mode40 Privacy Policy 

Effective Date: August 3, 2026
Last Revised: August 3, 2026 

mode40 Ltd. (“mode40”, “we”, “us”, or “our”) is a Canadian technology company headquartered in Manitoba. We build and operate software-as-a-service applications for enterprise manufacturers and, where applicable, K-12 education customers. Our products include manufacturing execution and analytics platforms (including MAST / the Singularity platform family), related AI assistants, and education products such as Lila AI (School Coach). 

This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information when you: 

  • visit our websites (including mode40.com and related product sites) (the “Sites”); 
  • communicate with us by email, phone, or form; 
  • use our cloud software services under a customer agreement (the “Services”). 

It is inspired in structure by common industrial SaaS privacy notices (including the public Fuuz policy you shared), but the substance is written for mode40: Canadian company, AWS-hosted production environment (default Canada Central), B2B customer relationships, and Privacy Trust Services Category commitments in our SOC 2 Type 1 service description draft. 

By using the Sites or Services, or by submitting information to us, you acknowledge this Privacy Policy. If you do not agree, do not use the Sites or Services. 

 

1. Who this policy covers 

1.1 Business customers and prospects (primary) 

mode40 is primarily a business-to-business (B2B) provider. Most information we handle is business contact information and customer operational data provided under a SaaS or services agreement. 

When you act as an employee, contractor, or representative of a company, partnership, nonprofit, or public body, we process your business contact details in that capacity. 

1.2 Website visitors 

If you browse our Sites without creating an account, we may still collect limited technical information as described below. 

1.3 End users of customer tenants 

For manufacturing and enterprise products, end users are typically employees or contractors of our customer. The customer is the controller (or equivalent) of operational and workforce data loaded into the tenant. mode40 processes that data as a service provider / processor under the customer agreement. 

1.4 Education products (Lila AI / School Coach) 

Where we provide education products that process personal information of students or school staff: 

  • the school or school division is responsible for any consent required under applicable youth-privacy or education law before providing student information to mode40; 
  • parent/student access, correction, and deletion requests should be routed through the school’s designated contact, who then instructs mode40; 
  • mode40 includes Privacy commitments in its SOC 2 Trust Services scope because of this processing. 

 

2. Information we collect 

2.1 Information you provide 

We may collect information you submit when you: 

  • request a demo, quote, or white paper; 
  • create or administer a user account; 
  • email, call, or message us; 
  • participate in support, onboarding, or professional services; 
  • apply for a job or partner program. 

Examples: 

Category  Examples 
Identity and contact  Name, business email, phone, job title, company, mailing address 
Account  Username, role, authentication identifiers (via SSO where configured) 
Commercial  Contract details, billing contacts, purchase history 
Support content  Tickets, attachments, call notes, meeting content you share with us 
Marketing preferences  Opt-in/opt-out choices 

You may sometimes provide this as a company representative. Business contact data can still identify you as a natural person. 

2.2 Information collected automatically 

When you visit the Sites or use the Services, we and our service providers may automatically collect: 

  • device and browser type, OS, language; 
  • IP address and approximate location derived from IP; 
  • timestamps, pages viewed, referring/exit pages; 
  • cookie and similar technology identifiers; 
  • application telemetry (feature usage, performance, error logs) needed to operate and secure the Services. 

We refer to this as Device and Usage Information. 

Technologies may include: 

  • Cookies and local storage; 
  • Log files; 
  • Pixels / tags / beacons on marketing pages; 
  • first-party product analytics inside authenticated product sessions. 

2.3 Information from customers (tenant data) 

When a customer uses the Services, the customer (or its systems) may upload or generate: 

  • manufacturing, quality, inventory, planning, and related operational data; 
  • workforce identifiers the customer chooses to store (names, badge IDs, roles); 
  • configuration, integrations, and audit logs; 
  • for education products: student and staff personal information the school provides. 

mode40 does not decide what customer operational data to collect inside a tenant beyond what the product requires to function. That is directed by the customer. 

2.4 Information from third parties 

We may receive limited information from: 

  • identity providers the customer configures (SSO / OIDC); 
  • cloud infrastructure and security vendors (e.g. AWS telemetry); 
  • CRM, email, and marketing tools (e.g. form fills, campaign engagement); 
  • partners or referral sources, where permitted. 

We do not currently require you to log in with consumer social networks to use our core industrial Services. 

2.5 What we mean by “personal information” 

In this policy, personal information means information about an identifiable individual, and includes contact data, Device and Usage Information when linked to a person, and any personal data inside customer tenant content. 

It does not include information that has been de-identified or aggregated so it can no longer reasonably identify a person. 

 

3. How we use personal information 

We use personal information to: 

  1. Provide and support the Services under customer contracts (hosting, authentication, features, support, updates). 
  1. Respond to demos, sales, and inquiries. 
  1. Secure the Sites and Services (monitoring, fraud/abuse prevention, incident detection and response). 
  1. Operate, maintain, and improve product reliability, performance, and usability. 
  1. Communicate service notices (security notices, material product or terms changes, transactional messages). 
  1. Send marketing about mode40 products and events, where permitted. You can opt out of marketing emails at any time. 
  1. Meet legal obligations and enforce agreements. 
  1. Business operations such as billing, accounting, audits (including SOC), and corporate transactions. 

3.1 Privacy commitment (education / personal information on behalf of schools) 

For personal information processed on behalf of school customers, mode40: 

  • collects only what is needed for the agreed Services; 
  • uses it only for agreed purposes; 
  • retains it only as long as required for those purposes or law; 
  • honours access and deletion instructions routed by the school. 

3.2 AI and model use 

mode40 AI features are model-agnostic. Depending on the customer deployment: 

  • inference may run in customer-approved managed services; 
  • open-weight models may run inside mode40’s AWS boundary; 
  • or models may run in the customer’s own environment. 

Customer content is not used to train public foundation models of third-party providers unless a customer has expressly agreed otherwise in writing. Deployment-specific model hosting is recorded under vendor management for that customer. 

3.3 Legal bases (where GDPR/UK GDPR applies) 

Where EU/UK law applies and mode40 is a controller, we rely on one or more of: 

  • Contract (Art. 6(1)(b)) – to provide requested Services or pre-contract steps; 
  • Legitimate interests (Art. 6(1)(f)) – security, product improvement, B2B marketing to corporate contacts, limited analytics, balanced against your rights; 
  • Consent (Art. 6(1)(a)) – where required (e.g. certain cookies or optional marketing); 
  • Legal obligation (Art. 6(1)(c)). 

Where mode40 is a processor, the customer’s legal bases govern the underlying processing; our processing is documented in the customer agreement / DPA. 

 

4. How we share personal information 

We do not sell personal information for money. 

We may share personal information with: 

Recipient  Why 
mode40 personnel  Deliver Services, support, security, and operations, on a need-to-know basis 
Subprocessors / service providers  Cloud hosting (AWS), email, CRM, support, analytics, security tooling – under contract and confidentiality 
Professional advisers  Lawyers, auditors, insurers, as needed 
Corporate transaction parties  Merger, acquisition, financing, or sale of assets, with appropriate protections 
Authorities  When required by law, legal process, or to protect rights, safety, and security 
Customer-directed parties  Integrations the customer enables; the customer’s own admins and users 

Service providers are not authorized to use personal information for their own unrelated promotional purposes. 

4.1 International transfers and residency 

  • Default production hosting region is AWS Canada Central (ca-central-1). 
  • Customer-chosen regions may be used where the contract requires it. 
  • We do not move, back up, or replicate customer production data across borders unless the customer configuration or agreement provides for it. 
  • Some corporate tools (email, collaboration, support) may process business contact data in other regions. We take steps designed to protect that information consistent with this policy and applicable law. 

If you access the Services from outside Canada, you understand that your information may be processed in Canada and in other locations of our subprocessors as configured for your deployment. 

 

5. Cookies and similar technologies 

We use cookies and similar technologies to: 

  • keep the Sites secure and working; 
  • remember preferences; 
  • understand Site traffic and campaign performance; 
  • (where used) support advertising measurement on marketing pages. 

You can control cookies through browser settings. Blocking some cookies may affect Site features. Where required by law, we will present cookie choices on the Site. 

Do Not Track: industry standards for DNT are not uniform. The Sites may not respond to every browser DNT signal. You can still use cookie controls and marketing opt-outs described here. 

 

6. Marketing communications (CASL / CAN-SPAM) 

We may send marketing emails to business contacts about mode40 products, events, and updates where permitted by law (including Canada’s Anti-Spam Legislation). 

You may opt out of marketing emails by: 

  • using the unsubscribe link in the message; or 
  • contacting us at the address below with “Opt-Out” in the subject line. 

We will still send non-marketing service messages (security, billing, product notices tied to an active account) as needed. 

 

7. Data retention 

We retain personal information only as long as reasonably needed for the purposes in this policy, including: 

  • delivering the Services and support; 
  • legal, accounting, and audit requirements (including security evidence); 
  • dispute resolution and enforcement of agreements; 
  • backups and disaster recovery for a limited period. 

Customer tenant data retention and deletion at contract end are governed by the customer agreement. Upon verified customer request at termination, we will delete or return customer personal data from active systems within the contractual timeline, except where retention is required by law or for legitimate security/audit archives. 

Usage and security logs are generally kept for shorter operational windows unless needed longer for security or legal reasons. 

 

8. Security 

We implement administrative, technical, and physical safeguards designed to protect personal information, including: 

  • encryption in transit (TLS 1.2+) and at rest (e.g. AWS KMS-managed keys for confidential data); 
  • identity and access controls, including workforce access via SSO / IAM patterns described in our security documentation; 
  • logging and monitoring (e.g. CloudTrail, CloudWatch, alerting); 
  • least-privilege access and change management discipline. 

No method of transmission or storage is perfectly secure. We cannot guarantee absolute security, but we design controls to reduce risk and to detect and respond to incidents. Security incidents affecting customer data are notified within contractual and legal timeframes. 

 

9. Your choices and rights 

9.1 All users 

Subject to law and verification, you may request to: 

  • access personal information we hold about you as a controller; 
  • correct inaccurate information; 
  • delete information where appropriate; 
  • object to or restrict certain processing; 
  • withdraw consent where processing is consent-based; 
  • opt out of marketing. 

Email privacy@mode40.com or info@mode40.com (subject: Privacy Request). 

9.2 Customer end users 

If you use mode40 only as an end user of a customer tenant, contact your organization first. They control most tenant data. We will support the customer in responding to requests as required by the agreement and law. 

9.3 Education / student data 

Parents and students should contact the school. Schools should send validated instructions to mode40 through their designated contact. 

9.4 EU/UK rights (where applicable) 

If GDPR/UK GDPR applies and mode40 is controller, you may also have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. We may need to verify identity before fulfilling a request. 

9.5 California / other US state rights (where applicable) 

If you are a resident of a US state with consumer privacy laws (e.g. California), and those laws apply to our processing of your personal information, you may have rights to know, delete, correct, and opt out of certain sharing. mode40 does not sell personal information as that term is commonly defined in those laws. Some B2B and employment-related data may be limited or exempt under those statutes. Submit requests to the contact below; we will verify and respond as required. 

9.6 Canada (PIPEDA and provincial laws) 

mode40 handles personal information in accordance with applicable Canadian private-sector privacy law, including PIPEDA principles of accountability, limiting collection, safeguarding, and individual access, as applicable to our role (controller or service provider). 

 

10. Children 

Our industrial Sites and manufacturing Services are not directed to children under 13 (or 16 where a higher digital-consent age applies). 

Education products may process student information only as instructed by the school customer, who is responsible for notices and consents required by law. We do not knowingly collect student personal information directly from children for mode40 marketing. 

If you believe we have collected a child’s information inappropriately, contact us and we will take appropriate steps to delete it. 

 

11. Third-party sites and services 

The Sites or Services may link to third-party websites, integrations, or services. Their privacy practices are their own. Review their policies before providing information. This Privacy Policy does not cover third-party services except as they process data on our behalf as subprocessors. 

 

12. Complementary customer responsibilities 

Customers should: 

  • manage their own user lifecycle and access rights; 
  • configure SSO and strong authentication for their users where available; 
  • review access and activity information mode40 makes available; 
  • notify mode40 promptly of suspected credential compromise; 
  • for school customers: obtain required consents and route data-subject requests through the school. 

 

13. Changes to this policy 

We may update this Privacy Policy from time to time. The “Last Revised” date will change when we do. Material changes will be posted on the Site and, where appropriate, communicated to customers or users. Continued use of the Sites or Services after an update means you accept the revised policy, except where applicable law requires express consent. 

 

14. Contact us 

Privacy requests and questions 

  • Email: privacy@mode40.com (or info@mode40.com if privacy@ is not yet provisioned) 
  • Web: https://www.mode40.com 
  • Attn: Privacy / VP IT & Security
    mode40 Ltd.
    Manitoba, Canada 

For SOC 2 and security documentation requests, customers may also use their normal account or security contact channel.