1. Who is responsible
Your consulting firm (the organization with a Dossierly workspace) decides why and how client personal information is processed for its immigration services. That firm is the organization responsible for the client file. Yuzu Solutions Inc. operates the software and processes client and booking-guest information on the firm’s instructions as a service provider. Yuzu Solutions Inc. is responsible for staff-account information it uses to run the service (name, email, authentication identifiers, and similar operational data). If you book an appointment or complete a form through a firm’s link, you are giving information to that firm. Yuzu Solutions Inc. hosts and processes it so the firm can use the software. Questions about immigration advice, retainers, fees, or how the firm uses your file should go to the firm — not to Yuzu Solutions Inc. as your representative.
2. Privacy officer
The person in charge of the protection of personal information at Yuzu Solutions Inc. is Adrien Yvin, Privacy Officer, info@dossierly.ca. That contact is published as required by Québec Law 25. You may write to the same address for PIPEDA inquiries about the platform. If you are a client of a consulting firm, contact that firm first about your immigration file.
3. Purposes
We process personal information to: • Provide the CRM, questionnaires, form preparation, document intake, client portal, calendar, and public booking features • Authenticate staff and, where a firm enables it, client portal access • Send appointment confirmations, change/cancel links, and reminder emails the firm configures • Sync busy times and bookings with a consultant’s Google Calendar or Outlook calendar when that consultant connects it, and create a Google Meet, Microsoft Teams, or Zoom join link when that meeting tool is selected • Maintain security, prevent booking abuse, keep audit records, and operate the service • Meet legal obligations that apply to Yuzu Solutions Inc. as a service provider and as an enterprise We do not sell personal information. We do not use client file contents for advertising. We do not use personal information for new purposes without notice and, where the law requires, a new consent.
4. What we collect
Depending on how the product is used, this may include: Staff and firm: name, email, role, representative profile fields used on IMM 5476, authentication identifiers, the firm’s default language, and — if a consultant connects Google Calendar, Outlook, Google Meet, Teams, or Zoom — that connected account’s email. Clients and booking guests: first name, last name, email, phone, address (when asked at booking), preferred language, immigration-status fields a firm records, questionnaire answers, extra questions a firm adds to a booking form, uploaded supporting documents (for example a passport), consultation notes, and generated form files. Immigration files often include sensitive information and may include information about family members, including minors. Bookings: appointment time, service, consultant, when privacy notice was accepted, meeting join links when created, Zoom or Teams meeting identifiers, and hashed email and IP used only to rate-limit the public booking page. Calendar and meetings (only if a consultant connects them): encrypted OAuth tokens; the connected account email; busy intervals and event titles from Google Calendar or Outlook; and meeting join URLs. New bookings are written to the connected calendar with the guest’s name, email, and phone in the event details. If Zoom is the meeting tool, we create a Zoom meeting on that consultant’s Zoom account with the appointment title and time, then store the meeting id and join URL. We do not send the guest’s email to Zoom as a registrant, do not access Zoom cloud recordings, chat, or phone, and do not use Zoom data for advertising. Technical: security audit events (including IP address and browser user-agent for some actions), hashed IP and email for booking abuse control (about 14 days), and — only if you opt in — product usage and performance metrics. Firms should collect only what they need for the engagement. Extra booking questions are stored with the appointment. We do not operate a biometric identification system.
5. Consent and notice
Firms are responsible for obtaining valid consent from clients where required — including express consent for sensitive information and, in Québec, parental or guardian authorization before collecting information about a child under 14 — and for explaining their own retainers and privacy practices. Staff must accept this Privacy Policy and the Terms and Conditions when they create a Dossierly account. The client portal requires both checkboxes when the client first creates a password or first signs in with Google. Public booking requires both checkboxes before a booking can be submitted. Checking those boxes is consent to the processing described here for that account, file, or appointment, subject to the firm’s instructions and applicable law. Those checkboxes are not pre-checked. Calendar, meeting, and payment tools are off until a staff member or the firm connects them. Connecting them is an instruction to communicate related details to that provider. Optional product analytics are off until you accept them in the cookie banner. You may refuse by not creating an account, not using the link, or not booking. You may ask the firm to withdraw consent or delete information, subject to professional retention rules. Some processing (security logs and legal retention) may continue where the law allows.
6. Governance
Yuzu Solutions Inc. maintains policies on collection, use, access, retention, destruction, confidentiality incidents, and vendors. A plain-language summary and related templates can be downloaded from this page and from Settings → Security in a firm workspace. Consulting firms remain responsible for their own governance toward their clients, including a privacy impact assessment when Québec Law 25 requires one.
7. Safeguards
We apply safeguards proportionate to the sensitivity of immigration files, including: • Encryption in transit (TLS) • Infrastructure encryption at rest for the database, authentication, and file storage • Application-level AES-256-GCM for uploaded client documents and for many client fields (names, emails, phones, notes, questionnaire answers, booking guest details, and similar), using a separate encryption key per firm • Some operational fields are stored without that application-level encryption (for example preferred language, immigration-status labels, appointment times, and security audit metadata) • Access controls scoped to each firm; Admin and Case Manager roles control who can administer the workspace versus work the caseload • Database service-role privileges restricted to server-only paths • Public booking pages identified by unguessable tokens; booking rate limits use hashed email and IP • Staff passwords handled by Supabase Auth; client portal passwords stored in a private schema and verified only on the server; optional Google sign-in for the client portal is verified on the server and does not create a staff account Yuzu personnel who hold the platform wrap key can technically decrypt firm keys in order to operate, restore, or secure the service, or to comply with law. We limit that access operationally. No method of transmission or storage is perfectly secure. You use the service understanding that residual risk.
8. Retention and destruction
Client and project records remain while the firm’s workspace is active. When a file is closed, the product sets a retain-until date of six years after closure to support typical College of Immigration and Citizenship Consultants closed-file duties. That professional retention is a documented purpose. A client may ask the firm to delete their information (including from the client portal Security page). The firm generally cannot destroy a closed file until those six years have passed. When purposes are fulfilled, Québec Law 25 requires destruction or anonymization. Deleting a client or a project from the workspace erases that record’s personal information in the application: identity and contact fields, notes, uploaded documents, questionnaire answers, portal access, and linked bookings (including an attempt to delete the matching Google Calendar or Outlook event and any Zoom or Teams meeting created for it). Disconnecting Zoom from Settings deletes that staff member’s Zoom OAuth tokens from Dossierly. People who remain on another file at the firm are kept. After the retain-until date, a firm administrator can destroy a closed file the same way. A placeholder project row and an encrypted destruction-register entry (client name and service summary) are kept for the firm’s professional record. Security audit rows for that file or person are kept as a record that the action occurred, with IP address, user agent, and event metadata removed. Hashed booking abuse events are deleted after about 14 days, and are also removed for an erased person’s email. Emails already sent, copies of calendar events or meetings held by Google, Microsoft, or Zoom, and database backups or point-in-time recovery copies can outlive an application delete until those copies expire. Firms remain responsible for their professional retention and secure-destruction duties.
9. Sharing and service providers
We use these providers to run Dossierly: • Supabase (Canada) — database, authentication, and file storage • Vercel — application hosting, logs, and optional Web Analytics and Speed Insights • Resend — transactional email when mail sending is configured (confirmations, reminders, and manage links) • Google — only if a staff member uses Google to sign in, a firm enables Google sign-in on the client portal, or a consultant connects Google Calendar or Google Meet • Microsoft — only if a consultant connects Outlook Calendar or Microsoft Teams • Zoom — only if a consultant connects Zoom • Square — only if the firm connects Square for priced bookings • Stripe — only if the firm connects Stripe for priced bookings A current list is available for download from this page. Those providers process the information we send them to provide their service. We do not disclose client file contents to third parties for their marketing. We may disclose information if required by law, to protect rights and security, or on the firm’s instructions (for example sending a reminder the firm wrote). When a consultant connects a calendar, that provider receives the booking details the product writes there (including guest name, email, and phone), and we receive busy times and event titles from that calendar. When Zoom is connected, Zoom receives the meeting title and start/end time on that consultant’s Zoom account and returns a join URL.
10. Location of processing
Primary application data (database, authentication, and stored files) is hosted in Canada (AWS Canada Central — Montréal — via Supabase). The application is hosted on Vercel. Compute and logs may be processed outside Canada, including in the United States. Optional analytics, if you accept them, may also be processed there. Transactional email via Resend, and Google, Microsoft, Zoom, or Square when a staff member or the firm connects those services, are processed by those providers outside Canada. If you are in Québec, some personal information may therefore be communicated outside Québec. Yuzu Solutions Inc. has assessed those communications under Law 25. Firms that enable a calendar, meeting, or payment tool instruct us to send the related information to that provider and remain responsible for their own transfer assessments where the law requires them.
11. Cookies and usage data
Essential cookies store a signed-in session (staff or client portal) and a few interface preferences, such as whether the sidebar is collapsed. The language of the page comes from the URL. Those cookies are necessary to operate the service. Vercel Web Analytics and Speed Insights are optional. They collect page-view and performance data to help us operate the product. They are not used to sell advertising. They are off until you accept them in the banner. You may refuse. Highest-confidentiality parameters are the default: analytics stay off unless you opt in.
12. Your rights
Subject to PIPEDA, Québec Law 25, and other applicable law, individuals may request access to, correction of, deletion of, a portable copy of computerized personal information (in a structured, commonly used technological format), or information about the handling of their personal information. We aim to respond within 30 days. Clients who use the client portal can open Security in that portal. There they can download a copy of their personal information and the information of other people on immigration files they belong to, and they can send a deletion request to the firm’s legal or security contact. That request is not an immediate erase: College of Immigration and Citizenship Consultants rules require a closed client file to be kept for six years after the file is closed. Until that hold ends, the firm generally cannot destroy the file. After that, a firm administrator can destroy it as described in section 8. Clients and booking guests may also contact the consulting firm directly. Guests can use the change or cancel links in their confirmation email while those links are valid. Firm administrators may use in-product export tools (person JSON export and project file ZIP) and, where professional retention allows, delete a person or destroy a closed file. You may also contact Yuzu Solutions Inc. using the details below. You may complain to the Office of the Privacy Commissioner of Canada, and in Québec to the Commission d’accès à l’information.
13. Confidentiality incidents
Yuzu Solutions Inc. keeps a register of confidentiality incidents. If we become aware of an incident, we assess whether it creates a risk of serious injury (Québec) or a real risk of significant harm (PIPEDA). Where the law requires, we will notify the Commission d’accès à l’information and/or the Office of the Privacy Commissioner of Canada, notify affected firms, and give firms the facts they need to notify their clients. We will notify individuals directly when we are the organization responsible for that information or when a firm cannot reasonably do so. This is not a waiver of any defence. Notification is made because the law requires it when the threshold is met.
14. Children and dependents
The service may store information about minors when they are part of an immigration file. Firms must ensure collection is necessary and, in Québec, generally authorized by a parent or guardian if the child is under 14, or as otherwise permitted by law. Yuzu Solutions Inc. does not knowingly collect children’s information except as a service provider on a firm’s instructions.
15. Automated decisions
Dossierly does not make a decision based exclusively on automated processing of personal information that produces legal effects or similarly significant effects concerning a person. Form fill is a drafting aid. Licensed staff must review every form and filing. If that changes, we will say so in this policy and offer the information the law requires.
16. Changes to this policy
We may update this policy to reflect product, legal, or security changes. The “Last updated” date will change when we do. Material changes will be highlighted in-product or by notice to firm administrators when practical. Where the law requires a new consent, we will ask for it.
17. Contact
Privacy Officer, Yuzu Solutions Inc.: Adrien Yvin — info@dossierly.ca If you are a client of a consulting firm, contact that firm for requests about your immigration file or booking. Templates for firms are available for download on this page.