Privacy Policy
Effective date: 2026-08-06 Current version: 1.0.0 Operator: Ironside Systems Contact: ironsidesystems2021@gmail.com
This Privacy Policy describes how Ironside Systems (Ironside, we, us, or our) handles personal information in connection with the Ironside Systems case-management platform (the Service).
1. Scope
1.1 This Policy applies to personal information handled by Ironside Systems when consultants and their clients access or use the Service.
1.2 Ironside Systems is the Service operator. A consultant practice, including Pakel Immigration Consultancy, is a customer or tenant and is not the Service operator.
1.3 The consultant controls the purposes for which the consultant collects and uses client case records. A client should ordinarily direct questions about the content, correction, use, or retention of a case record to the consultant responsible for that matter.
2. Roles and record control
2.1 Consultants retain ownership and control of their client records.
2.2 The Service stores and retrieves client case records and document files through the tenant's configured shared Google Drive. Those records remain subject to the consultant's authority, Drive permissions, and legal obligations.
2.3 Ironside Systems independently determines how it handles the limited information required to administer, authenticate, operate, secure, and audit the Service. The legal characterization of each party's role depends on the information and applicable law.
3. Information handled by Ironside Systems
3.1 Consultant account information. We may handle a consultant's name, email address, practice details, regulatory identifier, phone number, account status, and credential-verification information.
3.2 Authentication information. We may handle password-verification data, external identity identifiers, session and access information, and records of policy acceptance.
3.3 Tenant and operational information. We may handle tenant identifiers, case and file references, workflow status, configuration, timestamps, and information needed to route authorized requests to the correct tenant records.
3.4 Client access information. Where a client uses an access code or links a login, we may handle the access reference and limited account-linking and credential-verification information required for that sign-in method.
3.5 Security and audit information. We may handle request metadata, IP addresses, device or browser information, authentication events, administrative actions, and other records reasonably required to prevent abuse, investigate incidents, and maintain accountability.
3.6 Support communications. We handle information a person includes when contacting us.
3.7 Consultant Records in Drive. Authorized Service requests may create, retrieve, update, or delete records in the tenant's shared Google Drive. Document uploads are directed to that Drive. The Service must process sufficient request and record information to complete an authorized operation.
4. Purposes
4.1 We handle personal information to:
- create and administer accounts and tenants;
- authenticate consultants and clients;
- provide requested case-management and file functions;
- route authorized operations to the tenant's shared Google Drive;
- maintain security, detect abuse, and investigate incidents;
- keep operational and audit records;
- respond to inquiries and requests;
- maintain, diagnose, and improve the reliability of the Service; and
- comply with applicable law and protect legal rights.
4.2 We do not sell or rent personal information or use it for behavioural advertising.
5. Google Drive and file operations
5.1 Each tenant uses a shared Google account and Drive configured for that tenant. Consultants assigned to the tenant may use the Service to access records within that tenant according to their authorized Service access.
5.2 Client document uploads are directed from the browser to the tenant's configured Google Drive. The Service manages the authorization and operational information required for that transfer and for later authorized record access.
5.3 Available functions may support operations on individual Drive files. An individual file operation is not an account-wide export or erasure process.
5.4 Ending Service access does not automatically delete records from the tenant's Google Drive. The consultant remains responsible for Drive permissions, exports, deletions, and retention decisions.
6. Disclosure
6.1 We may disclose personal information:
- to service providers used for hosting, identity, file storage, communications, security, and related operations;
- to the consultant responsible for the relevant tenant or matter;
- where required by applicable law, legal process, or a lawful authority;
- where reasonably necessary to protect a person, the Service, or legal rights; or
- in connection with a business reorganization or transfer, subject to appropriate handling requirements.
6.2 Service providers receive only the information reasonably required for their functions. The current provider categories and relevant processing roles are described in the Sub-Processor Disclosure.
6.3 We do not disclose personal information to data brokers or for third-party advertising.
7. Cross-border processing
7.1 Service providers may process information outside Canada, including in the United States and other jurisdictions in which they operate.
7.2 Information processed in another jurisdiction may be subject to that jurisdiction's laws and lawful-access requirements.
8. Retention
8.1 Ironside Systems retains limited account, authentication, operational, security, and audit information for as long as reasonably required to provide and secure the Service, administer access, comply with law, maintain records, and establish or defend legal rights.
8.2 Different records may require different retention periods. We do not represent that all Service information is removed on a single schedule or automatically erased when access ends.
8.3 Consultant Records in the tenant's Google Drive remain under the consultant's control and retention practices. Ironside Systems does not promise automatic deletion of those Drive records.
9. Individual requests
9.1 Subject to applicable law, an individual may request access to or correction of personal information handled by Ironside Systems, withdraw consent where consent is the applicable basis, or make a complaint.
9.2 A client request about the content, correction, export, or deletion of a client case record should first be directed to the consultant controlling that record.
9.3 A request concerning limited information held by Ironside Systems may be sent to the contact in section 16. We may verify identity and authority before acting and may retain information where permitted or required by law.
9.4 The Service does not promise a self-service account-wide export, deletion, or retention-scheduling workflow. Requests are assessed individually according to applicable law, security needs, the information involved, and the respective roles of Ironside Systems and the consultant.
10. Safeguards
10.1 We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information and the nature of the Service.
10.2 Safeguards include access controls, protected communications, credential protection, tenant separation, security monitoring, and audit records.
10.3 No safeguard can eliminate every risk. Consultants are responsible for safeguarding their own accounts, devices, shared Google account, Drive permissions, and client communications.
11. Security incidents
11.1 We assess suspected security incidents involving personal information under our control and take the notification, recordkeeping, mitigation, and other steps required by applicable law.
11.2 Consultants must promptly notify us if they reasonably suspect unauthorized Service access that may affect their tenant.
12. Cookies and similar technologies
12.1 The Service may use cookies or comparable storage that is necessary for authentication, security, preferences, and operation.
12.2 We do not use advertising cookies or third-party advertising trackers.
13. Children
13.1 The Service is intended for use by consultants and persons interacting with a consultant about immigration or related services. Consultants are responsible for obtaining any authority required to handle information about a minor.
13.2 A request concerning a minor's client case record should first be directed to the consultant controlling that record.
14. Automated functions
14.1 The Service may calculate or organize information supplied by a consultant or client. These functions are administrative tools and do not replace the consultant's review or decision-making.
14.2 Ironside Systems does not use personal information to make credit, insurance, employment, or immigration eligibility decisions about individuals.
15. Changes to this Policy
15.1 We may update this Policy. The version and effective date at the top identify the Policy then in effect.
15.2 Where required by law or the Service's acceptance process, a material update may be presented for notice or acceptance.
16. Contact and complaints
16.1 Privacy questions, requests, or complaints concerning Ironside Systems may be sent to ironsidesystems2021@gmail.com.
16.2 A client may also contact the consultant responsible for the client's matter regarding records controlled by that consultant.
16.3 An individual may have the right to complain to the Office of the Privacy Commissioner of Canada or another privacy regulator with jurisdiction.
End of Privacy Policy.
