At Openomi (operated by Daemon Craft Inc.), we take the protection of your personal information very seriously. This privacy policy explains how we collect, use, disclose and protect your information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada.
Table of Contents
1. Information We Collect
1.1 Information You Provide
- Account information: name, email address, password, phone number
- Professional information: company name, RCIC license number (if applicable)
- Payment information: processed securely by Stripe (we do not store your card numbers)
- Uploaded documents: bank statements, passports, acceptance letters and other immigration documents
- Client information: names, contact information, UCI numbers, immigration information
1.2 Automatically Collected Information
- Usage data: pages visited, features used, time spent on the platform
- Technical information: IP address, browser type, operating system, device identifiers
- Connection logs: date, time and duration of sessions
⚠️ Sensitive data: Immigration documents may contain sensitive personal information (nationality, immigration status, financial information). This data is processed with the highest level of protection and is used only to provide our audit services.
2. How We Use Your Information
We use your information to:
- Provide, operate and improve our compliance audit services
- Analyze uploaded documents using artificial intelligence technologies
- Verify compliance with Immigration, Refugees and Citizenship Canada (IRCC) requirements
- Detect anomalies and potential document fraud risks
- Generate audit reports and recommendations
- Process your payments and manage your subscription
- Send you service-related communications (confirmations, alerts, updates)
- Respond to your support requests
- Improve our service quality (aggregated, anonymized statistics — never to train AI models on your data)
- Comply with our legal obligations
2.1 Legal Basis for Processing
We process your data on the following bases: performance of our contract with you, your consent (when required), our legitimate interests (service improvement) and our legal obligations.
3. Sharing and Disclosure
We never sell your personal information. We may share your information only in the following cases:
3.1 Service Providers
- Amazon Web Services (AWS): data hosting and storage (servers in Canada)
- Google (Gemini AI): artificial intelligence processing for document analysis
- LandingAI: document data extraction
- Stripe: payment processing
These providers are contractually required to protect your data and use it only to provide their services.
3.2 Legal Requirements
We may disclose your information if required by law or in response to legitimate requests from public authorities (court orders, warrants).
3.3 International Transfers
Your data is primarily stored in Canada (AWS Canada). Some of our service providers may process data in the United States. In such cases, we ensure appropriate safeguards are in place.
4. Data Retention
We retain your data according to the following periods:
| Data Type | Retention Period |
|---|---|
| Account data | Duration of relationship + 3 years |
| Audit documents (PDFs, images) | 90 days after the audit, then deleted (or on request) |
| Audit reports | 6 years (immigration compliance) |
| Billing data | 7 years (tax requirements) |
| Connection logs | 1 year |
Uploaded documents are deleted 90 days after the audit (or on request); only audit reports are kept for 6 years, in accordance with the requirements of the College of Immigration and Citizenship Consultants (CICC).
5. Data Security
We implement robust technical and organizational security measures:
- Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
- Authentication: Multi-factor authentication (MFA) available
- Access control: Role-based access control (RBAC), principle of least privilege
- Secure hosting: AWS infrastructure with SOC 2, ISO 27001 certifications
- Monitoring: Intrusion detection and 24/7 monitoring
- Backups: Encrypted daily backups with geo-redundancy
🔒 Security commitment: In case of a data breach affecting your personal information, we will notify you within 72 hours in accordance with PIPEDA.
6. Local Data Processing Tools
Certain tools on the Openomi platform are designed to process your data entirely within your web browser. These tools never transmit your files to our servers or any third party.
- PDF Compression: Your PDF files are compressed directly in your browser using client-side image rendering technology. The file is never uploaded to any server. All processing occurs locally on your device and no data is collected or stored by Openomi.
- Form Management (PDF Form Filling): PDF forms (including IRCC immigration forms) are opened and filled entirely within your browser. No form data is sent to our servers. Saved signatures are stored exclusively in your browser's local storage (localStorage) and are never transmitted to Openomi or any third party.
🛡️ Zero data collection: For these local processing tools, Openomi does not collect, store, access, or transmit any of your files or data. Your documents remain entirely on your device throughout the process.
6.1 Browser Local Storage
Some features (such as saved signatures and guest usage counters) use your browser's local storage. This data is stored only on your device, is never sent to our servers, and can be cleared at any time via your browser settings.
7. Your Rights
In accordance with PIPEDA and applicable provincial laws, you have the following rights:
- Right of access: Obtain a copy of your personal information
- Right of rectification: Correct inaccurate or incomplete information
- Right of deletion: Request deletion of your data (subject to legal retention obligations)
- Right to withdraw consent: Withdraw your consent at any time
- Right to portability: Receive your data in a structured format
- Right to file a complaint: With the Office of the Privacy Commissioner of Canada
To exercise these rights, contact us at privacy@openomi.io. We will respond within 30 days.
9. Third-Party Services
Our platform may contain links to third-party sites. We are not responsible for their privacy practices. We encourage you to read their privacy policies.
Consult the policies of our main providers:
10. Children and Minors
Our services are not intended for persons under 18 years of age. We do not knowingly collect personal information from minors. If you are a parent or guardian and believe your child has provided us with information, please contact us immediately.
11. Changes to This Policy
We may update this policy periodically. In case of significant changes, we will notify you by email or via a notification on the platform. The "last updated" date at the top of this page indicates the current version.
12. Contact Us
For any questions regarding this policy or your personal information:
Office of the Privacy Commissioner of Canada
If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca
13. List of Sub-processors
We rely on the following third-party sub-processors to operate the Openomi platform. Each is bound by a written data-processing agreement (DPA) and is required to apply security and confidentiality measures at least equivalent to ours.
| Sub-processor | Purpose | Hosting region | Certifications |
|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting, database (RDS), object storage (S3), Cognito authentication, Bedrock LLMs | ca-central-1 (Canada) — Bedrock: us-east-1 (USA) | SOC 2 Type II, ISO 27001, ISO 27701, PCI-DSS |
| Google LLC (Gemini API) | Generative AI for question generation, content evaluation and document analysis | United States | SOC 2 Type II, ISO 27001 |
| Stripe, Inc. | Payment processing and subscription management | United States | PCI-DSS Level 1, SOC 2 Type II |
| Twilio, Inc. | VoIP telephony for calls to IRCC from the browser | United States | SOC 2 Type II, ISO 27001 |
| LandingAI, Inc. | Document data extraction (OCR / structured fields) | United States | SOC 2 Type II |
We update this list when we add or replace a sub-processor. Material changes are communicated via the platform or by email at least 15 days before the change takes effect.
14. Use of Your Data by Artificial Intelligence
When you use AI features (audits, chat, TCF / IELTS evaluation), we send the strictly necessary content to AI providers (Google Gemini, AWS Bedrock).
- Your data is NEVER used to train third-party AI models. AWS Bedrock and Google Gemini API explicitly contractually prohibit such reuse.
- Daemon Craft Inc. (Daemon Craft) also does not use your documents, audits or client data to train, fine-tune or build its own AI models or algorithms.
- Audio recordings (TCF Oral Expression, IRCC calls) are deleted within 30 days after evaluation, except when you actively choose to keep them in your history.
- Documents uploaded for an audit are stored encrypted on S3 and are accessible only to you and to the auditing AI; they are deleted upon request or 90 days after the end of the relevant audit.
- No human at Daemon Craft Inc. reads your documents except (i) at your explicit request for support, or (ii) on a strict need-to-know basis to investigate fraud or abuse.
Conversations with the chat assistant are retained for 12 months for audit traceability, then deleted.
15. Detailed Retention Schedule
In addition to the schedule in section 4, we apply the following durations:
| Type of data | Active retention | Archival | Total |
|---|---|---|---|
| Audit documents (PDFs, images) | 90 days after audit | 0 | 90 days |
| Audit reports | Duration of relationship | 6 years (CICC) | Relationship + 6 years |
| TCF / IELTS audio submissions | 30 days | 0 | 30 days |
| IRCC call recordings | 30 days | 0 | 30 days |
| Chat history with assistant | 12 months | 0 | 12 months |
| Account profile and stats | Duration of relationship | 0 | Until deletion request |
| Connection logs | 12 months | 0 | 12 months |
| Billing data | Active subscription | 7 years (CRA) | 7 years |
Upon a verified deletion request, we hard-delete your account and personal data within 30 days, except for items we are legally required to keep.
16. Data Breach Notification
In line with PIPEDA s. 10.1 and Quebec Law 25, in the event of a confidentiality incident posing a real risk of significant harm:
- We notify the Office of the Privacy Commissioner of Canada and, where applicable, the Quebec CAI within 72 hours of becoming aware of the breach.
- We notify affected individuals as soon as feasible by email and via an in-app banner, with a description of the breach, the data involved, the steps already taken and the recommended actions.
- We keep a register of all confidentiality incidents for 24 months and make it available to authorities upon request.
17. Data Protection Officer
In accordance with Quebec Law 25 (s. 3.1), Daemon Craft Inc. has designated a Data Protection Officer (DPO) responsible for ensuring compliance with applicable privacy laws.
You may contact the DPO directly for any complaint, request to access, correct or delete your data, or to exercise the right to data portability.
Email: privacy@openomi.io
The DPO commits to a substantive response within 30 calendar days. Failing a satisfactory response, you may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
18. Data Processing Agreement (DPA)
For business customers (RCIC consultants, schools, NGOs), we offer a standard Data Processing Agreement compliant with PIPEDA, Quebec Law 25 and (for European customers) GDPR.
The DPA covers: defined roles (controller / processor), security measures, sub-processor list, data-subject-rights mechanism, breach notification process, audit rights and indemnification.
Email privacy@openomi.io with the subject "DPA request" to receive a signable copy. The signed DPA prevails over this Privacy Policy for the matters it covers.