Legal
Privacy Policy
Effective date: 6 May 2026
1. Who we are
Nannoy Labs Ltd. ("Nannoy Labs", "we", "us", "our") is a company registered in Nigeria and operates the Nannoy learning platform at nannoy.com and app.nannoy.com. We are the data controller for personal data collected through these services.
If you have any privacy-related questions, contact us at hello@nannoy.com.
2. What data we collect
We collect the following categories of personal data:
| Category | Examples |
|---|---|
| Account data | Name, email address, password (hashed via AWS Cognito), or Google profile data if you sign in with Google |
| Profile data | Bio, location, avatar, notification preferences |
| Learning data | Course progress, lesson completions, assessment scores |
| Payment data | Billing plan, renewal dates (card details handled by Paystack — we never store raw card numbers) |
| Usage data | Pages visited, features used, timestamps |
| Communication data | Emails sent and received, support messages |
We do not collect sensitive personal data (e.g. health information, racial or ethnic origin, political opinions).
3. How we use your data
- Providing the service: Creating and managing your account, delivering courses, tracking progress, issuing certificates.
- Communications: Sending transactional emails (account confirmation, password reset, enrollment confirmation, certificate issuance) and, where you have opted in, progress updates, course recommendations, and marketing messages.
- AI personalisation: Generating personalised AI courses based on your selected learning goals and profile. Content is generated by AWS Bedrock models; your data is processed solely to generate your course and is not used to train external AI models.
- Payments: Processing subscription payments via Paystack. We share only the minimum data required (name, email) with Paystack to process transactions.
- Security & compliance: Detecting fraud, complying with legal obligations, enforcing our Terms of Service.
- Product improvement: Analysing aggregated usage patterns to improve the platform. We do not sell individual user data.
4. Legal basis for processing (UK & EU users)
Where applicable under the UK GDPR / EU GDPR, we process personal data on the following legal bases:
- Contract — processing necessary to provide the service you signed up for.
- Legitimate interests — fraud prevention, security, service improvement, and direct marketing to existing customers (with easy opt-out).
- Consent — for optional marketing emails. You can withdraw consent at any time via your profile settings or the unsubscribe link in any email.
- Legal obligation — where we are required to process data to comply with applicable law.
5. Who we share your data with
We do not sell your personal data. We share data only with the service providers necessary to operate the platform:
- Amazon Web Services (AWS) — cloud hosting, database, email delivery (SES), and AI model inference (Bedrock). Data is processed in the EU (eu-west-1 region).
- Paystack — payment processing. Governed by Paystack's own privacy policy.
- AWS Cognito — authentication and identity management.
- Google — if you choose to sign in with Google, we receive your name, email address, and profile picture from Google. This data is governed by Google's Privacy Policy. We do not receive your Google password.
All processors are bound by data processing agreements and are required to handle your data only as instructed.
6. Data retention
We retain your personal data for as long as your account is active or as needed to provide you with the service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it for longer (e.g. financial records for up to 7 years).
7. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your data ("right to be forgotten").
- Restriction — ask us to limit how we process your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — opt out of marketing emails at any time via your profile settings or the unsubscribe link in any email.
To exercise any of these rights, email us at hello@nannoy.com. We will respond within 30 days.
8. Cookies
We use strictly necessary cookies to maintain your session (login state and course selection). We do not use third-party advertising or tracking cookies. You can clear cookies through your browser settings at any time; doing so will log you out of the platform.
9. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. Passwords are never stored in plain text and are managed securely via AWS Cognito. However, no system is completely secure, and we encourage you to use a strong, unique password for your Nannoy account.
10. Children
Our service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a notice on the platform. The effective date at the top of this page will always reflect the date of the latest revision. Continued use of the platform after changes are posted constitutes your acceptance of the revised policy.
12. Contact us
For any privacy-related questions, data requests, or complaints:
If you are located in the UK or EU and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the UK).