TP-CAMP OneSuite
Security & Data Protection Policy
- Effective Date:
- 23 September 2026
- Last Updated:
- 23 September 2026
1. Purpose
This Security & Data Protection Policy (“Policy”) describes the principles and safeguards TP-CAMP OneSuite (“OneSuite,” “TP-CAMP,” “we,” “us,” or “our”) uses to protect customer information, personal information, business records and the integrity of the OneSuite ecosystem.
Our objectives are to:
- protect the confidentiality, integrity and availability of information;
- prevent unauthorized access to customer workspaces;
- protect music-rights and ownership information;
- protect financial and business information;
- maintain appropriate separation between customers;
- reduce security and fraud risks;
- protect TP-CAMP's systems and intellectual property;
- respond appropriately to security incidents; and
- process personal information responsibly and consistently with applicable law.
Security is a shared responsibility between TP-CAMP, its service providers, workspace administrators and individual users.
2. Scope
This Policy applies across the TP-CAMP OneSuite ecosystem, including applications and services relating to:
- OneSuite account and workspace administration;
- Catalog;
- Splits;
- Operations;
- Invoice;
- Finance;
- AI-assisted functionality;
- connected integrations;
- administrative systems;
- APIs and application interfaces; and
- other OneSuite services introduced in the future.
Different components may use different technical infrastructure while remaining subject to TP-CAMP's overall security principles.
3. Security Principles
TP-CAMP seeks to design and operate OneSuite according to principles including:
Least privilege — users and systems should receive only the access reasonably required for their authorized functions.
Separation of customers — one customer's workspace should not provide access to another customer's private records without authorization.
Server-side authorization — important permissions should not depend solely on controls displayed in the user's browser.
Defense in depth — security should not depend on a single control where additional reasonable safeguards are appropriate.
Data minimization — information should not be unnecessarily collected, transmitted or exposed.
Secure defaults — sensitive functionality should default toward appropriately restricted access.
Auditability — important actions should be capable of being investigated where appropriate.
Resilience — systems should be designed to reduce the impact of errors, misuse and security incidents.
4. Customer Data
Customer Data may include information such as:
- account information;
- contact information;
- music catalogue metadata;
- songwriter and contributor information;
- publishing information;
- master ownership information;
- split information;
- rights registrations;
- music-industry identifiers;
- contracts and documents;
- project information;
- campaign information;
- invoices;
- financial records;
- payment-related records;
- communications;
- AI interactions; and
- other information processed through OneSuite.
TP-CAMP seeks to protect Customer Data according to its sensitivity, purpose and applicable technical environment.
5. Customer Ownership
TP-CAMP's security controls do not give TP-CAMP ownership of Customer Data.
Customers retain their applicable rights in their information and intellectual property as described in the Terms of Service and Copyright & Intellectual Property Policy.
TP-CAMP processes Customer Data to provide, secure, support and administer OneSuite and for other legitimate purposes described in applicable OneSuite policies.
6. Account Authentication
OneSuite uses authentication controls intended to restrict account access to authorized users.
Depending on the service and technical implementation, security measures may include:
- authenticated user accounts;
- secure session management;
- centralized identity controls;
- short-lived authorization mechanisms;
- application-specific sessions;
- entitlement verification; and
- server-side authorization checks.
TP-CAMP may modify authentication controls as technology and security requirements evolve.
7. Connected Application Security
OneSuite operates as an ecosystem of connected applications.
Connected applications may maintain separate technical sessions or infrastructure while relying on OneSuite for identity, workspace and entitlement information.
Cross-application access should be designed so that:
- the requesting user is appropriately authenticated;
- the destination application can verify authorization;
- access is limited to the intended application;
- authorization information has an appropriately limited lifetime where applicable; and
- sensitive server credentials are not intentionally exposed to ordinary users.
8. Authorization and Permissions
Authentication establishes who a user is.
Authorization determines what that user is permitted to do.
OneSuite may use role-based or permission-based controls to determine whether a user may:
- view information;
- create information;
- edit information;
- manage records;
- manage team members;
- access particular applications;
- perform administrative actions; or
- use other restricted functionality.
Important permissions may be verified by the server rather than relying solely on visible interface controls.
9. Workspace Isolation
OneSuite is intended to maintain logical separation between customer workspaces.
A user authorized for one workspace should not automatically receive access to another workspace.
TP-CAMP may use technical measures such as:
- workspace identifiers;
- authorization rules;
- database access controls;
- server-side validation;
- application permissions; and
- related safeguards
to support customer separation.
10. Team Access
Workspace owners and authorized administrators may be able to invite and manage team members.
Depending on available functionality, administrators may be able to:
- assign roles;
- grant application access;
- restrict permissions;
- suspend users;
- reactivate users; and
- remove users.
Customers are responsible for granting access only to persons who are appropriately authorized.
11. Least-Privilege Access
TP-CAMP seeks to limit access to sensitive systems and information according to legitimate operational need.
Access should not be granted merely because it may be convenient.
Administrative and technical access may be restricted according to role, responsibility and the nature of the system.
12. Server-Side Secrets and Credentials
Sensitive server credentials, integration secrets, API credentials and similar information should be stored and used in environments appropriate to their purpose.
TP-CAMP seeks to avoid intentionally exposing private server credentials in public application interfaces or client-side code where they are intended to remain confidential.
Users must not attempt to obtain, reveal or misuse OneSuite's private credentials.
13. Protection of Passwords and Credentials
Users are responsible for protecting their login credentials.
Users should:
- use strong passwords;
- avoid sharing credentials;
- restrict access to their devices;
- sign out from shared devices;
- promptly report suspected account compromise; and
- follow additional security controls made available by OneSuite.
TP-CAMP may require credential resets or other protective measures where compromise is suspected.
14. Session Security
OneSuite may use cookies, session identifiers, tokens or similar technologies to maintain authenticated sessions.
Session information may be limited by:
- expiration;
- application scope;
- server verification;
- revocation;
- secure storage practices; or
- other technical controls.
Further information concerning cookies and browser technologies is provided in the Cookie Policy.
15. Cross-Application Data Transfers
Certain OneSuite applications may exchange authorized information to provide connected workflows.
Examples may include exchanging:
- catalogue metadata;
- recording information;
- ownership information;
- split information;
- operational records;
- invoice information;
- finance-related information; or
- other authorized data.
Cross-application transfers may use security measures intended to help verify authenticity and integrity.
16. Integration Integrity
Where appropriate, OneSuite integrations may implement controls designed to reduce risks such as:
- unauthorized requests;
- forged requests;
- duplicate events;
- replayed requests;
- stale updates;
- unintended processing loops; and
- unauthorized workspace access.
The precise technical implementation may remain confidential for security reasons.
17. Audit and Security Records
TP-CAMP may maintain appropriate technical records concerning system activity.
Depending on the system, these may include records relating to:
- authentication;
- authorization;
- administrative actions;
- integration events;
- security events;
- payment events;
- account changes;
- system errors; and
- other activity reasonably necessary for security, troubleshooting, compliance or dispute investigation.
Audit information may be protected from unauthorized modification or access.
18. Encryption and Secure Transmission
Where appropriate and technically supported, TP-CAMP seeks to use industry-standard secure communication methods for data transmitted between users, OneSuite systems and service providers.
Encryption and secure transport reduce risk but cannot guarantee that a system will never be compromised.
19. Data at Rest
Customer information may be stored through databases, infrastructure providers or other systems supporting OneSuite.
TP-CAMP seeks to use service providers and configurations appropriate to the sensitivity and operational requirements of the information being processed.
The exact protections may vary according to the infrastructure and service involved.
20. Payment Security
OneSuite may use specialized third-party payment providers to process payments.
TP-CAMP seeks to avoid unnecessarily storing complete payment-card credentials where payment processing can be securely handled by the applicable payment provider.
Payment systems may use controls such as:
- provider-hosted payment interfaces;
- server-side transaction verification;
- transaction identifiers;
- webhook verification;
- duplicate-event protection;
- payment-status validation; and
- reconciliation controls.
21. Payment Information
Customers should not intentionally enter full payment-card credentials into ordinary OneSuite text fields, support messages or AI prompts unless a specific authorized payment interface expressly requests that information.
Payment credentials should be entered only through the designated payment process.
22. Financial Data
Invoice and Finance applications may contain commercially sensitive financial information.
Access to financial information should be restricted to appropriately authorized users.
Customers are responsible for managing their internal permissions and determining which team members should have access to financial records.
23. Music Rights Data
OneSuite may process commercially and legally significant music-rights information, including:
- writer information;
- publisher information;
- master ownership;
- contributor shares;
- registrations;
- society information;
- identifiers; and
- related rights records.
TP-CAMP recognizes that unauthorized modification of such information could have significant consequences.
OneSuite may therefore apply additional validation, permissions, historical records or synchronization safeguards to important rights information where appropriate.
24. Ownership Changes and Auditability
Where technically available, important ownership changes may be subject to controls such as:
- revision tracking;
- validation;
- authorization checks;
- historical records;
- duplicate protection; or
- other safeguards.
TP-CAMP may preserve historical information where reasonably necessary to investigate rights disputes or maintain data integrity.
25. Contracts and Documents
OneSuite may process contracts, split sheets and other business documents.
Access to such material should be limited to appropriately authorized users.
Where electronic-signature functionality is available, TP-CAMP may maintain technical records relating to execution or signing events where reasonably necessary for integrity, security and evidentiary purposes.
26. Artificial Intelligence Security
Certain OneSuite functionality may use third-party AI services.
Where AI is integrated into OneSuite, TP-CAMP seeks to limit access to information reasonably necessary for the applicable feature.
The existence of AI functionality does not mean an AI provider automatically receives unrestricted access to every customer's workspace.
Further details are provided in the AI Usage & Transparency Policy.
27. AI Credentials
Credentials used to communicate with external AI providers should be handled as sensitive information.
Users must not attempt to access, extract or misuse TP-CAMP's private AI service credentials.
28. CRM and Communication Systems
TP-CAMP may use third-party customer relationship management, email and communications services.
Access to such systems should be limited to appropriate business purposes.
Customer information transferred to those services should be limited to information reasonably necessary for the applicable purpose.
29. Third-Party Service Providers
TP-CAMP may rely on third-party providers for services such as:
- cloud infrastructure;
- database services;
- authentication;
- payment processing;
- artificial intelligence;
- customer relationship management;
- email;
- monitoring;
- communications; and
- other technical services.
TP-CAMP seeks to select and configure providers with consideration for security, reliability and the nature of the information involved.
No third-party provider can be guaranteed to be entirely free from security risk.
30. Third-Party Access
Use of a service provider does not give that provider unrestricted ownership of Customer Data.
Providers may process information where reasonably necessary to provide their services, subject to applicable contractual terms, provider policies and legal requirements.
31. Data Minimization
TP-CAMP seeks to avoid collecting or processing information that is unnecessary for the legitimate operation of OneSuite.
Users should similarly avoid entering unnecessary sensitive information into:
- general notes;
- support requests;
- AI prompts;
- description fields; or
- other areas not specifically designed for that information.
32. Privacy by Design
Where reasonably practical, TP-CAMP seeks to consider privacy and security when designing new functionality.
This may include considering:
- what information is required;
- who should have access;
- how permissions are enforced;
- how information moves between systems;
- whether information should be retained;
- what audit information is appropriate; and
- what safeguards are proportionate to the risk.
33. Secure Development
TP-CAMP seeks to incorporate reasonable security considerations into the development and maintenance of OneSuite.
Depending on the system and risk involved, this may include:
- access-control review;
- input validation;
- server-side authorization;
- secure handling of secrets;
- dependency management;
- error handling;
- security testing;
- vulnerability remediation; and
- review of material integrations.
34. Testing and Production Data
Where reasonably practical, TP-CAMP should avoid unnecessary exposure of live Customer Data during testing.
Where production information must be used to investigate a genuine technical problem, access should be limited to what is reasonably necessary.
35. Vulnerability Management
TP-CAMP may review identified vulnerabilities according to their severity, likelihood and potential impact.
Remediation priority may consider risks to:
- customer information;
- authentication;
- authorization;
- financial information;
- rights data;
- system availability; and
- OneSuite infrastructure.
36. Security Testing
TP-CAMP may perform or authorize security testing of OneSuite.
Users and third parties must not conduct intrusive security testing, exploit vulnerabilities or attempt unauthorized access without appropriate authorization.
Good-faith security concerns may be reported through official TP-CAMP support or security channels.
37. Security Monitoring
TP-CAMP may monitor appropriate technical signals to detect or investigate:
- suspicious authentication;
- unauthorized access;
- fraud;
- abuse;
- malicious requests;
- unusual system activity;
- integration failures;
- payment anomalies; and
- other potential security events.
Security monitoring should be proportionate to the legitimate purpose and handled consistently with applicable privacy requirements.
38. Security Incident
A security incident may include unauthorized access, disclosure, alteration, destruction or loss of information, or another event materially affecting the confidentiality, integrity or availability of OneSuite systems or data.
Not every technical error or service interruption constitutes a personal-data breach or material security incident.
39. Incident Response
Where TP-CAMP becomes aware of a suspected material security incident, TP-CAMP may take appropriate steps such as:
- identifying and assessing the incident;
- containing affected systems or functionality;
- restricting compromised access;
- preserving relevant evidence;
- rotating affected credentials;
- investigating the cause and scope;
- working with relevant service providers;
- correcting or mitigating vulnerabilities;
- restoring affected services;
- monitoring for recurrence; and
- providing legally required notifications where applicable.
The exact response will depend on the nature and severity of the incident.
40. Customer Notification
Where a security incident materially affects Customer Data, TP-CAMP will seek to provide appropriate notice where required by applicable law or where TP-CAMP determines that notification is reasonably necessary to help affected customers protect themselves.
A notice may include, where appropriate and known:
- the nature of the incident;
- affected systems or information;
- actions taken;
- recommended customer actions; and
- available support information.
TP-CAMP will not knowingly delay a legally required notification for the purpose of concealing a security incident.
41. Responsible Incident Communication
Security notifications must balance transparency with the need to:
- protect ongoing investigations;
- avoid exposing additional vulnerabilities;
- comply with legal requirements;
- protect affected customers; and
- coordinate with relevant providers or authorities.
TP-CAMP is not required to publicly disclose technical details that would materially increase security risk.
42. Customer Security Responsibilities
Security is a shared responsibility.
Customers and users are responsible for:
- protecting login credentials;
- maintaining secure devices;
- controlling team access;
- removing users who no longer require access;
- assigning appropriate permissions;
- reviewing suspicious activity;
- maintaining accurate contact information;
- avoiding unnecessary disclosure of sensitive information; and
- promptly reporting suspected compromise.
43. Workspace Administrator Responsibilities
Workspace owners and administrators have elevated responsibility for managing their organization's access.
Administrators should periodically review:
- active team members;
- assigned roles;
- application access;
- administrative permissions;
- former employees or contractors;
- shared accounts; and
- other access that may no longer be appropriate.
44. Compromised Accounts
Where TP-CAMP reasonably suspects that an account has been compromised, TP-CAMP may take protective action.
This may include:
- terminating active sessions;
- temporarily restricting access;
- requiring reauthentication;
- requiring credential changes;
- restricting sensitive actions;
- contacting the account owner; or
- suspending access while the matter is investigated.
Such action may be taken without advance notice where delay could increase security risk.
45. Emergency Security Measures
TP-CAMP may temporarily disable:
- an integration;
- a feature;
- an API;
- an account;
- a workspace;
- a payment function;
- an AI feature; or
- another affected service
where reasonably necessary to contain a credible security threat.
Security measures may take priority over ordinary availability where necessary to protect customers or OneSuite.
46. Fraud Prevention
TP-CAMP may use reasonable information and technical controls to detect or prevent:
- payment fraud;
- account takeover;
- false identities;
- unauthorized entitlements;
- fraudulent rights claims;
- abuse of trials;
- manipulated transactions;
- forged integration requests; and
- other misuse.
Suspected fraud may result in investigation, restriction or suspension consistent with the Terms of Service and Acceptable Use Policy.
47. Protection of TP-CAMP Infrastructure
Users must not attempt to:
- access administrative systems without authorization;
- obtain private credentials;
- bypass security controls;
- manipulate entitlement systems;
- access another customer's information;
- exploit vulnerabilities;
- disrupt service availability;
- inject malicious code;
- falsify integration requests; or
- interfere with audit or security records.
Such activity may result in immediate restriction or termination and may be referred to appropriate authorities where warranted.
48. Backups and Recovery
TP-CAMP or its infrastructure providers may maintain backups, replicas or recovery mechanisms appropriate to the systems involved.
Backups are intended primarily for service resilience and disaster recovery.
They should not be treated as a substitute for customers maintaining appropriate independent records of critical business information.
TP-CAMP does not guarantee that every individual record can always be restored from backup.
49. Business Continuity
TP-CAMP seeks to design OneSuite so that material service failures can be investigated and service restored within reasonable operational constraints.
Recovery priorities may consider:
- authentication;
- customer access;
- rights data;
- financial data;
- critical integrations;
- application availability; and
- security.
50. Data Integrity
TP-CAMP may implement safeguards designed to reduce accidental or unauthorized modification of important records.
These may include:
- validation;
- permission checks;
- revision controls;
- duplicate detection;
- event verification;
- audit information; and
- reconciliation processes.
No technical safeguard eliminates the need for users to verify important business and rights information.
51. Data Retention for Security
Certain security information may be retained after ordinary account activity ends where reasonably necessary for:
- fraud prevention;
- incident investigation;
- rights disputes;
- payment disputes;
- audit history;
- legal compliance;
- system integrity; or
- defense of legal claims.
Detailed retention principles are addressed in the Data Retention & Deletion Policy.
52. Account Closure and Security Records
Closing an account does not necessarily require immediate deletion of every technical record associated with that account.
TP-CAMP may retain limited records where reasonably necessary to:
- establish that an account existed;
- prevent fraud;
- preserve security history;
- comply with law;
- resolve disputes;
- maintain financial records; or
- protect TP-CAMP and its customers.
Retention does not give TP-CAMP ownership of the customer's underlying intellectual property.
53. Access to Customer Data by TP-CAMP Personnel
Authorized TP-CAMP personnel or contractors should access Customer Data only where reasonably necessary for legitimate purposes such as:
- customer support;
- troubleshooting;
- security;
- incident response;
- account administration;
- legal compliance; or
- other authorized operational purposes.
Access should be limited according to legitimate need.
54. Confidentiality
Persons authorized to access non-public Customer Data on behalf of TP-CAMP should be subject to appropriate confidentiality expectations or obligations.
Customer information must not be used for unrelated personal purposes.
55. Data Protection
Where TP-CAMP processes personal information, it seeks to do so according to applicable data-protection requirements and the principles described in the Privacy Policy.
These may include appropriate consideration of:
- lawful processing;
- purpose limitation;
- data minimization;
- accuracy;
- security;
- retention; and
- individual rights.
56. International Processing
OneSuite and its service providers may process information using infrastructure located outside the customer's country.
Where personal information is processed internationally, TP-CAMP seeks to use providers and arrangements appropriate to applicable legal requirements.
Further information is provided in the Privacy Policy.
57. Data Requests
Requests concerning access, correction or deletion of personal information should be handled according to the Privacy Policy, Data Retention & Deletion Policy and applicable law.
A request to delete personal information may be subject to legitimate exceptions where information must be retained for security, legal, financial, contractual or other lawful purposes.
58. Separation of Privacy and Security
Privacy and security are related but distinct.
Privacy concerns how information is collected, used, disclosed and retained.
Security concerns the safeguards used to protect information and systems.
TP-CAMP addresses both through its broader legal, technical and operational framework.
59. No Absolute Security Guarantee
No internet-based service, database, application, AI system or electronic communication method can be guaranteed to be completely secure.
TP-CAMP therefore does not represent that OneSuite is immune from every:
- vulnerability;
- attack;
- outage;
- unauthorized access attempt;
- third-party failure; or
- human error.
TP-CAMP's commitment is to use reasonable and proportionate safeguards and to respond appropriately when credible security risks are identified.
60. Security Information Is Confidential
TP-CAMP may withhold detailed information about security architecture where disclosure could:
- expose credentials;
- reveal exploitable weaknesses;
- facilitate attacks;
- compromise customers;
- weaken fraud controls; or
- otherwise materially increase risk.
This Policy is intended to explain TP-CAMP's security approach without publishing information that could undermine it.
61. Customer Security Assessments
Institutional or enterprise customers may request reasonable security information concerning OneSuite where necessary for their internal vendor review.
TP-CAMP may provide appropriate information at its discretion and may require confidentiality protections before disclosing non-public security documentation.
TP-CAMP is not required to disclose:
- passwords;
- private keys;
- API secrets;
- exploit information;
- proprietary source code;
- credentials;
- security information concerning other customers; or
- information that would materially weaken OneSuite security.
62. Security Reports From Researchers
TP-CAMP encourages responsible reporting of suspected security vulnerabilities.
A person reporting a vulnerability should avoid:
- accessing unnecessary Customer Data;
- modifying customer records;
- disrupting services;
- publicly disclosing an unremediated vulnerability;
- extortion;
- social engineering; or
- using a vulnerability for personal gain.
A report should contain sufficient information for TP-CAMP to investigate the issue.
63. Law Enforcement and Legal Process
TP-CAMP may preserve or disclose information where required by valid legal process or applicable law.
Where legally permitted and appropriate, TP-CAMP may assess requests for:
- validity;
- appropriate authority;
- scope; and
- relevance.
TP-CAMP does not provide unrestricted customer access merely because a third party requests information.
64. Security and Intellectual Property Disputes
Where a rights or ownership dispute involves allegations of unauthorized access or record manipulation, TP-CAMP may preserve relevant audit or security information.
TP-CAMP's preservation of technical evidence does not mean TP-CAMP has determined the ultimate legal ownership of the disputed intellectual property.
65. Security and Service Suspension
TP-CAMP may suspend or restrict access where reasonably necessary to protect:
- the affected customer;
- other customers;
- third parties;
- OneSuite infrastructure;
- payment systems;
- integrations; or
- TP-CAMP itself.
Where appropriate, access may be restored after the relevant risk has been addressed.
66. Security Does Not Override Mandatory Rights
Security controls will not be intentionally used to eliminate legal or privacy rights that cannot lawfully be excluded.
TP-CAMP may, however, require reasonable identity or authority verification before acting on a request involving sensitive information.
67. Relationship to Other Policies
This Security & Data Protection Policy forms part of TP-CAMP OneSuite's broader legal and security framework.
It should be read together with the:
- Terms of Service;
- Privacy Policy;
- Cookie Policy;
- Acceptable Use Policy;
- Copyright & Intellectual Property Policy;
- AI Usage & Transparency Policy;
- Refund Policy;
- Cancellation Policy; and
- Data Retention & Deletion Policy.
68. Changes to Security Controls
TP-CAMP may modify its security architecture, providers, controls and procedures without publishing every technical change.
This flexibility is necessary to:
- respond to new threats;
- improve protection;
- remediate vulnerabilities;
- change infrastructure;
- improve reliability; and
- adopt improved security technologies.
Material changes affecting customer privacy or contractual rights will be addressed through appropriate policy or contractual updates where required.
69. Changes to This Policy
TP-CAMP may update this Security & Data Protection Policy as:
- OneSuite develops;
- security practices evolve;
- new integrations are introduced;
- threats change;
- service providers change; or
- applicable legal requirements evolve.
The current version will display its effective or last-updated date.
Material changes may be communicated through the OneSuite website, application interface, email or another reasonable method.
70. Security Contact
Suspected account compromise, unauthorized access, security vulnerabilities or other security concerns should be reported promptly through the official TP-CAMP OneSuite support or security contact channel.
Users should provide sufficient information for TP-CAMP to identify and investigate the issue while avoiding unnecessary disclosure of sensitive information through insecure channels.
The current Security & Data Protection Policy will be available through the TP-CAMP OneSuite website.
