Compliance
CNT AG is committed to the highest standards of transparency, integrity, and ethical behavior. Our business practices are based on the requirements of national and international regulations as well as recognized standards to promote responsible conduct in all business areas.
Standards and Obligations
Responsible conduct is at the core of CNT AG's corporate culture. We adhere to all relevant legal, ethical, and company-specific guidelines to ensure transparent and sustainable business practices.
We place special emphasis on compliance with the General Data Protection Regulation (GDPR), legal minimum wage requirements, and international guidelines for corruption prevention as described in ISO 37001. Additionally, we align ourselves with the UN Guiding Principles on Business and Human Rights and the OECD Guidelines for Multinational Enterprises.
This commitment also includes promoting fair working conditions, sustainable environmental protection, equality, and diversity. This is complemented by adherence to industry-specific regulations, such as those of the Federal Network Agency, the Telecommunications Act (TKG), and a comprehensive IT security concept.
Our internal compliance guidelines serve as a framework for implementing these standards in daily practice. Employees are encouraged not only to adhere to these guidelines but also to actively contribute to the ongoing development of a responsible corporate culture.
Infrastructure and Data Security
CNT AG currently operates CNT Call Manager, including the associated cloud features we provide, exclusively in German data centers. Customer data and backups of that data are also stored on servers exclusively in Germany. The infrastructure used for these purposes is subject to German jurisdiction.
We implement technical, organizational, and contractual measures to protect customer data. These include role-based access permissions, logging of administrative access, encryption of data in transit, and confidentiality obligations and security requirements for the service providers we engage.
These measures also help protect non-personal customer data against government access from third countries and transfers to authorities in those countries where such access or transfers would conflict with EU law or the law of a Member State. Government requests for access to or disclosure of data undergo legal review and are documented by the responsible internal teams. We also assess available legal remedies against unlawful or disproportionate requests. Data is disclosed only where the legal requirements are met, and disclosure is limited to the minimum amount of data necessary. We notify affected customers before complying with a request to the extent required and permitted by law.
This information covers the infrastructure used by our subcontractors to provide these services. For third-party services separately procured and connected by the customer, the information provided by the respective provider applies. This information is provided to meet the disclosure obligations under Article 28 of Regulation (EU) 2023/2854 (Data Act) for the data processing services covered. We keep this information up to date.
Last updated: September 18, 2026
Whistleblower System
For concerns or reports of possible violations of legal, ethical, or internal company standards – including those along our supply chain – our whistleblower system is available to all employees, business partners, suppliers, and customers. It provides a safe and confidential way to report incidents of any kind. All reports received are carefully reviewed to identify issues, address them purposefully, and continuously strengthen our standards.
Contact for Whistleblowers: compliance@cnt.com