Data Processing Agreement
Last updated: September 22, 2026 · Forms part of the Terms of Service
Between ImmCase Digital Solutions Ltd (“ImmCase”, the processor) and the firm subscribing to ImmCase (you, the controller). It applies whenever you put personal information about your clients, applicants, their family members, employers or anyone else into ImmCase.
1. Which of us decides what
You are the controller. You decide whose information goes into ImmCase, what is recorded, how long it is kept, and who in your firm may see it. You are responsible for having the authority to put that information there, and for the consents your professional and privacy obligations require.
We are the processor. We hold and process that information only to provide the service, and only on your instructions. Your instructions are: the Terms of Service, the settings you choose in the product, and anything you ask us in writing.
We will not use your client data for our own purposes, disclose it except as this agreement allows, or use it to train, fine-tune or evaluate machine-learning models.
If we think an instruction of yours would breach Canadian privacy law, we will tell you rather than simply carry it out.
2. What is processed
Categories of people. Your clients and applicants; their family members and dependants; employers, sponsors and referees; your own staff.
Categories of information. Identity and contact details; immigration identifiers such as UCI and application numbers; dates of birth and nationality; passport, travel and status history; education and employment history; language test results; financial information supporting an application; correspondence; uploaded documents; and case, checklist and file-management records.
Some of this is sensitive, including information about health, family composition, financial position and, in some matters, the circumstances of a protection claim. It is handled with the separation and access controls in section 4.
Duration. For as long as your workspace is open, then as section 8 sets out.
3. Your obligations
You will:
- have a lawful basis and any necessary consent for the information you enter;
- keep your users’ access rights current, and remove people who leave;
- use the field- and role-level controls the platform provides where a matter needs them;
- meet your own obligations under the College of Immigration and Citizenship Consultants Act, the Code of Professional Conduct and the Client File Management Regulation. Those are yours, and this agreement does not move them.
4. What we do to keep it safe
This describes the platform as it is today, not as we intend it to be.
Separation. Each firm gets its own database, its own file storage, its own cache namespace and job queue, and its own hostname. An unrecognised host is rejected. One firm’s records cannot be returned to another by a mistaken query, because they are not in the same database.
Access control. Role-based permissions per module (view, create, edit, delete) and per field (write, read-only, invisible). Fields marked invisible are removed on the server before a record is sent to the browser.
Authentication. Passwords are stored as salted hashes. Sessions expire and can be revoked by a firm administrator. Multi-factor authentication is not yet available in ImmCase; it is a committed roadmap item.
In transit. TLS on every endpoint, including desktop sync and calendar clients.
At rest. Dedicated servers in Canada, in an OVHcloud facility in Beauharnois, Québec, on redundant storage with operating-system access controls. Credentials we hold on your behalf — mailbox passwords, tokens issued by Microsoft and Google, storage and telephony keys — are encrypted inside the database. Client records themselves are not encrypted at the application layer, and full-disk encryption is not currently applied to production hosts. We will update this section when that changes.
Audit trail. Changes to client records are recorded with the user, the time and the IP address, and document activity is kept in its own append-only log.
Backups. Nightly per-firm database dumps on a rolling retention window. A restore is per firm and does not require or affect another firm’s data.
People. Access to production is limited to named personnel who need it, under confidentiality obligations, with individual credentials, and is revoked on role change or departure.
5. Sub-processors
You give general authorisation for the sub-processors below. We remain responsible for what they do with your data, and we impose obligations on them no less protective than these.
| Sub-processor | Purpose | What it receives |
|---|---|---|
| OVHcloud | Dedicated server hosting in Canada (Beauharnois, Québec) | All application data |
| SMTP2GO | Delivery of email the service sends on its own behalf, such as notifications and password resets | Those messages’ content and recipient addresses |
| Stripe | Subscription billing and card payments | Billing details only — never client or case data. Card numbers go directly to Stripe and never reach us. |
Services we operate ourselves on the same Canadian infrastructure — text recognition on uploaded documents, realtime updates, video calling, in-browser document editing and our IRCC data service — are not third-party sub-processors, but they do process your data and are covered by section 4. ImmCase does not send client data to external artificial-intelligence providers.
Optional integrations you switch on (a connected mailbox, a messaging channel, a calendar account, a document service) send data to that provider because you chose to connect it. That choice is yours, and that provider’s terms apply to it. Email your staff send from ImmCase goes out through your own connected mailbox, not through SMTP2GO.
Changes. We will give you at least 30 days’ notice before adding or replacing a sub-processor that handles client data. If you reasonably object on data-protection grounds, tell us within that period and we will either propose an alternative or you may terminate the affected service without penalty for the unused portion of your term.
6. Security incidents
If we confirm a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to your client data, we will:
- notify your firm’s designated contact without undue delay, and in any case within 72 hours of confirmation;
- tell you what we know: what happened, which categories and roughly how many records, the likely consequences, and what we are doing about it;
- keep you updated as we learn more, rather than wait for a complete picture before the first notification;
- help you meet your own obligations under PIPEDA, BC PIPA and your professional rules.
You decide whether to notify affected individuals, the Privacy Commissioner or the College — it is your data and your regulatory relationship. We will not notify your clients on your behalf without your instruction.
7. Helping you meet your obligations
Access and correction requests. If we receive a request from one of your clients, we will not answer it ourselves. We will pass it to you promptly and help you respond, including by producing the data we hold.
Records and audits. On reasonable written notice, not more than once a year unless a regulator or an incident requires it, we will give you the information you reasonably need to confirm we are meeting this agreement. Where that would disclose another firm’s data or compromise platform security, we will provide it in a form that does not.
Privacy impact assessments. We will give you reasonable assistance if you carry one out.
8. Return and deletion
On termination or expiry of your subscription:
- for 30 days you may request an export of your data in a machine-readable format, and we will provide it at no charge;
- after that, and no later than 90 days after closure, we delete your database, your file storage and any archive copy made while closing your workspace. We do not keep a long-term archive of your data;
- backups age out on their normal rolling schedule, and we do not restore a deleted workspace from them except at your written request within the export window;
- we may keep the minimum account and billing records that tax and corporate law require, which do not include your client files.
On written request we will confirm deletion in writing.
Export before you close. Your six-year retention duty under CICC Client File Management Regulation 2021-001 s. 7.2 survives the end of this agreement. We do not hold your files for you afterwards.
9. International transfers
Your client data is stored and processed in Canada. We will not move where it is stored or processed outside Canada without telling you first; if that ever changes we will identify the destination and the safeguard relied on, and give you the right to object.
Two things in section 5 are outside that statement, and we would rather say so: service email relayed through SMTP2GO is handled on that provider’s infrastructure, and optional integrations you enable may operate outside Canada. Connecting an integration is your decision.
10. Liability and precedence
This agreement is subject to the limitation of liability in the Terms of Service.
Where this agreement and the Terms conflict on the handling of client personal information, this agreement prevails.
11. Governing law
The laws of the Province of British Columbia and the federal laws of Canada applicable there, with the courts of British Columbia having exclusive jurisdiction.
Contact
Questions about this agreement, or notices under it:
ImmCase Digital Solutions Ltd
Email: privacy@immcase.com
Mailing address: 105-111 W Broadway, Vancouver, BC V5Y 1P4, Canada
See also our Privacy Policy and Terms of Service.
