This article maps where Canto's privacy and compliance documentation lives, what each resource covers, and who to contact with specific questions.
Canto's role
In the context of providing you with products and solutions, Canto acts as a data processor. Your organization, as the Canto customer, is the data controller. This means:
- Your organization decides what data is stored in Canto, for what purpose, and for how long.
- Canto processes that data only as instructed by your organization, under the terms of the Data Processing Agreement (DPA).
- Canto does not use your data for its own purposes.
This applies to all Canto features, including AI features. Where Canto's AI analyzes or processes assets in your library, it does so on your request and as a processor acting on your behalf.
Where to find what
Canto's compliance documentation is spread across several destinations depending on the audience and level of detail required.
| Resource | Where to find it | What it covers |
|---|---|---|
| Trust Center | trust.canto.com | Security certifications (SOC 2 Type 2, ISO 27001, HIPAA), downloadable compliance documents (Security Whitepaper, CAIQ, HECVAT Lite, Data Flow Diagram), sub-processor list, and AI security documentation. Start here for vendor security reviews and procurement questionnaires. |
| Privacy Policy | canto.com/privacy-policy | Which types of personal data Canto processes, for which purposes and in which scope. Applies to all processing of personal data carried out by Canto, including on the marketing website and external online presences such as social media profiles. |
| AI Policy | canto.com/legal/cantoai | How Canto's AI features handle customer data: the no-training commitment, data integrity principles, third-party AI sub-processor standards, acceptable use requirements, and EU AI Act compliance approach. |
| Cookies and Similar Tracking Technologies Policy | canto.com/cookie-policy/ | What cookies and similar tracking technologies Canto places on your device when you visit canto.com, why they are used, and how to control them. This does not apply to Canto Platform. |
| Security page | canto.com/features/security | Overview of Canto's security architecture, hosting regions, certifications, and access controls. A good starting point for a general security overview. |
| Help Center — Cookie Usage by Canto | support.canto.com | Overview of the cookies set in the Canto Portal environment. |
| Help Center — Privacy & AI | This section | Practical, customer-facing guidance: GDPR user rights and admin actions, HIPAA, data residency, how to request compliance documents, AI features and privacy. |
Documents available on request
The following documents are available through the Trust Center at trust.canto.com. Some are available after signing an NDA.
- SOC 2 Type 2 report
- ISO 27001 certificate
- HIPAA compliance report
- Security Whitepaper
- CAIQ (Consensus Assessment Initiative Questionnaire)
- HECVAT Lite
- Data Flow Diagram and Network Diagram
To request access, visit trust.canto.com and use the document request function.
Who to contact
The right contact depends on your question:
- General privacy and data subject requests: privacy@canto.com
-
Questions to the DPO:
Rechtsanwalt Ulf Neumann
Geprüfter Datenschutzbeauftragter
Lederstraße 134
D - 72764 Reutlingen
Fon: +49-(0)7121-347654-0
Fax: +49-(0)7121-347654-9
Email: info@neumann.law - Security incidents and vulnerability disclosure: security@canto.com
- Compliance documents and vendor security reviews: trust.canto.com
- DPA: Contact your account manager (existing customers) or your dedicated sales representative.
- Product and feature questions: Submit a request via the Help Center.
|
Please note: If your organization has a dedicated Account Manager, they can direct you to the correct contact or document for specific compliance requirements. |
Frequently asked questions
Does Canto have a Data Processing Agreement (DPA)?
Yes. Canto's DPA is available on request from your account manager or sales representative.
Is Canto GDPR compliant?
Yes. Canto acts as a data processor and processes customer data in accordance with GDPR requirements. Relevant documentation — including the DPA, Privacy Policy, and sub-processor list — is available through the Trust Center and Privacy Policy pages linked above. For practical guidance on exercising data subject rights within Canto, see the article GDPR in Canto.
Does Canto use my content to train its AI?
No. Canto does not use customer assets or content to train its AI models. Analysis performed by Canto's AI features is processed only for your organization's benefit. For full details, see the AI Policy and the How Canto's AI Works article.
Where can I find Canto's sub-processor list?
The current sub-processor list is maintained in the Trust Center at trust.canto.com. Canto notifies customers of sub-processor changes in accordance with the DPA.