Privacy Policy
1. Overview
Vizado (“we,” “our,” or “the Platform”) is an independent software-as-a-service case management platform. This Privacy Policy describes how we collect, use, and protect information when agencies and their authorised staff use the Platform.
Vizado acts as a data processor on behalf of registered agencies (the data controllers). Each agency is independently responsible for its own privacy obligations to its clients under the Personal Information Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy legislation.
2. Information We Collect
Agency account data — business name, business email address, phone number, subdomain slug, licensing body and number, and the name and email of the primary contact provided during registration.
Staff user data — name and email address of each staff member invited to an agency workspace.
Client and case data— all client records, case files, documents, messages, notes, and related data entered into the Platform by the agency or its staff. Vizado processes this data strictly on the agency’s instruction and does not access it for any other purpose.
Usage and technical data — log files, IP addresses, browser type, session timestamps, and feature interaction events. This data is used solely for platform security, debugging, and aggregate performance monitoring.
3. How We Use Information
- To provision, operate, and maintain the agency workspace
- To authenticate users and enforce access controls
- To send platform notifications (system alerts, billing, registration confirmations)
- To detect, investigate, and prevent fraudulent or abusive activity
- To produce aggregate, anonymised analytics about platform usage (no individual is identifiable)
- To comply with applicable Canadian law and lawful governmental requests
We do not sell, rent, or otherwise share personal information with third parties for marketing purposes. We do not use client case data for any purpose other than providing the Platform to the agency that controls that data.
4. Agency Responsibility for Client Data
5. Data Storage and Security
All data is stored on servers located in Canada. Data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Access to production systems is restricted to authorised engineering personnel under strict least-privilege controls.
Despite these measures, no system is perfectly secure. Agencies should use strong, unique passwords, enable two-factor authentication where available, and report any suspected unauthorised access to support@app.vizado.io immediately.
6. Data Retention
Agency account and staff data is retained for the duration of the active subscription and for 90 days following termination, after which it is securely deleted. Agencies may request earlier deletion by contacting support. Client and case data follows the same schedule unless the agency exports and deletes it sooner through the Platform.
7. Your Rights
Under PIPEDA, individuals have the right to access, correct, and in certain circumstances request the deletion of their personal information. Requests from agency staff or contacts should be directed to privacy@app.vizado.io. Requests relating to client data must be directed to the relevant agency, as Vizado acts only on the agency’s instruction for that data.
8. Cookies
We use a limited set of cookies necessary for platform operation. See our Cookies Policy for details.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered agencies by email and by in-platform notice at least 14 days before material changes take effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.
10. Contact
Privacy inquiries: privacy@app.vizado.io
Vizado · Burnaby, British Columbia, Canada