Plain-language summary
SSO collects information needed to operate music, media, technology, business, security, support, and distribution services. We use it for defined operational and legal purposes, limit access, retain it according to business and legal needs, and provide privacy choices where applicable.
1. Scope and controller
This Policy applies to SSO Artists Entertainment, LLC and SSO-controlled websites, applications, dashboards, APIs, support channels, and services that link to it. It does not replace a customer-specific privacy notice, employee notice, artist or partner agreement, or data-processing addendum.
SSO may act as a data controller or business when deciding why and how personal information is processed. For some enterprise or customer-directed processing, SSO may act as a processor or service provider under the customer's instructions and contract.
When a customer or partner controls the relevant data, requests may need to be directed to that organization first.
2. Information we collect
| Category | Examples |
|---|---|
| Identity and contact information | Name, professional name, username, email, telephone number, postal address, country, organization, title, and contact preferences. |
| Account and access information | Account identifiers, roles, permissions, organization domains, authentication events, session data, security settings, and account status. |
| Business and contractual information | Company details, sales orders, quotes, agreements, service plans, authorized users, correspondence, and relationship history. |
| Music, media, and catalog information | Artist and contributor names, credits, identifiers, release data, ownership and rights information, territories, files, artwork, lyrics, audiovisual assets, delivery instructions, and related metadata. |
| Financial and transaction information | Billing contacts, invoice information, payment status, payout instructions, tax documentation, royalty statements, transaction identifiers, and fraud-prevention information. Payment-card details may be processed directly by payment providers. |
| Technical and usage information | IP address, device and browser information, operating system, referring pages, timestamps, page and feature usage, API calls, error logs, diagnostics, cookie identifiers, and approximate location derived from IP. |
| Communications and support information | Messages, forms, support tickets, call or meeting notes, attachments, feedback, survey responses, and communications preferences. |
| Security, compliance, and dispute information | Audit logs, fraud and abuse signals, rights claims, takedown requests, verification records, sanctions or compliance screening, incident records, and evidence submitted in disputes. |
| Inferences and derived information | Operational classifications, service eligibility, catalog matching, risk indicators, troubleshooting conclusions, and analytics derived from the information above. |
Do not submit sensitive personal information unless SSO requests it for a legitimate purpose and an appropriate secure channel is available.
3. Sources of information
- Directly from you, such as through forms, accounts, contracts, uploads, support requests, meetings, and communications.
- From your organization, label, artist team, administrator, representative, or authorized collaborators.
- From digital service providers, distribution partners, rights organizations, metadata services, payment providers, and other parties involved in delivering or reporting services.
- From publicly available or licensed sources, such as public artist profiles, business registries, professional pages, catalog databases, and rights records.
- Automatically from devices, browsers, APIs, applications, cookies, local storage, logs, and security systems.
- From professional advisers, compliance vendors, fraud-prevention providers, and parties to claims, disputes, or transactions.
4. How information is used
- Provide, configure, authenticate, administer, and support the Services.
- Process content, validate metadata, manage catalogs, route deliveries, synchronize systems, and provide reporting.
- Create and manage accounts, roles, permissions, subscriptions, contracts, billing, payments, payouts, and statements.
- Communicate about services, incidents, maintenance, support, transactions, policy changes, and relationship management.
- Secure systems, prevent fraud and abuse, investigate incidents, enforce agreements, and maintain audit trails.
- Comply with law, legal process, rights requests, tax requirements, sanctions, recordkeeping duties, and platform obligations.
- Improve reliability, accessibility, usability, documentation, analytics, product performance, and customer experience.
- Evaluate service eligibility, partnerships, customer requests, and business operations.
- Protect SSO, users, artists, rights holders, partners, platforms, and the public.
- Conduct corporate transactions, audits, financing, restructuring, or due diligence subject to appropriate safeguards.
5. Legal bases for processing
Where the GDPR, UK GDPR, or similar law applies, SSO relies on one or more lawful bases depending on the context:
| Lawful basis | Typical use |
|---|---|
| Contract | Creating and administering accounts, delivering contracted services, processing content, billing, support, and carrying out requested transactions. |
| Legitimate interests | Securing systems, preventing fraud, maintaining business records, improving services, communicating with business contacts, analyzing performance, and protecting legal rights, balanced against individual rights. |
| Legal obligation | Tax, accounting, sanctions, legal process, rights requests, regulatory obligations, and required recordkeeping. |
| Consent | Optional communications, certain cookies or analytics, and other processing where consent is requested. Consent may be withdrawn prospectively. |
| Vital interests or public interest | Used only in uncommon circumstances where necessary and legally permitted. |
6. How information is disclosed
SSO may disclose personal information to:
- Authorized users and organizations connected to the relevant account, project, release, catalog, or contract.
- Digital service providers, media platforms, retailers, delivery endpoints, rights organizations, metadata and reporting partners, and other recipients needed to perform requested services.
- Cloud hosting, infrastructure, security, communications, analytics, customer-support, payment, accounting, professional-services, and other vendors acting under appropriate terms.
- Professional advisers, auditors, insurers, banks, financing sources, and transaction counterparties where reasonably necessary.
- Government authorities, regulators, courts, law enforcement, and other parties when required by law or reasonably necessary to protect rights, safety, and system integrity.
- A buyer, successor, affiliate, or other party involved in a merger, financing, reorganization, acquisition, sale, or transfer of all or part of SSO's business or assets.
- Other parties at your direction, with your consent, or as otherwise disclosed when the information is collected.
Public release metadata and credits may be intentionally distributed and displayed publicly as part of music and media services.
8. Sale, sharing, and targeted advertising
SSO does not knowingly sell personal information for money. SSO's core business involves delivering customer-authorized content and metadata to platforms and partners, which is not intended as a sale of personal information.
If SSO engages in processing that applicable U.S. privacy law defines as a "sale," "sharing," or targeted advertising, SSO will provide any legally required notice and opt-out mechanism. Disclosures to processors and service providers for business purposes are subject to contractual or legal restrictions where required.
9. Retention
SSO retains personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide services, maintain catalogs and transaction histories, reconcile statements, comply with law, resolve disputes, prevent fraud, enforce agreements, and preserve security and audit records.
Retention periods depend on the type of information, contractual requirements, legal limitation periods, platform reporting cycles, rights and ownership disputes, financial and tax obligations, backup schedules, and whether an account or business relationship remains active.
When information is no longer required, SSO may delete, anonymize, aggregate, or securely isolate it, subject to technical and legal limitations.
10. Security
SSO uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, alteration, disclosure, loss, or misuse. Measures may include access controls, role restrictions, logging, encryption in transit, secure development and configuration practices, monitoring, backups, vendor review, and incident response.
No method of transmission, storage, or security is completely risk-free. Users are responsible for protecting credentials, limiting authorized access, and using secure channels for sensitive information.
11. International transfers
SSO and its service providers, customers, platforms, and partners may process information in the United States and other countries. Those countries may have data-protection laws that differ from the laws where you live.
Where required, SSO uses recognized transfer mechanisms and safeguards, which may include adequacy decisions, standard contractual clauses, contractual commitments, transfer assessments, and supplementary technical or organizational measures.
12. Privacy choices and rights
Depending on your location and the processing involved, you may have rights to:
- Request access to personal information and information about its processing.
- Correct inaccurate or incomplete information.
- Request deletion or erasure, subject to legal and operational exceptions.
- Request restriction of processing.
- Object to certain processing, including direct marketing and some legitimate-interest processing.
- Receive certain information in a portable, machine-readable format.
- Withdraw consent prospectively where processing is based on consent.
- Appeal a denied request where applicable.
- Complain to a competent privacy or data-protection authority.
SSO may verify your identity and authority before completing a request. Authorized agents may be required to provide proof of authorization. Some rights are not absolute and may be limited by law, contractual confidentiality, the rights of others, security, fraud prevention, legal claims, and recordkeeping obligations.
13. United States state privacy rights
Residents of certain U.S. states may have rights to know, access, correct, delete, or obtain a copy of personal information; opt out of certain sales, sharing, targeted advertising, or profiling; limit certain uses of sensitive personal information; and appeal a decision.
SSO will not unlawfully discriminate against a person for exercising an applicable privacy right. A request may be submitted through the contact portal. State-specific rights apply only where the relevant law covers SSO and the processing.
14. Children's privacy
The Services are designed primarily for businesses, professionals, artists, labels, rights holders, and authorized representatives and are not directed to children under 13. SSO does not knowingly collect personal information online directly from children under 13 without legally required notice and verifiable parental consent.
If you believe a child under 13 submitted personal information through an SSO-controlled service, contact SSO so the information can be reviewed and handled appropriately. Commercial accounts and binding service arrangements must be created or approved by a person with legal capacity and authority.
15. Third-party services and public information
The Services may link to or integrate with third-party websites, platforms, payment services, social networks, and tools. Their privacy practices are governed by their own notices, not this Policy.
Music and media distribution commonly involves public metadata, artist names, credits, identifiers, artwork, release information, and links. Once information is public or delivered to independent recipients, SSO may not be able to control all copies, indexing, caches, archives, or downstream use.
16. Changes to this Policy
SSO may update this Policy to reflect legal, technical, operational, or service changes. The "Last updated" date identifies the current version. Material changes may be communicated through the Services, an account notice, or another reasonable channel where required.
17. Contact and requests
Submit privacy questions or requests through the contact portal. Select or describe the request type and include enough information to identify the relevant account, organization, interaction, or data.
For security, do not include passwords, full payment-card numbers, or unnecessary sensitive documents in the initial request. SSO may request additional verification through an appropriate channel.
