MRAA Privacy Policy

Effective Date: July 24, 2026
Last Updated: July 24, 2026

1. Introduction

This Privacy Policy explains how the MRAA program, the website located at mraa.me, its membership portal, certification system, payment center, public certification database, and related services collect, use, disclose, retain, and protect information.

MRAA is operated by KLM Enterprises Services LLC. In this policy, “MRAA,” “we,” “our,” and “us” refer to KLM Enterprises Services LLC when operating MRAA services.

By using an MRAA website, creating an account, submitting an application, requesting certification, making a payment, uploading documentation, or otherwise interacting with MRAA, you acknowledge this Privacy Policy.

2. Information We Collect

MRAA may collect the following categories of information.

A. Contact and identity information

This may include:

  • Legal name

  • Professional, artist, stage, brand, or business name

  • Email address

  • Mailing address

  • Telephone number

  • Date of birth or age-confirmation information

  • Account username

  • Identity-verification information

  • Authorized representative information

B. Membership and application information

This may include:

  • Applicant category

  • Individual, artist, label, company, influencer, brand, or industry-professional information

  • Biography and professional profile

  • Employment, role, credit, or project information

  • Membership application answers

  • Approval, denial, suspension, and renewal records

  • Communications with MRAA staff

C. Certification information

Depending on the applicant type, this may include:

  • Artist and release information

  • Song, album, EP, campaign, brand, or project titles

  • ISRC, UPC, catalog number, release date, distributor, and label

  • Platform names and profile URLs

  • Campaign dates, reach, engagement, credits, achievements, and analytics

  • Royalty statements, distributor reports, platform reports, screenshots, agreements, invoices, campaign records, or other supporting materials

  • Certification decisions, levels, dates, certificate numbers, and review notes

D. Payment information

Payments may be processed by third-party payment providers.

MRAA may receive:

  • Payment status

  • Amount paid

  • Transaction identifier

  • Billing name and address

  • Payment method type

  • Refund, dispute, or chargeback information

MRAA generally does not receive or store complete payment-card numbers or card security codes when payment is processed by an independent payment provider.

E. Uploaded documents

Applicants may upload identification, contracts, licenses, reports, statements, screenshots, analytics, release documentation, business documents, or other supporting evidence.

Applicants must not upload Social Security numbers, full payment-card numbers, bank passwords, medical information, or unrelated sensitive personal information unless MRAA specifically requests it through a secure process.

F. Website and device information

When a person visits or uses MRAA services, MRAA may automatically collect:

  • Internet Protocol address

  • Browser and device type

  • Operating system

  • Referring page

  • Pages viewed

  • Date and time of access

  • Login activity

  • General geographic region

  • Cookie or similar technology identifiers

  • Security, fraud-prevention, and error-log information

3. How We Use Information

MRAA may use information to:

  • Process membership applications

  • Verify applicant identity and eligibility

  • Review supporting documentation

  • Process certification requests

  • Determine an appropriate certification level

  • Create and administer member accounts

  • Process payments and issue receipts

  • Communicate about applications, memberships, certification requests, renewals, payments, and account security

  • Request additional documentation

  • Detect false, altered, misleading, duplicate, or unauthorized submissions

  • Prevent fraud, abuse, unauthorized access, and policy violations

  • Maintain internal review and audit records

  • Issue certificates, recognition records, and awards

  • Publish authorized certification information

  • Improve MRAA services and website performance

  • Comply with legal obligations

  • Establish, exercise, or defend legal claims

  • Enforce MRAA policies and agreements

4. Public Certification Records

Certification is intended to provide public recognition and independent verification.

When an applicant receives certification, MRAA may publish approved professional information such as:

  • Artist, professional, business, influencer, brand, label, or recipient name

  • Project, release, campaign, or achievement title

  • Cover artwork or approved image

  • Certification level

  • Certification number

  • Certification date

  • ISRC, UPC, label, company, or distributor

  • Approved performance metric or milestone

  • Certificate or award recipient

  • Public profile or biography

MRAA will not intentionally publish private identification documents, complete payment information, private contracts, residential addresses, account passwords, internal review notes, or raw supporting documents unless publication is required by law or separately authorized.

Applicants may be asked to approve public-facing information before publication. MRAA may preserve the public record of a certification after membership expires.

5. How We Disclose Information

MRAA may disclose information to the following parties.

A. Service providers

MRAA may use companies that provide:

  • Website hosting

  • Cloud storage

  • Email delivery

  • Payment processing

  • Fraud prevention

  • Customer support

  • Website analytics

  • Security monitoring

  • Document processing

  • Accounting or professional services

  • Award production and shipping

These providers may use information only for contracted services or as permitted by their disclosed terms and applicable law.

B. Professional advisers

Information may be provided to attorneys, accountants, auditors, insurers, consultants, or other advisers when reasonably necessary.

C. Legal and safety purposes

MRAA may disclose information when reasonably necessary to:

  • Comply with a subpoena, court order, legal process, or government request

  • Investigate fraud, infringement, or false documentation

  • Protect MRAA, its applicants, members, staff, partners, or the public

  • Enforce an agreement or policy

  • Respond to a rights owner or authorized representative

  • Establish, exercise, or defend legal claims

D. Business transactions

Information may be transferred as part of a merger, acquisition, financing, reorganization, sale of assets, or transfer of the MRAA program, subject to applicable law.

6. Sale and Targeted Advertising

MRAA does not sell personal information for money.

MRAA may use analytics, advertising, social-media, or measurement technologies that may be treated as sharing, targeted advertising, or a similar regulated activity under certain privacy laws.

Where required, visitors may be provided with cookie controls or a method to opt out. MRAA will honor legally recognized browser-based opt-out signals where required by applicable law and technically supported.

7. Data Retention

MRAA retains information for as long as reasonably necessary to:

  • Process an application or request

  • Maintain membership and certification records

  • Preserve the integrity of public certification records

  • Detect repeat, fraudulent, or conflicting submissions

  • Resolve payment disputes

  • Enforce agreements

  • Satisfy accounting, tax, legal, and regulatory obligations

  • Defend legal claims

Retention periods may differ depending on the type of record. MRAA may retain a limited record of a denied, revoked, suspended, or fraudulent submission after other documents are deleted.

8. Data Security

MRAA uses reasonable administrative, technical, and organizational safeguards designed to protect information.

These safeguards may include:

  • Restricted staff access

  • Password protection

  • Encryption in transit

  • Security monitoring

  • Access logs

  • Secure payment processors

  • Document-access controls

  • Backups

  • Authentication and account-verification procedures

No website, storage system, or electronic transmission can be guaranteed completely secure. Applicants are responsible for using strong passwords, protecting login credentials, and promptly reporting suspected unauthorized access.

9. Privacy Rights

Depending on a person’s location and applicable law, that person may have the right to request:

  • Access to personal information

  • Correction of inaccurate information

  • Deletion of certain information

  • A portable copy of certain information

  • Restriction of certain processing

  • Withdrawal of consent

  • Opt-out from certain targeted advertising or data sharing

  • Review of a decision made through qualifying automated processing

  • Appeal of a denied privacy request

Some information may be exempt from deletion or disclosure when it must be retained for security, fraud prevention, accounting, certification integrity, legal compliance, or legal claims.

Privacy requests may be sent to support@mraa.me. MRAA may verify the requester’s identity before completing the request.

Authorized agents may submit requests where permitted by law, but MRAA may require proof of authorization and identity.

MRAA will not unlawfully discriminate against a person for exercising an applicable privacy right.

10. Children and Minors

MRAA services are not directed to children under 13, and MRAA does not knowingly collect personal information directly from children under 13.

A person under 18 may submit an application only with the involvement and authorization of a parent, legal guardian, or legally authorized representative where required.

If MRAA learns that information was collected from a child in violation of applicable law, MRAA may delete the information and close the related account or application.

11. International Users

MRAA is operated from the United States. Information submitted from another country may be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in the user’s jurisdiction.

12. Third-Party Websites and Services

MRAA services may link to payment providers, social-media platforms, streaming services, analytics providers, distributors, retailers, framers, award producers, or other third parties.

MRAA is not responsible for the privacy practices, security, availability, or content of independent third parties. Users should review each provider’s privacy policy before submitting information.

13. Changes to This Policy

MRAA may update this Privacy Policy to reflect changes in its services, technology, business practices, or legal obligations.

The revised policy will be posted with an updated effective date. Material changes may also be communicated by email, account notice, or website announcement when appropriate.

14. Contact Information

Privacy questions or requests may be directed to:

MRAA — Privacy
Operated by KLM Enterprises Services LLC
P.O. Box 140572
Kansas City, Missouri 64114
United States
Email: support@mraa.me

MRAA Privacy Policy

Contact MRAA

© 2024–2026 Music Recognition Awards and Accolades Association of America, operating as a KLM Enterprises Services LLC company. All rights reserved.

VIEW LEGAL