Legal
Privacy policy
IMECore helps teams run Independent Medical Examinations in British Columbia. This policy explains what personal information we handle, why we handle it, who can see it, where it lives, how long we keep it, and how you can ask to see or correct it.
Last updated: 28 August 2026. This page is not legal advice. The signed agreement with your workspace governs.
The agreement controls
This policy summarizes how IMECore handles personal information. The signed data processing agreement in the DPA summary governs. If there is a conflict, the signed agreement governs.
Scope
Who this policy covers and which law applies
IMECore holds personal information about injured people, examiners, and workspace users. Canadian law always applies. Which provincial law applies depends on the client.
PIPEDA, federal
The federal baseline for private-sector personal information. It always applies.
BC PIPA, provincial
Private-sector work in BC. Insurers, law firms, and employers sit here.
FOIPPA, public sector
WorkSafeBC is a public body. ICBC is a Crown corporation. We treat both as public-body work. FOIPPA requires storage and access in Canada.
What we collect
The information we process
We collect the minimum needed to run a case. Referral packages arrive as they are. We do not pull extra sources.
Claimant identity
Name, date of birth, address, personal health number, and claim numbers such as ICBC, WorkSafeBC, and disability policy numbers.
Medical records
The referral record package. Often thousands of pages: clinical notes, imaging reports, specialist consults, and hospital files.
Exam findings
The examiner's notes, measurements, and dictated observations from the examination.
Reports and drafts
The finished IME report and every draft. It links identity to medical opinion. It is the most sensitive object we hold.
Workspace use
Account details, workspace membership, examiner schedules, invoices, messages, and the audit log. This supports the workflow and shows who accessed what and when.
Why
Why we use it and the legal basis
We use personal information only to provide the service:
- open and run IME cases from intake through to billing;
- collect, index, and organize medical records for a specific case;
- schedule examinations and support report drafting and delivery;
- keep the audit trail and keep the service secure; and
- help you with case handling on your written request.
The workspace is the controller. It decides why information is collected. IMECore is the processor. We act only on the workspace's documented instructions.
The legal basis under PIPEDA and BC PIPA is the consent the workspace obtains from the individual, or another basis the law allows such as an employment or legal-proceeding purpose. The workspace is responsible for that notice and basis. We do not pool personal health information across cases to train models or for analytics outside the case.
Access
Who can see it
Workspace tenancy
Every case belongs to one workspace. We scope every request to that workspace. A user in one workspace cannot read another workspace's cases, records, or reports.
Role-based access
Roles include intake coordinator, records specialist, examiner, referrer, and workspace admin. Each role gets the minimum access its job needs. Agents carry their own identity and the same limits.
Examiners and referrers
An examiner sees only cases assigned to them. A referrer sees only documents the workspace delivers to them. The portal, not email, carries records.
Subprocessors
A small list of subprocessors may process data to host the service, send mail, or run model inference. See the subprocessor list for who, what, where, and whether health information may reach them.
Where
Where it is stored
- Case data, extracted fields, and indexes live on Cloudflare. Record PDFs, OCR output, and report files live there too. We ask Cloudflare to keep them in Western North America. That is a location hint, not a guarantee. Cloudflare does not offer a Canada-only choice for this storage today.
- Model inference that carries personal health information runs only in Canada. We verify that on every request. We do not send health information to providers without a Canada-only option.
- No health information goes to a United States region, replica, log sink, or analytics tool. Exports and backups follow the same rule.
Cloudflare does not offer a Canada-only choice for this storage today. See the platform docs and the subprocessor list. Azure in Canada Central is the Canada-resident path.
Retention
How long we keep it
We do not set retention periods in this policy. Each workspace sets its own retention policy. A workspace may set a default and overrides per client type, for example public-body work for WorkSafeBC and ICBC.
When the retention period ends, or on a valid request, the case appears in a review queue measured from when the case closed. A human approves deletion. Nothing deletes on a timer. Deletion removes the case, its records in R2, rows in D1, and derived indexes. An audit entry records the deletion. A small stub of the fact that a case existed and was deleted on a given date may remain if counsel requires it. Cases under legal hold never appear for deletion.
The exact years depend on limitation periods and insurer contracts. Your workspace agreement sets them. See the data processing agreement and the retention notes in security.
Rights
Your rights and how to use them
Under PIPEDA and BC PIPA you may have the right to ask to see the personal information we hold about you and to ask us to correct it where it is inaccurate.
- Ask the organization that collected your information. For IME work that is often the insurer, law firm, employer, or WorkSafeBC. They hold the case file and they instruct us.
- Or email privacy@imecore.com. We will help the workspace gather the record and reply within the time the law sets. We may need to verify your identity first.
- If you use the examinee portal, you can also manage notices and requests in your privacy choices.
You may complain to the Office of the Privacy Commissioner of Canada OPC or the Office of the Information and Privacy Commissioner for BC OIPC BC if you are not satisfied with the reply.
Contact
Questions about privacy
Email privacy@imecore.com with your name, your workspace if you have one, and what you want to know. We will route an access or correction request to the right workspace and reply in line with PIPEDA and BC PIPA.
For the written duties, see the DPA summary, the record of processing, and trust and security.
FAQ
Questions about your information
Who decides why my information is used?
The workspace that opened your case decides. IMECore processes your information only to provide the service on that workspace's instructions. We do not sell it and we do not use it to train a general model.
How do I ask to see or correct my information?
Email privacy@imecore.com or ask the organization that collected your information. We will help that organization gather the record. You can also use the portal privacy choices where the workspace enables portal access.
Where does my information live?
Production case data lives on Cloudflare with a Western North America location hint. There is no Canada-only choice for this storage, so the hint is best-effort. Model inference that carries personal health information runs only in Canada and is verified on every request. See the security and subprocessors pages for the detail.
Need a copy of your information?
Email privacy@imecore.com and we will help the workspace gather the record.