Loading...

Discover the top creators platform on the market! Learn more

Privacy Policy

Last Updated: 03-05-2025

Privacy Policy

1. Introduction

BD Dreamer Ltd ("we", "us", "our") operates the influencer marketing platform BD Dreamer. We are registered in England and Wales (Company No: [Insert Number]) and comply with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)

2. Information We Collect

2.1 Personal Data

We collect when you:

  • Register as an influencer: Name, email, phone number, social media handles, engagement metrics, payment details
  • Register as a brand: Company name, contact details, VAT number, payment information
  • Use our platform: IP address, device information, browser type

2.2 Special Category Data

We do not intentionally collect:

  • Racial/ethnic origin
  • Political opinions
  • Religious beliefs
  • Health data
  • Sexual orientation

3. How We Use Your Data

Purpose Legal Basis
Account creation & management Contractual necessity
Payment processing Legal obligation
Campaign matching Legitimate interest
Marketing communications Consent
Platform improvements Legitimate interest

4. Data Sharing & Transfers

We share data with:

  • Payment processors (Stripe, PayPal) - encrypted transactions only
  • HMRC for tax compliance
  • Influencers/Brands strictly for campaign fulfilment
  • Sub-processors under GDPR-compliant contracts

All data remains in the UK/EEA unless adequate safeguards are in place.

5. Data Retention

We retain data for:

  • Active accounts: Until deletion request
  • Financial records: 6 years (UK tax law)
  • Inactive accounts: 2 years then anonymized

6. Your Rights

Under UK GDPR, you have the right to:

  1. Access your data (free SAR within 30 days)
  2. Rectify inaccuracies
  3. Request erasure
  4. Restrict processing
  5. Data portability
  6. Object to processing
  7. Withdraw consent

Contact our DPO: dpo@bddreamer.co.uk

ICO Complaint: ico.org.uk/make-a-complaint

7. Security Measures

We implement:

  • AES-256 encryption
  • Regular penetration testing
  • Two-factor authentication
  • Staff GDPR training

8. Changes to This Policy

We will notify users of material changes via email 30 days in advance.