Regulated Canadian Immigration Consultant Mississauga, Ontario
Home » Data Handling Policy
1. Purpose

Purpose and scope

This policy applies to personal information handled by Argus personnel, authorized contractors and service providers in connection with leads, prospective clients, clients, former clients and business operations.

It supports client confidentiality, professional responsibilities, applicable Canadian privacy requirements and responsible information-security practices. The supervising RCIC remains responsible for professional immigration work.

2. Accountability

Roles and responsibilities

The responsible RCIC oversees professional confidentiality, staff supervision and compliance with professional obligations. Personnel are expected to access only the information needed for their assigned role, follow company security procedures, maintain confidentiality and report suspected privacy or security incidents promptly.

Administrative or operational staff do not provide immigration advice unless they are independently authorized to do so.

3. Classification

How information is classified

Argus may classify information according to sensitivity so that stronger controls can be applied where appropriate:

  • Public: information approved for public release, including website and marketing content.
  • Internal: business information not intended for public distribution.
  • Confidential: personal information such as contact details, CRM notes, consultation history or billing records.
  • Highly confidential: sensitive client material such as passports, government identification, immigration documents, financial or medical records and government-portal information.
4. Collection

Data minimization

Information should be collected only where there is a defined business, professional, legal or service purpose. Initial website inquiries normally require only basic contact details and the immigration case the person wants help with.

Sensitive documents should generally be collected only when needed for an assessment or active client matter and through an approved method.

5. Access control

Least privilege and approved systems

Access to personal information is limited according to job responsibilities and operational need. Access should be reviewed when people join, change roles or leave, and periodically as part of security administration.

Argus uses approved company systems and service providers for case management, CRM, communications, documents, cloud infrastructure and related business functions. Personal cloud storage or personal email accounts should not be used as permanent repositories for client information.

Multi-factor authentication, unique accounts and secure access methods should be used where supported.

6. Cross-border operations

Authorized support personnel in India

Argus may use authorized employees located in India for administrative and operational support, including lead qualification, appointment scheduling, client communication, CRM administration, document organization, case administration, billing support and IT support.

These personnel operate under supervision and confidentiality requirements. They must not present themselves as RCICs, determine immigration eligibility, develop immigration strategy, sign immigration submissions or independently provide regulated immigration advice unless separately authorized.

Argus remains responsible for protecting client information regardless of where authorized processing occurs.

7. Communications

Email, messaging and document sharing

Personnel are expected to use approved company communication channels, verify recipients, minimize unnecessary sensitive information in email or messaging, and use secure document-sharing methods where appropriate. Personal email accounts should not be used for company business.

8. AI & automation

Use of artificial intelligence

Argus may use approved AI-assisted services for drafting, analysis, classification or website tools. Where a website tool uses AI, information intentionally submitted for that tool may be transmitted through Argus cloud infrastructure to approved third-party AI service providers to perform the requested analysis.

AI-assisted processing must remain subject to appropriate privacy, security and access safeguards. Personnel must not place confidential client documents, government credentials or highly sensitive personal information into unapproved public AI tools. Public-facing tools instruct visitors not to submit unnecessary sensitive identifiers.

Where a tool accepts document uploads, temporary source files are stored in encrypted cloud storage and are configured for automatic deletion after the retention period disclosed for the tool. The current default for temporary AI-tool uploads is 7 days unless a different period is stated. Uploaded source documents are not intended to be copied into GoHighLevel; limited contact details, attribution data, tool type, analysis identifiers and result summaries may be sent to Argus lead-management systems when a visitor chooses to unlock a detailed result or request contact.

AI-generated or automated outputs are not treated as a substitute for professional judgment. Material used for professional immigration services remains subject to review by authorized personnel within the applicable scope of service.

9. Retention & disposal

Retention and secure disposal

Client files are retained in accordance with applicable professional, legal and regulatory requirements. Lead information is kept only for a reasonable business or compliance period, and financial records are retained according to applicable accounting/tax requirements.

When information is no longer required, approved disposal may include secure deletion, confidential shredding or other appropriate destruction methods.

10. Incidents

Privacy and security incidents

Lost devices, phishing, unauthorized access, accidental disclosure, ransomware, incorrect recipients and suspicious activity should be reported promptly. Argus may investigate, contain, document and remediate incidents and provide legally required notifications where applicable.

11. Security monitoring

Monitoring and audit

Security monitoring may include system access, login activity, audit logs, downloads, exports, email security events and other technical records necessary to protect company systems, investigate incidents and support compliance.

12. Review

Policy review

Last updated: October 6, 2026. This public policy is reviewed when material changes occur to legal obligations, CICC requirements, technology, business operations, security risks or organizational structure.

This page summarizes Argus data-governance practices for public transparency. Internal procedures may contain additional operational controls.