How mode40 collects, uses, and protects personal information across this website, our communications, and the Singularity.
Effective date: September 24, 2026Last updated: September 24, 2026
This policy explains how mode40 ltd. (“mode40”, “we”, “us”) handles personal information: what we collect, why, who we share it with, where it is stored, how long we keep it, and the choices you have. We are a Canadian company incorporated under the Canada Business Corporations Act, with our head office in Steinbach, Manitoba. Our software, the Singularity, gives operators a single connected view of their data, decisions and operations. We also provide the consulting and services around it.
In short:
We wrote this policy in plain language on purpose. If any part is unclear, or you need it in another format, email privacy@mode40.com and we will help.
mode40 ltd. is responsible for personal information under its control, including information we hand to service providers. Our Privacy Officer is our Vice President, IT and Security, who is accountable for our compliance with this policy and with the privacy laws that apply to us, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for people in Quebec, the Act respecting the protection of personal information in the private sector. You can reach the Privacy Officer at privacy@mode40.com or at the address in Section 18.
This policy applies when you:
It does not govern the operational data our customers load into the Singularity. For that data, the customer decides what is collected and why, and we act as their service provider under a signed agreement. Section 10 explains how that works. If you use the Singularity through your employer, your employer’s own policies apply to that data, and questions about it should go to them.
It also does not cover our own employees and contractors, who are covered by our internal policies.
When you use the Site, our systems and the service providers named in Section 8 collect technical information: your IP address, browser and device type, operating system, language, the pages you view, how you arrived at the Site, the date and time of each visit, and approximate location derived from your IP address. Some of this is collected with cookies and similar technologies, described in Section 4. Most of it is collected only after you accept optional cookies.
We may receive business contact details from event organizers, partners who refer you to us, public professional sources such as company websites and LinkedIn, and business-contact data providers. If you interact with an email we send, our email platform records whether it was opened and which links were clicked. If you have accepted optional cookies, a visitor-identification service may tell us which organization a visit came from (Section 4).
We do not ask for, and ask you not to send us through the Site, sensitive information such as health information, government identification numbers, financial account details, or export-controlled technical data.
Cookies are small files a website stores in your browser. We and our service providers use them, along with similar technologies such as scripts and pixels, for the purposes below.
We ask before we set any optional cookie. Until you choose Accept in the notice shown on your first visit, Google Analytics, HubSpot tracking, and Apollo do not load. If you choose Decline, or close the notice without choosing, they stay off. We remember your choice for 12 months, and you can change it at any time with the “Cookie settings” link at the bottom of every page. Withdrawing your acceptance stops these tools from loading on your next page view; it does not delete information they already collected, which you can ask us to remove under Section 13.
You can also block or delete cookies in your browser settings, or use Google’s Analytics opt-out add-on. Blocking essential cookies may stop parts of the Site from working. The Site does not currently read Do Not Track or Global Privacy Control browser signals. Because optional tools are off until you accept them, ignoring or declining the notice gives you the same result those signals are designed to give.
We use personal information only for the purposes we have identified, or for purposes a reasonable person would consider appropriate in the circumstances. If we want to use it for a new purpose, we will tell you and, where required, ask for your consent.
We rely on your consent to collect, use, and share personal information, except where the law allows or requires otherwise. Consent may be express, for example when you tick a box to receive emails or choose Accept in our cookie notice, or implied, for example when you send us your business card and ask us to follow up. Where the law allows, we also collect and use the business contact information of people acting in a business capacity, such as a work email and job title, in order to communicate with them about their work.
You can withdraw your consent at any time, subject to legal or contractual limits, by contacting us or, for cookies, by using the “Cookie settings” link. If you withdraw consent, we may not be able to provide some things you have asked for.
We do not make decisions about you on the Site, or in our dealings with you, that are based solely on automated processing and that have legal or similarly significant effects for you. Our team may use AI-assisted tools to help draft, transcribe, and summarize our own work; a person is responsible for every decision about you. We do not sell or license personal information to anyone to train AI models. AI features inside the Singularity are governed by each customer’s agreement with us (Section 10).
We do not sell personal information for money, and we do not rent or trade our contact lists. Some laws define “sale” or “sharing” broadly enough to cover the analytics and visitor-identification tools described in Section 4. Where such a law applies, you can opt out by declining or withdrawing cookie consent. Beyond that, we share personal information only as follows.
We are based in Manitoba. Some members of our team work in the United States, and several of our service providers store or process information in the United States, so personal information we collect through the Site is routinely transferred outside your province and, if you are in Canada, outside Canada. In particular, HubSpot, Google, Apollo.io, and Microsoft process information in the United States, and Cloudflare routes Site traffic through its global network. When information is in another country, it is subject to that country’s laws and may be accessible to its courts, law enforcement, and national security authorities under those laws.
Before we send personal information outside Canada, we consider the sensitivity of the information, the purpose, and the protections the recipient provides, and we use contracts that require our providers to protect it. If you are in Quebec, this includes the assessment the law requires before personal information is communicated outside the province. You can ask us for more information about where your information is held by writing to privacy@mode40.com.
When an organization uses the Singularity, it controls the data it loads into the platform, including any personal information about its employees and contractors. mode40 processes that data on the customer’s behalf, only to provide and support the service and as set out in the customer’s agreement with us. In particular:
Security and governance describes how the platform protects customer data.
We keep personal information only as long as we need it for the purposes in this policy, or as long as the law requires. Where we have used personal information to make a decision about you, we keep it long enough for you to ask to see it. As a general guide:
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access limited to the people who need it, multi-factor authentication on our systems, and monitoring. No system is completely secure, so we cannot guarantee that information will never be accessed without authorization.
If a breach of our security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, along with any other regulator or organization the law requires. We keep a record of every breach of our security safeguards for at least 24 months, as the law requires, whether or not it has to be reported.
You can ask us:
Send requests to privacy@mode40.com. We may ask you to confirm your identity before we act, and we will respond within 30 days. If the law permits an extension and we need one, we will tell you before the 30 days end and explain why. Access is free of charge. If we cannot grant a request in full, for example because the law requires us to keep the information or it would reveal someone else’s personal information, we will explain why in writing and tell you how to challenge our decision. We will not treat you differently for exercising your rights.
We send commercial electronic messages in line with Canada’s Anti-Spam Legislation (CASL) and other applicable laws. We send them with your express consent, for example when you tick the box on our contact form, or where the law allows us to rely on implied consent, for example because you have an existing business relationship with us or you have published or given us your business email without saying you do not want unsolicited messages. We keep a record of the consent we rely on.
Every marketing email identifies mode40, includes our mailing address and a way to reach us, and includes an unsubscribe link. We process unsubscribe requests within 10 business days, and usually much sooner. You can also email privacy@mode40.com. We will still send messages you need about an active relationship, such as replies to your requests, meeting confirmations, or notices about an agreement.
The Site is for businesses and professionals. It is not directed to children, and we do not knowingly collect personal information from anyone under 16 through it. If you believe a child has given us personal information, contact us and we will delete it.
The Site links to websites and services we do not control, such as partner sites and LinkedIn. Their privacy practices are their own, and we encourage you to read their policies.
We may update this policy as our practices or the law change. We will post the updated policy on this page with a new “Last updated” date. If we make a significant change to how we use personal information, we will give more prominent notice on the Site and, where required, ask for your consent. Earlier versions are available on request.
Questions, requests, and complaints can be sent to our Privacy Officer:
Privacy Officer (Vice President, IT and Security)mode40 ltd.385 Loewen BlvdSteinbach, Manitoba R5G 0B3Canadaprivacy@mode40.com
We use cookies to understand how the site is used and to connect form submissions to earlier visits. No analytics or marketing cookies are set until you choose. Privacy Policy