Help Center

Privacy & Compliance at Canto – Where to Find What

  • Updated

    ~ minute read

This article maps where Canto's privacy and compliance documentation lives, what each resource covers, and who to contact with specific questions.


Canto's role

In the context of providing you with products and solutions, Canto acts as a data processor. Your organization, as the Canto customer, is the data controller. This means:

  • Your organization decides what data is stored in Canto, for what purpose, and for how long.
  • Canto processes that data only as instructed by your organization, under the terms of the Data Processing Agreement (DPA).
  • Canto does not use your data for its own purposes.

This applies to all Canto features, including AI features. Where Canto's AI analyzes or processes assets in your library, it does so on your request and as a processor acting on your behalf.


Where to find what

Canto's compliance documentation is spread across several destinations depending on the audience and level of detail required.

Resource Where to find it What it covers
Trust Center trust.canto.com Security certifications (SOC 2 Type 2, ISO 27001, HIPAA), downloadable compliance documents (Security Whitepaper, CAIQ, HECVAT Lite, Data Flow Diagram), sub-processor list, and AI security documentation. Start here for vendor security reviews and procurement questionnaires.
Privacy Policy canto.com/privacy-policy Which types of personal data Canto processes, for which purposes and in which scope. Applies to all processing of personal data carried out by Canto, including on the marketing website and external online presences such as social media profiles.
AI Policy canto.com/legal/cantoai How Canto's AI features handle customer data: the no-training commitment, data integrity principles, third-party AI sub-processor standards, acceptable use requirements, and EU AI Act compliance approach.
Cookies and Similar Tracking Technologies Policy canto.com/cookie-policy/ What cookies and similar tracking technologies Canto places on your device when you visit canto.com, why they are used, and how to control them. This does not apply to Canto Platform.
Security page canto.com/features/security Overview of Canto's security architecture, hosting regions, certifications, and access controls. A good starting point for a general security overview.
Help Center — Cookie Usage by Canto support.canto.com Overview of the cookies set in the Canto Portal environment.
Help Center — Privacy & AI This section Practical, customer-facing guidance: GDPR user rights and admin actions, HIPAA, data residency, how to request compliance documents, AI features and privacy.

Documents available on request

The following documents are available through the Trust Center at trust.canto.com. Some are available after signing an NDA.

  • SOC 2 Type 2 report
  • ISO 27001 certificate
  • HIPAA compliance report
  • Security Whitepaper
  • CAIQ (Consensus Assessment Initiative Questionnaire)
  • HECVAT Lite
  • Data Flow Diagram and Network Diagram

To request access, visit trust.canto.com and use the document request function.


Who to contact

The right contact depends on your question:

  • General privacy and data subject requests: privacy@canto.com
  • Questions to the DPO:
    Rechtsanwalt Ulf Neumann
    Geprüfter Datenschutzbeauftragter
    Lederstraße 134
    D - 72764 Reutlingen
    Fon: +49-(0)7121-347654-0
    Fax: +49-(0)7121-347654-9
    Email: info@neumann.law
  • Security incidents and vulnerability disclosure: security@canto.com
  • Compliance documents and vendor security reviews: trust.canto.com
  • DPA: Contact your account manager (existing customers) or your dedicated sales representative.
  • Product and feature questions: Submit a request via the Help Center.

Please note:

If your organization has a dedicated Account Manager, they can direct you to the correct contact or document for specific compliance requirements.


Frequently asked questions

Does Canto have a Data Processing Agreement (DPA)?

Yes. Canto's DPA is available on request from your account manager or sales representative.

Is Canto GDPR compliant?

Yes. Canto acts as a data processor and processes customer data in accordance with GDPR requirements. Relevant documentation — including the DPA, Privacy Policy, and sub-processor list — is available through the Trust Center and Privacy Policy pages linked above. For practical guidance on exercising data subject rights within Canto, see the article GDPR in Canto.

Does Canto use my content to train its AI?

No. Canto does not use customer assets or content to train its AI models. Analysis performed by Canto's AI features is processed only for your organization's benefit. For full details, see the AI Policy and the How Canto's AI Works article.

Where can I find Canto's sub-processor list?

The current sub-processor list is maintained in the Trust Center at trust.canto.com. Canto notifies customers of sub-processor changes in accordance with the DPA.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request