At Lumaana Residence, “Your Home, Perfected,” we are committed to protecting the privacy and security of the Personal Data we collect and process. This Privacy Policy outlines how Lumaana Residence (referred to as “we,” “us,” or “our”) manages your Personal Data when you visit our website, make a booking, or use our services, in compliance with the Nigeria Data Protection Act (NDPA) 2023 and other applicable laws.

By visiting our website or using our services, you consent to the collection and use of your Personal Data as described in this policy.

1. Scope and Application

This policy applies to all Personal Data collected and processed by Lumaana Residence regarding our website visitors, prospective guests, guests, corporate clients, and job applicants.

2. Definitions (Based on NDPA 2023)

  • Personal Data: Any information relating to an identified or identifiable natural person (Data Subject).
  • Processing: Any operation performed on Personal Data, such as collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, or erasure.
  • Data Subject: The individual to whom the Personal Data relates (i.e., you, the user/guest).
  • Consent: Any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her.

3. Data Protection Principles

We commit to processing Personal Data in accordance with the principles of the NDPA, ensuring that data is:

  1. Processed in a fair, lawful, and transparent manner.
  2. Collected for specified, explicit, and legitimate purposes (Purpose Limitation).
  3. Adequate, relevant, and limited to what is necessary (Data Minimisation).
  4. Accurate and, where necessary, kept up to date.
  5. Retained for no longer than is necessary for the purposes for which it was collected (Storage Limitation).
  6. Processed in a manner that ensures appropriate security, integrity, and confidentiality.

4. Personal Data We Collect

We collect various types of information depending on your interaction with us:

Category of DataExamples of Information CollectedPurpose and Legal Basis (NDPA)
Identity DataName, title, date of birth, nationality, passport/ID number, corporate affiliation.Contract Performance (for booking/stay); Legal Obligation (security/immigration checks).
Contact DataEmail address, phone number, physical residence address.Contract Performance (to communicate regarding bookings); Consent (for marketing).
Transaction DataPayment card details (processed securely via third-party providers), booking history, services purchased.Contract Performance (to process payments and fulfil the booking).
Preference DataRoom preferences (e.g., non-smoking), dietary requirements (may be Sensitive Personal Data).Consent (for sensitive data); Contract Performance (to tailor the stay experience).
Technical DataIP address, device type, browser type, operating system, geographical location, website usage statistics (via cookies).Legitimate Interest (to improve website functionality and security); Consent (for non-essential cookies).
Security DataCCTV footage (at our physical locations), access control logs.Legitimate Interest/Legal Obligation (for the security and safety of guests and property).

5. How We Collect Your Data

  1. Directly from You: When you make a reservation (online or via phone), fill out a contact form, subscribe to our newsletter, check in at a residence, or communicate with our staff.
  2. From Third Parties: Online Travel Agencies (OTAs), booking platforms, corporate travel agents, or other partners through whom you make a reservation.
  3. Automatically: Through cookies, server logs, and other tracking technologies when you browse our website.

6. How We Use Your Data

We use your Personal Data for the following purposes:

  • To Fulfil Bookings and Services: To process and confirm your reservation, manage your stay, process payments, and provide housekeeping, laundry, and dining services.
  • To Communicate: To send booking confirmations, pre-arrival information, post-stay satisfaction surveys, and to respond to your inquiries.
  • Marketing (With Consent): To send you promotional materials, special offers, and updates about Lumaana Residence properties and services. You can withdraw this consent at any time.
  • Safety and Security: To ensure the safety of all guests, staff, and our premises, including monitoring via CCTV where necessary and conducting identification checks.
  • Business Operations and Improvement: To analyse website usage, customer trends, and performance metrics to improve our properties and services (based on Legitimate Interest).
  • Legal Compliance: To comply with legal or regulatory obligations, such as tax, immigration, and security reporting requirements in Nigeria.

7. Disclosure and Transfer of Personal Data

We will not sell, rent, or trade your Personal Data. We may share your data with the following parties only where necessary:

  • Internal Staff: Relevant employees of Lumaana Residence (e.g., Reception, Housekeeping, IT) on a need-to-know basis to fulfil your booking and provide services.
  • Third-Party Service Providers: Partners who perform essential services on our behalf, such as payment processors, IT service providers, website analytics, and professional advisers. These providers are bound by confidentiality agreements and are obligated to comply with the NDPA.
  • Law Enforcement/Regulators: Where legally required by the Nigerian government, the Nigeria Data Protection Commission (NDPC), or other competent regulatory bodies.

Cross-Border Data Transfer

As a Nigerian company, our primary data processing takes place within Nigeria. However, if your Personal Data must be transferred outside of Nigeria (e.g., by using an international cloud service or booking platform), we will ensure that the transfer is protected by appropriate safeguards in accordance with the NDPA, such as ensuring the recipient country has an adequate level of data protection or through binding corporate rules or standard contractual clauses.

8. Data Security

We have implemented appropriate technical and organisational security measures to protect your Personal Data against unauthorised access, alteration, disclosure, accidental loss, destruction, or damage. These measures include:

  • Physical security at our premises.
  • Internal policies and staff training on data handling.
  • Use of encryption and secure payment gateways for online transactions.
  • Access controls to our systems on a “need-to-know” basis.

9. Data Retention

We will retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements.

Generally, we retain data related to:

  • Bookings: For a period necessary to manage any potential contractual claims, usually up to six (6) years after your last transaction, or as required by Nigerian law.
  • Marketing Consent: Until you withdraw your consent or after a period of non-engagement.

10. Your Rights as a Data Subject (NDPA)

Under the NDPA 2023, you have the following rights regarding your Personal Data:

  • The Right to Be Informed: To be provided with clear, transparent, and easily accessible information about how we process your data.
  • The Right of Access: To request confirmation of whether we are processing your data and to obtain a copy of the data we hold about you.
  • The Right to Rectification: To have inaccurate or incomplete Personal Data corrected or updated without undue delay.
  • The Right to Erasure (Right to Be Forgotten): To request the deletion of your Personal Data when there is no compelling reason for us to continue processing it.
  • The Right to Object: To object to the processing of your Personal Data, particularly for direct marketing purposes.
  • The Right to Restrict Processing: To request the temporary limitation of processing your Personal Data under certain conditions.
  • The Right to Data Portability: To receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
  • The Right to Lodge a Complaint: To lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights have been violated.

To exercise any of these rights, please contact our Data Protection Officer (DPO) using the contact details provided below.

11. Use of Cookies

Our website uses cookies (small text files placed on your device) to collect Technical Data and improve your browsing experience. We use cookies to:

  • Ensure the basic functionality of the website.
  • Remember your preferences (e.g., language).
  • Perform analytics to understand how visitors use our site.

By continuing to use our website, you consent to the use of cookies. You can manage your cookie preferences through your web browser settings.

12. Changes to This Policy

We reserve the right to modify this Privacy Policy at any time. Any changes will be effective immediately upon posting the revised policy on this page. We encourage you to review this page periodically for the latest information on our privacy practices.