Privacy Policy

Privacy Policy

Last updated: September 22, 2026

This Privacy Policy explains how ImmCase Digital Solutions Ltd (“ImmCase”, “we”, “us”) handles personal information in the ImmCase practice-management service and on www.immcase.com.

ImmCase is used by immigration firms and consultants to run their practice: contacts, applicants, cases, documents, checklists, quotes and invoices. Two other policies cover specific products and remain in force for them: the ImmCase CRM mobile app and ImmCase Meet.

Who is responsible for the information

This distinction matters, because most of the personal information inside ImmCase is not ours.

  • Your firm is responsible for its client information. When a firm uses ImmCase, the firm decides what information it collects about its clients and applicants, why, who in the firm may see it, and how long it is kept. In data-protection terms the firm is the controller and we are its service provider.
  • We are responsible for the service itself — the accounts we issue, the billing relationship with the firm, and the security of the platform the firm’s records sit on.

If you are a client of a firm that uses ImmCase and you want to see, correct or delete your information, please contact that firm directly. They hold the records and they decide what happens to them. We will support the firm in responding, but we cannot act on their records on our own initiative.

What we handle

  • Your firm’s records. Contacts, applicants, cases, notes, checklists, uploaded documents, quotes, invoices, payments and agreements. This is your firm’s data. We store and process it to deliver the service, and for no other purpose.
  • Account information. The name, work email address and role of each user your firm creates, and the password they set, which is stored hashed and never in readable form.
  • Billing information. Your firm’s company details and subscription history. Card details are entered directly with our payment processor and are never held on our servers.
  • Technical records. Our servers log ordinary request information such as IP address, browser type, the page or endpoint requested and the time, which we use to run and secure the service. ImmCase also keeps an audit trail inside each firm’s environment recording which user created, changed, uploaded or downloaded what, and when — a record the firm can consult as part of its own file-management obligations.

Connected mailboxes

ImmCase can connect a firm’s email account so that correspondence appears alongside the matching contact or case. This section describes exactly what that involves, including when a mailbox is connected with Microsoft or Google sign-in.

  • How the connection is authorised. When you connect an Outlook, Microsoft 365 or Gmail mailbox, you sign in with Microsoft or Google directly and approve the access. Your email password is never shown to us or stored by us. We receive only the access and refresh tokens that Microsoft or Google issue, and we keep those encrypted.
  • What we read. We retrieve messages from the folders you choose over a recent time window that your firm configures, rather than the entire mailbox history. For each message we store a copy in your firm’s own ImmCase environment: sender and recipients, subject, date, the message body, and the names, types and sizes of attachments. This is what makes mail searchable in the CRM and attachable to a case.
  • What we do with it. Display your mail in ImmCase, link it to the matching contact or case, and send the messages you choose to send. Nothing else.
  • What we never do. We do not use the contents of your mailbox for advertising, we do not sell it, we do not share it with anyone outside the sub-processors listed below, and we do not use it to train, fine-tune or evaluate any machine-learning model.
  • Sending. Messages you send from ImmCase go out through your own connected mailbox to the recipients you address them to.
  • Turning it off. You can disconnect a mailbox in ImmCase at any time, which stops the synchronisation and removes the stored credentials. You can also revoke our access from your Microsoft or Google account security settings. Messages already copied into your firm’s environment remain part of your firm’s records, under your firm’s retention rules, until your firm deletes them.

Where it is stored

ImmCase production data — client records, uploaded documents and generated submissions — is stored on dedicated servers located in Beauharnois, Quebec, Canada, operated in an OVHcloud facility. ImmCase runs on dedicated hardware rather than shared multi-customer cloud instances. Each firm receives its own separate database — not a shared table with a customer column — so one firm’s records cannot be returned to another by a mistaken query.

Who else is involved

We use a small number of service providers to deliver ImmCase. They act on our instructions and are bound by confidentiality obligations. Firms are notified in advance of any material change to this list.

  • OVHcloud — dedicated server hosting, in Canada. Holds all application data.
  • SMTP2GO — delivery of outbound email that ImmCase sends on the service’s behalf, such as notifications and password resets. Receives message content and recipient addresses.
  • Stripe — payment processing for subscriptions. Receives billing details only, never client or case data.

We also disclose information where the law requires it. We do not sell personal information, and we have never done so.

Document processing and artificial intelligence

  • Text recognition runs on our own infrastructure in Canada. Reading text out of uploaded client documents is done on ImmCase-operated servers. Client documents are not sent to third-party recognition services.
  • No training on client data. Information held in ImmCase is not used to train, fine-tune or evaluate any machine-learning model, by us or by anyone else.
  • No third-party model providers. ImmCase does not send a firm’s client data to external artificial-intelligence providers.

If we introduce a feature that would transmit data externally, we will say so in an updated version of this policy and, where appropriate, make it opt-in.

How we protect it

  • All application and API traffic is encrypted in transit with TLS; plain HTTP requests are redirected to HTTPS, and administrative interfaces are not publicly exposed.
  • Credentials we hold on your behalf — mailbox passwords, the access tokens issued by Microsoft and Google, and storage and telephony keys — are encrypted inside the database, so they are unreadable even to someone holding a database dump. Client records themselves are not encrypted at the application layer; they are protected by the separation and access controls described here and by operating-system controls on the servers.
  • User passwords are stored hashed, never in readable form.
  • Permissions are assigned by role and by module, so staff see only the functions and files their role requires. Sessions expire after inactivity and can be terminated by a firm administrator.
  • Our own administrative access is limited to named personnel, uses individual credentials, is logged, and is revoked on role change or departure. Support staff enter a firm’s environment only where necessary to resolve a request or incident.

We would rather state our current limitations than describe controls we do not have: multi-factor authentication is not yet available in ImmCase and is a committed roadmap item, and full-disk encryption is not currently applied to production hosts — sensitive data is protected at the application and database layer instead. A fuller security and retention overview is available to firms on request.

If something goes wrong

If we confirm a security incident affecting a firm’s data, we will notify that firm’s designated contact without undue delay and in any case within 72 hours of confirmation, with the facts known at the time, the categories of data involved, and the remedial steps taken or planned. Because the firm is responsible for the personal information it holds, any notification to affected individuals or to a regulator remains the firm’s decision; we will provide the information reasonably required to support it.

How long it is kept, and getting it back

  • Retention is your firm’s decision. Records and documents are kept for as long as the firm requires them, to match its own professional record-keeping obligations. We do not impose a shorter period and we do not delete records automatically.
  • Deletion. Records deleted by a user are removed from the active application immediately. Deleted data may persist in backups until those backups expire on their normal cycle. On written request we will confirm deletion in writing.
  • Export. A firm may export its data at any time during its subscription. On termination, a complete export of structured records and stored documents is provided in a machine-readable format. There is no charge for a standard export and no contractual restriction on a firm’s ability to move its data. The retrieval window is 30 days. After it, and no later than 90 days after closure, the firm’s data — including any archive copy made while closing the account — is deleted from production systems, and from backups as those backups expire. We do not keep a long-term archive of a firm’s data. The details are in our Data Processing Agreement.

This website

Separately from the ImmCase service, www.immcase.com collects very little:

  • What you send us. If you use the contact form or email us, we receive your name, email address and message, and use them to answer you and prepare a proposal.
  • Server logs. Ordinary request information, used for security and troubleshooting.
  • Language cookie. One functional cookie, pll_language, remembers whether you prefer English, Spanish or French.
  • Analytics. We use Google Analytics to understand which pages visitors find useful. It sets cookies in your browser and sends Google information about your visit, including a truncated version of your IP address, the pages you view and general location. You can opt out with Google’s browser add-on, or by blocking these cookies in your browser.

We do not use advertising or cross-site tracking cookies on this website.

Your rights

Depending on where you live, you may have the right to ask for access to the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict how we use it, and to receive it in a portable format. You may also complain to your data-protection authority — in Canada, the Office of the Privacy Commissioner of Canada or your provincial equivalent.

To exercise these rights over information we hold as a service provider — that is, records inside a firm’s ImmCase environment — please contact that firm. For information we hold in our own right, such as a user account or a billing relationship, write to us at the address below and we will respond within the time your law allows.

Children

ImmCase is a professional tool for adults and is not directed to children. Immigration files legitimately include information about minors, entered by a firm about its own clients; that information is the firm’s responsibility and is handled like any other client record.

Changes to this policy

We may update this policy. Changes are posted on this page with a new “Last updated” date, and we will tell subscribing firms directly about any change that materially affects them.

Contact us

ImmCase Digital Solutions Ltd
Email: privacy@immcase.com
Website: www.immcase.com