SSO LEGAL

GDPR and Data Rights

This notice provides additional information for people protected by the EU General Data Protection Regulation, the UK GDPR, and comparable data-protection laws.

Effective: July 27, 2026Last updated: July 27, 2026

How this document works

This notice supplements the SSO Privacy Policy. It applies only where the relevant data-protection law applies to SSO's processing and does not expand statutory rights beyond their legal scope.

1. When this notice applies

This notice applies when SSO processes personal data of individuals in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction whose law provides comparable rights, and that law applies to the processing.

"Personal data," "processing," "controller," "processor," and similar terms have the meanings assigned by applicable data-protection law.

2. Controller and processor roles

SSO as controller

SSO generally acts as controller when it determines the purposes and means of processing for website administration, account management, business relationships, billing, security, support, legal compliance, service improvement, and SSO's own communications.

SSO as processor

SSO may act as processor or service provider when it processes personal data on documented instructions from a customer, such as certain catalog, contributor, account, delivery, analytics, or enterprise-service data. In that situation, the customer is generally responsible for the primary privacy notice and rights response, and SSO assists as required by contract and law.

The role may differ by data element and processing activity.

3. Data-protection principles

Where applicable, SSO's processing is designed around the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.

These principles inform collection decisions, access controls, retention, vendor management, security, documentation, and the handling of individual requests.

4. Purposes and lawful bases

PurposeTypical lawful basis
Create and administer accounts; provide requested services; process content and deliveries; support usersPerformance of a contract or steps requested before entering a contract
Manage customer, artist, label, partner, vendor, and professional relationshipsContract and legitimate interests in operating and managing SSO's business
Bill, pay, reconcile, report, collect, and maintain financial recordsContract, legal obligation, and legitimate interests
Secure services; authenticate access; detect fraud, abuse, infringement, and technical incidentsLegitimate interests, legal obligation, and establishment or defense of legal claims
Comply with tax, accounting, sanctions, legal process, regulatory, and recordkeeping dutiesLegal obligation and public-interest requirements where applicable
Improve reliability, user experience, documentation, analytics, and service performanceLegitimate interests, and consent where required for specific technologies
Send requested or service-related communicationsContract and legitimate interests
Send optional marketing communications or use optional cookiesConsent where required; otherwise legitimate interests where permitted
Handle disputes, rights claims, takedowns, and enforcementLegitimate interests, legal obligation, and legal claims

When SSO relies on legitimate interests, it considers the purpose, necessity, reasonable expectations, data sensitivity, relationship, potential impact, and available safeguards.

5. Categories and sources of personal data

SSO may process identity, contact, account, professional, organizational, contractual, catalog, contributor, rights, payment, tax, transaction, technical, usage, communications, support, security, compliance, and dispute information.

Data may come from you; your employer, label, organization, representative, or collaborators; customers and partners; digital platforms and delivery recipients; rights and metadata organizations; service providers; public or licensed sources; and automated technical collection.

More detail appears in the Privacy Policy.

6. Special-category and sensitive data

SSO does not generally require special-category personal data for ordinary website and distribution operations. Do not submit health information, biometric identifiers used for unique identification, political or religious beliefs, sexual-orientation information, or other specially protected data unless SSO specifically requests it for a lawful and necessary purpose.

If SSO processes special-category data, it will identify an applicable legal condition, such as explicit consent, employment-law obligations, vital interests, data manifestly made public by the individual, substantial public interest, or establishment or defense of legal claims, as applicable.

7. Recipients and processors

Personal data may be disclosed to authorized customer and organizational users; digital service providers and delivery recipients; cloud, security, communications, analytics, support, payment, accounting, and professional-service vendors; rights and metadata organizations; advisers and auditors; transaction counterparties; and authorities where legally required.

Processors are engaged under terms requiring appropriate confidentiality, security, purpose restrictions, and assistance obligations where required. SSO evaluates vendors based on the nature of the processing and associated risk.

8. International transfers

Personal data may be transferred to and processed in countries outside the EEA, UK, or Switzerland, including the United States. When required, SSO uses an approved transfer mechanism.

  • An adequacy decision issued by the relevant authority.
  • European Commission Standard Contractual Clauses or the applicable UK transfer mechanism.
  • Contractual, technical, and organizational safeguards based on the transfer circumstances.
  • Another lawful derogation or mechanism available under applicable law.

You may request information about the applicable safeguard, subject to confidentiality and security limitations.

9. Retention

SSO retains personal data only for as long as reasonably necessary for the relevant purposes and legal obligations. Criteria include contract duration, account activity, catalog and delivery lifecycle, statement and reporting cycles, tax and accounting rules, legal limitation periods, disputes, rights claims, fraud prevention, security logs, backups, and instructions from a controlling customer.

Data may be deleted, anonymized, aggregated, or isolated when no longer needed. Some records must be retained after an account or public release is removed.

10. Automated decision-making and profiling

SSO may use automation to validate files and metadata, classify errors, match identifiers, detect anomalies, prioritize support, monitor security, and assist operational review.

SSO does not ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. If SSO introduces such processing where applicable law requires additional protections, SSO will provide relevant information and a method to request human review or contest the decision.

11. Your data-protection rights

Subject to applicable conditions and exceptions, you may have the following rights:

RightWhat it generally means
InformationReceive clear information about how personal data is processed.
AccessConfirm whether data is processed and receive a copy plus required supplementary information.
RectificationCorrect inaccurate data and complete incomplete data.
ErasureRequest deletion in circumstances recognized by law.
RestrictionRequest that processing be limited in specified circumstances.
PortabilityReceive certain data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible.
ObjectionObject to direct marketing and, in some cases, processing based on legitimate interests or public interest.
Withdraw consentWithdraw consent at any time for future processing based on consent, without affecting prior lawful processing.
Automated decisionsObtain safeguards related to qualifying solely automated decisions, including human intervention where applicable.
ComplaintLodge a complaint with a competent supervisory authority.

12. Submitting and verifying a request

Submit a request through the contact portal and identify the right you wish to exercise. Include your name, contact information, relationship to SSO, relevant organization or account, and enough context to locate the data.

SSO may request information reasonably necessary to verify identity, authority, and scope. Verification is used to protect personal data from unauthorized disclosure or deletion. SSO may ask an authorized agent to provide written authority and may contact the individual directly where permitted.

SSO aims to respond within the period required by applicable law. A period may be extended for complex or numerous requests where the law permits, with notice. Requests may be refused or charged a reasonable fee only where legally allowed, such as when a request is manifestly unfounded or excessive.

13. Complaints and supervisory authorities

Contact SSO first so the concern can be reviewed. You also have the right, where applicable, to complain to the data-protection authority where you live, work, or believe an infringement occurred.

SSO will not retaliate against a person for making a good-faith privacy request or complaint.

14. Cookies and electronic communications

Strictly necessary technologies may be used to deliver, secure, and authenticate the Services. Analytics, preference, or marketing technologies are used based on consent where consent is required.

You may withdraw cookie consent through available controls or browser settings. Withdrawal does not affect processing that occurred before withdrawal. See the Cookie Policy.

15. Data controlled by an SSO customer or partner

If SSO processes your personal data solely for an organization that controls the data, submit your request to that organization. SSO will support the controller according to its instructions, contract, and applicable law.

SSO may still process limited information as an independent controller for security, account administration, legal compliance, billing, fraud prevention, and protection of legal rights.

16. Contact

Use the contact portal for GDPR, UK GDPR, transfer-safeguard, or other data-rights questions. If SSO is legally required to appoint a data-protection officer or representative for a particular processing activity, the relevant contact information will be provided in the applicable notice or service documentation.