Skip to content

Privacy Policy

What we collect, why, how long we keep it and how to have it deleted. Written to the Republic of Belarus Law No. 99-Z on Personal Data Protection.

Last updated 9/7/2026

1. Who processes your data

Beatium is a beat discovery service: producers publish tracks, buyers listen and message them directly. The data operator is the owner of the service; anything about this policy goes to support@709614.site.

Terms are used as defined by Law No. 99-Z. This policy covers both the website and the Beatium mobile app — one service, one account.

2. What we process

Only what the service cannot run without:

  • Account: email address, name or handle, phone (optional), a password hash — the password itself is never stored and cannot be recovered.
  • Profile: avatar, bio, links to your own storefronts (Telegram, VK, BeatStars and the like).
  • Content and activity: uploaded beats and their metadata, likes, comments, follows, and listening history — which is what ranks your feed.
  • Messages: the text of direct messages, who is in the conversation, timestamps and read receipts.
  • Technical: IP address (abuse protection and view counting), session and token identifiers, client type.
  • Consent record: the version of the User Agreement you accepted, the date, and whether you consented to personal-data processing.

3. Why, and on what basis

  • Registration and sign-in, including email confirmation — performance of the contract with you, and your consent.
  • Marketplace features: publishing beats, search, the feed, likes, comments, follows — performance of the contract.
  • Direct messages between users — performance of the contract, and your consent.
  • Moderation of uploads and handling of reports — legitimate interest and statutory requirements.
  • Security: protection against password guessing, spam and abuse, and rate limiting — legitimate interest.

We show no advertising, sell nothing to ad networks, and build no profiles for third parties.

4. Direct messages

Messages are stored on the server in plain form: there is no end-to-end encryption. That means they are technically accessible to the operator, and it is stated plainly here because there is no honest way to imply otherwise. Privacy of correspondence is protected by art. 28 of the Constitution of the Republic of Belarus; the content of messages is accessed only on a request from a participant, to handle a report, or where the law requires it.

Do not send anything through chat that should not sit on someone else’s server: card details, passwords, documents.

5. How long we keep it

  • Account data, profile, beats and messages — for as long as the account exists. Deleting the account deletes them.
  • Unconfirmed registrations and one-time codes (email confirmation, password reset) — hours, expiring with the code.
  • Technical logs and abuse-protection data — a limited period needed to investigate incidents; passwords, tokens and message bodies are stripped from logs.
  • The consent record is kept while the account exists and, after deletion, only as far as needed to evidence that consent was given.

6. Who else sees it

We do not sell personal data. The only processors involved are the ones the service runs on:

  • Google LLC (USA) — Google sign-in, if you use it, and delivery of service email (address confirmation, password reset).
  • Amazon Web Services — servers and storage.
  • Publicly visible is only what you publish yourself: name, handle, avatar, bio, links, beats and comments. Your email address and phone number are never shown to other users.

7. Cross-border transfer

The processors named above are outside the Republic of Belarus, so a cross-border transfer takes place (art. 9 of Law No. 99-Z). It is made on the basis of the consent given at registration, and only to the extent the corresponding feature requires.

8. Your rights

Under chapter 3 of Law No. 99-Z you may:

  • Obtain information about the processing and a copy of your data — on request to the address below, answered within 5 working days.
  • Correct inaccurate data — in your profile, or on request, within 15 days.
  • Withdraw consent and demand that processing stop and the data be deleted — by deleting the account in the app, or on request, within 15 days.
  • Obtain information about disclosures of your data to third parties — on request, within 15 days.
  • Complain to the National Personal Data Protection Center (cpd.by) and to a court.

9. How to make a request

Email support@709614.site from the address on the account — that is how we can tell the request comes from the person whose data it is. Say which right you are exercising: a copy, a correction, deletion, or disclosure information.

10. How the data is protected

  • The connection to the server is TLS only; the app refuses cleartext connections.
  • Passwords are stored as hashes (bcrypt), access is separated by role, and sessions are short-lived tokens with rotation.
  • Passwords, tokens and other sensitive fields are stripped from logs.
  • Uploads are validated, and request rates are limited both per account and per address.

11. Cookies and local storage

There are no advertising or analytics cookies. One session cookie is used (httpOnly, unreadable by scripts) — without it you cannot stay signed in. Browser local storage holds your own settings only: language, message drafts, the unread counter. All of it is cleared when you sign out or clear site data.

12. Age

The service is not for anyone under 16, or under the age of digital consent in their country. Such an account is deleted if found.

13. Breaches

If the protection of personal data is breached, the operator notifies the National Personal Data Protection Center without delay and within three working days of becoming aware of it (art. 16 of Law No. 99-Z), and notifies affected users where required.

14. Changes

The current version always lives at this address. Material changes are announced in the service; the date of the last change is at the top of this page.

Questions about this document: support@709614.site

User Agreement