Legal
Security & data residency
Zahata Global Inc. · operator of MyGCMS · effective July 27, 2026
Your immigration file contains sensitive personal information. Zahata Global Inc. builds MyGCMS to protect it with encryption, Canadian data residency, and least-privilege access.
Encryption
All data is encrypted in transit using TLS. Documents and records are encrypted at rest using AES-256. Session tokens are signed and stored in secure, http-only cookies.
Canadian data residency
Uploaded identity and consent documents are stored in Canada (AWS ca-central-1). We are completing the migration of database storage to a Canadian region so that both documents and application data reside in Canada, supporting compliance with Canadian privacy expectations.
Private storage & access
Our document store blocks all public access. Files are never publicly addressable and are served only through short-lived, signed links scoped to the requesting user or an authorized reviewer. Documents are never cached in a content delivery network. Access to records is restricted and logged.
Human approval checkpoint
No request is released for government filing without review by authorized Zahata Global Inc.staff, who verify identity, signed consent, and attestations. Automated components prepare and check the packet; people approve at the legal boundary.
Compliance
We operate in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). In the event of a material breach, we follow PIPEDA breach-notification requirements, including reporting to the Office of the Privacy Commissioner of Canada and affected individuals.
Reporting a concern
If you believe you have found a security issue, please contact privacy@mygcms.com. We appreciate responsible disclosure.