It should be read with the BTR Partner Terms (https://partners.btrmusic.com/terms). Personal information about artists and listeners using BeatsToRapOn and BTR Music is covered by the Platform Privacy Policy at https://beatstorapon.com/privacy, not this notice.
1. Who this notice covers
This notice applies to personal information about:
- Partner Users — staff, contractors and representatives of a distributor, label, aggregator or other rights holder who use the Partner Services, sign agreements, or act as technical, rights, finance or legal contacts;
- Individuals named in deliveries — artists, featured artists, producers, songwriters, composers, performers, mixers, photographers, designers and other contributors whose names, roles, identifiers or images are included in metadata, credits, artwork or accompanying files;
- Complainants and correspondents — people who submit rights complaints, takedown notices, counter-notices or other correspondence relating to partner catalogue; and
- Verification subjects — directors, beneficial owners and signatories whose details are provided for partner verification, sanctions screening or payment set-up.
2. Personal information we collect
Account and identity
- name, job title, business email address, business phone number, employer or organisation, role in the Partner Portal, and the Partner Users you add or remove;
- organisation details that may identify individuals in the case of sole traders or small entities: business name, registration numbers (for example ABN, ACN or overseas equivalents), registered address, director and signatory names, and beneficial-ownership information where required for verification.
Credentials and access
- passwords (stored as salted hashes), multi-factor authentication settings, API key identifiers (keys are stored hashed), SSH/SFTP public keys, session tokens and login history.
Portal, API and SFTP activity
- IP addresses, timestamps, user-agent strings, request logs, actions taken in the Partner Portal (uploads, edits, takedowns, connection requests, user and key management), API and SFTP transfer logs, error logs and audit trails recording which Partner User did what.
Delivery data
- metadata contained in DDEX ERN messages and API submissions, including artist and contributor names, roles, artist identifiers (BTR Artist IDs, ISNI, IPI and proprietary identifiers where supplied), label and publisher names, P and C lines, biographies, artwork that may depict identifiable people, and any contact details included in delivery files or messages.
Commercial and payment
- bank account or PayPal details, remittance contacts, tax identification numbers, tax residency and treaty documents, invoices, payment history, withholding records and statements.
Communications
- support requests, QC-flag discussions, dispute correspondence, takedown and counter-notice correspondence, meeting notes and emails exchanged with BTR.
Compliance
- results of sanctions, anti-money-laundering and fraud screening, verification documents you provide, and records of any investigation into artificial streaming, infringement or breach of the Partner Terms.
Cookies and device information
- see section 14. The Partner Portal uses only strictly necessary and preference cookies. It does not use advertising cookies or cross-site tracking.
We do not require sensitive information (such as health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric or criminal-record information) to provide the Partner Services. Please do not include it in deliveries, metadata, artwork descriptions or correspondence.
3. Where we collect it from
- directly from Partner Users when they register, use the Partner Portal, send deliveries, or contact us;
- from the partner organisation when it nominates users, contacts and payment details;
- automatically from your devices and our systems through logs, cookies and API/SFTP activity;
- from delivery files, which may contain personal information about third parties supplied by the partner;
- from artists who confirm or dispute a partner connection through their own BTR account;
- from rights holders, complainants, collective management organisations and their representatives;
- from payment, tax, verification and sanctions-screening providers; and
- from public registers and published sources used to verify a partner's identity, registration or authority.
4. How we use it and the legal basis
Where the GDPR, UK GDPR or a similar law applies, our legal basis for each purpose is shown. Under the Australian Privacy Act 1988 (Cth) we collect and use personal information only where reasonably necessary for the functions and activities below.
| Purpose | Examples | Legal basis (where required) |
|---|---|---|
| Operate the Partner Services | create and manage partner accounts and users, authenticate logins, issue and rotate API/SFTP credentials, provide the Partner Portal dashboard | performance of a contract; legitimate interests |
| Verify partners | confirm identity, registration, authority over catalogue and connection to artists; screen against sanctions lists | legal obligation; legitimate interests; performance of a contract |
| Ingest, review and publish catalogue | validate deliveries, run content-integrity and rights checks, resolve QC flags, publish approved content with credits and metadata, process updates and takedowns | performance of a contract; legitimate interests |
| Report and pay | generate usage reports, calculate and pay royalties, issue or receive invoices, apply withholding tax, keep financial records | performance of a contract; legal obligation |
| Keep the service secure | detect unauthorised access, fraud, artificial streaming, malware and abuse; keep audit trails | legitimate interests; legal obligation |
| Handle rights complaints and disputes | receive and process notices and counter-notices, preserve evidence, respond to regulators and courts | legal obligation; legitimate interests |
| Communicate with partners | service notices, delivery acknowledgements, QC and takedown notices, changes to terms, support | performance of a contract; legitimate interests |
| Partner announcements and marketing | occasional news about the Partner Services or BTR Music to partner contacts | legitimate interests, with opt-out; consent where required |
| Improve the Partner Services | analyse portal usage, error rates and support requests to fix problems and plan features | legitimate interests |
| Comply with law | tax, accounting, sanctions, anti-money-laundering, consumer, copyright and privacy obligations; respond to lawful requests | legal obligation |
We do not use partner personal information for behavioural advertising, and we do not sell it.
5. Automated decision-making
The Partner Services use automated systems that may make, or substantially assist in making, decisions that affect partners and the individuals named in deliveries. We disclose this in line with the Australian Privacy Principles as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth), and Article 22 of the GDPR/UK GDPR where applicable.
| Automated process | Kinds of information used | Kinds of decision it can make or assist |
|---|---|---|
| Delivery validation | DDEX/API metadata, identifiers, BTR Artist IDs, partner–artist connection records | accept, reject or hold a delivery; reject deliveries for artists not connected to the partner |
| Audio content-integrity scanning | audio transcripts generated by speech-to-text, language detection, classification scores, short evidence excerpts | hold or reject a recording containing embedded advertising, off-platform redirection or third-party tags; route ambiguous cases to human review |
| Duplicate and rights matching | audio fingerprints, ISRCs, UPCs, titles, artist names, prior delivery history | flag or merge duplicate recordings; hold conflicting ownership claims |
| Artificial-streaming and fraud detection | streaming logs, device and account signals on the listener side, play patterns, account history | exclude streams from usage reports; withhold payment for affected content pending review; suspend an artist connection |
| Sanctions and verification screening | partner and signatory names, addresses, registration details | delay or refuse account activation or payment pending manual review |
| AI-generated content detection | audio signal analysis, disclosure fields supplied in deliveries | label content to listeners; exclude from recommendation surfaces; apply royalty rules stated in the Partner Terms |
High-confidence detections may trigger automated operational action. Decisions that materially affect a partner's account, payment or an artist's connection are reviewed by BTR staff before becoming final, or on request. You may ask for human review of any automated outcome, and for an explanation of the general logic involved, by using the dispute function in the Partner Portal or by contacting us (section 17).
6. Who we disclose it to
We disclose personal information only where needed for the purposes in section 4, to:
- Service providers acting for us: cloud hosting, database and storage providers; content delivery and media processing; email and notification delivery; speech-to-text, classification and AI-assisted moderation providers; fraud, sanctions and verification screening providers; payment, payout and tax-compliance providers; customer-support tooling; security and monitoring services; and professional advisers (lawyers, accountants, auditors, insurers). Providers are bound by contract to use the information only for the services they perform for us.
- Approved Artists: an artist sees the partner's organisation name, connection status and which of their recordings a partner has delivered. We do not show artists your Partner Users' personal details other than an organisation-level contact where you nominate one.
- Collective management organisations and rights registries where required to license or account for musical works, or to resolve conflicting claims: work and recording metadata, contributor names and identifiers, and aggregated usage.
- Rights holders and complainants where reasonably necessary to investigate or resolve an infringement or ownership dispute: the identity of the delivering partner and the relevant delivery metadata.
- Regulators, courts, law enforcement and government agencies where required by law, court order or a lawful request, including the Australian Taxation Office, the Office of the Australian Information Commissioner, and equivalent bodies overseas.
- App-store and platform providers only to the extent delivery metadata is displayed in the BTR Music apps.
- A buyer or successor in a merger, acquisition, financing or sale of the BTR business, under confidentiality.
7. What we send to partners
- Usage reports (DDEX DSR) contain aggregated play counts by recording, release, territory, use type and period. They never contain listener names, identifiers, device details or locations.
- Dashboard analytics are aggregated and may be bucketed or delayed to prevent re-identification of listeners.
- QC, rights and takedown notices may identify the complainant or rights holder where the law permits and it is necessary for you to respond.
We do not provide partners with access to listener accounts or listener-level data, and partners must not attempt to re-identify listeners from any information we provide.
8. Public display of delivery metadata
Catalogue metadata you deliver — artist names, featured-artist names, contributor credits, label names, biographies, artwork and P/C lines — is published to listeners in the BTR Music mobile app as part of ordinary catalogue display. It may be shown in in-app search results, playlists, charts, artist profiles and scenes, in share links and link previews that open the app, and in BTR's own promotional channels. Partner Content is not published on beatstorapon.com. Partners are responsible for ensuring the individuals named have been informed and that the partner is entitled to supply the information (section 13).
9. International transfers
BTR is based in Australia. Our servers and service providers are located in Australia, the United States and [●other regions]. Personal information may therefore be stored or accessed outside the country where you are located, including outside the European Economic Area and the United Kingdom.
Where required, we rely on contractual protections such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and we take reasonable steps under Australian Privacy Principle 8 to ensure overseas recipients handle personal information in a way that is consistent with the Australian Privacy Principles. Details of the mechanism used for a particular transfer are available on request.
10. Retention
| Category | Retention |
|---|---|
| Partner account, users and contacts | For the term of the partner relationship and [●24] months after termination, then deleted or de-identified |
| Credentials and access logs | Credentials deleted on revocation; access and audit logs kept [●24] months |
| API/SFTP transfer logs and delivery acknowledgements | [●24] months |
| Delivery metadata and credits | While the content is live, plus as long as needed for royalty accounting, audit and dispute resolution (at least 7 years after the last reporting period in which the content earned royalties) |
| Usage reports, invoices, payment and tax records | 7 years from the end of the relevant financial year, as required by Australian tax and corporations law |
| Verification and sanctions-screening records | For the term of the relationship plus 7 years, as required by applicable anti-money-laundering and sanctions law |
| Rights complaints, takedown and dispute records | For as long as needed to resolve the matter, defend claims and enforce repeat-infringer measures, then reviewed for deletion |
| Support and general correspondence | [●24] months after the matter closes |
| Backups | Rolled off within [●90] days of deletion from live systems |
Information may be kept longer where a legal hold, investigation, dispute or regulatory requirement applies.
11. Security and data breaches
We protect personal information with measures including encryption in transit, hashed storage of passwords and API keys, key-based SFTP access, role-based access control within partner organisations, multi-factor authentication where enabled, audit logging, network segregation of pre-release content, rate limiting, monitoring and staff access controls. No system is completely secure; partners must protect their own credentials and devices.
If a data breach occurs that is likely to result in serious harm to individuals, we will assess and notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and comply with breach-notification obligations under the GDPR, UK GDPR and other applicable laws. We will notify affected partners without undue delay where a breach involves their Partner Users, credentials or unreleased content, as set out in the Partner Terms.
12. Your rights and choices
Everyone. You may ask us to access or correct personal information we hold about you. We will respond within 30 days, may need to verify your identity or authority, and may refuse or limit a request where the law permits (for example, where information is subject to legal privilege or a legal hold, or where it is commercially sensitive information about the partner organisation).
EEA, UK and Switzerland. Where the GDPR or UK GDPR applies you also have rights to erasure, restriction, objection (including to processing based on legitimate interests and to direct marketing), data portability, withdrawal of consent, and rights in relation to automated decision-making described in section 5. You may complain to your local supervisory authority.
United States. Where a state privacy law applies, you may have rights to know, access, correct, delete and port personal information and to opt out of sale, sharing or targeted advertising. We do not sell or share personal information for cross-context behavioural advertising. We do not discriminate against you for exercising a right.
Other regions. We will honour rights available under the privacy law of your location.
Marketing. Partner contacts may opt out of announcements and marketing at any time using the unsubscribe link or by contacting us. Service notices, delivery acknowledgements, takedown and security notices are not marketing and cannot be opted out of while the partner account is active.
Partner Users. Requests about your own personal information may be made directly to us. Requests to change organisation-level records (users, payment details, contacts) must come from an authorised Partner User.
13. Partner responsibilities
By supplying personal information to BTR through the Partner Services, the partner confirms that it:
- has a lawful basis to provide the personal information of its Partner Users and of the individuals named in its deliveries, and has given them any notice required by applicable law, including a reference to this notice;
- has the right to supply artwork depicting identifiable people and the credits and biographies it delivers;
- will not deliver sensitive information, or personal information not needed for catalogue delivery and display;
- will keep its Partner Users, contacts and payment details accurate and current, and remove users promptly when their authority ends;
- will pass on to BTR, without delay, any access, correction or deletion request it receives from an individual that relates to information held by BTR; and
- will not attempt to re-identify listeners or use any information received from BTR for a purpose other than administering its catalogue and receiving payment.
Where a partner uses the Partner API to build its own tooling, the partner is responsible for the privacy compliance of that tooling.
14. Cookies and similar technologies
The Partner Portal uses:
- strictly necessary cookies for login sessions, CSRF protection and security;
- preference cookies to remember settings such as language, table layout and dismissed notices; and
- first-party, server-side analytics to measure portal performance and errors.
The Partner Portal does not use advertising cookies, third-party analytics SDKs or cross-site tracking. You can block cookies in your browser, but login will not work without strictly necessary cookies.
15. Children
The Partner Services are for business users aged 18 and over. We do not knowingly collect personal information from anyone under 18 through the Partner Portal. Where delivery metadata names an artist or contributor under 18, the partner is responsible for holding the consents required to publish that information.
16. Changes to this notice
We may update this notice from time to time. We will post the updated version at https://partners.btrmusic.com/privacy, change the "Last updated" date, and, for material changes, notify partner contacts by email and in the Partner Portal at least 30 days before the change takes effect where practicable.
17. Contact and complaints
Privacy officer: [●name or role], OUTERMARK GROUP PTY LTD, Level 1, 446 Oxford St, Bondi Junction NSW 2022, Australia.
Email: info@beatstorapon.com [●or partners@btrmusic.com]
We will acknowledge complaints within 7 days and aim to resolve them within 30 days. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au), or, if you are in the EEA or UK, to your local data-protection authority.
EU/UK representative: [●appoint if BTR regularly processes EEA/UK personal data at scale; otherwise remove this line].