Privacy Policy
Last updated: 30 April 2026
Certiva LLC, a Michigan limited liability company, trading as “Certiva Publishers” · 24566 Jade Dr, Farmington Hills, Michigan 48336 · hello@certivapublishers.com · (810) 522-4879
1. Who we are and what this covers
Certiva LLC, a Michigan limited liability company trading as "Certiva Publishers" ("Certiva," "we," "us"), provides author and self-publishing services. This policy explains what personal information we collect, why, what we do with it, and what rights you have.
It covers certivapublishers.com and our services. It does not cover third-party websites we link to, or retailers such as Amazon, Apple Books, Barnes & Noble, Kobo, or IngramSpark, which have their own policies.
Data controller. For the purposes of the UK and EU General Data Protection Regulation, Certiva LLC is the controller of the personal information described here. Contact details are in section 14.
2. The short version
- We collect what we need to publish your book and run our business. Not more.
- We do not sell your personal information.
- We do not use your manuscript to train AI models, and we do not sell or license it to anyone who would.
- We keep your unpublished manuscript confidential.
- Our website sets no advertising or analytics cookies and runs no tracking pixels.
- You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Email hello@certivapublishers.com and we will respond within 30 days.
3. What we collect
3.1 Information you give us
| Category | Examples |
|---|---|
| Identity and contact | Name, pen name, email, postal address, phone number |
| Contact form | Your name, email, the service you selected, and whatever you write in the message box. Submissions are emailed to us and stored on our server. |
| Project and manuscript | Manuscripts, chapters, outlines, artwork, photographs, audio, author biography, dedications, and everything else you submit for publication |
| Payment | Billing name and address, and the last four digits and expiry of a card. We do not store full card numbers or security codes โ full card details go directly to our payment processor. |
| Tax | Where required for reporting, a taxpayer identification number and a W-9 or W-8BEN |
| Communications | Emails, messages, support requests, and consultation notes |
| Marketing | Newsletter subscriptions and survey responses, where you have opted in |
3.2 Information we collect automatically
Our web host keeps standard server logs: IP address, browser type and version, operating system, device type, referring URL, pages requested, and timestamps. These are used for security, abuse prevention, and diagnosing faults.
When you submit the contact form, we also record the date and time, your IP address, and the page you submitted from, alongside your message. We use that only to prevent abuse of the form and to answer you.
We do not run analytics software, advertising pixels, session recording, or behavioural tracking on this website. See section 8.
3.3 Information from others
Payment confirmations from our payment processor. Sales and setup confirmations from distributors and retailers, where you have asked us to act on your behalf. Delivery updates from carriers for printed copies.
3.4 Sensitive information
We do not collect biometric data, precise geolocation, or health information as profile data about you, and we ask that you not send such information in a support message.
Two categories of sensitive information we do handle, and how:
(a) Taxpayer identification numbers. We collect a TIN only where required for tax reporting. We do not use it to infer anything about you.
(b) Special-category material inside your manuscript. A memoir will often contain information about health, religion, sexual orientation, political opinion, or racial or ethnic origin โ about you, and sometimes about others. Under GDPR that is Article 9 special-category data, and storing it inside a manuscript file does not change what it is. Where GDPR applies, we process it on the basis of your explicit consent under Article 9(2)(a), which we obtain at manuscript submission; once the book is published, Article 9(2)(e) also applies because you have manifestly made it public. You may withdraw consent, though once a book is published we cannot recall it from the world (see section 9.3).
4. Why we use it, and our legal basis
If you are in the UK, the EEA, or another jurisdiction with equivalent law, this is our lawful basis under Article 6 GDPR.
| Purpose | What we use | Legal basis |
|---|---|---|
| Providing the services you bought | Identity, contact, project, manuscript | Contract (Art. 6(1)(b)) |
| Quoting, invoicing, taking payment, collections | Payment, identity | Contract; legitimate interests for collections |
| Tax reporting | Tax data | Legal obligation (Art. 6(1)(c)) |
| Responding to enquiries and support | Contact, communications | Contract; legitimate interests for pre-contract enquiries |
| Distribution and retailer setup | Identity, project, metadata | Contract |
| Website security, fraud prevention, abuse detection | Server logs | Legitimate interests (Art. 6(1)(f)) |
| Showing your published book in our portfolio | Published title, cover, short excerpt, author name | Consent / licence granted in Terms ยง9.5, limited to published works, withdrawable at any time with removal within 30 days |
| Marketing emails | Contact, marketing preferences | Consent (Art. 6(1)(a)), withdrawable at any time |
| Special-category material inside your manuscript | See ยง3.4(b) | Explicit consent (Art. 9(2)(a)); once published, also Art. 9(2)(e) |
| Legal claims, disputes, regulatory response | Whatever is relevant | Legal obligation; legitimate interests |
4.1 Our legitimate interests, stated plainly. Where we rely on legitimate interests, our interest is in running a secure, solvent, improving business, and we have balanced it against your rights. You may object at any time (section 11) and we will stop unless we have compelling grounds that override your interests.
4.2 We will not use your information for a materially different purpose without telling you and, where required, obtaining your consent.
5. Your manuscript: special commitments
Your manuscript is the most sensitive thing you give us. These commitments are contractual, not aspirational, and they also appear in our Terms.
5.1 We do not train AI on it. We do not use your manuscript, artwork, audio, or any material you supply to train, fine-tune, evaluate, or benchmark artificial-intelligence or machine-learning models. We do not sell, license, or otherwise make it available to any third party for that purpose. We require our contractors, in their contracts with us, not to submit your material to any AI tool whose terms permit training on submitted content.
5.2 Confidentiality. Unpublished manuscripts are confidential. Access is limited to the people working on your project, each bound by a written confidentiality obligation.
5.3 Storage. Manuscripts are stored in access-controlled systems and encrypted in transit.
5.4 AI tools in production. We may use AI-assisted tools for grammar checking, transcription, formatting, or keyword research. Our policy is to use business or enterprise plans whose terms exclude submitted content from model training, and a person reviews all AI output before it reaches you. Where a deliverable is materially AI-produced, we tell you before you approve it.
We cannot audit every tool every freelancer opens, and we will not claim otherwise. If you would prefer that no AI tool touches your manuscript at all, tell us in writing before work begins. We will honour that at no extra charge and confirm it back to you. See Terms, section 13.
5.5 Retention and deletion. See section 9. In short: we keep working files for the length of your engagement plus a wind-down period, and you can ask us to delete them sooner.
6. Who we share it with
We share personal information only as described here. We do not sell it, and we do not rent or trade mailing lists.
6.1 Service providers. Each is bound to use your information only on our instructions or under its own published terms as a processor.
| Provider | What it does | What it receives |
|---|---|---|
| Hostinger International Ltd. | Website hosting, contact-form delivery, and email | Server log data; contact form submissions; website and email content |
| Google Fonts | Serves the typefaces used on our site | Your IP address and browser data, as an unavoidable part of requesting a font file (see section 8.2) |
| Payment processor named on your invoice | Processing card, PayPal, or bank payments | Payment and billing details |
| Freelance editors, designers, narrators, developers | Producing the work you purchased | Your manuscript and project materials, limited to what the task requires, under written confidentiality obligations |
| Print and distribution partners (for example IngramSpark, Amazon KDP) | Printing, retail distribution, and catalogue listing, where you have asked us to set these up | Your author and book metadata, and your files |
6.2 Retailer accounts are yours. Where a retailer account is set up in your name, that retailer's relationship is with you, and its privacy policy governs what it does with your data. We do not receive your sales income and generally do not have access to your retailer account beyond what you grant us.
6.3 Other disclosures. We may disclose information where required by law, court order, or a valid legal request; to establish, exercise, or defend legal claims; to protect the rights, property, or safety of any person; or to a successor in a merger, acquisition, or sale of assets, in which case we will tell you.
6.4 Aggregated data. We may publish anonymous, aggregated statistics that cannot identify you.
7. International transfers
We are based in the United States and our service providers may be located in the United States and elsewhere. If you are in the UK or the EEA, transferring your information to the United States means it may be processed in a country that has not been found to provide an equivalent level of data protection.
Where we transfer personal information out of the UK or EEA, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with appropriate technical measures. You may request details of the safeguards we use by emailing us.
8. Cookies and tracking
8.1 What our website does today. Our website is a static site. It sets no analytics cookies, no advertising cookies, and no tracking pixels. We do not run Google Analytics, Meta Pixel, or any session-recording or behavioural-tracking tool. Any cookie set is strictly necessary for the site to function.
Because we do not perform behavioural tracking, there is nothing here for a "Do Not Track" or Global Privacy Control signal to switch off โ but if we ever add analytics or advertising technology, we will honour those signals and update this section before it goes live.
8.2 External font requests. Our pages load typefaces from Google Fonts. Requesting a font file necessarily discloses your IP address and basic browser information to Google, which handles it under its own privacy policy. This is the only third-party request our pages make.
8.3 Server logs. Our host records standard access logs as described in section 3.2. These are retained for a short period for security and diagnostics.
8.4 If this changes. If we add analytics, advertising, or embedded third-party content, we will update this section, and where consent is required we will ask for it before setting non-essential cookies.
9. How long we keep things
| What | How long |
|---|---|
| Enquiries that do not become projects | 24 months from last contact, then deleted |
| Manuscripts and working files, active projects | For the engagement, plus 24 months |
| Final deliverable files | 24 months after completion, so we can re-supply them to you |
| Contracts, invoices, and payment records | 7 years, for tax and accounting obligations |
| Marketing contacts | Until you unsubscribe, then a suppression record only |
| Server logs | Short-term, per our host's retention settings |
9.1 Deletion on request. You can ask us to delete your manuscript and working files at any time. We will do so within 30 days, except where we must keep a record for tax, accounting, or legal-claim purposes โ in which case we keep the minimum and tell you what it is.
9.2 Held projects. Files for projects placed on hold are kept for 24 months, with 30 days' written notice before anything is deleted (Terms, section 5.5).
9.3 What we cannot undo. Once a book is published and distributed, we cannot recall copies that have been sold, delist third-party marketplace entries, or erase cached listings and reviews. We can submit takedown requests; we cannot control retailers.
10. Security
We use access controls, encrypted transmission, hosting on infrastructure with its own security programme, limited staff access on a need-to-know basis, and written confidentiality obligations for everyone who touches your work.
No method of transmission or storage is completely secure, and we will not claim otherwise. If a breach affects your personal information and creates a risk to you, we will notify you and any required regulator without undue delay, and where feasible within 72 hours of becoming aware of it.
Please help us: send manuscripts and personal documents through the channel we agree with you, keep your email account secure, and tell us immediately if you think an account or message has been compromised.
11. Your rights
Depending on where you live, you may have some or all of these rights:
- Access โ a copy of the personal information we hold about you
- Correction โ fix anything inaccurate or incomplete
- Deletion โ ask us to erase it, subject to section 9.1
- Portability โ receive it in a structured, machine-readable format
- Restriction and objection โ ask us to pause or stop a particular use, including any use based on legitimate interests
- Withdraw consent โ at any time, without affecting processing already carried out
- Complain โ to a supervisory authority
11.1 How to exercise them. Email hello@certivapublishers.com with the subject "Privacy Request." We will respond within 30 days, and may extend by a further 60 days for complex requests, telling you why. We do not charge for this, and we will not treat you differently for asking.
11.2 Verification. We will take reasonable steps to confirm you are who you say you are before acting on a request about someone's personal information. An authorised agent may act for you with written permission.
11.3 California residents. Under the CCPA/CPRA you have the rights listed above, plus the right to know the categories of information collected, disclosed, and sold or shared. We do not sell or share personal information as those terms are defined, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
11.4 UK and EEA residents. You may complain to your national data protection authority, including the UK Information Commissioner's Office (ico.org.uk).
11.5 Everyone else. Ask us anyway. We apply these rights to all our clients as a matter of policy, whether or not a statute requires it.
12. Children
Our services are for adults. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email us and we will delete it.
Children's books are written and published by adults, and any manuscript content about a real child is subject to the consent requirement in Terms section 15.9.
13. Marketing
We send marketing email only where you have opted in or are an existing client, and every message has a working unsubscribe link. Unsubscribing takes effect promptly and does not affect emails about a project you have with us, which are service messages rather than marketing.
We do not sell or rent your email address, and we do not upload client lists to advertising platforms for audience targeting.
14. Changes to this policy
We may update this policy. We will change the "Last updated" date and post the revised policy here. For material changes we will email account holders at least 30 days before they take effect. We keep dated earlier copies and will send you yours on request.
15. Contact us
Certiva Publishers โ a Certiva LLC company 24566 Jade Dr, Farmington Hills, Michigan 48336 hello@certivapublishers.com ยท (810) 522-4879
For privacy requests, use the subject line "Privacy Request." We respond within 30 days.