Data Handling Policy

Last updated july 22, 2026

Effective Date: July 13, 2026
Review Frequency: Annually or upon significant legal, operational, or technology changes.

1. Purpose

This Data Handling Policy establishes how Argus Immigration Consultancy Inc. collects, accesses, stores, uses, shares, retains, and disposes of personal information.

The objectives of this policy are to:

Protect client confidentiality.

Comply with the RCIC Code of Professional Conduct, Client File Management Regulation, and applicable Canadian privacy laws.

Ensure secure handling of information by employees located in Canada and India.

Protect the integrity and availability of client information.

Reduce privacy and cybersecurity risks.

This policy also demonstrates Argus Immigration’s commitment to protecting personal information through responsible data governance and industry best practices.

2. Scope

This policy applies to:

RCICs

Employees

Contractors

Consultants

Temporary staff

Third-party service providers

Employees located in India providing operational support

It covers all information relating to:

Leads

Prospective clients

Clients

Former clients

Employees

Vendors

3. Regulatory Framework

This policy is designed to support compliance with:

College of Immigration and Citizenship Consultants (CICC) Code of Professional Conduct

Client File Management Regulation

PIPEDA

Applicable provincial privacy legislation where required

Nothing in this policy replaces the professional responsibilities of the supervising RCIC.

4. Roles and Responsibilities

The supervising RCIC is responsible for:

Maintaining client confidentiality

Supervising employees

Reviewing immigration advice

Ensuring compliance with professional obligations

Managing privacy incidents

Employees must:

Access only information required for their role.

Maintain confidentiality.

Follow all security procedures.

Report suspected breaches immediately.

5. India Operations

Argus Immigration employs authorized personnel located in India to perform administrative and operational functions.

These employees work under the supervision of the supervising RCIC and may assist with:

Lead qualification

Appointment scheduling

Client communication

CRM management

Document organization

Case administration

Billing support

IT support

They must not:

Provide immigration advice

Determine eligibility

Develop immigration strategy

Sign immigration submissions

Represent themselves as RCICs

The supervising RCIC remains responsible for all professional work.

6. Information Classification

Public

Information approved for public release.

Examples:

Website

Marketing materials

Public service information

Internal

Business information not intended for public distribution.

Examples:

SOPs

Reports

Internal pricing

Operational documentation

Confidential

Personal information including:

Name

Email

Phone

Address

CRM notes

Consultation history

Billing information

Highly Confidential

Sensitive client information including:

Passport

Immigration documents

Government identification

Financial records

Medical documents

Refugee information

Government portal credentials

7. Collection of Information

Information shall only be collected when necessary.

For prospective clients this normally includes:

Name

Email

Phone number

Immigration objective

Country

Appointment details

Sensitive documents should generally only be collected after a person becomes a client or where required for an immigration assessment.

8. Access Control

Argus follows the Principle of Least Privilege.

Employees receive access only to systems necessary for their role.

Access is reviewed:

upon hiring

role changes

termination

periodic audits

Multi-factor authentication should be enabled wherever available.

Shared accounts are prohibited.

Employees must use strong, unique passwords and must not share passwords with others.

9. Approved Systems

Client information should only be stored in approved systems including:

Athena

Officio

LeadConnector / GoHighLevel

Microsoft 365

Google Workspace

AWS infrastructure

Approved company databases

Company email

Personal devices and personal cloud storage must not be used to permanently store client information.
Sensitive information should be protected using encryption during storage and transmission whenever technically feasible.

10. Confidentiality

All employees must sign confidentiality agreements.

Confidential information shall not be:

discussed in public

shared with unauthorized persons

copied for personal use

removed from company systems without authorization

Confidentiality obligations continue after employment ends.

11. Cross-Border Processing

Client information may be accessed by authorized employees located in India for administrative and operational support.

Argus Immigration remains responsible for protecting all client information regardless of where it is processed.

Appropriate contractual, technical, and administrative safeguards must be maintained.

12. Email and Communication

Employees shall:

verify recipients before sending

use company email accounts

minimize sensitive information in emails

use secure document-sharing methods whenever possible

Personal email accounts shall not be used for company business.

13. Artificial Intelligence

AI-generated content must always be reviewed and approved by authorized personnel before being used for client communications or immigration-related documentation.

Public AI tools (including ChatGPT, Claude, Gemini, Copilot, or similar services) shall not receive confidential client information unless expressly approved by management and appropriate safeguards are in place.

Employees should:

remove personal identifiers whenever possible

never upload passports or immigration documents

never upload government credentials

verify all AI-generated content before use

AI may assist with drafting but must never replace professional RCIC judgment.

14. Data Retention

Client files shall be retained in accordance with CICC Client File Management Regulations.

Lead information shall be retained only as long as reasonably necessary for business and legal purposes.

Financial records shall be retained in accordance with applicable tax and accounting requirements.

15. Secure Disposal

When information is no longer required it shall be securely destroyed through:

secure deletion

encrypted media destruction

confidential shredding

approved disposal methods

Information shall not be disposed of through ordinary garbage or unsecured recycling.

16. Privacy Incidents

Employees must immediately report:

lost devices

phishing attempts

unauthorized access

accidental disclosure

ransomware

incorrect emails

suspicious activity

Management shall investigate, document, contain, and remediate every incident.

Where legally required, affected individuals and regulators shall be notified.

17. Monitoring

Monitoring is performed to protect company systems, detect unauthorized access, investigate security incidents, and support regulatory compliance.

Argus Immigration may monitor:

system access

login activity

audit logs

downloads

exports

email usage

security events

18. Policy Violations

Violations may result in:

removal of access

disciplinary action

termination of employment

contractual remedies

reporting to regulators where appropriate

legal action

19. Employee Acknowledgement

Every employee and contractor must acknowledge that they:

have read this policy;

understand their confidentiality obligations;

will protect client information;

will use company systems responsibly; and

understand that violations may result in disciplinary or legal action.

Document Review

This policy shall be reviewed annually or whenever there are significant changes to:

legislation

CICC requirements

technology platforms

business operations

security risks

organizational structure

Scroll to Top