This Privacy Policy describes how CRIIO (“CRIIO,” “we,” “us,” or “our”) collects, uses, processes, stores, discloses, and protects personal information in connection with CRIIO websites, applications, dashboards, platforms, products, licensing programs, music distribution services, rights-management services, royalty administration services, YouTube-related services, Catholic music services, church music licensing services, and other products and services that link to this Privacy Policy (collectively, the “Services”).
By accessing or using the Services, you acknowledge the practices described in this Privacy Policy. Where consent is required by applicable law, CRIIO will request consent separately as appropriate.
This Privacy Policy should be read together with CRIIO’s Terms of Service and any additional agreement governing a particular CRIIO service.
CRIIO may collect information directly from you, automatically through your use of the Services, from organizations or individuals acting on your behalf, and from third parties involved in music distribution, licensing, rights administration, payments, analytics, or other services.
We may collect:
When you use CRIIO to distribute, register, administer, license, monetize, or manage creative works, we may collect information including:
Some of this information may relate to other people. If you provide CRIIO with personal information concerning another individual, you represent that you are authorized to provide that information to CRIIO and that CRIIO may process it for the purposes associated with the Services, subject to applicable law.
We may collect or process information associated with:
Payment card and banking information may be processed directly by third-party payment processors. CRIIO may receive transaction identifiers, payment status, limited payment-account information, and other records rather than complete card or banking credentials.
For licensing, royalty, rights-management, and related services, CRIIO may process information concerning:
We may collect information you provide when communicating with CRIIO through email, customer support, forms, telephone, social media, account messaging, surveys, applications, or other communication channels.
When you access the Services, we may automatically collect information such as:
CRIIO may receive information from third parties, including digital service providers, music platforms, licensing partners, collection organizations, rights-management organizations, payment processors, service providers, distributors, business partners, public databases, and users who submit information relating to you or your works.
We may combine such information with information already maintained by CRIIO where permitted by law.
CRIIO may use personal information for legitimate business and operational purposes including:
Where applicable law requires a legal basis for processing personal information, CRIIO may rely upon:
Performance of a contract, when processing is necessary to provide services you requested.
Legitimate interests, including operating and improving CRIIO, preventing fraud, protecting intellectual property, maintaining security, administering business relationships, and enforcing agreements, where those interests are not overridden by applicable privacy rights.
Legal obligations, including tax, accounting, regulatory, judicial, and law-enforcement requirements.
Consent, where applicable law requires consent for particular processing.
Different legal bases may apply to different processing activities.
CRIIO may disclose information as reasonably necessary to operate the Services.
Recipients may include:
Information submitted as music metadata or rights information may also become available to industry participants or the public when reasonably necessary to identify, distribute, license, attribute, monetize, or administer a work.
CRIIO may engage third parties to perform services on its behalf.
These parties may process personal information as necessary to provide their services to CRIIO, subject to contractual arrangements and applicable law.
Third-party services may maintain their own privacy policies and terms. CRIIO is not responsible for the independent privacy practices of third parties acting as separate controllers or businesses.
CRIIO does not sell personal information for money merely as part of operating its music services.
However, privacy laws can define “sale” or “sharing” more broadly than an ordinary commercial sale, particularly where advertising, analytics, cookies, or cross-context behavioral advertising technologies are involved.
Where CRIIO engages in activities legally considered a sale or sharing of personal information, CRIIO will provide applicable disclosures and opt-out mechanisms required by law.
CRIIO and its service providers may use:
These technologies may be used for authentication, security, preferences, functionality, analytics, performance measurement, fraud prevention, and other permitted purposes.
Where legally required, CRIIO will obtain consent before using non-essential cookies or similar technologies.
Users may also control certain cookies through browser settings. Blocking cookies may prevent some portions of the Services from functioning properly.
CRIIO may use analytics services to understand how users interact with the Services, diagnose technical issues, measure performance, and improve products and functionality.
Analytics providers may collect technical information such as IP addresses, device information, pages visited, interactions, and session information according to their respective agreements and privacy practices.
CRIIO may send transactional communications concerning accounts, security, payments, releases, licenses, royalties, service changes, and other operational matters.
Where permitted by law, CRIIO may also send promotional or marketing communications.
Users may unsubscribe from eligible marketing communications using the unsubscribe mechanism provided in the communication.
Opting out of marketing communications does not prevent CRIIO from sending necessary transactional, legal, security, or account-related communications.
CRIIO uses administrative, technical, organizational, and physical safeguards designed to protect personal information against unauthorized access, acquisition, alteration, disclosure, destruction, or loss.
However, no electronic transmission, network, database, storage system, or security technology can be guaranteed to be completely secure.
Accordingly, CRIIO cannot guarantee absolute security of information.
Users are responsible for maintaining the confidentiality of account credentials, using secure passwords, protecting devices used to access CRIIO, and promptly notifying CRIIO of suspected unauthorized account activity.
CRIIO may retain personal information for as long as reasonably necessary to:
Termination or deletion of an account does not necessarily require CRIIO to immediately erase all information associated with that account.
For example, CRIIO may retain information necessary to maintain historical royalty statements, licensing records, copyright ownership records, payment records, audit trails, fraud-prevention records, or evidence relating to disputes and legal obligations.
Information may also persist temporarily in backups and disaster-recovery systems.
Certain information provided to CRIIO may be intended for public or industry distribution.
For example, artist names, release titles, songwriter credits, publisher information, artwork, copyright notices, identifiers, and other metadata may be distributed to music services, licensing systems, rights organizations, industry databases, or the public as necessary to perform requested services.
Information made public or distributed at your direction may remain available through third-party services even after it has been removed from CRIIO.
CRIIO cannot control deletion from independent third-party systems.
Depending upon your jurisdiction, you may have rights concerning your personal information.
These may include rights to:
These rights vary by jurisdiction and are subject to statutory exceptions.
For example, California recognizes rights including know, delete, correct, opt out of sale or sharing, limit certain uses, and non-discrimination. GDPR rights include access, rectification, erasure, restriction, portability, and objection.
CRIIO may need to verify your identity before fulfilling a privacy request.
Verification may require information reasonably necessary to confirm that the requester is the person to whom the information relates or is an authorized representative.
CRIIO may deny or limit requests where permitted by law, including where CRIIO cannot reasonably verify identity or where an exception applies.
If the California Consumer Privacy Act, as amended (“CCPA”), applies to CRIIO’s processing of your information, California residents may have additional rights.
Depending upon applicability and statutory exceptions, these may include rights to know, access, correct, delete, opt out of certain sales or sharing, limit certain uses of sensitive personal information, and receive equal service without unlawful discrimination for exercising privacy rights. California’s Attorney General describes these rights and requires covered businesses to explain how consumers may exercise them.
CRIIO will not unlawfully discriminate against an individual for exercising applicable privacy rights.
CRIIO may maintain information when permitted by CCPA exceptions, including where information is reasonably necessary to complete transactions, perform contracts, protect security, exercise legal rights, or satisfy legal obligations.
CRIIO operates internationally and may process information in the United States and other countries where CRIIO, its affiliates, contractors, service providers, business partners, platforms, or infrastructure providers operate.
These jurisdictions may have data-protection laws different from those in your country.
Where required by applicable law, CRIIO will use an appropriate legal mechanism for international transfers of personal information.
Where GDPR, UK GDPR, or comparable laws apply, users may have additional rights concerning processing of personal data.
CRIIO will process applicable requests in accordance with governing law and may require identity verification before fulfilling a request.
Individuals may also have the right to complain to the competent supervisory authority.
CRIIO’s general-audience Services are not directed to children under 13, and CRIIO does not intend to knowingly collect personal information directly from children under 13 through those Services without legally required authorization.
COPPA applies to child-directed online services and to general-audience services with actual knowledge that they collect personal information from children under 13.
If CRIIO learns that personal information has been collected directly from a child under 13 in circumstances requiring parental consent and appropriate consent was not obtained, CRIIO may take steps to delete or otherwise address that information as required by applicable law.
A parent or legal guardian who believes a child has provided personal information to CRIIO may contact CRIIO using the contact information below.
Important: if CRIIO later intentionally offers child-directed education products or accounts to children under 13, this provision alone will not be sufficient. COPPA can require parental notice, verifiable parental consent, parental access/deletion mechanisms, security protections, and appropriate retention practices.
Some CRIIO accounts may be created, administered, or paid for by organizations such as businesses, publishers, labels, churches, dioceses, schools, ministries, or other institutions.
Where an organization controls an account, authorized administrators may be able to access or manage information associated with that account.
The organization’s own privacy obligations may apply independently of CRIIO’s obligations.
CRIIO may preserve and process relevant personal information, communications, agreements, metadata, ownership records, payment information, and other records where reasonably necessary to investigate or resolve:
Deletion requests may therefore be subject to legal and legitimate record-retention requirements.
CRIIO may preserve, access, or disclose information when CRIIO reasonably believes doing so is necessary or appropriate to:
Where legally permitted and appropriate, CRIIO may challenge requests that it believes are invalid, excessive, or unlawful.
If CRIIO is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, corporate restructuring, investment transaction, or transfer of some or all of its business, information may be disclosed or transferred as part of evaluating, negotiating, or completing that transaction, subject to applicable law.
CRIIO may create aggregated, statistical, or de-identified information from information collected through the Services.
Where information has been lawfully de-identified so that it is no longer personal information under applicable law, CRIIO may use it for analytics, research, product development, business intelligence, security, industry analysis, and other lawful purposes.
Where required by applicable law, CRIIO will maintain de-identified information in de-identified form and will not attempt to reidentify it except as permitted by law.
CRIIO may use artificial intelligence, machine learning, automation, matching technologies, and similar tools to support its Services.
These technologies may assist with functions such as:
Where required by applicable law, CRIIO will provide additional disclosures or rights concerning automated decision-making.
Use of automated technology does not eliminate CRIIO’s obligations under applicable privacy law.
The Services may contain links or integrations with third-party websites, applications, platforms, or services.
CRIIO does not control the independent privacy practices of those third parties.
This Privacy Policy does not govern information processed independently by a third party after a user leaves CRIIO or interacts directly with that third party.
Users should review the privacy policies of relevant third-party services.
Browser-based privacy signals and “Do Not Track” mechanisms are not uniformly standardized.
Where applicable law requires CRIIO to recognize an opt-out preference signal, such as a legally recognized Global Privacy Control signal, CRIIO will process the signal as required by applicable law.
CRIIO may amend this Privacy Policy periodically to reflect changes in the Services, technologies, business practices, legal requirements, or other circumstances.
The revised policy will identify its updated effective or revision date.
Where applicable law requires additional notice or consent for a material change, CRIIO will provide such notice or obtain such consent.
Continued use of the Services after an updated policy becomes effective will be governed by the updated policy to the extent permitted by applicable law.
Nothing in this Privacy Policy constitutes a representation or warranty that any information, system, transmission, database, network, or security measure is completely secure or immune from unauthorized access, interruption, loss, misuse, or cyberattack.
CRIIO’s security obligations remain subject to applicable law and applicable contractual commitments.
Certain CRIIO products or programs may be governed by supplemental privacy notices, agreements, consent forms, or service-specific terms.
If a supplemental privacy notice applies to a particular processing activity, that notice should be read together with this Privacy Policy.
To the extent of a conflict, the service-specific privacy terms will govern the relevant processing to the extent permitted by applicable law.
Questions, concerns, and privacy requests may be submitted to:
CRIIO
Privacy Department
California, United States
Email: privacy@criio.com
Website: CRIIO.com
Individuals submitting privacy-rights requests should include sufficient information for CRIIO to identify the applicable account and verify the request, but should not send passwords, complete payment-card numbers, or other unnecessary sensitive credentials by email.