Who we are
This Privacy Policy explains how Nova System Inc. ("Nova System", "we", "us", "our") collects, uses, discloses, and protects personal information in connection with the Meridian platform and its products · including Polaris (desktop CRM) and Aurora (mobile companion app).
Nova System is incorporated in British Columbia, Canada. This policy is governed by Canadian privacy law, including the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).
Who uses our products
Polaris and Aurora are business tools for licensed immigration consulting firms. Day-to-day users are owners, RCICs (Regulated Canadian Immigration Consultants), case workers, and support staff inside those firms. Aurora is not intended for end consumers seeking immigration services.
When a firm subscribes to Meridian, the firm itself is the data controller for any client/case information they store in the system. Nova System acts as the data processor on the firm's behalf · we host and operate the software, but we don't decide what client data goes in.
What we collect
Information you provide directly
- Account details: your name, work email, role, optional phone number, and an optional profile photo. Provided when your firm's admin creates your staff account or when you sign in for the first time.
- Authentication data: a password hash (PBKDF2-SHA256), failed-login counters, and lock-out timestamps for security.
- Content you create in the app: voice notes, photographs of documents, typed notes, task and time-entry data, and chat messages you send to teammates or clients via the app.
Information collected automatically
- Technical logs: server access logs (IP address, request path, response code, user-agent) retained for up to 30 days for security and abuse prevention.
- Push notification tokens: when you allow push notifications, Aurora registers an opaque device token with OneSignal so we can deliver alerts to your device. We do not see the underlying APNs/FCM identifier.
- Device information: operating system version and a hashed device identifier supplied by OneSignal for push deduplication.
Information we do not collect
- We do not embed third-party advertising trackers.
- We do not sell personal information.
- We do not use your firm's client data to train AI models. AI features call third-party APIs (see "AI subprocessors" below) on a per-request basis with no model fine-tuning.
- We do not collect location data beyond what is implied by IP-based geolocation in server logs.
How we use information
- To operate the service: authenticate you, route your requests, store the content you create, deliver push notifications, and surface the right data on the right screen.
- To secure the service: detect abuse, rate-limit, investigate incidents, and recover accounts.
- To support you: respond to questions you send to support@thenovasystem.com.
- To improve the product: analyze aggregated, non-identifying usage patterns. Where possible, we use derived counters (e.g., "X firms used feature Y this month") rather than identifying logs.
How we share information
We share personal information only with the following categories of recipients, all bound by data-protection contracts:
- Infrastructure providers: Cloudflare Inc. (compute, storage, content delivery) and OneSignal Inc. (push notification delivery). Cloudflare stores data at edge locations including in Canada and the United States.
- AI subprocessors: Anthropic PBC (Claude/Sonnet models for case intelligence and chat) and Cloudflare Workers AI. Requests are sent on-demand; neither subprocessor retains the request to train models.
- Email delivery: Resend.com for transactional emails (verification codes, password resets, notifications).
- Twilio Inc.: where the firm has enabled SMS notifications.
- Stripe Inc.: for subscription billing on the firm-level account (Stripe never receives mobile-app user data; only firm-level billing data).
- Law enforcement and regulators: only where required by valid legal process under Canadian law.
Cross-border data transfers
Some of our subprocessors process data outside Canada (primarily the United States). We rely on contractual and technical safeguards to protect transferred data. If you are uncomfortable with cross-border processing, your firm's admin can request a Canada-only deployment under our enterprise plan.
How long we keep information
- Account records: for as long as you remain an active staff member at a Meridian-subscribed firm.
- Case content: controlled by your firm. When the firm deletes a case, it is soft-deleted for 30 days then purged.
- Server logs: 30 days.
- Backups: 90 days of point-in-time backups, then permanently overwritten.
Your rights
Under PIPEDA and PIPA, you have the right to:
- Access: request a copy of the personal information we hold about you.
- Correct: ask us to amend information that is inaccurate.
- Withdraw consent: for non-essential processing.
- Delete your account: see /account-deletion for the in-app + email path.
- Complain: to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).
Children
Polaris and Aurora are workplace tools for adult immigration professionals. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us with personal information, please email privacy@thenovasystem.com and we will delete it.
Security
We use industry-standard safeguards including TLS in transit, AES-GCM at rest for sensitive fields, PBKDF2-SHA256 password hashing, JWT-based session management, scoped service bindings between workers, and a tightly-restricted admin-access consent workflow with email approval. See /security for more detail.
Changes to this policy
We may update this policy from time to time. The "Effective" date at the top of this page reflects the latest revision. Material changes will be announced in-app and by email to firm owners.
Contact
For privacy questions:
Nova System Inc.
Vancouver, British Columbia, Canada
privacy@thenovasystem.com