Privacy Policy
Last updated 5 August 2026. This policy explains what Modern Technologies, Inc. collects when you use Cando, how we use it, and the choices you have.
1. Who we are
Cando is operated by Modern Technologies, Inc., a Delaware corporation. When this policy says “we”, “us” or “Cando”, that is who it means.
For your account information and the data we collect on our website, we are the data controller. For the content your business runs through Cando - your files, your customers’ details, the data in your connected tools - we process it on your instructions, and your business remains the controller of it. If your business needs a data processing agreement with us, email privacy@cando.build.
This policy covers the Cando platform and our website. It sits alongside our terms of service, and together they describe the agreement between us.
2. What we collect
When you sign up we collect account information - your name, email address, phone number and details about your business.
When you use Cando we collect the content you and your agents work with: the files you upload, the jobs you run, and the data that flows through the tools you connect.
We also collect usage data automatically - things like your IP address, browser and device type, the pages you visit and how long you spend on them, and diagnostic logs when something goes wrong.
Payment details are collected by our payment processor, not by us. We do not store card numbers on our servers.
3. How we use it
We use your information to run Cando: to execute the jobs your agents do, to keep your account working, to answer support requests and to bill you.
We also use it to keep the platform safe - detecting fraud and abuse - and to understand how Cando is used so we can improve it.
We will email you about the service, and occasionally about new features. You can opt out of marketing at any time; service emails like receipts and security notices will keep coming while you have an account.
Where the GDPR applies, our legal bases are: performing our contract with you for your account and content data, our legitimate interests for usage and security data, and your consent for marketing, which you can withdraw at any time.
4. AI and your data
We do not use your data to train AI models. Not your files, not your messages, not the jobs your agents run - nothing.
The AI providers we build on, such as OpenAI and Anthropic, are under agreements that stop them training on anything Cando sends them too.
Your agents only reach the tools you have connected, with the permissions you have granted, and their actions are recorded in an audit trail you can export.
5. Connected tools
When you connect a tool like Xero, MYOB, Gmail or WhatsApp, we access it only to do the jobs you have asked your agents to do. We request the narrowest permissions we can, and you can disconnect a tool at any time.
Data we receive through Google services is handled according to Google’s API policies, and we do not use it to develop, improve or train generalised AI or machine learning models.
8. Advisors
Your advisor only sees your data when you grant them access, and you can remove that access whenever you like.
Advisors are independent businesses, and they handle your information under their own legal obligations as well as their agreement with us.
9. Payments
Payments are processed by Stripe. Your card details go directly to them and are protected under the PCI-DSS standard; we do not see or store your card number.
10. Keeping and deleting data
We keep your information for as long as you use Cando, or as long as we need it for the purpose it was collected. What that means in practice depends on the amount, nature and sensitivity of the data, and on any legal obligations we have to keep it.
You can export your data or ask us to delete it at any time from your settings, or by emailing privacy@cando.build. We keep your data for 30 days after your account closes so you can still get a copy, then delete or de-identify your personal information within 90 days, except what the law requires us to keep - billing and tax records, for example. Deleted data also leaves our backups on their normal rotation cycle, within 35 days of deletion.
11. Security
Your data is encrypted in transit and at rest, access inside our team is limited to people who need it for their work, and two-factor authentication is required on our internal systems. We back up databases daily and test our defences regularly.
If a security incident affects your data, we will tell you promptly - what happened, what information was involved and what we are doing about it - and we will notify you and the relevant regulators within the timeframes the law requires, including under the Australian Notifiable Data Breaches scheme and the GDPR.
No method of transmission or storage is completely secure. We use strong, commercially reasonable protections, but we cannot promise absolute security - nobody honestly can.
12. Where your data lives
Cando runs on servers in the United States, so your information is processed there even if you are somewhere else.
When we move data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the EU Standard Contractual Clauses and equivalent safeguards.
13. Your rights
You can access, correct, export or delete your personal information, ask us to restrict or stop processing it, and withdraw consent you have given. Email privacy@cando.build and a person will handle it.
If you are in the EU or the UK, these are your GDPR rights, and you can also complain to your local data protection authority. If you are in California, the CCPA gives you the right to know what we collect, to ask us to delete it, and to not be discriminated against for asking - and we do not sell personal information in the first place.
If you are in Australia, you also have rights under the Privacy Act 1988, including access and correction, and you can complain to the OAIC if you think we have got something wrong.
14. Children
Cando is built for businesses and you must be 18 or over to use it. We do not knowingly collect information from children, and if we learn that we have, we will delete it.
15. Changes to this policy
We will update this policy as the platform grows. If we make a meaningful change we will email you and post a notice in the product before it takes effect. The date at the top shows the latest version.