IP addresses and request metadata; support communications. Audio is processed transiently to convert it to text and is not stored. |
| Special categories | Not intended. The Customer must not configure hubs to collect special categories of data (such as health data) or information about criminal convictions unless the Order addresses it. Thalovant does not perform speaker identification or create voiceprints. |
| Retention | Utterance text on paid hubs: up to 90 days. Kid-labelled hubs and anonymous or preview sessions: no utterance text, no IP address, no memory and no conversation journal. Memory items: until deleted by the Customer or its users. Other data: as set out in the Privacy Notice. |
| Location | Thalovant infrastructure in Montreal, Quebec, Canada, plus the subprocessors listed in section 6. |
4. Confidentiality
Thalovant ensures that its personnel and contractors who can access Customer personal data are bound by confidentiality obligations, receive appropriate training, and access personal data only as needed to provide the Services, to provide support the Customer requested, or to comply with law.
5. Security
5.1 Measures. Thalovant implements appropriate technical and organisational measures to protect Customer personal data, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing and the risks to data subjects. The current measures are described in Annex 2.
5.2 Updates. Thalovant may update its measures, provided that the overall level of protection is not reduced.
6. Subprocessors
6.1 General authorisation. The Customer authorises Thalovant to engage the subprocessors listed on the Subprocessors page.
6.2 Changes. Thalovant gives at least 30 days' notice before adding or replacing a subprocessor, by updating the Subprocessors page and emailing Customers who have asked to be notified. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.
6.3 Flow-down. Thalovant imposes on each subprocessor data protection obligations that are at least as protective as this DPA, and remains responsible to the Customer for its subprocessors' performance.
7. Assistance
7.1 Data subject requests. Taking into account the nature of the processing, Thalovant helps the Customer respond to requests from data subjects to exercise their rights, mainly through self-service tools in the dashboard (for example, viewing and deleting memory items and utterance history). If Thalovant receives a request directly, it refers the data subject to the Customer, unless the law requires otherwise.
7.2 Impact assessments and consultations. Thalovant provides reasonable information to help the Customer carry out data protection impact assessments, privacy impact assessments (including those required by Quebec law before communicating personal information outside Quebec), and prior consultations with supervisory authorities.
7.3 Records. Thalovant keeps records of its processing activities as required by Data Protection Laws.
8. Personal data breaches
8.1 Notification. Thalovant notifies the Customer of a personal data breach affecting Customer personal data without undue delay and, where feasible, within 48 hours after becoming aware of it.
8.2 Content. The notification describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases.
8.3 Response. Thalovant takes reasonable steps to contain and remedy the breach, and cooperates with the Customer so that it can meet its own notification and record-keeping obligations, including the confidentiality incident register required by Quebec law.
8.4 No admission. Notifying a breach is not an admission of fault.
9. International transfers
9.1 Canada. Thalovant is established and processes Customer personal data in Canada. The European Commission has recognised that Canada provides an adequate level of protection for personal data transferred to recipients subject to PIPEDA, and the UK and Switzerland recognise Canada in the same way.
9.2 Onward transfers. Where a subprocessor processes personal data in a country without an adequacy decision (for example, the United States), Thalovant ensures an appropriate safeguard is in place, such as the subprocessor's certification under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) or the European Commission's Standard Contractual Clauses, together with any supplementary measures needed.
9.3 Customers outside adequate countries. If Thalovant, acting as processor, transfers personal data back to a Customer located in a country without an adequacy decision, the parties agree that Module 4 (processor to controller) of the Standard Contractual Clauses applies where required, and they are incorporated by reference.
9.4 Quebec. Before personal information is communicated outside Quebec, the Customer carries out the assessment required by Quebec law. Thalovant provides the information reasonably needed for it, including this DPA and the Subprocessors page.
10. Return and deletion
10.1 Export. During the term and for 30 days after it ends, the Customer can export its hub configuration and memory items from the dashboard.
10.2 Deletion. After the export period, Thalovant deletes Customer personal data from its active systems within 30 days, and from backups when they are overwritten in the normal backup cycle, unless the law requires it to keep some data. Data kept for legal reasons remains protected by this DPA and is used only for that reason.
10.3 Certification. On request, Thalovant confirms deletion in writing.
11. Audits
11.1 Information. Thalovant makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation and answers to reasonable security questionnaires.
11.2 Audits. If that information is not sufficient, or if a supervisory authority requires it, the Customer may carry out an audit, or have an independent auditor bound by confidentiality carry it out, no more than once a year, with at least 30 days' notice, during business hours, and without access to other customers' data. The Customer bears its own audit costs.
12. US state privacy laws
Where the CCPA or a similar US state law applies, Thalovant: processes personal information only for the business purposes set out in this DPA; does not sell or share personal information (as those terms are defined in the CCPA); does not retain, use or disclose personal information outside the direct business relationship with the Customer or for any purpose other than those business purposes; does not combine it with personal information received from other sources except as the law allows; complies with the applicable obligations of those laws and provides the same level of privacy protection they require; and notifies the Customer if it can no longer meet those obligations. The Customer may take reasonable steps to stop and remedy unauthorised use. Thalovant certifies that it understands these restrictions.
13. Quebec and Canada
For personal information governed by Quebec law, Thalovant, as mandatary: uses the information only to carry out its mandate; does not keep it after the mandate ends, except as section 10 allows; takes the security measures described in Annex 2; notifies the Customer's person in charge of the protection of personal information without delay of any violation or attempted violation of the obligations regarding the confidentiality of the information; and allows the Customer to carry out the verifications described in section 11.
14. General
14.1 Liability. Each party's liability under this DPA is subject to the limitations in the Business Terms, except where Data Protection Laws do not allow those limitations.
14.2 Precedence. If there is a conflict, the Standard Contractual Clauses (where they apply) prevail over this DPA, and this DPA prevails over the Business Terms for the processing of personal data.
14.3 Governing law. This DPA is governed by the law that governs the Business Terms, except where Data Protection Laws or the Standard Contractual Clauses require another law.
Annex 1. Contacts
| Party | Role | Contact |
|---|---|---|
| Customer | Controller | The account owner and any privacy contact named in the dashboard or Order. |
| Thalovant Technologies Inc., 2727 rue Saint-Patrick, Montréal, Quebec H3K 0A8, Canada | Processor | Privacy officer: privacy@thalovant.com |
| Not appointed yet | Thalovant's EU representative (GDPR article 27) | Contact through privacy@thalovant.com until the representative's details are published. |
Annex 2. Technical and organisational measures
- Location and isolation. Hubs and AI models run on Thalovant-operated hardware in Montreal, Canada. No third-party AI provider receives Customer personal data. Each Customer's hubs, memory and configuration are logically separated.
- Encryption. Data in transit between clients, the edge network and Thalovant systems is encrypted with TLS.
- Access control. Staff access to production systems is limited to people who need it, protected by strong authentication, and logged. Customer access is controlled through accounts, scoped API tokens and ACL policies.
- Data minimisation. Raw audio is not stored. No speaker identification or voiceprints. Utterance text is kept for up to 90 days on paid hubs only; kid-labelled hubs and anonymous sessions keep none.
- Resilience. Backups of configuration data, monitoring of availability, and a documented incident response process.
- Secure development. Dependency and vulnerability scanning, code review, and security updates for our software.
- Vendor management. Subprocessors are reviewed before use and bound by data protection terms.
- Vulnerability reports. Security issues can be reported to security@thalovant.com.
Annex 3. Subprocessors
The current list, with each subprocessor's purpose, location and transfer safeguard, is maintained on the Subprocessors page.
Version 2026-10-01. English is the default language of these documents. Version française (draft translation). Questions: support@thalovant.com.