Data Processing Agreement
Last updated: July 25, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Immicase Inc. ("Immicase," "we," "us") and the subscribing firm ("Customer," "you") for use of the Immicase platform. This DPA governs how Immicase processes personal data on behalf of the Customer in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
1. Definitions
- "Personal Data" means any information about an identifiable individual processed by Immicase on behalf of the Customer through the platform.
- "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and deletion.
- "Sub-processor" means any third party engaged by Immicase to process Personal Data on behalf of the Customer.
- "Data Breach" means any unauthorized access to, disclosure of, or loss of Personal Data.
2. Scope and Purpose of Processing
Immicase processes Personal Data solely to provide the immigration case management services described in the applicable subscription agreement. This includes:
- Storing and managing client profiles, case records, documents, invoices, and communication logs
- Facilitating client portal access, document uploads, and questionnaire completion
- Processing payments through Stripe Connect on behalf of the Customer
- Sending transactional emails (invoices, retainers, notifications) via Resend on behalf of the Customer
- Providing optional AI-assisted features (KriftAI) when enabled by the Customer
Immicase does not sell, rent, or share Customer data with third parties for marketing or advertising purposes.
3. Customer Responsibilities
The Customer is the data controller and is responsible for:
- Obtaining appropriate consent from individuals whose Personal Data is processed through Immicase
- Ensuring that Personal Data entered into the platform is accurate and lawfully collected
- Managing user access and permissions within their firm account
- Responding to data access and deletion requests from individuals, using the export and erasure tools provided by Immicase
4. Security Measures
Immicase implements the following technical and organizational measures to protect Personal Data:
- Zero-knowledge client-side encryption: Sensitive identifiers (passport numbers, UCIs, national IDs) are encrypted in the browser using AES-256-GCM before transmission. Immicase servers never receive these values in plaintext.
- Encryption in transit: All data transmitted between clients and servers is encrypted using TLS 1.3.
- Encryption at rest: Data stored in the database is encrypted at rest using AES-256.
- Row-level security: Database queries enforce row-level isolation between firms. One firm cannot access another firm's data.
- Role-based access control: 5 user roles with 18 granular permissions, customizable per firm.
- Immutable audit trail: All data access and modifications are logged with timestamps and user attribution. Audit entries cannot be modified or deleted.
- Brute-force protection: Accounts lock after 5 failed login attempts for 15 minutes.
- Authentication security: JWT-based authentication with revocation on logout, bcrypt password hashing (cost factor 12), and SHA-256 token hashing for reset and invitation tokens.
- Rate limiting: Tiered per endpoint to prevent abuse.
- Security headers: HSTS, Content Security Policy, X-Frame-Options, and CORS policies enforced on all responses.
5. Data Hosting and Residency
All Customer data is hosted in Canada. Immicase uses the following infrastructure providers:
- Application hosting: Vercel (Canadian edge network)
- Database and storage: Supabase / PostgreSQL (Canadian region)
Customer data does not leave Canada during normal platform operations. If a change in hosting location is ever required, Immicase will notify affected Customers at least 30 days in advance.
6. Sub-processors
Immicase engages the following sub-processors to deliver the service. Each sub-processor is bound by contractual obligations to protect Personal Data:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Vercel Inc. | Application hosting and edge delivery | Canada |
| Supabase Inc. | Database, authentication, and file storage | Canada |
| Stripe Inc. | Payment processing (Stripe Connect) | Canada / US |
| Resend Inc. | Transactional email delivery | US |
| LiveKit Inc. | Video consultation infrastructure | US / Canada |
Immicase will notify the Customer of any new sub-processors at least 14 days before engagement. The Customer may object to a new sub-processor by contacting Immicase within that period.
7. Data Breach Notification
In the event of a Data Breach affecting Customer data, Immicase will:
- Notify the affected Customer without undue delay, and in any event within 72 hours of becoming aware of the breach
- Provide details of the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed to address the breach
- Cooperate with the Customer in fulfilling any notification obligations the Customer may have under PIPEDA or applicable provincial legislation
- Take immediate steps to contain, investigate, and remediate the breach
8. Data Subject Rights
Immicase provides the Customer with tools to fulfill data subject requests under PIPEDA:
- Right to access: The Customer can export all data associated with a client as a portable JSON bundle at any time.
- Right to erasure: The Customer can permanently delete a client's data, including scrubbing personally identifiable information from audit log entries. Deletion requires a typed confirmation code to prevent accidental erasure.
- Right to correction: The Customer can update any client data through the platform at any time.
9. Data Retention and Deletion
Customer data is retained for the duration of the subscription. Upon cancellation:
- Customer data is retained for 90 days to allow for reactivation
- After 90 days, data is permanently deleted from all production systems
- The Customer may request immediate deletion at any time by contacting Immicase
- Backups containing Customer data are purged within 30 days of production deletion
10. KriftAI (Optional AI Processing)
When the Customer enables KriftAI (optional AI suite), the following additional terms apply:
- AI processing is initiated only by explicit user action — AI never processes data autonomously
- Each AI assistant is toggled on or off independently by the Customer
- Sensitive identifiers (passport numbers, UCIs) protected by zero-knowledge encryption are never sent to AI models in plaintext
- AI outputs are advisory only — a licensed RCIC reviews and approves every output before use
- The Customer may disable KriftAI at any time with no impact on core platform functionality
- AI processing may involve sending non-sensitive case data to third-party AI model providers; these providers are bound by data processing agreements that prohibit training on Customer data
11. Audit Rights
The Customer may request information about Immicase's data processing practices and security measures. Immicase will cooperate with reasonable audit requests, subject to confidentiality obligations and reasonable advance notice.
12. Term and Termination
This DPA is effective for the duration of the Customer's subscription to Immicase. The obligations in this DPA that relate to data protection survive termination of the subscription until all Customer data has been deleted in accordance with Section 9.
13. Contact
For questions about this DPA or Immicase's data processing practices, contact:
Immicase Inc.
Vancouver, BC, Canada
Email: privacy@immicase.ca
Phone: +1-778-840-9126