Security and Privacy Terms

Cato Digital Terms

Security and Privacy Terms

Last Updated: Sep 18, 2026

These Cato Privacy and Security Terms (“Privacy and Security Terms”) are a Policy under the Cato Service Terms and govern Cato’s handling and protection of Customer Content in connection with the Services.

These Privacy and Security Terms do not govern personal information Cato collects for account administration, billing, support, website operation, communications, or similar business purposes. Cato’s handling of that information is described in the Cato Privacy Notice.

Capitalized terms not defined in these Privacy and Security Terms have the meanings given in the Service Terms or Governing Agreement.

1. Customer Content.

1.1. Permitted Use. Cato will access, use, or disclose Customer Content only as reasonably necessary to: (a) provide, maintain, support, secure, or protect the Services; (b) investigate or address fraud, abuse, security issues, or violations of applicable Policies; (c) carry out Customer’s instructions or requests; or (d) comply with applicable law or valid legal process.

1.2. Personnel Access. Cato will restrict access to Customer Content to personnel who are authorized to access it for a permitted purpose and will require such personnel to comply with appropriate confidentiality and security obligations.

1.3. Service Providers. Cato may use affiliates, contractors, and service providers to assist in providing, maintaining, securing, or supporting the Services. Cato will require service providers that access Customer Content on Cato’s behalf to be subject to appropriate confidentiality and security obligations.

2. Security Program.

2.1. Security Measures. Cato will maintain an information security program containing reasonable and appropriate administrative, technical, and physical safeguards designed to protect the Cato Network and Customer Content against unauthorized access, use, disclosure, alteration, or destruction.

2.2. Security Controls. Cato’s security program will include measures appropriate to the nature of the Services and risks presented, which may include logical and physical access controls, authentication and authorization controls, vulnerability management and testing, change-management and configuration controls, and employee security and confidentiality training.

When storage media used to provide the Services is released for reuse or permanently removed from service, Cato will use sanitization or destruction practices appropriate to the applicable media and designed to prevent recovery of Customer Content.

2.3. Security Program Changes. Cato may update its security measures from time to time to address changes in technology, threats, law, or the Services.

3. Security Incidents.

3.1. Security Incident. A “Security Incident” means a confirmed compromise of Cato’s security resulting in unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Customer Content stored or processed through the Services.

Unsuccessful attempts or activities that do not result in unauthorized access to Customer Content are not Security Incidents. These may include unsuccessful log-in attempts, scans, probes, pings, denial-of-service attempts, or similar network activity.

3.2. Notification. Cato will notify Customer without undue delay after becoming aware of a Security Incident and will take reasonable measures to contain, investigate, and mitigate the Security Incident.

3.3. Information. Cato will provide information about a Security Incident that is reasonably available to Cato and reasonably necessary for Customer to understand the nature and potential impact of the Security Incident. Cato may provide information in stages as its investigation progresses.

3.4. Communications. Security Incident notices may be delivered to an Account administrator, designated security contact, or other appropriate contact associated with Customer’s Account. Customer is responsible for keeping its Account contact information current.

3.5. No Admission. Cato’s investigation, response to, or notification of a Security Incident does not constitute an admission of fault or liability.

4. Government and Legal Requests.

4.1. Redirecting Requests. If Cato receives a binding legal demand from a governmental or law enforcement authority seeking Customer Content, Cato will, where reasonably practicable, direct the requesting authority to seek the Customer Content directly from Customer.

4.2. Notice. If Cato is required to disclose Customer Content, Cato will provide Customer reasonable notice before disclosure where legally permitted so that Customer may seek a protective order or other available remedy.

4.3. Scope of Disclosure. Where Cato is legally required to disclose Customer Content, Cato will disclose only the Customer Content reasonably necessary to comply with the applicable legal requirement.

5. Security Information.

Upon reasonable written request, Cato will make available information reasonably sufficient to describe its security measures and practices applicable to the Services.

Cato may require appropriate confidentiality protections and may withhold information where disclosure could reasonably compromise security, reveal another customer’s information, or disclose Cato or third-party confidential information.

Nothing in this Section creates a right to inspect Cato facilities, systems, source code, networks, personnel records, or other sensitive information unless Cato expressly agrees otherwise in writing.

6. Specialized Regulatory Requirements.

If Customer’s use of the Services requires a data processing addendum, business associate agreement, standard contractual clauses, or other specialized regulatory terms with Cato, Customer must obtain Cato’s written agreement before using the Services for processing subject to those requirements.

Unless Cato expressly agrees otherwise in writing, the Services are not represented as satisfying Customer-specific regulatory, certification, or compliance requirements.

Cato Digital

Ready to get started?

View available application or storage servers.
Cato Digital ™, and © Cato Digital, inc  | Terms | Privacy