Trust Centre · Privacy

Nigeria data protection policy

How personal data is collected, used, shared, protected and acted on across 24-SEVEN guest, property and event workflows.

Version 3.0Status: commissioning policyJurisdiction focus: Nigeria
Commissioning disclosure: the final legal controller identity, DPO or DPCO appointment, NDPC registration category and registration reference have not been approved for publication. They must be completed before commercial processing. The rights workflow below is operational for owner-review testing.

Who determines the use of data

The contracting 24-SEVEN operator determines how marketplace, support and platform data is used. A participating hotel may separately determine how it uses reservation and guest-service data. Controller, joint-controller and processor roles must be written into each onboarding agreement and data-processing schedule; this page does not silently assign a role that has not been contracted.

Data we handle

  • Identity and contact details supplied for reservations, events, support, hotel applications and partner accounts.
  • Stay, room, rate, preference, event, communication and transaction-reference information.
  • Property evidence, authorised images, operational contacts and partner activity.
  • Technical, security and audit data such as IP address, device/session events, access history and abuse controls.
  • Payment status, provider references, amount and currency. Card numbers and CVV values are not intentionally collected or stored by this application.

Purposes and lawful bases

PurposeTypical lawful basis
Search, holds, reservations, events and requested servicesContract or steps requested before contract
Fraud prevention, security, audits and service improvementLegitimate interests, balanced against individual rights
Tax, accounting, lawful requests and regulatory dutiesLegal obligation
Optional marketing, non-essential analytics or similar choicesConsent where required, with a withdrawal route
Urgent protection of a personVital interests where the legal conditions apply

Recipients and international transfers

Only authorised staff, the relevant property and approved providers receive the minimum data required for their role. Providers may include hosting, email, payment, security, analytics, maps and AI services after due diligence and a written data agreement. A transfer outside Nigeria requires a recorded lawful transfer basis and safeguards under the Nigeria Data Protection Act; the live supplier and transfer registers must be approved before commissioning.

Retention and deletion

Data is retained by record type under a controlled schedule: while the service or account is active, for the period needed to resolve disputes and meet accounting or legal duties, and then deleted or irreversibly anonymised. Legal holds suspend routine deletion. The approved period, trigger, owner and disposal evidence belong in the internal retention register; this policy does not invent a period before the operator’s legal and tax review is complete.

Security and incidents

Controls include least-privilege access, protected sessions, encrypted secrets and backups, audit logging, rate limiting, data minimisation, verified payment handoff, release controls and recovery testing. No system can promise absolute security. Suspected personal-data breaches are contained, assessed and documented; where the Nigeria Data Protection Act requires it, the NDPC is notified within the applicable 72-hour period and affected people are informed where the risk threshold is met.

Your rights

Subject to applicable conditions and lawful exemptions, you may ask for access, correction, deletion, restriction, objection or data portability, withdraw consent, and complain to the Nigeria Data Protection Commission. Email verification is the first identity check. We may request proportionate additional evidence through a protected channel and will never ask you to upload government identity documents into this public form.

Submit a privacy-rights request

The form issues a reference and sends a verification link to the email address supplied. The internal target date shown to operators is a management control, not a promise that overrides law, identity verification, legal holds or complex-request rules.

Contact and complaints

Until the appointed privacy contact is published, use 24sevenreservations@gmail.com and include your request reference. You may also contact the Nigeria Data Protection Commission.

Authoritative references