Legal Policy

Privacy Policy

This Privacy Policy explains how Bookbloom LLC (“Bookbloom,” “we,” “us”) collects, uses, shares, and protects personal data when you use Knovia (knovia.co) and related services (the “Platform”). It is intended for a global user base and addresses rights under the Nigeria Data Protection Act 2023 (NDPA), UK GDPR, EU GDPR, and the California Consumer Privacy Act / CPRA (CCPA) where those laws apply.

Last updated: August 2026

1. Who We Are

The data controller for personal data processed through the Platform is Bookbloom LLC, a limited liability company organised under the laws of the United States of America. Knovia is our consumer brand.

Knovia LTD (Nigeria) may act as a local payment-operations entity and, where applicable, as a processor or sub-processor for payment-related processing. It is not the contracting party for Platform use under the Terms of Service.

For privacy enquiries and to exercise your data-protection rights, contact us at privacy@knovia.co. That is the channel we use for privacy correspondence under this Policy.

2. Data We Collect — Buyers

Depending on how you use the Platform, we may collect:

  • Account data: Name or display name, email address, password credentials (stored hashed), country or locale preferences, and account timestamps.
  • Purchase and payment metadata: Products or services purchased, amounts, currencies, timestamps, status, and payment references. We do not store full card numbers or CVV. Card data is handled by licensed payment providers.
  • Access and delivery records: Evidence that digital content or services were delivered or accessed (for example session timing, pages or segments accessed, online vs offline use). Used to operate the service, apply refund rules, and respond to payment disputes.
  • Device and security data: Limited device and browser signals, IP address, and similar technical data used for account security, abuse prevention, and enforcing published access limits (such as device limits). Not used to build advertising profiles.
  • Reviews and support: Ratings, review text, and messages you send to support.
  • Cookies and similar tech: As described in Section 11 and our Cookie Policy.

3. Data We Collect — Educators and Ambassadors

In addition to relevant buyer-type data, educators (and ambassadors where applicable) may provide:

  • Identity data: Legal name, date of birth, nationality, residential address, phone number, and government ID type/number (stored with heightened protections).
  • Verification materials: Images or documents used to verify identity (for example a hold-up photo with ID) and, where offered, institutional email or employment/credential documents for enhanced verification.
  • Public profile data: Academic brands, bios, storefront content, and listing metadata you choose to publish.
  • Payout data: Bank or wallet details needed to pay you (encrypted; masked in product UI where shown).
  • Commercial records: Earnings, fees, withdrawals, subscription tier history, tax-relevant transaction records, and related audit trails.
  • Change history: Records of changes to locked identity fields, retained for security and compliance.

Legal name and government ID are used for verification, payouts, compliance, and transactional notices — not as your default public marketplace identity (academic brands are used publicly where you set them).

4. What We Do Not Collect

  • Nigeria BVN: We do not collect Bank Verification Numbers.
  • Full payment card data: We never store full PAN/CVV on our systems.
  • Advertising profiles: We do not sell personal information for cross-site advertising or build ad profiles from your reading behaviour. With consent (Accept all), we may use advertising and measurement platforms for campaign delivery and analytics as described in the Cookie Policy.
  • Biometric templates: Hold-up photos are used for identity verification; we do not create biometric templates for marketing or unrelated matching.
  • Institutional email for marketing: If provided solely for institutional verification, it is not used for general Platform marketing after the verification step.

6. Who We Share Data With

We share personal data only as needed to operate the Platform, comply with law, or with your direction. Recipients fall into these categories (we do not publish a full public vendor directory; the operational list is maintained internally under data-processing agreements):

  • Payment processing providers — collect buyer payments and disburse educator / ambassador payouts across supported regions.
  • Identity verification providers — process verification images/documents; images are deleted or retained only as required after the verification outcome, per Section 9.
  • Cloud infrastructure and hosting providers — host application, database, and file storage.
  • Security, CDN, and bot-protection providers — protect the Platform and deliver assets.
  • Email delivery providers — send transactional and (if consented) marketing messages.
  • Customer support and live chat providers — process help requests and (when you start a live chat during staffed hours) live chat transcripts and contact details needed to respond. Chatwoot stores handed-off threads per their retention (Hacker plan: 30 days) even though Knovia does not keep the in-product Help bubble transcript (that stays in your browser tab only). Chat is optional and may be offline outside 10:00–18:00 WAT, Monday to Saturday; tickets may include limited account context (role, path) without government ID images or bank details.
  • Help-chat language model — when you use Knovia Help, the message you send is processed by an AI provider (Anthropic) for that request so we can answer from Help articles. Knovia does not store that bubble transcript. Identity-verification photos use a separate flow and never enter Help chat.
  • Content screening providers — help detect infringing or policy-violating content (typically content text/files, not unnecessary identity data).
  • Error monitoring and analytics providers — reliability and performance; configured to minimise personal data and scrub sensitive fields where practicable.
  • Advertising and measurement platforms — only after you choose Accept all; used for analytics, conversion measurement, and consented advertising/retargeting. Vendor names appear in the Cookie Policy.
  • Search and indexing providers — power marketplace discovery and search where used.
  • Professional advisers and authorities — lawyers, auditors, or regulators when required or appropriate.
  • Corporate successors — in a merger, acquisition, or asset transfer, subject to continued confidentiality obligations.

We do not sell personal information as that term is commonly understood under the CCPA. Cross-context advertising measurement or retargeting cookies/pixels load only after you choose Accept all; choosing Essential only keeps those tags off.

7. Sensitive Data Protections

  • Government ID numbers and payout account details are stored with industry-standard encryption and access controls; payout details are masked in product UI (for example last four digits).
  • Verification images are transmitted securely to verification processors and are not treated as public content.
  • Data in transit is protected with HTTPS/TLS. Data at rest is encrypted using industry-standard methods.
  • Access by personnel is limited to operational need and is logged. Client-facing error reports are scrubbed to avoid exposing government IDs, verification images, or full bank details.

8. Your Rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your data; to object to certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority (for example the Nigeria Data Protection Commission / NDPC, or an EU/UK data protection authority).

California (CCPA/CPRA): You may have rights to know, delete, correct, and opt out of sale/sharing. We do not sell personal information. Advertising measurement or retargeting cookies/pixels load only after Accept all; Essential only (or the Cookie Policy preference reset) turns them off. We will not discriminate against you for exercising CCPA rights.

To exercise rights, email privacy@knovia.co with your name, account email, and request. We aim to respond within 14 days (or sooner if a shorter period is mandatory). We may need to verify your identity. Reasonable requests are free of charge.

Some identity fields are locked after educator verification and can only be changed through support with documentation, as described in the Terms of Service.

9. Erasure and Retention

When you request account deletion, we delete or anonymise personal data that is no longer needed, typically within 30 days, except where retention is required or permitted by law or necessary for disputes, security, or financial compliance.

CategoryTypical retention
Account profile data after deletion requestDeleted/anonymised within ~30 days (subject to exceptions below)
Purchase, payout, and financial recordsAbout 7 years (tax/audit/legal)
Identity / KYC recordsAbout 7 years from collection or as required by law/providers
Hold-up / verification imagesDeleted when verification completes, unless retention is required for fraud, dispute, or legal reasons
Access / delivery logsAbout 2 years from the relevant activity, or longer if a dispute remains open
Locked-field change history and security audit logsLonger-term / as needed for security and compliance
ReviewsWhile the listing exists; may retain anonymised or aggregated forms

10. International Transfers

The Platform is global. Personal data may be processed in the United States and other countries where we or our service providers operate (including payment corridors relevant to your transactions).

Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms under the NDPA, UK GDPR, and/or EU GDPR. Details of specific transfer tools are maintained in our internal records of processing, not as a public vendor catalogue.

Your NDPA, GDPR, and other statutory rights are not waived merely because processing occurs outside your country.

11. Cookies

We use cookies and similar technologies that are necessary to run the Platform (for example authentication and security), limited functional cookies such as referral attribution and consent records, and — only after you choose Accept all — marketing measurement and advertising cookies or pixels. We do not sell personal information. Advertising and measurement platforms are processors for those purposes; vendor names and tag details appear in our Cookie Policy.

Full cookie descriptions and controls are in our Cookie Policy. Blocking essential cookies may prevent login or checkout. You can change marketing consent via the Cookie Policy preference link.

12. Security Breach Notification

If a personal data breach poses a risk to individuals' rights and freedoms, we will notify the appropriate supervisory authority within applicable deadlines (including the NDPA's 72-hour expectation where it applies, and UK/EU GDPR timelines where they apply) and notify affected users without undue delay when the law requires or when risk to them is high.

13. Children

The Platform is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we learn that we have, we will delete the account and related data promptly.

Users aged 13–17 may use the Platform only with parental or guardian consent, as required at registration. Contact privacy@knovia.co if you believe a child under 13 has registered.

14. Institutional and Employer Requests

We will not disclose whether a person has an account, or other user data, to academic institutions, employers, or third parties in response to informal requests.

We may disclose data when required by court order, binding legal process, or applicable law, or when necessary to process payments, prevent fraud/abuse, enforce our Terms, or protect rights and safety — consistent with Section 6 and the Terms of Service.

Educators remain responsible for complying with their own employment or institutional rules. We are not liable for institutional consequences of an educator's decision to use the Platform.

15. Automated Decisions

We use automated and semi-automated tools for security, fraud prevention, content screening, and verification routing. These tools do not, on their own, produce legal effects equivalent to denying fundamental rights without human review pathways for material adverse outcomes (for example failed verification may enter manual review). You may contact privacy@knovia.co to contest a decision that significantly affects you.

16. Changes to This Policy

We may update this Policy. For material changes affecting your rights or how we use data, we will give at least 14 days' notice by email and/or in-product notice where reasonably practicable. Continued use after the effective date constitutes acceptance. Non-material updates may take effect when posted.

17. Contact

Privacy and data-rights requests:

privacy@knovia.co

Legal: legal@knovia.co

Data Controller

Bookbloom LLC · Knovia · privacy@knovia.co

Global service. NDPA 2023, UK/EU GDPR, and CCPA rights apply where those laws cover you. Knovia LTD (Nigeria) may support payment operations and is not the Platform contracting party.

Privacy Policy — Knovia