Request access
Law 25

Privacy policy

Last updated: July 22, 2026

Vizir, the operating name of 9566-4629 Québec inc. (a Quebec company, operated in Quebec), is a management, collection and document-preparation service built for licensed immigration lawyers, notaries and consultants in Canada. Protecting personal information is at the core of the service. This policy explains what information we collect, why, how we protect it, and what your rights are, in accordance with Quebec's Act respecting the protection of personal information in the private sector (Law 25) and PIPEDA (Canada).

1. Person responsible for personal information protection

In accordance with Law 25, the person responsible for the protection of personal information within our organization is:

9566-4629 Québec inc., doing business as Vizir

Quebec business number (NEQ): 1182097924

Responsible person: Sid Ahmed Si Merabet, Director

Email: contact@vizir.ca

Phone: +1 (514) 550-6236

Website: vizir.ca

You may contact this person for any question regarding this policy or the exercise of your rights.

2. Two distinct roles

Vizir acts in two capacities, with different responsibilities:

  • For this site and your account, when you visit the site, request access or subscribe, Vizir is the controller of the information about you (your professional contact details, your billing data).
  • For files processed in the platform, when a firm uses Vizir to build its clients' files, Vizir acts as the firm's service provider (agent). The firm remains responsible for its clients' information; Vizir processes it only on the firm's behalf, on its instructions, never for any other purpose. Vizir never contacts a firm's clients.

3. Information we collect

a) Access request (site visitors), if you submit the form: name, firm, professional license number, email, language preference, and the submission IP address (security and abuse prevention). These requests are stored on our Canadian hosting and trigger an internal alert to our team. Only to process your request (registry check, account setup, contact).

b) Account holders, professional identity and contact details, license number, login credentials (passwords are stored encrypted / hashed, never in clear text), and your firm's settings.

c) Billing and payment data, billing name and email, chosen plan, invoice history. Where offered, card payments are processed by our provider Stripe: Vizir never sees or stores your full card number. We keep only the non-sensitive elements returned by Stripe (card brand, last four digits, expiry, payment status). See section 7.

d) Minimal technical data, connection and security logs (timestamp, IP address, action performed) needed to secure the service and maintain the audit log.

e) Audience measurement, when enabled: aggregated, anonymous statistics (Plausible Analytics), no cookies, no personal identifiers, no ad tracking.

f) Firms' client files, documents and information uploaded to a file are processed on the firm's behalf (see section 2). They are hosted in Canada, encrypted and isolated per firm.

We do not collect any information without your knowledge and use no advertising profiling tools.

4. Purposes of collection

  • process your access request and verify your registration with your professional order's registry;
  • open, secure and administer your account;
  • provide the service: collecting, verifying and preparing files;
  • manage the subscription, billing and payments;
  • keep the service secure and maintain the required audit log;
  • show you, on screen within the service, the information needed to follow your file (never unsolicited advertising).

5. Consent and basis

We process your information on the basis of your request, your consent, and performance of the service contract. You may withdraw your consent at any time by writing to contact@vizir.ca; withdrawal is not retroactive and may prevent continuation of the service. Within the platform, the consent of individuals concerned by a file is collected individually, in accordance with Law 25.

6. Providers and subprocessors

We rely on a limited number of providers, contractually bound to protect your information and use it only to deliver their service:

ProviderRoleLocation
Supabase (cloud hosting)Database and case file storageCanada
Anthropic (AI analysis, enabled at the firm's choice)Assisted reading of a case's documents; never an automated decisionUnited States
VercelSite delivery and transient form processingUnited States
StripeCard payment processingUnited States / Ireland
Plausible Analytics (when enabled)Anonymous, cookieless audience measurementEuropean Union
ResendOnly the internal alert alerting us to an access request submitted on this site. Never an email sent from the platform, never a case documentUnited States

The platform sends no email. The Vizir application sends no email: not to the firm, not to its clients. Alerts, reminders and case updates appear on screen, in the dashboard and in the case timeline. No case data is sent to an email delivery service. The only sending that remains is the internal alert telling us that an access request was submitted on this public site: it goes to our own address, contains the contact details you entered in the form, and never any case document. If you write to us at contact@vizir.ca, your message is handled by our team as ordinary correspondence.

Access by our own staff. The human checks that form part of the service, meaning the second review of a file's documents, are carried out by Vizir's internal staff and not by an outside vendor: this is not subcontracting. Every person is bound by a written confidentiality undertaking, accesses only the files required for the task at hand, and each of their accesses is written to the audit log that the firm can review. Part of our team works from France: this access from outside Quebec is framed by contract and covered by the privacy impact assessment required under section 17 of Law 25, on the same footing as the other disclosures outside Quebec described below. The company's management is in Quebec. These points are restated in plain language on our Security page.

We do not sell, rent or disclose your personal information to third parties for commercial purposes.

7. Payments and billing (Stripe)

Where card payment is offered, it is processed by Stripe, a specialized provider compliant with the PCI-DSS standard. When you enter your card details, they are sent directly to Stripe and do not pass through Vizir's servers in readable form. Vizir never stores your full card number or security code. We receive from Stripe only what is needed for billing (name, email, card brand and last four digits, payment status). Stripe's processing is governed by its own privacy policy: stripe.com/privacy.

8. Cookies and local storage

The public site uses no tracking, advertising or analytics cookies. We only use your browser's local storage to remember your language preference. Within the application, a strictly necessary cookie keeps your session securely open; it has no advertising purpose. Stripe may set cookies strictly necessary to secure payment and prevent fraud.

9. Data retention

Unsuccessful access requests are deleted no later than 12 months after receipt. Account and billing data are kept for the duration of the business relationship, then for the period required by legal and accounting obligations. Audit logs tied to files are kept for 7 years, in line with applicable requirements. After these periods, information is securely destroyed or anonymized.

10. Security

Files are hosted in Canada, encrypted at rest and in transit, isolated per firm (a firm can never see another firm's data), and every action (including every access) is written to a tamper-proof log. Access is restricted on a least-privilege basis. We apply security measures that are reasonable and proportionate to the sensitivity of the information.

11. Disclosure outside Quebec

Some providers (notably Vercel, which delivers the site and transiently processes form submissions, Stripe, and Resend for the sole internal alert described in section 6) may process information outside Quebec, including in the United States and Europe. Before any disclosure outside Quebec, we carry out a privacy impact assessment and frame such disclosures by contract, in accordance with section 17 of Law 25. File data and access requests are themselves hosted in Canada.

12. Anonymized statistics

Fully anonymized, aggregated statistics (never your documents, never the identity of a person or a file) may be used to improve the service and publish studies on real processing times, above minimum aggregation thresholds that prevent any re-identification. This processing complies with Law 25 and PIPEDA. Firms' professional secrecy and file confidentiality remain fully intact.

13. Your rights

Under Law 25, you have the following rights:

  • Access: obtain a copy of the information we hold about you;
  • Rectification: have inaccurate, incomplete or ambiguous information corrected;
  • Withdrawal of consent: withdraw your consent to the use of your information;
  • Portability: receive your information in a structured, commonly used technological format;
  • De-indexing and deletion: request that the dissemination of your information cease or that it be deleted where the law permits.

For a firm's client information, the request must be addressed to the responsible firm; we assist in fulfilling it. To exercise a right, write to contact@vizir.ca. We respond within the legal timeframe (generally 30 days).

14. Privacy incident

In the event of a confidentiality incident presenting a risk of serious harm, we take reasonable measures to reduce its consequences, keep an incident register, and notify Quebec's Commission d'accès à l'information as well as the individuals concerned, in accordance with Law 25.

15. Complaint to the Commission d'accès à l'information

If you believe your rights have not been respected, you may file a complaint with Quebec's Commission d'accès à l'information (CAI): www.cai.gouv.qc.ca.

16. Changes to this policy

We may update this policy to reflect changes in our practices or in regulations. The date of the latest update appears at the top of the page.