Privacy Policy
This Privacy Policy explains how Navaelith Quenelmont Press, an imprint of Dr. Brown Cares LLC ("the House," "we," "us"), collects, uses, discloses, and protects personal information when you use navaelithquenelmont.com and related services (the "Service").
Contact. connect@drbrowncares.com — see the Imprint for the legal address.
1. Information We Collect
- Account data — name, email, authentication identifiers.
- Reading activity — volumes and chapters you open, progress, bookmarks, highlights, notes.
- Correspondence — letters, feedback, and messages you send us.
- Membership & billing — plan tier, status, and payment tokens (payment card numbers are held by our PCI-DSS-compliant processor; we never see or store them).
- Technical data — IP address, device, browser, referrer, and timestamps required to operate and secure the Service.
- Consent choices — whether you have accepted analytics or correspondence cookies.
2. How We Use It
To operate the reading experience, deliver purchased content, authenticate you, fulfill your membership, prevent fraud and abuse, comply with law, and — with your consent — measure aggregate reading patterns and send onboarding correspondence. Legal bases under GDPR / UK GDPR: contract (Art. 6(1)(b)), legitimate interests in operating a secure service (Art. 6(1)(f)), consent for analytics and marketing (Art. 6(1)(a)), and legal obligation (Art. 6(1)(c)).
3. Who We Share It With
We do not sell or share personal information as those terms are defined under the CCPA/CPRA, nor do we engage in cross-context behavioral advertising. We disclose data only to service providers acting on our written instructions:
- Hosting, database, authentication, and email delivery infrastructure.
- Payment processing (for membership).
- Aggregate, privacy-preserving analytics — only if you consent.
- Legal, tax, and accounting advisors on a need-to-know basis.
We may disclose information when required by valid legal process, to protect the safety of readers or the public, or in connection with a merger or asset transfer (in which case this Policy binds the successor).
4. How Long We Keep It
Account and reading data: for the life of your account plus 30 days after deletion (to reverse accidental deletions). Financial records: 7 years (US IRS retention). Correspondence: 3 years unless you ask us to purge sooner. Server logs: 90 days.
5. Your Rights
EU / UK / EEA (GDPR & UK GDPR). Rights of access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time. You may lodge a complaint with your local data protection authority.
California (CCPA / CPRA). Rights to know, delete, correct, limit use of sensitive personal information, and opt out of "sale" or "sharing" for cross-context behavioral advertising. We do not sell or share. You may still exercise the opt-out via our Do Not Sell or Share My Personal Information page. We honor Global Privacy Control (GPC) signals.
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other US state consumer privacy laws. Comparable rights of access, correction, deletion, portability, and opt-out of targeted advertising and profiling.
Brazil (LGPD). Rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing.
Canada (PIPEDA). Rights of access, correction, and challenge of compliance.
Australia (Privacy Act 1988). Access and correction rights under the Australian Privacy Principles.
How to exercise. Email connect@drbrowncares.com or, if signed in, use Account → Export or delete my data. We verify identity before acting and respond within 30 days (extendable to 90 for complex requests). You may authorize an agent in writing.
6. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 13 (COPPA, US) or under the applicable age of digital consent (13–16, EU member state; 13, UK). If you believe a child has provided information, contact us and we will delete it.
7. International Transfers
We are based in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. For transfers from the EEA, UK, and Switzerland we rely on Standard Contractual Clauses (SCCs) and the UK IDTA where required.
8. Security
TLS in transit, encryption at rest, row-level access controls, principle of least privilege, and audit logs. No system is perfectly secure. We will notify affected users and regulators of a personal data breach as required by law (GDPR Art. 33/34; US state breach-notification laws).
9. Cookies & Similar Technologies
See the Cookies Policy. EU/UK/Brazil visitors receive a prior-consent banner with granular categories.
10. Email & Marketing
Onboarding and transactional emails are sent as part of your account. Marketing correspondence requires opt-in (double opt-in for EU/UK/Canada under GDPR and CASL). Every marketing email includes an unsubscribe link and our postal address (CAN-SPAM).
11. Do Not Track
We treat Global Privacy Control (GPC) as a valid opt-out signal. Browser Do Not Track headers vary in meaning and are not enforced.
12. Changes
Material changes will be announced on this page and, when required by law, by email at least 30 days before taking effect.
13. Contact & Data Controller
Data controller: Dr. Brown Cares LLC — connect@drbrowncares.com. See Imprint for postal address. EU/UK representatives may be appointed as required; contact us for current information.
This policy is provided for transparency and is not legal advice.