BTR · BTR Music · Partners · Legal · Privacy

Partner Privacy Notice.

This notice is issued by OUTERMARK GROUP PTY LTD (ACN 699 247 277) of Level 1, 446 Oxford St, Bondi Junction NSW 2022, Australia, operator of BTR Music and BeatsToRapOn ("BTR", "we", "us"). It explains how we collect, use, disclose, store and protect personal information in connection with the BTR Partner Portal at partners.btrmusic.com, the Partner API and SFTP endpoints, partner onboarding, catalogue deliveries and usage reporting (together, the Partner Services).

Version 1.0 · Last updated · 23 September 2026 · New South Wales, Australia

Quick version. We collect the details needed to run a partner account, verify who you are, take deliveries, pay you and keep the service secure. Delivery metadata such as artist and contributor names is published in BTR Music as part of the catalogue. Usage reports we send you are aggregated and never contain listener personal information. We do not sell personal information. Some checks on deliveries and streams are automated; you can ask for human review.

Partner users

Names, business contact details, roles, credentials, portal and API activity, verification and payment details for the people who run your partner account.

Delivery data

Artist and contributor names, identifiers, credits and artwork in your DDEX and API deliveries are published in the BTR Music app as catalogue metadata.

Your control

Access and correction rights for everyone. GDPR, UK GDPR and US state-law rights where they apply. Human review of any automated decision on request.

It should be read with the BTR Partner Terms (https://partners.btrmusic.com/terms). Personal information about artists and listeners using BeatsToRapOn and BTR Music is covered by the Platform Privacy Policy at https://beatstorapon.com/privacy, not this notice.


1. Who this notice covers

This notice applies to personal information about:

2. Personal information we collect

Account and identity
- name, job title, business email address, business phone number, employer or organisation, role in the Partner Portal, and the Partner Users you add or remove;
- organisation details that may identify individuals in the case of sole traders or small entities: business name, registration numbers (for example ABN, ACN or overseas equivalents), registered address, director and signatory names, and beneficial-ownership information where required for verification.

Credentials and access
- passwords (stored as salted hashes), multi-factor authentication settings, API key identifiers (keys are stored hashed), SSH/SFTP public keys, session tokens and login history.

Portal, API and SFTP activity
- IP addresses, timestamps, user-agent strings, request logs, actions taken in the Partner Portal (uploads, edits, takedowns, connection requests, user and key management), API and SFTP transfer logs, error logs and audit trails recording which Partner User did what.

Delivery data
- metadata contained in DDEX ERN messages and API submissions, including artist and contributor names, roles, artist identifiers (BTR Artist IDs, ISNI, IPI and proprietary identifiers where supplied), label and publisher names, P and C lines, biographies, artwork that may depict identifiable people, and any contact details included in delivery files or messages.

Commercial and payment
- bank account or PayPal details, remittance contacts, tax identification numbers, tax residency and treaty documents, invoices, payment history, withholding records and statements.

Communications
- support requests, QC-flag discussions, dispute correspondence, takedown and counter-notice correspondence, meeting notes and emails exchanged with BTR.

Compliance
- results of sanctions, anti-money-laundering and fraud screening, verification documents you provide, and records of any investigation into artificial streaming, infringement or breach of the Partner Terms.

Cookies and device information
- see section 14. The Partner Portal uses only strictly necessary and preference cookies. It does not use advertising cookies or cross-site tracking.

We do not require sensitive information (such as health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric or criminal-record information) to provide the Partner Services. Please do not include it in deliveries, metadata, artwork descriptions or correspondence.

3. Where we collect it from

Where the GDPR, UK GDPR or a similar law applies, our legal basis for each purpose is shown. Under the Australian Privacy Act 1988 (Cth) we collect and use personal information only where reasonably necessary for the functions and activities below.

Purpose Examples Legal basis (where required)
Operate the Partner Services create and manage partner accounts and users, authenticate logins, issue and rotate API/SFTP credentials, provide the Partner Portal dashboard performance of a contract; legitimate interests
Verify partners confirm identity, registration, authority over catalogue and connection to artists; screen against sanctions lists legal obligation; legitimate interests; performance of a contract
Ingest, review and publish catalogue validate deliveries, run content-integrity and rights checks, resolve QC flags, publish approved content with credits and metadata, process updates and takedowns performance of a contract; legitimate interests
Report and pay generate usage reports, calculate and pay royalties, issue or receive invoices, apply withholding tax, keep financial records performance of a contract; legal obligation
Keep the service secure detect unauthorised access, fraud, artificial streaming, malware and abuse; keep audit trails legitimate interests; legal obligation
Handle rights complaints and disputes receive and process notices and counter-notices, preserve evidence, respond to regulators and courts legal obligation; legitimate interests
Communicate with partners service notices, delivery acknowledgements, QC and takedown notices, changes to terms, support performance of a contract; legitimate interests
Partner announcements and marketing occasional news about the Partner Services or BTR Music to partner contacts legitimate interests, with opt-out; consent where required
Improve the Partner Services analyse portal usage, error rates and support requests to fix problems and plan features legitimate interests
Comply with law tax, accounting, sanctions, anti-money-laundering, consumer, copyright and privacy obligations; respond to lawful requests legal obligation

We do not use partner personal information for behavioural advertising, and we do not sell it.

5. Automated decision-making

The Partner Services use automated systems that may make, or substantially assist in making, decisions that affect partners and the individuals named in deliveries. We disclose this in line with the Australian Privacy Principles as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth), and Article 22 of the GDPR/UK GDPR where applicable.

Automated process Kinds of information used Kinds of decision it can make or assist
Delivery validation DDEX/API metadata, identifiers, BTR Artist IDs, partner–artist connection records accept, reject or hold a delivery; reject deliveries for artists not connected to the partner
Audio content-integrity scanning audio transcripts generated by speech-to-text, language detection, classification scores, short evidence excerpts hold or reject a recording containing embedded advertising, off-platform redirection or third-party tags; route ambiguous cases to human review
Duplicate and rights matching audio fingerprints, ISRCs, UPCs, titles, artist names, prior delivery history flag or merge duplicate recordings; hold conflicting ownership claims
Artificial-streaming and fraud detection streaming logs, device and account signals on the listener side, play patterns, account history exclude streams from usage reports; withhold payment for affected content pending review; suspend an artist connection
Sanctions and verification screening partner and signatory names, addresses, registration details delay or refuse account activation or payment pending manual review
AI-generated content detection audio signal analysis, disclosure fields supplied in deliveries label content to listeners; exclude from recommendation surfaces; apply royalty rules stated in the Partner Terms

High-confidence detections may trigger automated operational action. Decisions that materially affect a partner's account, payment or an artist's connection are reviewed by BTR staff before becoming final, or on request. You may ask for human review of any automated outcome, and for an explanation of the general logic involved, by using the dispute function in the Partner Portal or by contacting us (section 17).

6. Who we disclose it to

We disclose personal information only where needed for the purposes in section 4, to:

7. What we send to partners

We do not provide partners with access to listener accounts or listener-level data, and partners must not attempt to re-identify listeners from any information we provide.

8. Public display of delivery metadata

Catalogue metadata you deliver — artist names, featured-artist names, contributor credits, label names, biographies, artwork and P/C lines — is published to listeners in the BTR Music mobile app as part of ordinary catalogue display. It may be shown in in-app search results, playlists, charts, artist profiles and scenes, in share links and link previews that open the app, and in BTR's own promotional channels. Partner Content is not published on beatstorapon.com. Partners are responsible for ensuring the individuals named have been informed and that the partner is entitled to supply the information (section 13).

9. International transfers

BTR is based in Australia. Our servers and service providers are located in Australia, the United States and [●other regions]. Personal information may therefore be stored or accessed outside the country where you are located, including outside the European Economic Area and the United Kingdom.

Where required, we rely on contractual protections such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and we take reasonable steps under Australian Privacy Principle 8 to ensure overseas recipients handle personal information in a way that is consistent with the Australian Privacy Principles. Details of the mechanism used for a particular transfer are available on request.

10. Retention

Category Retention
Partner account, users and contacts For the term of the partner relationship and [●24] months after termination, then deleted or de-identified
Credentials and access logs Credentials deleted on revocation; access and audit logs kept [●24] months
API/SFTP transfer logs and delivery acknowledgements [●24] months
Delivery metadata and credits While the content is live, plus as long as needed for royalty accounting, audit and dispute resolution (at least 7 years after the last reporting period in which the content earned royalties)
Usage reports, invoices, payment and tax records 7 years from the end of the relevant financial year, as required by Australian tax and corporations law
Verification and sanctions-screening records For the term of the relationship plus 7 years, as required by applicable anti-money-laundering and sanctions law
Rights complaints, takedown and dispute records For as long as needed to resolve the matter, defend claims and enforce repeat-infringer measures, then reviewed for deletion
Support and general correspondence [●24] months after the matter closes
Backups Rolled off within [●90] days of deletion from live systems

Information may be kept longer where a legal hold, investigation, dispute or regulatory requirement applies.

11. Security and data breaches

We protect personal information with measures including encryption in transit, hashed storage of passwords and API keys, key-based SFTP access, role-based access control within partner organisations, multi-factor authentication where enabled, audit logging, network segregation of pre-release content, rate limiting, monitoring and staff access controls. No system is completely secure; partners must protect their own credentials and devices.

If a data breach occurs that is likely to result in serious harm to individuals, we will assess and notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and comply with breach-notification obligations under the GDPR, UK GDPR and other applicable laws. We will notify affected partners without undue delay where a breach involves their Partner Users, credentials or unreleased content, as set out in the Partner Terms.

12. Your rights and choices

Everyone. You may ask us to access or correct personal information we hold about you. We will respond within 30 days, may need to verify your identity or authority, and may refuse or limit a request where the law permits (for example, where information is subject to legal privilege or a legal hold, or where it is commercially sensitive information about the partner organisation).

EEA, UK and Switzerland. Where the GDPR or UK GDPR applies you also have rights to erasure, restriction, objection (including to processing based on legitimate interests and to direct marketing), data portability, withdrawal of consent, and rights in relation to automated decision-making described in section 5. You may complain to your local supervisory authority.

United States. Where a state privacy law applies, you may have rights to know, access, correct, delete and port personal information and to opt out of sale, sharing or targeted advertising. We do not sell or share personal information for cross-context behavioural advertising. We do not discriminate against you for exercising a right.

Other regions. We will honour rights available under the privacy law of your location.

Marketing. Partner contacts may opt out of announcements and marketing at any time using the unsubscribe link or by contacting us. Service notices, delivery acknowledgements, takedown and security notices are not marketing and cannot be opted out of while the partner account is active.

Partner Users. Requests about your own personal information may be made directly to us. Requests to change organisation-level records (users, payment details, contacts) must come from an authorised Partner User.

13. Partner responsibilities

By supplying personal information to BTR through the Partner Services, the partner confirms that it:

Where a partner uses the Partner API to build its own tooling, the partner is responsible for the privacy compliance of that tooling.

14. Cookies and similar technologies

The Partner Portal uses:

The Partner Portal does not use advertising cookies, third-party analytics SDKs or cross-site tracking. You can block cookies in your browser, but login will not work without strictly necessary cookies.

15. Children

The Partner Services are for business users aged 18 and over. We do not knowingly collect personal information from anyone under 18 through the Partner Portal. Where delivery metadata names an artist or contributor under 18, the partner is responsible for holding the consents required to publish that information.

16. Changes to this notice

We may update this notice from time to time. We will post the updated version at https://partners.btrmusic.com/privacy, change the "Last updated" date, and, for material changes, notify partner contacts by email and in the Partner Portal at least 30 days before the change takes effect where practicable.

17. Contact and complaints

Privacy officer: [●name or role], OUTERMARK GROUP PTY LTD, Level 1, 446 Oxford St, Bondi Junction NSW 2022, Australia.

Email: info@beatstorapon.com [●or partners@btrmusic.com]

We will acknowledge complaints within 7 days and aim to resolve them within 30 days. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au), or, if you are in the EEA or UK, to your local data-protection authority.

EU/UK representative: [●appoint if BTR regularly processes EEA/UK personal data at scale; otherwise remove this line].