1.1 This Privacy Policy is issued by Dreamfo Technology Ltd ("Dreamfo", "we", "us", "our"), a limited company registered in Nigeria with the Corporate Affairs Commission under registration number RC 8474842, whose registered office is at E3-H1, Along 300,000 Kubwa Express Way, Abuja, FCT, Nigeria.
1.2 We operate the aistrobit platform at https://aistrobit.com. This is the identity and contact information required by GDPR Art 13(1)(a) and the transparency obligation under the Nigeria Data Protection Act 2023 (NDPA) §34, and reflects the ICO right-to-be-informed guidance.
1.3 General contact: admin@dreamfo.com.
1.4 Data protection contact / Data Protection Officer. Questions about this Policy or about how we handle personal data may be sent to admin@dreamfo.com. This is the contact point required by GDPR Art 13(1)(b) and Arts 37–39.
2.1 aistrobit is offered on two tiers, and our data-protection role differs between them. This distinction follows GDPR Art 4(7)/(8), Art 28, and the corresponding controller/processor definitions in the NDPA.
2.2 Our own data (we are the controller). For personal data about our account holders, website visitors, prospects, and our own newsletter subscribers, Dreamfo is the data controller, and this Privacy Policy governs.
2.3 Self-serve SaaS tier — client campaign data (we are the processor). When a client uses aistrobit to run its own campaigns, the client is the data controller of its subscriber lists and campaign data, and Dreamfo acts as a processor on the client's documented instructions under a Data Processing Agreement (GDPR Art 28). For that data, the client's own privacy notice governs, not this Policy. We process such data only as described in that DPA.
2.4 Managed service tier (we may be a controller or joint controller). Where Dreamfo runs campaigns on a client's behalf under a Master Services Agreement, Dreamfo may act as a controller or joint controller for certain activities. The applicable role is allocated in that agreement and, where the parties are joint controllers, in the GDPR Art 26 Joint Controller Responsibility Matrix at Annex A to the Master Services Agreement (Doc 7), which allocates transparency, data-subject-rights fulfilment, and breach-notification duties between Dreamfo and the client.
3.1 As controller (clause 2.2) we collect and process the following categories:
3.2 Where we act as processor (clause 2.3), the client determines what personal data is loaded into the platform; the categories above describe the platform's data model, but the client is the controller of that data.
3.3 Where personal data reaches us from a client or another source rather than directly from the individual, the additional transparency obligations of GDPR Art 14 apply and are met through the controller-client's own notice.
4.1 We rely on the following legal bases under GDPR Art 6 (and, for the platform in Nigeria, NDPA §25):
| Purpose | Legal basis |
|---|---|
| Providing the platform and performing our contract with the account holder | GDPR Art 6(1)(b) (contract); NDPA §25 |
| Sending marketing email to our own subscribers | GDPR Art 6(1)(a) (consent), read with the ePrivacy Directive Art 13 / PECR reg 22; NDPA §25/§26 |
| Security, fraud prevention, service improvement, and compliance | GDPR Art 6(1)(f) (legitimate interests); NDPA §25 |
| Meeting our legal obligations (e.g. tax, breach notification, honouring opt-outs) | GDPR Art 6(1)(c); NDPA §25 |
4.1a The lawful bases at NDPA §25 are given effect and operationalised by the NDPC General Application and Implementation Directive (GAID) 2025 (in force 19 September 2025), which is the controlling implementation instrument for the NDPA in 2026 and supersedes the earlier NDPR 2019. Where this Policy cites an NDPA section, that citation is to be read together with the corresponding GAID 2025 provisions.
4.2 We do not process special categories of data (GDPR Art 9) or CCPA "sensitive personal information" as part of the core service, and clients are prohibited from loading such data without a lawful basis (see the Acceptable Use Policy, Doc 4).
5.1 For marketing email to individuals in the EU, UK and Nigeria, consent is required and is obtained by enforced double opt-in: a subscriber's consent is recorded as confirmed (confirmed_at) only when the subscriber clicks a signed confirmation link that we send to the address provided. Consent that is not confirmed does not result in marketing email.
5.2 We retain, per subscriber, the consent timestamp, source and IP address as demonstrable evidence of consent. This satisfies GDPR Art 7 (consent must be freely given, specific, informed, unambiguous, and demonstrable), NDPA §26, and the ePrivacy Directive Art 13 / PECR reg 22 opt-in rule.
5.3 The consent standard differs by the recipient's jurisdiction; the jurisdiction-scoped rules are set out in clause 13 and in the Anti-Spam & Consent Policy (Doc 5).
6.1 We share personal data with service providers who act as our sub-processors, including hosting/infrastructure providers, our mail-transfer/relay provider, and our payment processor. This disclosure is made under GDPR Art 13(1)(e) / 14(1)(e).
6.2 A current list of sub-processors is available on request from admin@dreamfo.com and is maintained under the Data Processing Agreement (Doc 2).
7.1 Dreamfo is established in Nigeria and processes personal data there. Where personal data of individuals in the EU/EEA or the UK is used with the platform, it is transferred to Nigeria, a country that does not benefit from an EU adequacy decision or a UK adequacy determination (verified against the European Commission's adequacy list, on which Nigeria does not appear). This is a restricted transfer under GDPR Chapter V (Arts 44–49) and the equivalent UK GDPR provisions, and it is regulated at the Nigerian end by NDPA §41–43.
7.1a Direct applicability of GDPR (Art 3(2)) alongside the transfer analysis. Independently of Dreamfo's establishment in Nigeria, Dreamfo's position is that its processing in connection with the platform — offering a bulk-email service used to communicate with, and monitor the engagement of (opens/clicks, bounces, complaints), individuals in the EU and UK — may bring Dreamfo within the direct territorial scope of GDPR Art 3(2) / UK GDPR Art 3(2) (offering services to, or monitoring the behaviour of, data subjects in the EU/UK), regardless of whether Dreamfo has any EU or UK establishment. Direct applicability under Art 3(2) and the Chapter V restricted-transfer regime are not mutually exclusive: Art 3(2) determines whether GDPR applies to Dreamfo's processing at all, while Chapter V separately governs the export of personal data from the EU/UK to Dreamfo in Nigeria. Dreamfo's position is that both apply together here — GDPR governs Dreamfo's processing directly under Art 3(2), and the movement of that data from an EU/UK exporter to Dreamfo as a Nigeria-based importer is additionally a restricted transfer requiring the Art 46(2)(c) safeguards described at clause 7.2. This dual-basis position, including whether an Art 27 EU representative and a UK representative must be appointed as a consequence of Art 3(2) applying, is noted at clause 1.5.
7.2 Because no adequacy route is available, we rely on appropriate safeguards under GDPR Art 46(2)(c):
7.3 These safeguards are supported by a documented Transfer Impact Assessment and by supplementary measures including encryption in transit via TLS 1.2+ (TLS 1.3 where the peer supports it), access controls, and physical per-client isolation (clause 9). The Transfer Impact Assessment is set out in full at Annex D to the Data Processing Agreement (Doc 2).
7.4 You may obtain a copy of the safeguards relied on for a transfer by contacting admin@dreamfo.com. This disclosure and access right is provided under GDPR Art 13(1)(f) / 14(1)(f).
8.1 We keep personal data only as long as necessary for the purposes for which it was collected, in accordance with GDPR Art 5(1)(e) and Art 13(2)(a), and the storage-limitation principle of the NDPA. The retention periods (or the criteria used to set them) by data category are set out in our Data Retention & Breach Response Plan (Doc 6).
8.2 Our suppression list (addresses that have unsubscribed, bounced, or complained) is retained indefinitely so that we can continue to honour opt-outs and avoid re-contacting those individuals. This indefinite retention is justified as necessary to comply with the continuing opt-out-honouring obligations of CAN-SPAM 15 U.S.C. §7704(a)(3) and the equivalent objection right at GDPR Art 21(3), and is reasoned in full in the Data Retention & Breach Response Plan (Doc 6, Part A).
9.1 We implement technical and organisational measures appropriate to the risk, in accordance with GDPR Art 32 and NDPA §39. These include physical per-client isolation (each client's deployment runs on its own server and database, with its own DKIM key and suppression list, and no shared tenant identifier), encryption in transit, access controls, signed-token consent confirmation, and automated breach/abuse detection.
10.1 Where our marketing website sets cookies or similar technologies that are not strictly necessary, we do so only with your consent, in accordance with the ePrivacy Directive Art 5(3) and PECR reg 6. Details, and controls, are provided in our cookie notice where applicable.
11.1 Depending on where you are, you have some or all of the following rights. To exercise any of them, contact admin@dreamfo.com.
11.2 EU / UK (GDPR / UK GDPR Arts 15–22): access; rectification; erasure; restriction of processing; data portability; objection (including an absolute right to object to direct marketing); and rights relating to automated decision-making. You also have the right to lodge a complaint with a supervisory authority (GDPR Art 77) — in the UK, the Information Commissioner's Office (ICO); in the EU, your national data protection authority.
11.3 Nigeria (NDPA §34–38, as implemented by the GAID 2025): access (§34(1)(b)), rectification (§34(1)(c)), erasure (§34(1)(d)/(2)), withdrawal of consent (§35), objection including the absolute right to object to direct marketing (§36(3)), and data portability (§38). These statutory rights are given operational effect by the NDPC General Application and Implementation Directive (GAID) 2025, the controlling implementation instrument as of 2026. You may lodge a complaint with the Nigeria Data Protection Commission (NDPC).
11.4 California and other US states: see the US state-privacy addendum at clause 13.
12.1 aistrobit is not directed to children, and we do not knowingly collect personal data from children. Where consent of a child is relevant, we apply the age thresholds of GDPR Art 8 and the child-data provisions of the NDPA.
13.1 Framing (opt-out, not opt-in). For recipients in the United States, marketing email is governed by CAN-SPAM, which is an opt-out regime: prior consent is not required, but opt-outs must be honoured. Nothing in this Policy implies that US recipients gave prior opt-in consent, nor that EU/UK/Nigerian recipients may be emailed without consent.
13.2 California (CCPA/CPRA — Cal. Civ. Code §1798.100 et seq.). California residents have the right to know (§1798.100/.110/.115), delete (§1798.105), correct (§1798.106), opt out of the sale or sharing of personal information (§1798.120), limit the use of sensitive personal information, and to non-discrimination for exercising these rights (§1798.125). We do not sell personal information. We provide notice at collection as required.
13.3 Sensitive data. "Sensitive" is defined differently across regimes: GDPR Art 9 special categories differ from the CCPA definition of "sensitive personal information." We apply the stricter standard where both could apply.
13.4 Other US states (catch-all). Residents of other US states with comprehensive privacy laws (for example Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and others taking effect through 2026) may have similar rights to access, correct, delete, obtain a copy of, and opt out of certain processing of their personal data. To exercise any such right, contact admin@dreamfo.com.
14.1 We may update this Privacy Policy. The current version is identified below; where changes are material we will take reasonable steps to notify affected individuals.