MODUSTRA IQ FR

Privacy Policy

Last updated: September 17, 2026

1. Who we are

Logiciels Modustra IQ ("Modustra IQ," "we," "us," "our") is a corporation registered in Quebec, Canada (incorporated August 12, 2026). Our business registration number (NEQ) is 1182453887. We publish the website at modustraiq.com and operate the Modustra IQ application, a customer relationship and order management service for manufacturers and their sales teams. You can reach us at support@modustraiq.com or by phone at 514-240-9346.

2. What this policy covers

This policy explains what personal information we collect through our website, the application and the emails we send, why we collect it, who handles it, how long we keep it, and what your rights are. It is written to meet the Act respecting the protection of personal information in the private sector (Quebec), as amended by Law 25.

It applies to you whether you are visiting the website, registering a company, using the application as a member of a company, or receiving a file or a document that a company sent you through it.

Two roles are worth telling apart. For the information we collect about you in order to run the service (your account, your sign-ins, your bill, your support requests), we decide how it is used and we are responsible for it. For the information a company enters into the application about its own customers, contacts and business, that company decides how it is used, and we handle it on the company's instructions as its service provider. Section 8 says more about that.

3. The website: waitlist and contact form

If you submit your email address through the waitlist form on our website, we collect that address and, if you gave it, your first name. We use them to send a one-time confirmation request and to let you know about the launch of Modustra IQ and news about the product. This is optional, it is separate from opening an account, and you can unsubscribe with the link in any message or by writing to us. The list is held by Kit, in the United States.

If you write to us through the contact form on the website, we collect your name, your email address, your message and the page you wrote from. The message is delivered to our mailbox by Web3Forms and we use it only to answer you. Adding yourself to the mailing list from that form is a separate, unticked choice.

The website counts visits with Umami Analytics, which sets no cookies and does not follow visitors between websites or over time. It records the page address, the referring site, browser, operating system, device type and approximate location, aggregated and never attached to a person; your network address is held only as a daily hash in memory and never stored.

4. Opening an account

When you register a company, we collect the things the application cannot work without: your company name, your first name and, if you give it, your last name, your work email address, and the password you choose. The password is stored only as a hash, which cannot be turned back into the password. We also record the plan, the number of seats and the billing period you chose, the language you read the form in, and the fact that you accepted this policy and the terms of service: which version of each, in which language, when, and the network address and browser they were accepted from.

We use this information to create your company's own database, to make you its first administrator, to sign you in, to bill you, to send you the welcome and confirmation email, and to reach you about your account. All of it is necessary to open the account; there is no optional field.

5. Being invited to an account

An administrator of a company can invite you to join it. We then hold your name, your work email address, the role and any territories or extra permissions the administrator gave you, and the language you read the application in. The invitation is emailed as a link that works once and expires after a week. When you choose a password, it is stored as a hash like every other.

If you are removed from a company later, your sign-in ends but your name stays on the records you created, because a quote or an order still has to say who wrote it.

6. Signing in and security records

Each sign-in, and each failed attempt, is recorded with the network address it came from and the browser used. Failed attempts are counted for fifteen minutes so that a run of them can be refused, and are then discarded. Requests to reset a password are recorded with the same details, and the emailed link works once and expires after ten minutes.

The application keeps a security audit trail of the actions that matter: signing in, deleting records, downloading files, changing company settings and the like. Each entry records who acted, what they did, when, the network address and the browser. The trail cannot be edited or deleted by anybody, including us, which is what makes it evidence; it is removed only when the company's database is deleted.

7. Billing and payment

Billing is handled by Stripe. When you choose a paid plan, we create a customer record at Stripe with your email address and company name, and Stripe creates the subscription. Your card details are entered in a form that Stripe serves and go straight to Stripe; they never reach our servers, and we never see the full card number.

We hold the identifiers Stripe gives us for your customer record and subscription, the status of the subscription, when the current period ends, and copies of the notifications Stripe sends us about your subscription, which we keep as the record of what was billed and when. Stripe is in the United States and processes your information there.

8. Your company's records

The application exists to hold your company's business: its customers, contacts, leads, deals, quotes, orders, invoices, credit notes, returns, production work, inventory, uploaded drawings and its logo. Much of that is personal information about other people, such as the names, titles, email addresses and telephone numbers of the people your company sells to. Leads filed from the companion app can also carry the details read from a business card and, if the app sends one, a link to the picture of that card.

That information belongs to your company. Your company decides why it is collected and what is done with it, and is responsible for having the right to collect it. We hold it in a database of your company's own, we use it only to provide the service to your company, and we look at it only when your company asks us for help or when it is necessary to keep the service running securely. If you believe a company using Modustra IQ holds information about you, your request belongs to that company in the first instance; we will help them answer it.

9. Sharing files with people outside your company

A member of your company can send drawings and documents to somebody outside it by an emailed link. We then hold that person's name and email address, the note the sender wrote, the language the message was sent in, a hash of the password protecting the link, and a count of what was downloaded and when. The link expires on the date the sender set and can be withdrawn earlier.

10. Support requests

When you send a bug report or a suggestion from inside the application, we collect what you wrote, your email address, your role and plan, the page you were on, your language, your browser and the size of its window, and which build of the application you were running. We use this to reproduce and fix what you reported and, if you asked to hear back, to reply. Support requests are held in our internal systems and are kept after an account closes, because a report is still true after the reporter has gone.

Mail sent to support@modustraiq.com is read and answered in Microsoft 365.

11. Cookies

We show no advertising, and the application uses no analytics or tracking tools; the website's visit counting is described in section 3. The website itself sets no cookies. The application sets a cookie recording which language you read in, and a session cookie once you sign in. Two more are short-lived and set only while they are needed: one during a QuickBooks connection, to check that the answer from Intuit belongs to the request that started it, and one when you open a shared file link, so that you are not asked for the password on every file. The card form served by Stripe may set Stripe's own cookies for fraud prevention, which are governed by Stripe's privacy policy.

12. Our service providers and where your information goes

We rely on a small number of service providers to run Modustra IQ. Each holds only what its job needs, under a written agreement, and none may use your information for its own purposes.

Because these providers are outside Quebec, your personal information may be transferred to, and processed in, jurisdictions whose privacy laws differ from Quebec's. Before communicating information outside Quebec, we assess the sensitivity of the information, the purposes, the protections in place and the law of the destination, as the Act requires, and we rely on contractual terms that require each provider to protect it.

We do not sell, rent or trade personal information, and we do not share it with anyone for advertising.

13. Optional QuickBooks integration

If an administrator of your company chooses to connect QuickBooks Online, Modustra IQ exchanges information with Intuit to provide the accounting features the administrator chooses to use. Depending on how it is used, this can include customer details, products and taxes, invoices, credit notes, QuickBooks company identifiers, and the status of each synchronization.

Nothing is sent to or read from QuickBooks unless an administrator connects the integration. The administrator can disconnect it at any time under Settings. Disconnecting stops any further exchange but does not delete information already transferred to QuickBooks; that information remains in your company's QuickBooks account, subject to its settings and to Intuit's privacy practices. The credentials the connection uses are stored encrypted, and are revoked at Intuit when the integration is disconnected.

Intuit processes information outside Quebec and Canada. We assessed the privacy risks and contractual protections of this integration before offering it. For more, consult Intuit's privacy statement.

14. Optional AI insights (Google Gemini)

A member of your company who can work customers or leads can ask the application for an AI reading of a customer account or a lead. When they press the button, the application sends that record to Gemini, a service of Google LLC, and shows the reading it writes back. Nothing is sent unless somebody presses the button, and the application never sends anything to Google on its own.

What is sent is the record of the company, not of the people at it: the company's name, type, website, industry and location, the notes your team wrote about it, and its quotes and orders with their line descriptions and totals. For a lead, it also includes where the lead came from and how warm it is rated. The names, email addresses and telephone numbers of the people at that company are never sent; the model is told only how many contacts there are and their job titles. Your costs and margins are never sent.

The reading is stored with the record it describes, replaced when somebody asks for a fresh one, and deleted with the record. Each request is written to your company's security audit trail with the name of the person who asked.

Google processes this information in the United States and may keep what is sent for a limited time to enforce its policies. On the free plan for this service, which we may use while the feature is new, Google may also use what is sent to improve its products and may have people review it; on the paid plan it does not. Your company can simply not use the feature. For more, consult Google's Gemini API terms and privacy policy.

What the model writes is an aid to judgment, not a record of fact. It can be wrong about a company, and the screen says so. The application acts on nothing it writes, and no decision about a person is made from it automatically.

15. Who else can see your information

Within your company, what you can see is decided by the role and permissions an administrator gives you. Administrators see everything in the company's account; salespeople see their own book; production seats see the work and nothing of sales. Your name, email address and role are visible to the other members of your company.

Our own staff can reach your company's account through an internal administration tool, to provision it, to fix a problem you reported, to manage billing, and to act on a request from you. That access is limited to what the task needs.

We disclose personal information outside these cases only when the law requires it, for example in answer to a court order, or when it is necessary to protect the safety of a person or the security of the service.

16. How long we keep your information

We keep personal information only as long as its purpose lasts, and then destroy it or anonymize it, subject to the periods the law imposes on us. By category:

Where a record has to be kept beyond its purpose for legal reasons, it is kept for that reason alone and used for nothing else.

17. Your rights and how to exercise them

Under Quebec's private-sector privacy law, you may ask us to confirm whether we hold personal information about you and to see it; to correct information that is inaccurate, incomplete or ambiguous; to delete information whose collection was not permitted or whose purpose has passed; to receive the information you provided to us in a structured, commonly used technological format; and to withdraw your consent to a use that depends on it. You may also complain to us, and to the Commission d'accès à l'information du Québec, about how we handle your information.

To exercise any of these rights, write to our privacy officer at support@modustraiq.com. We will confirm your identity first, which for an account holder usually means writing from the address on the account. We answer within thirty days of receiving a request. Where we refuse a request in whole or in part, we say why, and which provision of the law allows it.

Withdrawing consent, or deleting information the service needs, may mean we can no longer provide the service to you. Some records must be kept after a deletion request for the periods in section 16; we tell you which.

If your request concerns information a company entered about you in its own account, we forward it to that company, which is responsible for answering, and we help them do so.

18. Confidentiality incidents

We keep a register of confidentiality incidents involving personal information. If an incident presents a risk of serious injury to the people concerned, we notify the Commission d'accès à l'information and the people affected promptly, take reasonable measures to reduce the harm, and record what happened and what was done.

19. How we protect your information

We use encrypted transmission (HTTPS) between your browser and our services, and between our services and our providers. Passwords are stored as salted hashes. Credentials for connected integrations are stored encrypted. Each company's data is held in a database of its own, separate from every other company on the platform, and every request is checked on the server against the role and company of the person making it. Sign-in and password reset requests are rate limited. Emailed links work once and expire. A security audit trail records the actions that matter and cannot be altered. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

20. Children

Modustra IQ is a business tool. It is not directed at anyone under the age of majority, and we do not knowingly collect personal information from minors.

21. Changes to this policy

Each version of this policy carries the date it took effect. When we change it in a way that matters, we email the administrators of every account before the change takes effect and, where the change concerns a new purpose or a new recipient, we ask for your acceptance again. Earlier versions are available on request.

22. Our privacy officer

Robert Hargrove, Founder, is the person in charge of the protection of personal information at Modustra IQ. They can be reached at support@modustraiq.com or 514-240-9346, or by mail at the address below.

23. Contact us

Logiciels Modustra IQ

280, chemin Philip-Toosey, Stoneham, QC, G3C 3B2

support@modustraiq.com, 514-240-9346

NEQ: 1182453887

← Back to home