Legal
Record of processing activities
What personal information IMECore holds, for whom, why, where it lives, who can see it, and on what legal basis. A privacy officer can use this to complete a PIA or to answer a regulator's request.
IMECore is the processor. The workspace is the controller. We process only on your documented instructions. Retention periods come from your workspace policy, not from this page.
At a glance
Every category in one table
Read the row for the information type you care about. Examples are illustrative, not exhaustive. Where the location says Cloudflare, the residency note below applies.
| Category | Examples | Purpose | Legal basis | Where it lives | Who may see it |
|---|---|---|---|---|---|
| Claimant identity | Name, date of birth, address, personal health number, claim numbers (ICBC, WorkSafeBC, disability policy) | Open the case, book the exam, identify the person to the examiner, produce the report, invoice correctly | Workspace instructions; consent obtained by the workspace; or employment / legal-proceeding purpose under PIPA | Cloudflare storage and the audit log | Workspace members by role; assigned examiner; subprocessors on the subprocessor list |
| Medical records | Referral package: clinical notes, imaging reports, specialist consults, hospital files; OCR output; search index | Collect, organize, and index the file so the examiner and reviewer can see the history | Workspace instructions; consent or other PIPA basis as above | Cloudflare storage; model processing only where data is not health information | Records and QA roles; assigned examiner; Azure Canada Central where inference is enabled |
| Exam findings | Examiner notes, measurements, dictated observations, functional scores | Capture the examination and support the medical opinion | Workspace instructions; examiner agreement and consent for the examination | Cloudflare storage and the audit log | Examiner who created it; report_writer and QA roles; workspace admin |
| Reports and drafts | Finished IME report and every draft; citation links back to source pages | Draft, review, approve, and deliver the opinion the referrer requested | Workspace instructions; contract with the referrer | Cloudflare storage and the audit log | Report_writer, QA, and admin; referrer only after approved delivery |
| Scheduling and examiner details | Examiner name and credentials, availability, booked slots, clinic assignment, payout rate where applicable | Match the right examiner to the deadline and the clinical question | Workspace instructions; examiner contractor agreement | Cloudflare storage and the audit log | Scheduler, clinic, and finance roles; examiner for their own slots |
| Billing and payouts | Invoice lines, tax, payout amounts, payment status | Invoice the referrer and pay the examiner; meet tax and accounting duties | Workspace instructions; contract and legal obligation | Cloudflare storage and Stripe for payments (no health content) | Finance and admin roles; Stripe under its DPA |
| Workspace account and access | User name, email, role, workspace membership, consent records, notification preferences | Run the workspace, enforce access, honor consent and privacy choices | Workspace instructions; consent for portal notices | Cloudflare storage and the audit log | Workspace admin; the individual for their own consent record; subprocessors that send mail |
| Operational and audit traces | Audit rows (who, what, when, why where a reason is carried), mail delivery log, queue receipts | Prove who accessed what, support breach review, and keep the service running | Legal obligation (PIPEDA breach record) and legitimate need to secure and account for processing | Audit log and platform logs | Workspace admin (read) and platform operators. Retention policy governs the audit class |
Where you read that data lives on Cloudflare, the residency note in the next section applies. There is no Canada-only choice for this storage today. The Western North America hint is best-effort. Model inference for health information is Canada-only and verified on every request.
Planes
Processing planes and safeguards
Tenancy plane
One workspace per tenant. Every case and record row carries a workspace ID. Every query and every agent call is scoped by it. This is the first isolation.
Role plane
Roles define what each person may view, edit, export, or approve. The permission check is the gate. An examiner sees only assigned cases. A referrer sees only delivered documents.
AI plane
Every request is checked before any information is sent for processing. Health information may only go to a model that runs in Canada. We verify with the provider that the work actually happened in Canada, on every request. We do not send health information to providers without a Canada-only option.
Retention plane
Retention policies are set per workspace, data class, and client type. A case surfaces for deletion only after its close date. A person approves deletion. Deletion removes the database rows, the files, and the derived indexes.
Keep in sync
What to keep alongside this record
- The subprocessor list at /legal/subprocessors. Keep the two in sync. A new model or store changes this record.
- The PIA and the DPA summary. The PIA names the risks. The DPA carries the residency and audit duties.
- The deployment findings for your environment. The record is only as true as the environment it describes. We share the findings on request.
To receive notice of processing changes, email privacy@imecore.com and ask to be added to the subprocessor notice list. We treat that list as the notice channel for ROPA and residency changes as well.
Need a copy for your PIA?
We can send this record as a spreadsheet with the deployment findings for your environment.