Legal Policy
Privacy Policy
This Privacy Policy explains how Bookbloom LLC (“Bookbloom,” “we,” “us”) collects, uses, shares, and protects personal data when you use Knovia (knovia.co) and related services (the “Platform”). It is intended for a global user base and addresses rights under the Nigeria Data Protection Act 2023 (NDPA), UK GDPR, EU GDPR, and the California Consumer Privacy Act / CPRA (CCPA) where those laws apply.
Last updated: August 2026
1. Who We Are
The data controller for personal data processed through the Platform is Bookbloom LLC, a limited liability company organised under the laws of the United States of America. Knovia is our consumer brand.
Knovia LTD (Nigeria) may act as a local payment-operations entity and, where applicable, as a processor or sub-processor for payment-related processing. It is not the contracting party for Platform use under the Terms of Service.
For privacy enquiries and to exercise your data-protection rights, contact us at privacy@knovia.co. That is the channel we use for privacy correspondence under this Policy.
2. Data We Collect — Buyers
Depending on how you use the Platform, we may collect:
- Account data: Name or display name, email address, password credentials (stored hashed), country or locale preferences, and account timestamps.
- Purchase and payment metadata: Products or services purchased, amounts, currencies, timestamps, status, and payment references. We do not store full card numbers or CVV. Card data is handled by licensed payment providers.
- Access and delivery records: Evidence that digital content or services were delivered or accessed (for example session timing, pages or segments accessed, online vs offline use). Used to operate the service, apply refund rules, and respond to payment disputes.
- Device and security data: Limited device and browser signals, IP address, and similar technical data used for account security, abuse prevention, and enforcing published access limits (such as device limits). Not used to build advertising profiles.
- Reviews and support: Ratings, review text, and messages you send to support.
- Cookies and similar tech: As described in Section 11 and our Cookie Policy.
3. Data We Collect — Educators and Ambassadors
In addition to relevant buyer-type data, educators (and ambassadors where applicable) may provide:
- Identity data: Legal name, date of birth, nationality, residential address, phone number, and government ID type/number (stored with heightened protections).
- Verification materials: Images or documents used to verify identity (for example a hold-up photo with ID) and, where offered, institutional email or employment/credential documents for enhanced verification.
- Public profile data: Academic brands, bios, storefront content, and listing metadata you choose to publish.
- Payout data: Bank or wallet details needed to pay you (encrypted; masked in product UI where shown).
- Commercial records: Earnings, fees, withdrawals, subscription tier history, tax-relevant transaction records, and related audit trails.
- Change history: Records of changes to locked identity fields, retained for security and compliance.
Legal name and government ID are used for verification, payouts, compliance, and transactional notices — not as your default public marketplace identity (academic brands are used publicly where you set them).
4. What We Do Not Collect
- Nigeria BVN: We do not collect Bank Verification Numbers.
- Full payment card data: We never store full PAN/CVV on our systems.
- Advertising profiles: We do not sell personal information for cross-site advertising or build ad profiles from your reading behaviour. With consent (Accept all), we may use advertising and measurement platforms for campaign delivery and analytics as described in the Cookie Policy.
- Biometric templates: Hold-up photos are used for identity verification; we do not create biometric templates for marketing or unrelated matching.
- Institutional email for marketing: If provided solely for institutional verification, it is not used for general Platform marketing after the verification step.
5. Why We Process Data (Lawful Bases)
Where GDPR/UK GDPR or similar regimes apply, we rely on one or more of: contract, legitimate interests, legal obligation, and consent. Under the NDPA, we process data for lawful purposes consistent with that Act.
| Purpose | Typical basis |
|---|---|
| Provide accounts, authentication, and core Platform features | Contract |
| Process purchases, deliver access, and handle refunds/cancellations | Contract |
| Verify educator identity and run KYC/AML-related checks | Legal obligation / Contract |
| Pay educators and ambassadors; keep financial records | Contract / Legal obligation |
| Fraud, abuse, chargeback, and security prevention | Legitimate interests / Legal obligation |
| Content integrity and marketplace trust (including reviews) | Legitimate interests |
| Transactional and service emails | Contract |
| Optional marketing communications | Consent (withdraw anytime) |
| Cookies beyond strictly necessary (where required) | Consent |
| Respond to lawful requests and protect legal rights | Legal obligation / Legitimate interests |
6. Who We Share Data With
We share personal data only as needed to operate the Platform, comply with law, or with your direction. Recipients fall into these categories (we do not publish a full public vendor directory; the operational list is maintained internally under data-processing agreements):
- Payment processing providers — collect buyer payments and disburse educator / ambassador payouts across supported regions.
- Identity verification providers — process verification images/documents; images are deleted or retained only as required after the verification outcome, per Section 9.
- Cloud infrastructure and hosting providers — host application, database, and file storage.
- Security, CDN, and bot-protection providers — protect the Platform and deliver assets.
- Email delivery providers — send transactional and (if consented) marketing messages.
- Customer support and live chat providers — process help requests and (when you start a live chat during staffed hours) live chat transcripts and contact details needed to respond. Chatwoot stores handed-off threads per their retention (Hacker plan: 30 days) even though Knovia does not keep the in-product Help bubble transcript (that stays in your browser tab only). Chat is optional and may be offline outside 10:00–18:00 WAT, Monday to Saturday; tickets may include limited account context (role, path) without government ID images or bank details.
- Help-chat language model — when you use Knovia Help, the message you send is processed by an AI provider (Anthropic) for that request so we can answer from Help articles. Knovia does not store that bubble transcript. Identity-verification photos use a separate flow and never enter Help chat.
- Content screening providers — help detect infringing or policy-violating content (typically content text/files, not unnecessary identity data).
- Error monitoring and analytics providers — reliability and performance; configured to minimise personal data and scrub sensitive fields where practicable.
- Advertising and measurement platforms — only after you choose Accept all; used for analytics, conversion measurement, and consented advertising/retargeting. Vendor names appear in the Cookie Policy.
- Search and indexing providers — power marketplace discovery and search where used.
- Professional advisers and authorities — lawyers, auditors, or regulators when required or appropriate.
- Corporate successors — in a merger, acquisition, or asset transfer, subject to continued confidentiality obligations.
We do not sell personal information as that term is commonly understood under the CCPA. Cross-context advertising measurement or retargeting cookies/pixels load only after you choose Accept all; choosing Essential only keeps those tags off.
7. Sensitive Data Protections
- Government ID numbers and payout account details are stored with industry-standard encryption and access controls; payout details are masked in product UI (for example last four digits).
- Verification images are transmitted securely to verification processors and are not treated as public content.
- Data in transit is protected with HTTPS/TLS. Data at rest is encrypted using industry-standard methods.
- Access by personnel is limited to operational need and is logged. Client-facing error reports are scrubbed to avoid exposing government IDs, verification images, or full bank details.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port your data; to object to certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority (for example the Nigeria Data Protection Commission / NDPC, or an EU/UK data protection authority).
California (CCPA/CPRA): You may have rights to know, delete, correct, and opt out of sale/sharing. We do not sell personal information. Advertising measurement or retargeting cookies/pixels load only after Accept all; Essential only (or the Cookie Policy preference reset) turns them off. We will not discriminate against you for exercising CCPA rights.
To exercise rights, email privacy@knovia.co with your name, account email, and request. We aim to respond within 14 days (or sooner if a shorter period is mandatory). We may need to verify your identity. Reasonable requests are free of charge.
Some identity fields are locked after educator verification and can only be changed through support with documentation, as described in the Terms of Service.
9. Erasure and Retention
When you request account deletion, we delete or anonymise personal data that is no longer needed, typically within 30 days, except where retention is required or permitted by law or necessary for disputes, security, or financial compliance.
| Category | Typical retention |
|---|---|
| Account profile data after deletion request | Deleted/anonymised within ~30 days (subject to exceptions below) |
| Purchase, payout, and financial records | About 7 years (tax/audit/legal) |
| Identity / KYC records | About 7 years from collection or as required by law/providers |
| Hold-up / verification images | Deleted when verification completes, unless retention is required for fraud, dispute, or legal reasons |
| Access / delivery logs | About 2 years from the relevant activity, or longer if a dispute remains open |
| Locked-field change history and security audit logs | Longer-term / as needed for security and compliance |
| Reviews | While the listing exists; may retain anonymised or aggregated forms |
10. International Transfers
The Platform is global. Personal data may be processed in the United States and other countries where we or our service providers operate (including payment corridors relevant to your transactions).
Where required, we use appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms under the NDPA, UK GDPR, and/or EU GDPR. Details of specific transfer tools are maintained in our internal records of processing, not as a public vendor catalogue.
Your NDPA, GDPR, and other statutory rights are not waived merely because processing occurs outside your country.
12. Security Breach Notification
If a personal data breach poses a risk to individuals' rights and freedoms, we will notify the appropriate supervisory authority within applicable deadlines (including the NDPA's 72-hour expectation where it applies, and UK/EU GDPR timelines where they apply) and notify affected users without undue delay when the law requires or when risk to them is high.
13. Children
The Platform is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we learn that we have, we will delete the account and related data promptly.
Users aged 13–17 may use the Platform only with parental or guardian consent, as required at registration. Contact privacy@knovia.co if you believe a child under 13 has registered.
14. Institutional and Employer Requests
We will not disclose whether a person has an account, or other user data, to academic institutions, employers, or third parties in response to informal requests.
We may disclose data when required by court order, binding legal process, or applicable law, or when necessary to process payments, prevent fraud/abuse, enforce our Terms, or protect rights and safety — consistent with Section 6 and the Terms of Service.
Educators remain responsible for complying with their own employment or institutional rules. We are not liable for institutional consequences of an educator's decision to use the Platform.
15. Automated Decisions
We use automated and semi-automated tools for security, fraud prevention, content screening, and verification routing. These tools do not, on their own, produce legal effects equivalent to denying fundamental rights without human review pathways for material adverse outcomes (for example failed verification may enter manual review). You may contact privacy@knovia.co to contest a decision that significantly affects you.
16. Changes to This Policy
We may update this Policy. For material changes affecting your rights or how we use data, we will give at least 14 days' notice by email and/or in-product notice where reasonably practicable. Continued use after the effective date constitutes acceptance. Non-material updates may take effect when posted.
17. Contact
Data Controller
Bookbloom LLC · Knovia · privacy@knovia.co
Global service. NDPA 2023, UK/EU GDPR, and CCPA rights apply where those laws cover you. Knovia LTD (Nigeria) may support payment operations and is not the Platform contracting party.