IEP POLICY
Privacy Notice
Version: privacy-2026-09-07-v2
1. Operator, scope and contact
IEP (International Education Platform) Canada Inc., Alberta, Canada, operates the IEP education-planning and Advisor booking platform. This notice explains how we handle personal information for those services. Contact our privacy owner at info@iep7.com to ask about access, correction, deletion, account closure, privacy choices or a complaint. Different mandatory rights may apply depending on where you live.
2. Adult accounts and minor beneficiaries
Account holders, contracting parties and payers must be 18 or older. A parent or legal guardian may use their own account to plan education for a beneficiary under 18. Planning details, including a beneficiary's birth year, describe that beneficiary and do not prove the account holder's age. Provide only information needed for the planning task; do not enter unnecessary child identity documents or sensitive details. Contact us if you believe a minor is using an account contrary to this model.
3. Information we handle
Account information includes email, name and profile information you supply, sign-in records, sessions and required acceptance evidence. Google sign-in, when chosen, supplies the account identity/profile needed to sign in; we do not obtain general access to your personal mailbox merely because you sign in with Google.
Planning information includes the education background, beneficiary birth year and other inputs, destinations, preferences, assessments, saved Plans, calculation results and related snapshots you provide or generate. Booking information includes the Advisor, time, timezone, meeting status, contact details you choose to provide, meeting link and relevant preparation information. Payment records include amounts, currency, voucher use, transaction/refund status and provider references. Stripe collects card details on its payment page; IEP uses payment references and status rather than storing your full card number in its application database.
We also keep essential service communications and delivery evidence, policy-version and choice evidence, and security/operational records needed to operate and protect the service. Full Plan delivery sends an IEP service copy to an IEP mailbox. Optional activity/referral analytics are described separately below.
4. Why we use information and who receives it
We use relevant information to authenticate accounts, prepare and save Plans, arrange and deliver meetings, process and reconcile payments, respond to support/privacy requests, prevent abuse, preserve necessary records and improve service reliability. Advisors receive the information needed for the requested meeting through authorized service workflows. Authorized IEP personnel and technical operators may access information for these purposes, subject to their responsibilities.
Hosting/database services, Stripe, Google Calendar/Meet and email providers process relevant information to deliver their functions. Payments are subject to Stripe's privacy information. Meeting invitations and emails may create copies held by recipients and their providers. Information may be processed outside your country, including by international providers; we do not promise that every copy remains in Canada. Applicable foreign laws may govern provider access. Contact us for information about the providers relevant to your request.
5. Personal Plans and publication
Your saved Full Plan is accessible to anyone with its permanent link, without sign-in or a viewing code. Share this link only with people you choose; it does not grant access to your account or bookings. Search-indexed Public Plan publication is a separate function and is disabled by default for this launch. A separately published snapshot, if one exists, must be reviewed separately when handling a removal request: deleting a source Plan does not automatically remove every published copy. Do not send a private report or meeting link to someone who should not have it.
6. Essential technology and optional analytics
Essential cookies and records support sign-in, security, account continuity, scheduling, payment and policy evidence. Optional page-view analytics and referral attribution remain off unless you allow them through Privacy choices. The optional-choice cookie can last up to 180 days. You can withdraw that choice in the footer. When withdrawal is confirmed, future optional collection stops and IEP clears its specified optional cookies and local tracking state. If confirmation fails, Privacy choices explains the failure and asks you to retry. Withdrawal does not itself erase historical analytics or necessary financial attribution. Ask info@iep7.com for deletion of existing data, subject to the retention and preservation rules below. Blocking essential cookies may prevent sign-in or booking.
7. Retention
We keep information for its stated purpose and the category schedule below, subject to a documented legal, financial, security or dispute hold limited to necessary records. Periods are IEP operating policies, not a statement that every period is legally required. We review eligible records monthly and aim to complete routine deletion or minimization within 30 days after the applicable retention deadline, unless a shorter legal deadline applies.
- Account/profile and owned Plans
- While active; review after 24 months without meaningful account, Plan or booking activity, with 30 days' notice before inactivity closure; verified closure/deletion requests can be handled earlier.
- Unclaimed anonymous planning data
- 90 days after last activity where no active booking, payment or preservation obligation depends on it.
- Minimum booking, transaction, refund, redeemed-voucher and essential financial delivery evidence
- Seven years after the end of the year containing final settlement, refund or dispute resolution, subject to professional validation and any necessary hold.
- Optional meeting notes/contact context
- 24 months after the meeting or cancellation unless needed for a documented dispute or another continuing purpose.
- Unused expired vouchers
- 90 days after expiry if no payment, dispute or investigation depends on them.
- Routine correspondence and Plan/support delivery records
- 24 months after last relevant contact; essential financial delivery evidence follows the longer financial schedule.
- Raw optional activity/referral analytics
- 90 days from each event or visit; separately justified financial attribution follows the financial schedule. Non-identifying aggregate statistics may remain only after their anonymity is checked.
- Terms/adult/guardian evidence and the accepted Terms text
- Seven years after account closure or final contractual resolution, whichever is later.
- Optional-consent evidence
- Two years after withdrawal or expiry; this does not authorize retaining the underlying activity for that long.
- Ordinary security/operational logs
- 90 days; relevant incident extracts may be retained under a documented case hold. Expired sign-in verification material is eligible for removal 24 hours after expiry, expired sessions after seven days, and inactive rate-limit records 24 hours after their enforcement window.
- Closed privacy/support requests
- Two years, unless a related financial/legal matter requires longer preservation.
- Temporary diagnostic exports/recovery copies
- 30 days after their purpose is complete, or earlier where safe; redacted release evidence may be kept separately.
Backups expire through the relevant system's configured rolling retention. Selective immediate erasure from every backup is not available. We record completed erasure requests so that information is removed or minimized again before a restored copy resumes ordinary use. Provider and recipient copies require separate handling; we cannot promise deletion from someone else's inbox.
8. Access, correction, deletion and closure requests
Write to info@iep7.com. We aim to acknowledge within five business days and complete a request within 30 calendar days of receipt, subject to applicable shorter deadlines or lawful extensions that we explain. We verify identity proportionately through an existing account or email channel; we do not routinely require a government identity document or a child's identity document.
We review the account, Plans, bookings, financial references, analytics, policy evidence, mailbox/provider copies and any publication. Depending on the record, we may delete it, remove unnecessary details, restrict it for a required preservation purpose, or explain why it must remain. An active booking or unresolved payment must be reconciled; it is not erased merely to make account deletion appear complete. We will describe what was removed or retained and relevant backup/provider limits. Some privacy rights and complaint routes depend on applicable law; contact us to raise a concern or obtain further information.
9. Protection and changes
We use access controls and other technical and organizational safeguards appropriate to the service. No internet service can promise absolute security. Please report suspected exposure or unauthorized use promptly. We identify this notice by version and update it when practices change; material new optional purposes require the relevant new choice rather than reusing an old grant. We keep the policy text needed to interpret retained evidence.