How this document works
This notice supplements the SSO Privacy Policy. It applies only where the relevant data-protection law applies to SSO's processing and does not expand statutory rights beyond their legal scope.
1. When this notice applies
This notice applies when SSO processes personal data of individuals in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction whose law provides comparable rights, and that law applies to the processing.
"Personal data," "processing," "controller," "processor," and similar terms have the meanings assigned by applicable data-protection law.
2. Controller and processor roles
SSO as controller
SSO generally acts as controller when it determines the purposes and means of processing for website administration, account management, business relationships, billing, security, support, legal compliance, service improvement, and SSO's own communications.
SSO as processor
SSO may act as processor or service provider when it processes personal data on documented instructions from a customer, such as certain catalog, contributor, account, delivery, analytics, or enterprise-service data. In that situation, the customer is generally responsible for the primary privacy notice and rights response, and SSO assists as required by contract and law.
The role may differ by data element and processing activity.
3. Data-protection principles
Where applicable, SSO's processing is designed around the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
These principles inform collection decisions, access controls, retention, vendor management, security, documentation, and the handling of individual requests.
4. Purposes and lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Create and administer accounts; provide requested services; process content and deliveries; support users | Performance of a contract or steps requested before entering a contract |
| Manage customer, artist, label, partner, vendor, and professional relationships | Contract and legitimate interests in operating and managing SSO's business |
| Bill, pay, reconcile, report, collect, and maintain financial records | Contract, legal obligation, and legitimate interests |
| Secure services; authenticate access; detect fraud, abuse, infringement, and technical incidents | Legitimate interests, legal obligation, and establishment or defense of legal claims |
| Comply with tax, accounting, sanctions, legal process, regulatory, and recordkeeping duties | Legal obligation and public-interest requirements where applicable |
| Improve reliability, user experience, documentation, analytics, and service performance | Legitimate interests, and consent where required for specific technologies |
| Send requested or service-related communications | Contract and legitimate interests |
| Send optional marketing communications or use optional cookies | Consent where required; otherwise legitimate interests where permitted |
| Handle disputes, rights claims, takedowns, and enforcement | Legitimate interests, legal obligation, and legal claims |
When SSO relies on legitimate interests, it considers the purpose, necessity, reasonable expectations, data sensitivity, relationship, potential impact, and available safeguards.
5. Categories and sources of personal data
SSO may process identity, contact, account, professional, organizational, contractual, catalog, contributor, rights, payment, tax, transaction, technical, usage, communications, support, security, compliance, and dispute information.
Data may come from you; your employer, label, organization, representative, or collaborators; customers and partners; digital platforms and delivery recipients; rights and metadata organizations; service providers; public or licensed sources; and automated technical collection.
More detail appears in the Privacy Policy.
6. Special-category and sensitive data
SSO does not generally require special-category personal data for ordinary website and distribution operations. Do not submit health information, biometric identifiers used for unique identification, political or religious beliefs, sexual-orientation information, or other specially protected data unless SSO specifically requests it for a lawful and necessary purpose.
If SSO processes special-category data, it will identify an applicable legal condition, such as explicit consent, employment-law obligations, vital interests, data manifestly made public by the individual, substantial public interest, or establishment or defense of legal claims, as applicable.
7. Recipients and processors
Personal data may be disclosed to authorized customer and organizational users; digital service providers and delivery recipients; cloud, security, communications, analytics, support, payment, accounting, and professional-service vendors; rights and metadata organizations; advisers and auditors; transaction counterparties; and authorities where legally required.
Processors are engaged under terms requiring appropriate confidentiality, security, purpose restrictions, and assistance obligations where required. SSO evaluates vendors based on the nature of the processing and associated risk.
8. International transfers
Personal data may be transferred to and processed in countries outside the EEA, UK, or Switzerland, including the United States. When required, SSO uses an approved transfer mechanism.
- An adequacy decision issued by the relevant authority.
- European Commission Standard Contractual Clauses or the applicable UK transfer mechanism.
- Contractual, technical, and organizational safeguards based on the transfer circumstances.
- Another lawful derogation or mechanism available under applicable law.
You may request information about the applicable safeguard, subject to confidentiality and security limitations.
9. Retention
SSO retains personal data only for as long as reasonably necessary for the relevant purposes and legal obligations. Criteria include contract duration, account activity, catalog and delivery lifecycle, statement and reporting cycles, tax and accounting rules, legal limitation periods, disputes, rights claims, fraud prevention, security logs, backups, and instructions from a controlling customer.
Data may be deleted, anonymized, aggregated, or isolated when no longer needed. Some records must be retained after an account or public release is removed.
10. Automated decision-making and profiling
SSO may use automation to validate files and metadata, classify errors, match identifiers, detect anomalies, prioritize support, monitor security, and assist operational review.
SSO does not ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. If SSO introduces such processing where applicable law requires additional protections, SSO will provide relevant information and a method to request human review or contest the decision.
11. Your data-protection rights
Subject to applicable conditions and exceptions, you may have the following rights:
| Right | What it generally means |
|---|---|
| Information | Receive clear information about how personal data is processed. |
| Access | Confirm whether data is processed and receive a copy plus required supplementary information. |
| Rectification | Correct inaccurate data and complete incomplete data. |
| Erasure | Request deletion in circumstances recognized by law. |
| Restriction | Request that processing be limited in specified circumstances. |
| Portability | Receive certain data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible. |
| Objection | Object to direct marketing and, in some cases, processing based on legitimate interests or public interest. |
| Withdraw consent | Withdraw consent at any time for future processing based on consent, without affecting prior lawful processing. |
| Automated decisions | Obtain safeguards related to qualifying solely automated decisions, including human intervention where applicable. |
| Complaint | Lodge a complaint with a competent supervisory authority. |
12. Submitting and verifying a request
Submit a request through the contact portal and identify the right you wish to exercise. Include your name, contact information, relationship to SSO, relevant organization or account, and enough context to locate the data.
SSO may request information reasonably necessary to verify identity, authority, and scope. Verification is used to protect personal data from unauthorized disclosure or deletion. SSO may ask an authorized agent to provide written authority and may contact the individual directly where permitted.
SSO aims to respond within the period required by applicable law. A period may be extended for complex or numerous requests where the law permits, with notice. Requests may be refused or charged a reasonable fee only where legally allowed, such as when a request is manifestly unfounded or excessive.
13. Complaints and supervisory authorities
Contact SSO first so the concern can be reviewed. You also have the right, where applicable, to complain to the data-protection authority where you live, work, or believe an infringement occurred.
SSO will not retaliate against a person for making a good-faith privacy request or complaint.
15. Data controlled by an SSO customer or partner
If SSO processes your personal data solely for an organization that controls the data, submit your request to that organization. SSO will support the controller according to its instructions, contract, and applicable law.
SSO may still process limited information as an independent controller for security, account administration, legal compliance, billing, fraud prevention, and protection of legal rights.
16. Contact
Use the contact portal for GDPR, UK GDPR, transfer-safeguard, or other data-rights questions. If SSO is legally required to appoint a data-protection officer or representative for a particular processing activity, the relevant contact information will be provided in the applicable notice or service documentation.
