Skip to content
IMECore

Legal

Record of processing activities

What personal information IMECore holds, for whom, why, where it lives, who can see it, and on what legal basis. A privacy officer can use this to complete a PIA or to answer a regulator's request.

IMECore is the processor. The workspace is the controller. We process only on your documented instructions. Retention periods come from your workspace policy, not from this page.

At a glance

Every category in one table

Read the row for the information type you care about. Examples are illustrative, not exhaustive. Where the location says Cloudflare, the residency note below applies.

Record of processing by category
CategoryExamplesPurposeLegal basisWhere it livesWho may see it
Claimant identityName, date of birth, address, personal health number, claim numbers (ICBC, WorkSafeBC, disability policy)Open the case, book the exam, identify the person to the examiner, produce the report, invoice correctlyWorkspace instructions; consent obtained by the workspace; or employment / legal-proceeding purpose under PIPACloudflare storage and the audit logWorkspace members by role; assigned examiner; subprocessors on the subprocessor list
Medical recordsReferral package: clinical notes, imaging reports, specialist consults, hospital files; OCR output; search indexCollect, organize, and index the file so the examiner and reviewer can see the historyWorkspace instructions; consent or other PIPA basis as aboveCloudflare storage; model processing only where data is not health informationRecords and QA roles; assigned examiner; Azure Canada Central where inference is enabled
Exam findingsExaminer notes, measurements, dictated observations, functional scoresCapture the examination and support the medical opinionWorkspace instructions; examiner agreement and consent for the examinationCloudflare storage and the audit logExaminer who created it; report_writer and QA roles; workspace admin
Reports and draftsFinished IME report and every draft; citation links back to source pagesDraft, review, approve, and deliver the opinion the referrer requestedWorkspace instructions; contract with the referrerCloudflare storage and the audit logReport_writer, QA, and admin; referrer only after approved delivery
Scheduling and examiner detailsExaminer name and credentials, availability, booked slots, clinic assignment, payout rate where applicableMatch the right examiner to the deadline and the clinical questionWorkspace instructions; examiner contractor agreementCloudflare storage and the audit logScheduler, clinic, and finance roles; examiner for their own slots
Billing and payoutsInvoice lines, tax, payout amounts, payment statusInvoice the referrer and pay the examiner; meet tax and accounting dutiesWorkspace instructions; contract and legal obligationCloudflare storage and Stripe for payments (no health content)Finance and admin roles; Stripe under its DPA
Workspace account and accessUser name, email, role, workspace membership, consent records, notification preferencesRun the workspace, enforce access, honor consent and privacy choicesWorkspace instructions; consent for portal noticesCloudflare storage and the audit logWorkspace admin; the individual for their own consent record; subprocessors that send mail
Operational and audit tracesAudit rows (who, what, when, why where a reason is carried), mail delivery log, queue receiptsProve who accessed what, support breach review, and keep the service runningLegal obligation (PIPEDA breach record) and legitimate need to secure and account for processingAudit log and platform logsWorkspace admin (read) and platform operators. Retention policy governs the audit class

Where you read that data lives on Cloudflare, the residency note in the next section applies. There is no Canada-only choice for this storage today. The Western North America hint is best-effort. Model inference for health information is Canada-only and verified on every request.

Planes

Processing planes and safeguards

Tenancy plane

One workspace per tenant. Every case and record row carries a workspace ID. Every query and every agent call is scoped by it. This is the first isolation.

Role plane

Roles define what each person may view, edit, export, or approve. The permission check is the gate. An examiner sees only assigned cases. A referrer sees only delivered documents.

AI plane

Every request is checked before any information is sent for processing. Health information may only go to a model that runs in Canada. We verify with the provider that the work actually happened in Canada, on every request. We do not send health information to providers without a Canada-only option.

Retention plane

Retention policies are set per workspace, data class, and client type. A case surfaces for deletion only after its close date. A person approves deletion. Deletion removes the database rows, the files, and the derived indexes.

Keep in sync

What to keep alongside this record

  • The subprocessor list at /legal/subprocessors. Keep the two in sync. A new model or store changes this record.
  • The PIA and the DPA summary. The PIA names the risks. The DPA carries the residency and audit duties.
  • The deployment findings for your environment. The record is only as true as the environment it describes. We share the findings on request.

To receive notice of processing changes, email privacy@imecore.com and ask to be added to the subprocessor notice list. We treat that list as the notice channel for ROPA and residency changes as well.

Need a copy for your PIA?

We can send this record as a spreadsheet with the deployment findings for your environment.