Canto
canto.comCanto is an AI-powered digital asset management (DAM) platform serving brand, marketing, and creative teams — an enterprise SaaS tool with marketing/adtech characteristics. The consumer-facing Trust Center and GDPR-oriented privacy policy disclose a strong security posture (SOC 2, ISO 27001:2022, HIPAA, GDPR, TX-RAMP, EU AI Act) and a recently updated privacy policy (July 30, 2026). However, the publicly accessible consumer documents are largely silent on input/output data ownership, model-training use of customer assets, and retention of customer content — these are only addressed in the enterprise/support documentation. The privacy policy is heavily marketing/website-oriented and collects significant PII and tracking data. For professional users, enterprise-tier contractual protections (DPA, BAA, no-training commitments) materially improve the posture; review these before uploading sensitive or proprietary assets.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The consumer privacy policy does not clearly state who owns the content, files, and assets a customer uploads to the DAM; it describes content data as a processed data type but is silent on ownership. The policy notes it is the user's responsibility to secure their own data and that Canto may irretrievably delete stored data after contract termination, implying customer control but not explicitly affirming customer ownership.
Output Data Ownership
The consumer-facing privacy policy and Trust Center are silent on ownership of AI-generated outputs. The product is explicitly AI-first (AI-powered DAM, AI image editing), yet the consumer documents supplied do not address who owns generated content. This silence is a risk signal at the consumer tier; ownership is only clarified in the enterprise documentation.
Training Data Usage
The consumer privacy policy states Google Workspace APIs are not used to train generalized AI/ML models and describes using chat interactions to 'teach' chatbots, but it does not clearly state whether customer-uploaded DAM assets are used to train or improve Canto's AI products. For the AI-first product this silence at the consumer tier is a moderate risk; a clear no-training commitment appears only in the enterprise documentation.
Data Retention & Deletion
The consumer privacy policy describes retention for website/marketing data (e.g., 4 years for contractual data, up to 10 years for tax, up to 2 years for cookies/newsletter blocklists) and deletion of account data on termination, with GDPR data subject rights. However, it gives no concrete deletion SLA for customer DAM assets and leaves deletion of uploaded content largely to statutory/legal retention rules. Specific asset retention/deletion timelines (30-day Trash/backup) appear only in the enterprise documentation.
Third-Party Data Sharing
Canto discloses numerous sub-processors and third-party service providers (AWS, Pendo, Zendesk, Intercom/Fin, Google Gemini, HubSpot, Google Analytics, Hotjar, Facebook pixel, Cognism, Salesloft, etc.), many for marketing, analytics, and advertising purposes. Disclosure is reasonably thorough and sharing is tied to stated purposes with contractual safeguards (SCCs), but the breadth of marketing/adtech trackers (Facebook custom audiences, remarketing) extends beyond what the core DAM service strictly requires, warranting a moderate rating.
Opt-Out Rights
The privacy policy provides multiple explicit opt-out mechanisms: cookie objection/withdrawal of consent, newsletter unsubscribe, browser-based cookie deactivation, industry opt-out portals (aboutads.info, youronlinechoices), and service-specific opt-outs (Google Optimize, Hotjar). GDPR data subject rights including objection and withdrawal of consent are referenced throughout. These are meaningful, documented opt-out rights for the website/marketing data.
Compliance & Certifications
The Trust Center lists an unusually broad set of relevant frameworks with supporting documentation available on request: SOC 2 (with SOC 2 Type 2 Report), ISO/IEC 27001:2022 (certificate and report), HIPAA, GDPR, EU AI Act, PIPEDA, TX-RAMP, and VPAT. Several are backed by named third-party audit reports (SOC 2 Type 2, ISO 27001:2022 report) accessible via the Trust Center, which supports a GREEN rating for the universal baseline plus enterprise_saas frameworks.
Model Explainability & Auditability
The Trust Center references AI governance items (AI Security, AI Monitoring, AI Risk Management) and audit logging / event & audit log management product features, plus an EU AI Act assessment, indicating some enterprise auditability and AI oversight. However, the consumer documents provide no substantive detail on model behavior transparency or explainability, and the specifics sit behind access-gated documentation.
Security Practices & Breach History
Canto maintains a dedicated Trust Center disclosing a comprehensive security program: SSL/TLS in transit, encryption/disk encryption, access controls and least privilege, IDS/IPS, anti-DDoS, endpoint detection, incident response with forensic retainer, business continuity/DR testing, cyber insurance, and data breach notification processes. No breach incidents are disclosed in the supplied text. The depth of disclosed controls and audit reports supports a favorable rating.
Enterprise vs. Consumer Risk Delta
There is a material difference between the public/consumer documents and the enterprise agreements. The consumer privacy policy is silent on asset ownership, no-training commitments, and asset deletion SLAs, while the enterprise/support documentation explicitly provides a no-training commitment, customer ownership of outputs, 30-day retention/deletion rules, DPA, and BAA availability. Professional users should rely on enterprise contracts rather than the public policy for these protections.
Human Review of User Inputs
The consumer privacy policy indicates staff/support access to data (e.g., Zendesk support tickets, Intercom Copilot assisting human agents, chat content storage), and chat content is stored and may be used to improve services. It does not clearly state whether human staff review customer DAM asset uploads or AI prompts. The silence on review of core product inputs at the consumer tier warrants a moderate rating.
Regulatory & Litigation Exposure
The privacy policy references disclosure of data to authorities, courts, and subcontractors where legally required, and the Trust Center lists data subject request handling and data breach notification processes. There are no disclosures of actual litigation, government data requests, or law enforcement cooperation history. The documents address legal-obligation disclosure generically but provide no transparency on actual requests.
PII & SPI Data Inventory
Canto collects significant PII — names, addresses, email, phone, IP addresses, device/meta data, usage data, payment data, and content including photographs/videos. It may process special category data (Article 9 GDPR, e.g., health/ethnic data) in the job application context, and user-uploaded content could contain images of identifiable individuals. Disclosure is detailed and tied to legal bases, but the breadth of PII and potential SPI in user content places this at moderate risk.
Policy–Product Currency
The privacy policy is recently updated (Last Update: July 30, 2026), within 12 months of the analysis date, and the Trust Center references AI governance and an EU AI Act assessment. However, the main consumer privacy policy is predominantly website/marketing-oriented and does not substantively cover the AI-first DAM capabilities (AI visual search, AI image editing/model providers) visible in the product surface; those are addressed only in separate support articles. Partial coverage caps this at YELLOW despite good recency.
Cross-Document Consistency
Multiple consumer documents were analyzed (Trust Center security policy and the privacy policy). No contradictions were found between them: the Trust Center's sub-processor disclosures (AWS, Pendo, Google/Gemini) align with the privacy policy's listed providers, and compliance claims are consistent across documents. No conflicting retention, licensing, or opt-out statements were detected across the consumer documents.
You've read all 15 risk ratings for Canto. Create a free account to see the exact policy wording behind each rating.