Privacy Policy
How ImmigrateOS collects, uses, discloses, stores, and deletes personal information — including Google, Microsoft, and other integrations used by immigration firms.
Effective date: August 18, 2026 · Last updated: August 21, 2026 · Version 2026.4
This policy is written for website visitors, firm staff, client-portal users, and third-party reviewers (including Google, Microsoft, Stripe, Dropbox, and similar partners). It is the public privacy statement for ImmigrateOS. It is not legal advice to your clients, and it does not replace a firm’s own privacy notice or retainer. Related documents: Terms of Service, Data Processing Addendum, and Security & compliance.
1. Who we are
ImmigrateOS (“ImmigrateOS,” “we,” “us,” or “our”) operates practice-management software for immigration consulting firms, RCIC practices, and immigration law firms. We are not affiliated with Immigration, Refugees and Citizenship Canada (IRCC), U.S. Citizenship and Immigration Services (USCIS), the College of Immigration and Citizenship Consultants (CICC), or any government agency.
Privacy contact: hello@immigrateos.com (subject line: Privacy request). You may also use our contact form.
This policy applies to:
- The marketing website at immigrateos.com (including demo bookings and public booking and enquiry pages we host for firms);
- The firm application (currently app.immigrateos.com);
- The client portal (a separate authenticated surface for a firm’s clients); and
- Optional integrations a firm enables, including Google Calendar (and optional Google Meet links on appointments), Google Drive, Microsoft 365 / Outlook / OneDrive, Apple Calendar, Dropbox, Stripe, Square, QuickBooks, Xero, Twilio, Slack, DocuSign, and customer webhooks or APIs.
2. Roles: controller and processor
Who is responsible for personal information depends on the context:
- Firm client and case files. The subscribing organization (the “Customer” or “firm”) is the controller (or equivalent) of client, applicant, and case information it stores in ImmigrateOS. ImmigrateOS is the processor (or service provider) acting on the firm’s documented instructions, including the Data Processing Addendum. That includes identity documents, medical records, financial statements, police certificates, and other sensitive immigration-file contents the firm or its clients upload.
- Accounts we operate. ImmigrateOS is the controller of information we collect to run the product itself: demo and sales inquiries, firm-staff account details needed for authentication and billing, subscription invoices, security logs we generate, and website usage data.
- Connected third-party accounts. When a firm connects Google, Microsoft, Dropbox, Stripe, or similar tools, that vendor is typically an independent controller of the account the user already has with them. ImmigrateOS receives only the access the user grants, for the purposes described in Integrations and Google API services.
If you are an applicant or client of a firm that uses ImmigrateOS, contact that firm first. They decide how to respond to access, correction, and deletion requests about your file. We will not release another organization’s client file to you without authorization.
We do not sell personal information. We do not rent it. We do not share it with third parties for their independent advertising or marketing.
3. Contents
- Who we are
- Roles: controller and processor
- PIPEDA principles
- What we collect
- Sources
- Purposes and legal bases
- Marketing website, cookies, and CASL
- Integrations (all vendors)
- Google API services and Limited Use
- Microsoft Graph
- Dropbox, Apple, payments, accounting, Twilio, Slack, DocuSign, API
- AI processing
- Subprocessors
- Storage and international transfers
- Retention and deletion
- Security and breach notice
- Children and minors in immigration files
- Automated processing
- Additional notices (Canada, US, EEA/UK)
- Privacy contact
- Access, correction, and deletion procedures
- Changes
4. PIPEDA principles
ImmigrateOS is designed for Canadian immigration practices operating under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial private-sector privacy statutes. We apply the following principles to information we control, and we provide product controls so firms can meet their own obligations as controllers:
- Accountability. We are responsible for personal information under our control, including information transferred to subprocessors listed in this policy.
- Identifying purposes. We identify the purposes for collection before or at the time of collection, as set out below.
- Consent. We obtain consent where required. For the Service, firm staff and portal users consent by creating an account, accepting in-product terms, and using optional integrations. Firms must obtain their clients’ consent (or another lawful basis) to store client files in ImmigrateOS.
- Limiting collection. We collect only what is reasonably required for the identified purposes.
- Limiting use, disclosure, and retention. We use and disclose personal information for the purposes described here, and we retain it only as long as necessary (see Retention).
- Accuracy. We rely on users to keep account and practice records accurate. We will correct information we control when you notify us.
- Safeguards. We use administrative, technical, and physical safeguards appropriate to the sensitivity of immigration case data (see Security).
- Openness. This policy, our Security page, and in-product privacy settings describe our practices.
- Individual access. Procedures are in Access and deletion.
- Challenging compliance. Contact us, then (if unresolved) the Office of the Privacy Commissioner of Canada or a provincial commissioner.
5. What we collect
5.1 Marketing website and demo bookings
- Contact, demo, and access forms: first name, last name, whether you practice as a solo RCIC or a firm, firm name, work email, firm size, programs you handle, message text, whether you want a live demo or sign-in access, preferred demo date/time when you book a walkthrough, and related scheduling metadata. Sign-in access is not public self-serve sign-up; we review requests and may email login details if we provision a workspace.
- Technical data: IP address, user-agent, pages viewed, referring URL, timestamps, and similar server logs needed to operate, secure, and diagnose the site.
- Cookies: essential cookies required for site function (for example, session or load-balancing). We do not use advertising cookies or sell browsing data to ad networks. See Cookies.
5.2 Firm staff accounts
- Name, work email, role, organization membership, authentication data, multi-factor authentication status, and session metadata.
- Staff sign-in is provided by WorkOS AuthKit. We receive identity assertions needed to create and maintain the staff session.
- Versioned acceptance of ImmigrateOS Terms of Use (timestamp, version, IP address, and user-agent at acceptance).
5.3 Client portal accounts
- Identity details the firm or client provides so the client can sign in (typically name and email).
- Portal authentication is a separate WorkOS AuthKit project, isolated from firm-staff accounts.
- Portal terms and privacy-consent records the firm configures, including version accepted and timestamp.
5.4 Practice and case records (Customer Data)
When a firm uses ImmigrateOS, we store the information the firm and its users enter or import:
- Leads, client profiles, family members, representatives, and related contacts;
- Cases, stages, checklists, tasks, notes, calendar events, appointments, and messages;
- Documents and document versions (re-uploads create a new version; files are not silently overwritten);
- Invoices, payment-plan metadata, and payment status (not card numbers);
- E-signature envelopes and status (native e-sign and optional DocuSign);
- Audit metadata: who accessed or changed a case, document, or financial record, and when.
Immigration files often include sensitive personal information, including government identity numbers, passport and visa images, biometric data contained in uploaded documents, medical and police certificates, financial statements, educational records, and information about children who are applicants or dependants. We collect that information only because a firm or authorized portal user uploads or imports it to deliver the Service.
5.5 Billing
Subscription plan, seat counts, invoices, payment status, and tax-relevant billing details. Card numbers and bank details for ImmigrateOS subscription payments are collected and stored by Stripe, not by ImmigrateOS. Client invoice checkout, when enabled, is handled by Stripe Connect or Square as the firm configures.
5.6 Integrations
OAuth tokens (stored encrypted), account identifiers (for example Google or Microsoft email), calendar IDs, file identifiers for user-selected imports, and the limited records required to keep that connection working. See Integrations and Google API services.
5.7 AI usage
Prompts, selected context, generated drafts, chat transcripts in the firm’s workspace, and usage metadata (feature name, token counts, cost). See AI processing.
5.8 Security and operations
Application logs, IP addresses, device/browser data, error reports, rate-limit data, and records of Terms acceptance. We use these to authenticate users, prevent abuse, investigate incidents, and operate the Service.
6. Sources of personal information
- You, when you submit a form, create an account, or use the Service;
- Your colleagues at the same firm, when they invite you or enter records;
- The firm’s clients, when they use the portal or public booking page;
- Prospective clients of a firm, when they submit a public enquiry form or book a consultation;
- Identity providers (WorkOS) when you sign in;
- Payment processors (Stripe, Square) for payment status;
- Integrations you connect (Google, Microsoft, Dropbox, Apple, QuickBooks, Xero, Twilio, Slack, DocuSign, and endpoints you register);
- Automatically, from your browser or device when you use the website or apps.
7. Purposes and legal bases
We collect and use personal information only as needed to:
- Respond to demo requests, sales questions, and support tickets;
- Create, authenticate, and secure staff and portal accounts (including MFA and session management);
- Provide case management, documents, messaging, billing, scheduling, e-signature, reporting, and related features;
- Process subscription payments, prevent fraud, and keep tax/accounting records;
- Send transactional email (invites, password or MFA flows, appointment reminders, invoice notices) when the feature is in use;
- Send product or marketing email only where permitted (see CASL);
- Run optional AI features the firm enables;
- Sync or import data from integrations the firm connects, solely to provide those features;
- Secure the Service, investigate incidents, keep an audit trail, and enforce our Terms;
- Meet legal, regulatory, and professional-record obligations;
- Understand how the marketing site is used so we can operate and improve it.
Where a “lawful basis” concept applies (for example GDPR-style analysis for EEA/UK individuals), we typically rely on: performance of a contract (providing the Service); legitimate interests (securing the Service, improving reliability, B2B communications with firm contacts); consent (optional integrations, certain cookies, CASL commercial electronic messages, and in-product consents); and legal obligation (tax, accounting, lawful requests). Firms remain responsible for the lawful basis on which they process their clients’ files.
We do not collect information from the marketing site or the product for advertising networks, data brokers, or unrelated profiling.
8. Marketing website, cookies, and CASL
8.1 Cookies and similar technologies
The marketing website uses cookies and similar technologies that are strictly necessary to deliver the page, remember essential preferences, and keep the site secure. We do not currently run third-party advertising pixels or cross-site advertising cookies on immigrateos.com. If we add optional analytics or marketing cookies, we will update this section and, where required, obtain consent.
The firm application and client portal use cookies or local storage required for authentication and session integrity (via WorkOS). Those cookies are essential to signed-in use.
You can control cookies in your browser. Blocking essential cookies may prevent sign-in or form submission from working.
8.2 Canada’s Anti-Spam Legislation (CASL)
Transactional messages about your account, invoices, security, or a booked demo are not marketing. Commercial electronic messages (for example product updates we send to a work email you gave us) are sent only with consent required by CASL, with a working unsubscribe. You can opt out of marketing email at any time; we may still send transactional messages needed to operate the Service.
8.3 Public booking pages
A firm may publish a branded /book/… page. Information a visitor submits there (name, email, appointment details) is Customer Data of that firm. ImmigrateOS processes it to create the appointment the visitor requested.
9. Integrations — how they work
Integrations are optional and off by default until an authorized firm user connects them in Settings. Connecting an integration is the user’s instruction to ImmigrateOS to access that account for the purposes described here and in our Terms of Service.
Common rules for every integration:
- We request the minimum scopes needed for the feature the user is enabling.
- Access tokens and refresh tokens are stored encrypted and used only to provide that feature.
- We do not sell integration data. We do not use it to train ImmigrateOS’s own models. We do not use it for advertising.
- The user (or an organization owner/admin) can disconnect the integration in Settings. Disconnection revokes or deletes stored tokens where the vendor API allows, and stops further sync or import.
- Files already imported into ImmigrateOS remain Customer Data in the firm’s workspace until the firm deletes them. Disconnecting Drive, OneDrive, or Dropbox does not automatically delete copies already imported.
- Each vendor’s own terms and privacy policy also apply to the user’s account with that vendor.
Product overview: immigrateos.com/integrations.
10. Google API services and Limited Use
This section is the disclosure Google reviewers and users should read before connecting Google Calendar or Google Drive. ImmigrateOS uses Google APIs only after a firm user signs in with Google and grants consent on Google’s consent screen.
Google API Services User Data Policy — Limited Use. ImmigrateOS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not:
- Use Google user data to serve advertisements;
- Sell Google user data;
- Use Google user data for credit scoring, lending, housing, employment, or insurance eligibility;
- Allow humans to read Google user data except: (a) with the user’s consent and for the user’s benefit (for example a support ticket the user opened); (b) as necessary for security purposes (investigating abuse, spam, or a breach); (c) to comply with applicable law; or (d) when the data is aggregated and does not identify the user;
- Transfer Google user data to third parties except (i) as necessary to provide or improve user-facing features that are prominent in the requesting application’s user interface (for example storing a user-selected Drive file in the firm’s ImmigrateOS document store on Google Cloud), (ii) as necessary to comply with applicable law, or (iii) as part of a merger, acquisition, or sale of assets with notice to users.
10.1 Google Calendar
Scopes requested: calendar event access (https://www.googleapis.com/auth/calendar.events) and the user’s Google email (https://www.googleapis.com/auth/userinfo.email).
What we access: the Google account email used to connect, and calendar events on the calendars the user selects for ImmigrateOS appointment sync.
How we use it: two-way sync of ImmigrateOS appointments. We create, update, and delete events that correspond to consultations and other appointments in ImmigrateOS, and we read those events so changes made on Google Calendar can update ImmigrateOS. When a consultant chooses to send a video meeting link, we ask Google Calendar to attach a Google Meet conference to that event and store the join URL on the appointment so it can be shown in ImmigrateOS and sent to the client. We do not use this connection to read Gmail, Contacts, Photos, or Drive.
What we store: encrypted OAuth tokens, Google account email, calendar identifiers needed for sync, and event identifiers linking an ImmigrateOS appointment to a Google event.
10.2 Google Drive
Scopes requested: read-only Drive access (https://www.googleapis.com/auth/drive.readonly) and the user’s Google email (https://www.googleapis.com/auth/userinfo.email).
What we access: metadata needed to list My Drive and Shared drives the connected account can see, and the content of files the user explicitly selects to import. Google Docs may be exported as PDF on import.
How we use it: one-way, user-initiated import into an ImmigrateOS client or case record, with document version history and audit trail. We do not write to Drive, do not modify or delete Drive files, do not continuously mirror the user’s entire Drive, and do not use Drive content for advertising or to train ImmigrateOS’s own models.
What we store: encrypted OAuth tokens, Google account email, and copies of the selected files plus metadata (name, type, size, source) in the firm’s ImmigrateOS workspace on Google Cloud in Canada. Originals remain in the user’s Google Drive.
10.3 Revoking Google access
A user may disconnect Google Calendar or Google Drive in ImmigrateOS (Settings → Integrations). The user may also revoke ImmigrateOS in their Google Account under Third-party connections. After revocation we stop calling Google APIs with those tokens and delete or invalidate stored tokens.
11. Microsoft Graph (Outlook, Microsoft 365, OneDrive)
Connecting Microsoft is optional and user-initiated.
11.1 Outlook / Microsoft 365 calendar
Scopes: offline_access, User.Read, Calendars.ReadWrite.
We read the signed-in user’s basic profile (to identify the connection) and read/write calendar events so ImmigrateOS appointments sync two-way with Outlook / Microsoft 365. We do not use this connection to read mailboxes, Teams chats, or OneDrive files.
11.2 OneDrive
Scopes: offline_access, User.Read, Files.Read.
We list folders and files the connected work account can access and import files the user selects into an ImmigrateOS client or case record. Import is one-way. We do not write to, move, or delete OneDrive files. Google Docs-style conversion does not apply; we import the file bytes the user selects.
Disconnect in Settings → Integrations, or revoke ImmigrateOS in the Microsoft account’s app permissions. Tokens are then invalidated.
12. Other integrations
12.1 Dropbox
User-initiated, one-way import. We browse folders the connected Dropbox account can access and copy files the user selects into ImmigrateOS document storage. We do not write to Dropbox. Tokens are stored encrypted and can be disconnected in Settings.
12.2 Apple Calendar (iCloud)
The firm provides iCloud credentials (typically an app-specific password). Credentials are stored encrypted and used only to sync appointments to a dedicated calendar named for the firm. We do not use those credentials to access iCloud Mail, Contacts, or iCloud Drive. Disconnecting deletes stored credentials from ImmigrateOS.
12.3 Stripe and Square
ImmigrateOS subscription: billed through Stripe. Stripe is the PCI-compliant card processor. ImmigrateOS stores customer and subscription identifiers, invoice status, and plan metadata — not PAN/CVV.
Client invoice checkout: if the firm connects Stripe Connect or Square, clients may pay invoices from the portal. Payment card data is entered on Stripe or Square hosted checkout. ImmigrateOS receives payment status, amounts, and identifiers needed to mark invoices paid. Government fees may be displayed separately from professional fees as the firm configures. ImmigrateOS is not the merchant of record for the firm’s client invoices.
12.4 QuickBooks Online and Xero
If connected, we sync contacts/clients, invoices the firm sends, and payment status so the firm’s books stay aligned. We do not use accounting data for advertising. The firm can disconnect in Settings; already-synced records in QuickBooks or Xero remain under the firm’s accounting account.
12.5 Twilio
If the firm connects Twilio, they provide their own Account SID and a Restricted API key. ImmigrateOS uses those credentials only to list numbers the firm already owns, send SMS the firm initiates (Messages and appointment reminders), and receive inbound replies on the selected number. We do not provision ImmigrateOS-owned phone numbers. SMS usage is billed by Twilio to the firm. Message bodies, sender and recipient numbers, and delivery identifiers may be processed by Twilio in Twilio’s regions. Clients can reply STOP, START, or HELP; ImmigrateOS stores STOP/START on the client record and replies with a confirmation. The firm remains the sender of record and is responsible for CASL consent and Canadian/US sender registration in their Twilio account.
12.6 Slack
Incoming webhooks only. ImmigrateOS posts event summaries the firm chooses (for example new lead, invoice paid, case stage changed) to channels the firm configures. We do not read Slack message history or user directories beyond what is required to deliver those posts.
12.7 DocuSign
If the firm connects DocuSign, we send documents for signature and receive envelope status. Signers interact with DocuSign under DocuSign’s terms. Native ImmigrateOS e-signature does not require DocuSign.
12.8 Webhooks and REST API
If the firm registers a webhook URL or uses API keys, ImmigrateOS will send event payloads (for example lead.created, invoice.paid) to that URL or allow programmatic access within the firm’s permissions. The firm is responsible for securing its endpoint and keys. Payloads may include personal information the firm already stored in ImmigrateOS. We do not send that data to Zapier, Make, or other automation tools unless the firm connects them.
13. AI processing
ImmigrateOS includes optional AI features: Assistant chat, dashboard briefing, case checklist generation, document metadata extraction, and message or report drafting. These features use third-party model providers routed through OpenRouter (and the model vendors connected through it).
When a staff member runs an AI feature, the request may include the prompt they write, selected client/case/document metadata, and extracted fields when they run extraction. Output is a draft for human review. It is not legal advice and is not sent to clients or government portals automatically.
We do not use a firm’s client files to train ImmigrateOS’s own models. Provider retention follows the connected model vendor. ImmigrateOS stores usage metadata for billing and limits. Chat transcripts stay in the firm’s organization workspace.
Firms can allow or disallow processing of client data, and can disable AI for sensitive documents (for example identity, medical, financial, or legal files). If you do not want a request processed by a third-party model, do not use AI features, or ask a firm administrator to turn them off.
14. Subprocessors
We use subprocessors to operate the product. Core client and case data is stored in Google Cloud Canada regions. Some processors handle limited data outside Canada when a feature requires it. The current list is in the table below. Processor terms for Customer Data are in the Data Processing Addendum.
| Provider | Purpose | Typical location |
|---|---|---|
| Google Cloud | API (Cloud Run), database (Cloud SQL), documents (Cloud Storage), queues (Memorystore) | Canada (northamerica-northeast1 Montreal default; northamerica-northeast2 Toronto available) |
| Vercel | Hosts the marketing site, firm app UI, and portal UI. Not the system of record for client files | Global edge; application data is read/written through the Canada API |
| WorkOS | Firm-staff authentication (AuthKit), including MFA, and a separate WorkOS project for client-portal authentication | United States (identity only) |
| Stripe | Subscription billing; optional Stripe Connect for client invoice checkout | United States / Stripe’s processing regions |
| Square | Optional client invoice checkout | United States / Square’s processing regions |
| Resend | Transactional email | United States |
| OpenRouter and connected model vendors | Optional AI features, only when used | Varies by model vendor |
| Google (user’s Workspace/account) | Optional Calendar sync and Drive import | Google’s regions for that account |
| Microsoft | Optional Outlook calendar sync and OneDrive import | Microsoft’s regions for that tenant |
| Dropbox, Apple, Intuit (QuickBooks), Xero, Twilio, Slack, DocuSign | Optional integrations the firm connects | Each vendor’s regions |
Each processor is used only for the purpose described. We do not authorize subprocessors to use Customer Data for their own advertising.
15. Storage and international transfers
Client records, case files, documents, messages, and audit logs are stored and processed in Google Cloud Canada regions:
- Montreal by default — northamerica-northeast1
- Toronto available — northamerica-northeast2 for firms that prefer it
The API, database, document storage, and queue cache stay in the same region. Data is encrypted in transit (TLS) and at rest (AES-256 on Google Cloud). The firm application and portal interfaces are served via Vercel (CDN). Sensitive client and case data is read and written through the Canada-hosted API; it is not stored as a system of record on Vercel edge nodes.
Limited information is processed outside Canada when you use authentication, payments, email, AI, or an optional integration. Those processors receive only what that feature needs. Where a transfer mechanism is required (for example EEA/UK data), we rely on the vendor’s contractual safeguards (such as Standard Contractual Clauses) plus encryption and access control. Connecting an integration is the firm’s instruction to transfer the data that integration requires.
16. Retention and deletion
16.1 Marketing website
Demo and contact submissions are kept as long as needed to respond, schedule walkthroughs, and maintain a business relationship, then for a reasonable period for sales records, tax, and legal requirements (typically up to seven years for financial/business records unless a shorter period is required or a longer legal hold applies). You can ask us to delete a marketing inquiry using the procedures below.
16.2 Platform data
Each firm sets retention in Settings for client records, cases, documents, messages, deleted items, and audit history. Typical options:
- Active records: keep indefinitely, or auto-expire after 1, 3, 5, 7, or 10 years, depending on the firm’s configuration and professional-file obligations.
- Deleted items (trash): recoverable for 7 to 90 days (default 30 days), then permanently deleted from production.
- Audit history: 1, 3, 7, or 10 years, or indefinitely, as configured by the firm.
- OAuth tokens: retained until the integration is disconnected, then deleted or invalidated.
- Billing records: retained as required for tax and accounting (typically seven years).
- Terms acceptances: retained for the life of the account and a reasonable period afterward as evidence of agreement.
We may retain backups for a limited period after deletion for disaster recovery. Those copies age out on the backup cycle and are not used for production access. We may also retain information required for billing disputes, security investigations, or legal holds.
Organization deletion is a support-reviewed request from an Owner or Admin — not an instant self-serve wipe — so we can verify identity and avoid destroying regulated files by accident. After we approve deletion, remaining workspace data is scheduled for removal from production systems, subject to backup cycles and legal holds.
17. Security and breach notification
We use administrative, technical, and physical safeguards appropriate to the sensitivity of immigration case data, including:
- Encryption in transit (TLS) and at rest (AES-256);
- Role-based access control inside each organization;
- Multi-factor authentication for firm staff (enforceable by the organization);
- Separate identity for the client portal;
- Immutable audit logs on sensitive writes (case status, documents, financial activity);
- Document versioning so files are not silently overwritten;
- Encrypted storage of integration tokens;
- Production access limited to authorized personnel on a need-to-know basis;
- PCI-compliant checkout through Stripe or Square; we do not store card numbers.
No method of transmission or storage is perfectly secure. If we become aware of a breach of security safeguards involving personal information under our control, we will notify affected firms, and where required individuals and regulators, as soon as feasible in line with PIPEDA and other applicable law. Firms that are controllers remain responsible for notifying their own clients when the law requires it; we will provide information reasonably needed for that notice.
See Security & compliance for infrastructure and PIPEDA/CICC posture. We do not claim SOC 2 or ISO certification on this site unless a current report is published there.
18. Children and minors in immigration files
ImmigrateOS is a B2B product. The marketing website and firm application are not directed at children under 13 (or the equivalent age of digital consent in the user’s jurisdiction). We do not knowingly collect personal information from children for marketing accounts.
Immigration files often include information about minors (for example dependent children on an application). That information is Customer Data processed on the firm’s instructions. The firm is responsible for collecting it lawfully and for any consent required from a parent or guardian.
19. Automated processing
AI features may suggest checklists, drafts, extracted fields, or risk flags. They do not make solely automated decisions that produce legal or similarly significant effects about an individual (for example, approving or refusing an immigration application). A human at the firm must review output before it is used with a client or a government authority. Firms can disable AI.
20. Additional notices
20.1 Canada
Depending on your province, you may have rights under PIPEDA and/or provincial legislation (for example Quebec Law 25, Alberta PIPA, or British Columbia PIPA). You may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial commissioner.
20.2 United States (including California)
We do not “sell” personal information and we do not “share” it for cross-context behavioural advertising as those terms are used in the California Consumer Privacy Act (as amended). We do not use or disclose sensitive personal information for purposes that require a right to limit under CCPA, other than to provide the Service. If you are a California resident and we are a “business” as to your information (for example a demo inquiry we control), you may request access, correction, deletion, or a copy of personal information we hold, using the procedures below. We will not discriminate against you for exercising those rights. If we act only as a service provider to your immigration firm, send the request to that firm.
20.3 EEA, UK, and Switzerland
If you are in the EEA, UK, or Switzerland and we process your personal data as a controller (for example a sales inquiry), you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is based on consent. You may lodge a complaint with your local supervisory authority. Transfers outside those regions are described in Storage and international transfers. When we process a firm’s client file as a processor, the Data Processing Addendum applies.
21. Privacy contact
For privacy questions, access or deletion requests, integration data questions, or to raise a concern:
Email: hello@immigrateos.com
Subject line: Privacy request
Website: immigrateos.com/contact
Please include your name, the email associated with your inquiry or account, your firm name if applicable, and whether you are asking about a website inquiry, a staff account, a portal account, an integration connection, or a client record held by a firm.
We may need to verify your identity before fulfilling a request. Authorized agents may submit requests with proof of authority.
22. Access, correction, and deletion procedures
22.1 Website visitors
- Email hello@immigrateos.com with the subject “Privacy request.”
- Tell us whether you want a copy of the information we hold, a correction, or deletion of a demo or contact submission, or to unsubscribe from marketing.
- We verify the request using the email address you used to contact us. We may ask for additional details if needed to locate your record and avoid disclosing someone else’s information.
- We respond within 30 days, or sooner if a shorter period is required by law. If we need more time, we will say so and explain why.
22.2 Firm staff
- Ask your organization owner or administrator, or email us from your work address.
- We can help correct account details, export data your role is allowed to access, close a staff account at the firm’s instruction, or disconnect integrations you connected.
- Organization-wide export lives in Settings → Import & Export. Organization deletion is requested in Settings → Data & privacy and is reviewed by ImmigrateOS support before production data is removed.
22.3 Portal users
Sign in to the portal to update information the firm has enabled you to edit, or contact the firm. Portal account closure is handled by the firm. Platform Terms of Use for portal users are accepted in-product; a copy of our public terms and this policy is always at /terms and /privacy.
22.4 Individuals whose data is in a firm’s workspace
- Send your access, correction, or deletion request to the firm that holds your file. They decide how to respond under privacy law and their professional obligations (including file-retention rules).
- Firms can log those requests in ImmigrateOS, generate a structured data package, and delete or correct records they control.
- If you cannot reach the firm, email us. We will not release another organization’s client file to you without authorization, but we will help route the request and confirm whether we process data for that firm.
We may decline or limit a request when the law allows — for example if we cannot verify identity, if disclosure would reveal another person’s information, if the request is manifestly unfounded, or if a firm must retain a file for professional or legal reasons. We will explain the reason when we can.
23. Changes
We may update this policy from time to time. The “Last updated” date and version at the top will change when we do. Material changes will be posted on this page. For active Customers, we will provide notice of material platform changes by email or in the product as required by the Terms of Service. Continued use of the website or Service after the effective date means you should review the revised policy. If you do not agree, stop using the website and, if you are a Customer, cancel as described in the Terms.
Prior versions are available on request at hello@immigrateos.com.