Data Handling Policy
Last updated july 22, 2026
Effective Date: July 13, 2026
Review Frequency: Annually or upon significant legal, operational, or technology changes.
1. Purpose
This Data Handling Policy establishes how Argus Immigration Consultancy Inc. collects, accesses, stores, uses, shares, retains, and disposes of personal information.
The objectives of this policy are to:
Protect client confidentiality.
Comply with the RCIC Code of Professional Conduct, Client File Management Regulation, and applicable Canadian privacy laws.
Ensure secure handling of information by employees located in Canada and India.
Protect the integrity and availability of client information.
Reduce privacy and cybersecurity risks.
This policy also demonstrates Argus Immigration’s commitment to protecting personal information through responsible data governance and industry best practices.
2. Scope
This policy applies to:
RCICs
Employees
Contractors
Consultants
Temporary staff
Third-party service providers
Employees located in India providing operational support
It covers all information relating to:
Leads
Prospective clients
Clients
Former clients
Employees
Vendors
3. Regulatory Framework
This policy is designed to support compliance with:
College of Immigration and Citizenship Consultants (CICC) Code of Professional Conduct
Client File Management Regulation
PIPEDA
Applicable provincial privacy legislation where required
Nothing in this policy replaces the professional responsibilities of the supervising RCIC.
4. Roles and Responsibilities
The supervising RCIC is responsible for:
Maintaining client confidentiality
Supervising employees
Reviewing immigration advice
Ensuring compliance with professional obligations
Managing privacy incidents
Employees must:
Access only information required for their role.
Maintain confidentiality.
Follow all security procedures.
Report suspected breaches immediately.
5. India Operations
Argus Immigration employs authorized personnel located in India to perform administrative and operational functions.
These employees work under the supervision of the supervising RCIC and may assist with:
Lead qualification
Appointment scheduling
Client communication
CRM management
Document organization
Case administration
Billing support
IT support
They must not:
Provide immigration advice
Determine eligibility
Develop immigration strategy
Sign immigration submissions
Represent themselves as RCICs
The supervising RCIC remains responsible for all professional work.
6. Information Classification
Public
Information approved for public release.
Examples:
Website
Marketing materials
Public service information
Internal
Business information not intended for public distribution.
Examples:
SOPs
Reports
Internal pricing
Operational documentation
Confidential
Personal information including:
Name
Email
Phone
Address
CRM notes
Consultation history
Billing information
Highly Confidential
Sensitive client information including:
Passport
Immigration documents
Government identification
Financial records
Medical documents
Refugee information
Government portal credentials
7. Collection of Information
Information shall only be collected when necessary.
For prospective clients this normally includes:
Name
Email
Phone number
Immigration objective
Country
Appointment details
Sensitive documents should generally only be collected after a person becomes a client or where required for an immigration assessment.
8. Access Control
Argus follows the Principle of Least Privilege.
Employees receive access only to systems necessary for their role.
Access is reviewed:
upon hiring
role changes
termination
periodic audits
Multi-factor authentication should be enabled wherever available.
Shared accounts are prohibited.
Employees must use strong, unique passwords and must not share passwords with others.
9. Approved Systems
Client information should only be stored in approved systems including:
Athena
Officio
LeadConnector / GoHighLevel
Microsoft 365
Google Workspace
AWS infrastructure
Approved company databases
Company email
Personal devices and personal cloud storage must not be used to permanently store client information.
Sensitive information should be protected using encryption during storage and transmission whenever technically feasible.
10. Confidentiality
All employees must sign confidentiality agreements.
Confidential information shall not be:
discussed in public
shared with unauthorized persons
copied for personal use
removed from company systems without authorization
Confidentiality obligations continue after employment ends.
11. Cross-Border Processing
Client information may be accessed by authorized employees located in India for administrative and operational support.
Argus Immigration remains responsible for protecting all client information regardless of where it is processed.
Appropriate contractual, technical, and administrative safeguards must be maintained.
12. Email and Communication
Employees shall:
verify recipients before sending
use company email accounts
minimize sensitive information in emails
use secure document-sharing methods whenever possible
Personal email accounts shall not be used for company business.
13. Artificial Intelligence
AI-generated content must always be reviewed and approved by authorized personnel before being used for client communications or immigration-related documentation.
Public AI tools (including ChatGPT, Claude, Gemini, Copilot, or similar services) shall not receive confidential client information unless expressly approved by management and appropriate safeguards are in place.
Employees should:
remove personal identifiers whenever possible
never upload passports or immigration documents
never upload government credentials
verify all AI-generated content before use
AI may assist with drafting but must never replace professional RCIC judgment.
14. Data Retention
Client files shall be retained in accordance with CICC Client File Management Regulations.
Lead information shall be retained only as long as reasonably necessary for business and legal purposes.
Financial records shall be retained in accordance with applicable tax and accounting requirements.
15. Secure Disposal
When information is no longer required it shall be securely destroyed through:
secure deletion
encrypted media destruction
confidential shredding
approved disposal methods
Information shall not be disposed of through ordinary garbage or unsecured recycling.
16. Privacy Incidents
Employees must immediately report:
lost devices
phishing attempts
unauthorized access
accidental disclosure
ransomware
incorrect emails
suspicious activity
Management shall investigate, document, contain, and remediate every incident.
Where legally required, affected individuals and regulators shall be notified.
17. Monitoring
Monitoring is performed to protect company systems, detect unauthorized access, investigate security incidents, and support regulatory compliance.
Argus Immigration may monitor:
system access
login activity
audit logs
downloads
exports
email usage
security events
18. Policy Violations
Violations may result in:
removal of access
disciplinary action
termination of employment
contractual remedies
reporting to regulators where appropriate
legal action
19. Employee Acknowledgement
Every employee and contractor must acknowledge that they:
have read this policy;
understand their confidentiality obligations;
will protect client information;
will use company systems responsibly; and
understand that violations may result in disciplinary or legal action.
Document Review
This policy shall be reviewed annually or whenever there are significant changes to:
legislation
CICC requirements
technology platforms
business operations
security risks
organizational structure