Security & Data

Your data.
Your rights.
Protected.

Music Manager handles some of the most commercially sensitive information in the creative industries, including catalogue structures, distribution gaps, revenue figures and rights metadata. We treat that responsibility seriously at every level of how we operate.

Encrypted in transit & at rest
Isolated per account
We don't sell your data to third parties
Terms accepted at signup
At a glance
Encrypted end-to-end
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Your catalogue data is never accessible in plaintext outside controlled processing environments.
Account isolation
Every account operates in a fully isolated environment. Your catalogue data, audit history and results are logically separated from every other account at the infrastructure level.
Your results, yours to keep
The reports you pay for are yours, and you can export them from your account.
Transparent data use
We are clear about what data we retain, why we retain it, and how aggregated insights from the platform are used. Your identity and specific rights are never exposed.
What we store

What we keep and why

Catalogue and ISRC data
The ISRC identifiers, metadata and distribution information you submit for an audit are retained for as long as your account is active. This is required to enable re-runs, where we re-analyse the same assets against updated DSP data or changed settings, without you needing to re-upload your catalogue. Re-runs using the same ISRCs with adjusted settings are free precisely because we retain this data securely on your behalf.
Audit results and reports
All audit results and reports are retained while your account is active and accessible through your account at any time. Reports are encrypted at rest and accessible only through authenticated account access.
Data we do not retain
Financial statements, distribution statements and any supporting documents uploaded as part of an audit run are processed and then deleted. We do not retain raw financial data beyond what is required to complete the analysis. Account-level personal data, including name, email and billing information, is retained only as long as required by applicable law and our contractual obligations.
Account inactivity
Accounts inactive for six consecutive months are automatically frozen. A reminder is sent approximately one month before the freeze threshold. Frozen accounts can be reactivated by contacting support@musicmanager.com. See our Terms and Conditions for full details.
What you own

Your rights as a customer

What we guarantee you
  • Access to your reports. Every audit report you pay for is yours. You can access and export your results at any time while your account is active.
  • Your rights are never shared. We will never disclose, sell or expose the specific rights, catalogue details, ISRCs or commercially sensitive information you submit to any third party, except where required by applicable law.
  • Your identity is never linked. No aggregated data we produce or share can be traced back to you as an individual customer, your account or your specific catalogue.
  • You control your account. You may close your account and request deletion of your personal data at any time, in line with our Terms and applicable data protection law.
What we ask in return
  • That the catalogue data and ISRCs you submit are yours to audit — or that you have the rights holder's authorisation to do so.
  • That you maintain the confidentiality of your account credentials. Music Manager is not liable for unauthorised access resulting from compromised credentials.
  • That audit results are used for your own commercial and operational purposes. Reports are not to be redistributed or resold without prior written agreement.
  • That you accept our Terms & Conditions at account creation — which govern how data is handled, what we commit to, and what our mutual obligations are.
How we use data

Aggregated intelligence

How our platform learns and improves
As Music Manager processes audits across catalogues and DSPs, our systems develop aggregated, fully anonymised intelligence about the state of the market, including distribution patterns, common metadata gaps, platform behaviour, territorial delivery trends and more. This intelligence has no connection to any individual customer, catalogue or ISRC.
How we use this intelligence
We use aggregated market intelligence to improve the accuracy and depth of our platform, to train and refine our analytical models, and to develop new features and capabilities. At no point does any of this involve the identification of individual customers, catalogues or rights.

The core principle: We will never expose, sell or reference any information that could identify you as a customer, your catalogue, your rights or your commercial position, directly or indirectly. What we learn from aggregated data is market-level intelligence that helps us improve the platform. Your data contributes to the whole. The whole is never traced back to you.

Technical measures

How we protect your data

Encryption
All data transmitted between your browser and our platform is encrypted using TLS 1.3. All data stored on our infrastructure — catalogue submissions, audit results, account data — is encrypted at rest using AES-256. Encryption keys are managed separately from the data they protect.
Access control
Access to customer data within our infrastructure is restricted on a strict need-to-know basis. All internal access is logged, audited and subject to role-based access controls. No employee has standing access to customer catalogue data outside of a defined support or operational process.
Infrastructure and hosting
Music Manager runs on enterprise cloud infrastructure with SOC 2 Type II certification. Data is hosted within the European Economic Area (EEA) and subject to EU data protection regulation. We do not transfer personal data outside the EEA without appropriate safeguards in place.
Vulnerability management
Our platform is subject to regular security reviews and penetration testing. We maintain a responsible disclosure policy and respond to reported vulnerabilities promptly. Security patches are applied on a defined cycle with critical updates deployed immediately.
Legal documents

By creating an account with Music Manager, you agree to our Terms & Conditions. These govern how your data is handled, what we commit to as a platform, and the mutual obligations between Music Manager and its customers. The current versions are below.

Versioned · accepted at signup