mode40 Privacy Policy
Effective Date: August 3, 2026
Last Revised: August 3, 2026
mode40 Ltd. (“mode40”, “we”, “us”, or “our”) is a Canadian technology company headquartered in Manitoba. We build and operate software-as-a-service applications for enterprise manufacturers and, where applicable, K-12 education customers. Our products include manufacturing execution and analytics platforms (including MAST / the Singularity platform family), related AI assistants, and education products such as Lila AI (School Coach).
This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you:
- visit our websites (including mode40.com and related product sites) (the “Sites”);
- communicate with us by email, phone, or form;
- use our cloud software services under a customer agreement (the “Services”).
It is inspired in structure by common industrial SaaS privacy notices (including the public Fuuz policy you shared), but the substance is written for mode40: Canadian company, AWS-hosted production environment (default Canada Central), B2B customer relationships, and Privacy Trust Services Category commitments in our SOC 2 Type 1 service description draft.
By using the Sites or Services, or by submitting information to us, you acknowledge this Privacy Policy. If you do not agree, do not use the Sites or Services.
1. Who this policy covers
1.1 Business customers and prospects (primary)
mode40 is primarily a business-to-business (B2B) provider. Most information we handle is business contact information and customer operational data provided under a SaaS or services agreement.
When you act as an employee, contractor, or representative of a company, partnership, nonprofit, or public body, we process your business contact details in that capacity.
1.2 Website visitors
If you browse our Sites without creating an account, we may still collect limited technical information as described below.
1.3 End users of customer tenants
For manufacturing and enterprise products, end users are typically employees or contractors of our customer. The customer is the controller (or equivalent) of operational and workforce data loaded into the tenant. mode40 processes that data as a service provider / processor under the customer agreement.
1.4 Education products (Lila AI / School Coach)
Where we provide education products that process personal information of students or school staff:
- the school or school division is responsible for any consent required under applicable youth-privacy or education law before providing student information to mode40;
- parent/student access, correction, and deletion requests should be routed through the school’s designated contact, who then instructs mode40;
- mode40 includes Privacy commitments in its SOC 2 Trust Services scope because of this processing.
2. Information we collect
2.1 Information you provide
We may collect information you submit when you:
- request a demo, quote, or white paper;
- create or administer a user account;
- email, call, or message us;
- participate in support, onboarding, or professional services;
- apply for a job or partner program.
Examples:
| Category | Examples |
| Identity and contact | Name, business email, phone, job title, company, mailing address |
| Account | Username, role, authentication identifiers (via SSO where configured) |
| Commercial | Contract details, billing contacts, purchase history |
| Support content | Tickets, attachments, call notes, meeting content you share with us |
| Marketing preferences | Opt-in/opt-out choices |
You may sometimes provide this as a company representative. Business contact data can still identify you as a natural person.
2.2 Information collected automatically
When you visit the Sites or use the Services, we and our service providers may automatically collect:
- device and browser type, OS, language;
- IP address and approximate location derived from IP;
- timestamps, pages viewed, referring/exit pages;
- cookie and similar technology identifiers;
- application telemetry (feature usage, performance, error logs) needed to operate and secure the Services.
We refer to this as Device and Usage Information.
Technologies may include:
- Cookies and local storage;
- Log files;
- Pixels / tags / beacons on marketing pages;
- first-party product analytics inside authenticated product sessions.
2.3 Information from customers (tenant data)
When a customer uses the Services, the customer (or its systems) may upload or generate:
- manufacturing, quality, inventory, planning, and related operational data;
- workforce identifiers the customer chooses to store (names, badge IDs, roles);
- configuration, integrations, and audit logs;
- for education products: student and staff personal information the school provides.
mode40 does not decide what customer operational data to collect inside a tenant beyond what the product requires to function. That is directed by the customer.
2.4 Information from third parties
We may receive limited information from:
- identity providers the customer configures (SSO / OIDC);
- cloud infrastructure and security vendors (e.g. AWS telemetry);
- CRM, email, and marketing tools (e.g. form fills, campaign engagement);
- partners or referral sources, where permitted.
We do not currently require you to log in with consumer social networks to use our core industrial Services.
2.5 What we mean by “personal information”
In this policy, personal information means information about an identifiable individual, and includes contact data, Device and Usage Information when linked to a person, and any personal data inside customer tenant content.
It does not include information that has been de-identified or aggregated so it can no longer reasonably identify a person.
3. How we use personal information
We use personal information to:
- Provide and support the Services under customer contracts (hosting, authentication, features, support, updates).
- Respond to demos, sales, and inquiries.
- Secure the Sites and Services (monitoring, fraud/abuse prevention, incident detection and response).
- Operate, maintain, and improve product reliability, performance, and usability.
- Communicate service notices (security notices, material product or terms changes, transactional messages).
- Send marketing about mode40 products and events, where permitted. You can opt out of marketing emails at any time.
- Meet legal obligations and enforce agreements.
- Business operations such as billing, accounting, audits (including SOC), and corporate transactions.
3.1 Privacy commitment (education / personal information on behalf of schools)
For personal information processed on behalf of school customers, mode40:
- collects only what is needed for the agreed Services;
- uses it only for agreed purposes;
- retains it only as long as required for those purposes or law;
- honours access and deletion instructions routed by the school.
3.2 AI and model use
mode40 AI features are model-agnostic. Depending on the customer deployment:
- inference may run in customer-approved managed services;
- open-weight models may run inside mode40’s AWS boundary;
- or models may run in the customer’s own environment.
Customer content is not used to train public foundation models of third-party providers unless a customer has expressly agreed otherwise in writing. Deployment-specific model hosting is recorded under vendor management for that customer.
3.3 Legal bases (where GDPR/UK GDPR applies)
Where EU/UK law applies and mode40 is a controller, we rely on one or more of:
- Contract (Art. 6(1)(b)) – to provide requested Services or pre-contract steps;
- Legitimate interests (Art. 6(1)(f)) – security, product improvement, B2B marketing to corporate contacts, limited analytics, balanced against your rights;
- Consent (Art. 6(1)(a)) – where required (e.g. certain cookies or optional marketing);
- Legal obligation (Art. 6(1)(c)).
Where mode40 is a processor, the customer’s legal bases govern the underlying processing; our processing is documented in the customer agreement / DPA.
4. How we share personal information
We do not sell personal information for money.
We may share personal information with:
| Recipient | Why |
| mode40 personnel | Deliver Services, support, security, and operations, on a need-to-know basis |
| Subprocessors / service providers | Cloud hosting (AWS), email, CRM, support, analytics, security tooling – under contract and confidentiality |
| Professional advisers | Lawyers, auditors, insurers, as needed |
| Corporate transaction parties | Merger, acquisition, financing, or sale of assets, with appropriate protections |
| Authorities | When required by law, legal process, or to protect rights, safety, and security |
| Customer-directed parties | Integrations the customer enables; the customer’s own admins and users |
Service providers are not authorized to use personal information for their own unrelated promotional purposes.
4.1 International transfers and residency
- Default production hosting region is AWS Canada Central (ca-central-1).
- Customer-chosen regions may be used where the contract requires it.
- We do not move, back up, or replicate customer production data across borders unless the customer configuration or agreement provides for it.
- Some corporate tools (email, collaboration, support) may process business contact data in other regions. We take steps designed to protect that information consistent with this policy and applicable law.
If you access the Services from outside Canada, you understand that your information may be processed in Canada and in other locations of our subprocessors as configured for your deployment.
5. Cookies and similar technologies
We use cookies and similar technologies to:
- keep the Sites secure and working;
- remember preferences;
- understand Site traffic and campaign performance;
- (where used) support advertising measurement on marketing pages.
You can control cookies through browser settings. Blocking some cookies may affect Site features. Where required by law, we will present cookie choices on the Site.
Do Not Track: industry standards for DNT are not uniform. The Sites may not respond to every browser DNT signal. You can still use cookie controls and marketing opt-outs described here.
6. Marketing communications (CASL / CAN-SPAM)
We may send marketing emails to business contacts about mode40 products, events, and updates where permitted by law (including Canada’s Anti-Spam Legislation).
You may opt out of marketing emails by:
- using the unsubscribe link in the message; or
- contacting us at the address below with “Opt-Out” in the subject line.
We will still send non-marketing service messages (security, billing, product notices tied to an active account) as needed.
7. Data retention
We retain personal information only as long as reasonably needed for the purposes in this policy, including:
- delivering the Services and support;
- legal, accounting, and audit requirements (including security evidence);
- dispute resolution and enforcement of agreements;
- backups and disaster recovery for a limited period.
Customer tenant data retention and deletion at contract end are governed by the customer agreement. Upon verified customer request at termination, we will delete or return customer personal data from active systems within the contractual timeline, except where retention is required by law or for legitimate security/audit archives.
Usage and security logs are generally kept for shorter operational windows unless needed longer for security or legal reasons.
8. Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including:
- encryption in transit (TLS 1.2+) and at rest (e.g. AWS KMS-managed keys for confidential data);
- identity and access controls, including workforce access via SSO / IAM patterns described in our security documentation;
- logging and monitoring (e.g. CloudTrail, CloudWatch, alerting);
- least-privilege access and change management discipline.
No method of transmission or storage is perfectly secure. We cannot guarantee absolute security, but we design controls to reduce risk and to detect and respond to incidents. Security incidents affecting customer data are notified within contractual and legal timeframes.
9. Your choices and rights
9.1 All users
Subject to law and verification, you may request to:
- access personal information we hold about you as a controller;
- correct inaccurate information;
- delete information where appropriate;
- object to or restrict certain processing;
- withdraw consent where processing is consent-based;
- opt out of marketing.
Email privacy@mode40.com or info@mode40.com (subject: Privacy Request).
9.2 Customer end users
If you use mode40 only as an end user of a customer tenant, contact your organization first. They control most tenant data. We will support the customer in responding to requests as required by the agreement and law.
9.3 Education / student data
Parents and students should contact the school. Schools should send validated instructions to mode40 through their designated contact.
9.4 EU/UK rights (where applicable)
If GDPR/UK GDPR applies and mode40 is controller, you may also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. We may need to verify identity before fulfilling a request.
9.5 California / other US state rights (where applicable)
If you are a resident of a US state with consumer privacy laws (e.g. California), and those laws apply to our processing of your personal information, you may have rights to know, delete, correct, and opt out of certain sharing. mode40 does not sell personal information as that term is commonly defined in those laws. Some B2B and employment-related data may be limited or exempt under those statutes. Submit requests to the contact below; we will verify and respond as required.
9.6 Canada (PIPEDA and provincial laws)
mode40 handles personal information in accordance with applicable Canadian private-sector privacy law, including PIPEDA principles of accountability, limiting collection, safeguarding, and individual access, as applicable to our role (controller or service provider).
10. Children
Our industrial Sites and manufacturing Services are not directed to children under 13 (or 16 where a higher digital-consent age applies).
Education products may process student information only as instructed by the school customer, who is responsible for notices and consents required by law. We do not knowingly collect student personal information directly from children for mode40 marketing.
If you believe we have collected a child’s information inappropriately, contact us and we will take appropriate steps to delete it.
11. Third-party sites and services
The Sites or Services may link to third-party websites, integrations, or services. Their privacy practices are their own. Review their policies before providing information. This Privacy Policy does not cover third-party services except as they process data on our behalf as subprocessors.
12. Complementary customer responsibilities
Customers should:
- manage their own user lifecycle and access rights;
- configure SSO and strong authentication for their users where available;
- review access and activity information mode40 makes available;
- notify mode40 promptly of suspected credential compromise;
- for school customers: obtain required consents and route data-subject requests through the school.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last Revised” date will change when we do. Material changes will be posted on the Site and, where appropriate, communicated to customers or users. Continued use of the Sites or Services after an update means you accept the revised policy, except where applicable law requires express consent.
14. Contact us
Privacy requests and questions
- Email: privacy@mode40.com (or info@mode40.com if privacy@ is not yet provisioned)
- Web: https://www.mode40.com
- Attn: Privacy / VP IT & Security
mode40 Ltd.
Manitoba, Canada
For SOC 2 and security documentation requests, customers may also use their normal account or security contact channel.