navisa
For individuals — Navisa PrepNavisa RelayHow it worksThe agentsPricing

Explore

Navisa InsightsProgram requirementsPractice guidesCompare NavisaPolicy tracker

Free tools

CRS calculatorDraw trackerPathway finderROI calculator
Sign inStart free trial
← Back to Navisa

Data Processing Agreement

NovaCore Systems Inc. · Version 2026-06-08 · Effective for all accounts created or renewed on or after this date.

Table of Contents

1

Parties & Roles

This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between your firm (“Firm”) and NovaCore Systems Inc.(“Navisa”, “we”, or “us”), a company incorporated in British Columbia, Canada. It governs how Navisa processes personal data on the Firm’s behalf.

  • ·The Firm is the Controller. The Firm determines the purposes and means of processing the personal data of its clients (the “Data Subjects”) and is responsible for the lawful basis of that processing, including obtaining all required client consents.
  • ·Navisa is the Processor. Navisa processes personal data only on documented instructions from the Firm, as set out in the Terms of Service, this DPA, and the Firm’s use of the Platform.
2

Definitions

  • ·Personal Data means any information relating to an identified or identifiable natural person processed by Navisa on behalf of the Firm via the Platform — for example, a client’s name, date of birth, passport number, immigration history, and uploaded documents.
  • ·Processing means any operation performed on Personal Data, including collection, storage, OCR extraction, AI analysis, transmission, and deletion.
  • ·Data Subject means the immigration applicant (the Firm’s client) to whom the Personal Data relates.
  • ·Sub-Processor means a third party engaged by Navisa to process Personal Data in the course of providing the Platform.
3

Scope & Purpose of Processing

Navisa processes Personal Data solely to provide the services described in the Terms of Service and on the Firm’s documented instructions. The purposes of processing include:

  • ·Client intake, case management, and document collection.
  • ·OCR extraction and AI-assisted analysis of uploaded documents (eligibility analysis, cross-document consistency checking, NOC matching).
  • ·Generation of letters of explanation, IRCC form data, and evidence packages.
  • ·Transactional notifications and client-portal document collection.

Navisa will not process Personal Data for any purpose other than providing the Platform, and will not use Personal Data for its own commercial purposes or to train AI models. Navisa ensures that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.

4

Sub-Processors

The Firm authorizes Navisa to engage the following Sub-Processors to provide the Platform. Each Sub-Processor is bound by contractual obligations no less protective than those in this DPA and processes Personal Data only as necessary to perform its service:

  • ·Stripe — Payment processing. PCI-DSS Level 1 certified. Payment card data is stored and processed entirely by Stripe.
  • ·Anthropic — Claude AI models for document analysis and content generation. Enterprise data agreement in place; no model training on customer data.
  • ·OpenAI — Text embeddings for IRCC policy search. Enterprise data agreement in place; no model training on customer data.
  • ·Xano — Backend database and API infrastructure (North America).
  • ·Vercel — Frontend hosting and edge delivery (North America).
  • ·Cloudflare R2 — Encrypted document storage (North America).
  • ·Pinecone — Vector database for IRCC policy search (contains only public policy content, not client Personal Data).

We will provide notice to Firm administrators before adding or replacing a Sub-Processor that processes client Personal Data, giving the Firm a reasonable opportunity to object on legitimate data-protection grounds. Navisa remains responsible for the acts and omissions of its Sub-Processors to the same extent as for its own.

5

Security Measures

Navisa implements appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, including:

  • ·TLS encryption for all Personal Data in transit.
  • ·Encryption at rest for all stored documents and database records.
  • ·Logical data isolation at the database level — no Firm can access another Firm’s data.
  • ·Role-based access controls limiting internal access to Personal Data on a need-to-know basis.
  • ·Regular security reviews of Sub-Processor agreements and infrastructure.
6

Data-Subject Rights Assistance

Taking into account the nature of the processing, Navisa will provide the Firm with reasonable assistance — through appropriate technical and organizational measures, insofar as possible — to help the Firm fulfil its obligations to respond to requests from Data Subjects exercising their rights (such as access, correction, deletion, or withdrawal of consent).

Because the Firm is the Controller, requests from Data Subjects should be directed to the Firm. If Navisa receives a request directly from a Data Subject, Navisa will promptly forward it to the relevant Firm and will not respond to the request itself except on the Firm’s documented instruction or as required by law.

7

Breach Notification

Navisa will notify the affected Firm without undue delay after becoming aware of a personal data breach affecting the Firm’s Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

Navisa will cooperate reasonably with the Firm and take such steps as are reasonably requested to assist the Firm in investigating, mitigating, and remediating the breach, and in meeting any applicable breach-notification obligations under PIPEDA, the GDPR, or other applicable law.

8

Return & Deletion of Data

On termination of the Terms of Service, or on the Firm’s written request, Navisa will make the Firm’s Personal Data available for export for 30 days following account closure. After this export window, Navisa will delete the Personal Data from active systems, except where retention is required by applicable law (such as billing records retained for Canadian tax purposes), in which case the data will remain protected and isolated for only as long as legally required. This is consistent with the termination provisions of the Terms of Service.

9

PIPEDA Compliance

As a Canadian company, Navisa processes Personal Data in a manner consistent with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Navisa will process Personal Data only for the identified purposes, will protect it with safeguards appropriate to its sensitivity, and will assist the Firm in meeting its accountability and openness obligations as a Controller. Data Subjects or Firms may raise privacy concerns with the Office of the Privacy Commissioner of Canada (priv.gc.ca).

10

GDPR Compliance

To the extent the General Data Protection Regulation (EU) 2016/679 (“GDPR”) applies to the Firm’s processing of Personal Data, this DPA constitutes the Firm’s documented instructions to Navisa as Processor under Article 28 of the GDPR. Navisa will:

  • ·Process Personal Data only on the Firm’s documented instructions, including with regard to international transfers.
  • ·Ensure that persons authorized to process Personal Data are bound by confidentiality.
  • ·Implement the security measures described in Section 5 (Article 32).
  • ·Engage Sub-Processors only as set out in Section 4 and under equivalent data-protection obligations.
  • ·Assist the Firm with Data-Subject requests (Section 6) and with breach notification (Section 7).
  • ·Return or delete Personal Data on termination as set out in Section 8.
  • ·Make available information reasonably necessary to demonstrate compliance with Article 28.

Where international transfers of Personal Data occur, Navisa will rely on an appropriate transfer mechanism recognized under the GDPR, such as the European Commission’s Standard Contractual Clauses, supplemented by additional safeguards where required.

11

General

In the event of any conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA prevails. This DPA is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein. We may update this DPA from time to time with notice to Firm administrators, consistent with the change-notice provisions of the Terms of Service.

12

Contact

Questions about this Data Processing Agreement or our data-processing practices? Contact us:

  • ·Email: privacy@navisa.io
  • ·Company: NovaCore Systems Inc.
  • ·Province: British Columbia, Canada