Legal
Security & data residency
Zahata Global Inc. · operator of MyGCMS · effective July 27, 2026
Your immigration file contains sensitive personal information. Zahata Global Inc. builds MyGCMS to protect it with encryption, Canadian data residency, and least-privilege access.
Encryption
All data is encrypted in transit using TLS. Documents and records are encrypted at rest using AES-256. Session tokens are signed and stored in secure, http-only cookies.
Canadian data storage
Personal data is stored in Canada. Uploaded identity and consent documents are held in Canada (AWS ca-central-1), and the application database also runs in AWS Canada (ca-central-1). Both documents and application data reside in Canada, supporting compliance with Canadian privacy expectations. Application compute is hosted with our platform provider; only storage-at-rest location is asserted here.
Private storage & access
Our document store blocks all public access. Files are never publicly addressable and are served only through short-lived, signed links scoped to the requesting user or an authorized reviewer. Documents are never cached in a content delivery network. Access to records is restricted and logged.
Human approval checkpoint
No request is released for government filing without review by authorized Zahata Global Inc. staff, who verify identity, signed consent, and attestations. Automated components prepare and check the packet; people approve at the legal boundary.
Compliance
We operate in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). In the event of a material breach, we follow PIPEDA breach-notification requirements, including reporting to the Office of the Privacy Commissioner of Canada and affected individuals.
Reporting a concern
If you believe you have found a security issue, please contact privacy@mygcms.com. We appreciate responsible disclosure.