Privacy Policy

Festival Hotel Conference Centre & Spa ("Festival Hotel", "we", "us") respects your privacy. This policy explains what personal data we collect when you use festivalhotellagos.com, book a room, enquire about an event or stay with us, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

We comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR) and the NDPA General Application and Implementation Directive 2025 (GAID). Where you are in the European Economic Area or the United Kingdom, we also comply with the General Data Protection Regulation (GDPR).

  1. Who we are
  2. What we collect
  3. Why we use it, and our lawful basis
  4. Who we share it with
  5. International transfers
  6. How long we keep it
  7. How we protect it
  8. Children
  9. Cookies
  10. Your rights
  11. Complaints
  12. Changes

1. Who we are

Data controller: Festival Hotel Conference Centre & Spa, Festac Town, Amuwo Odofin, Lagos, Nigeria.
General enquiries: info@festivalhotellagos.com · +234 805 049 7475
Data Protection Officer: dataprotection@updcplc.com

The hotel sits within the Custodian Investment Plc / UPDC group and is managed by Premium Swiss Hotels & Resorts (PSH), which operates our reservation system.

2. What personal data we collect

You give us

We collect automatically

We receive from others

3. Why we use your data and our lawful basis

We only process personal data where the NDPA (s.25) and, where applicable, GDPR Art. 6 permit it:

What we doLawful basis
Take, confirm and manage your reservation; provide the room, meeting space, dining, spa and fitness services you bookedPerformance of a contract with you
Process payment, deposits, refunds and chargebacksPerformance of a contract; legal obligation
Answer enquiries you send us by form, e-mail, phone or WhatsAppSteps taken at your request before entering a contract; legitimate interests
Guest registration and identification at check-in; reporting to the authorities where requiredLegal obligation
Accounting, tax, audit and record-keepingLegal obligation
Site security, fraud prevention and protecting the booking system from abuseLegitimate interests in operating a safe hotel and website
Improving the website and understanding how it is usedYour consent (analytics cookies)
Sending offers, newsletters and promotionsYour consent, which you may withdraw at any time
Accommodating dietary, accessibility or health-related requestsYour explicit consent
Establishing, exercising or defending legal claimsLegitimate interests; legal obligation

We do not sell your personal data, and we do not make decisions producing legal or similarly significant effects about you by automated means alone.

4. Who we share it with

Every processor acts on our documented instructions under a written agreement that meets NDPA s.29 and GDPR Art. 28.

5. International transfers

Some of the providers above are outside Nigeria — in particular our management company is based in Switzerland, and infrastructure providers may store data in the European Union or the United States.

We transfer personal data abroad only where NDPA ss.41–43 permit it: the recipient country provides an adequate level of protection, or appropriate contractual safeguards are in place, or the transfer is necessary to perform our contract with you. For transfers out of the EEA or UK we rely on adequacy decisions or Standard Contractual Clauses. You can request details of the safeguards used by writing to our DPO.

6. How long we keep it

DataRetention period
Booking and guest records7 years after the stay, to meet accounting and tax obligations
Payment and financial records7 years (Companies and Allied Matters Act and tax rules)
Guest registration and identification recordsAs required by applicable hospitality and immigration rules, then deleted
Event and meeting enquiries that do not become bookings12 months from the last contact
General correspondence24 months from the last contact
Marketing consents and preferencesUntil you withdraw consent, plus 12 months to evidence the withdrawal
Cookie consent records6 months, then we ask you again
Website technical logs90 days

When a retention period ends, we securely delete or irreversibly anonymise the data.

7. How we protect your data

As required by NDPA s.24(1)(f) and GDPR Art. 32 we apply technical and organisational measures appropriate to the risk, including encryption of data in transit (HTTPS), access controls on a need-to-know basis, restriction of payment card data to our PCI-DSS compliant provider, staff confidentiality obligations and data protection training, supplier due diligence and written processing agreements, and logging and monitoring of our systems.

If a breach occurs that is likely to result in a risk to your rights, we will notify the Nigeria Data Protection Commission within 72 hours and inform you without undue delay where the risk is high.

8. Children

Under the NDPA (s.31) a child is anyone under 18 years of age. Our website, booking form and enquiry forms are intended for adults, and we ask you to confirm that you are 18 or older before you submit them.

We knowingly collect a child's personal data only where a young guest is travelling as part of a booking. In that case:

If you believe a child has given us personal data without a parent or guardian's consent, contact dataprotection@updcplc.com and we will delete it.

9. Cookies

We use cookies and similar technologies as set out in our Cookie Policy. Only strictly necessary cookies are set before you choose. You can change or withdraw your choices at any time through the Cookie settings link in the footer of every page.

10. Your rights

Under NDPA ss.34–37 and GDPR Arts. 15–22 you have the right to:

To exercise any of these, write to dataprotection@updcplc.com. We respond within 30 days and may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

11. Complaints

Please raise any concern with our DPO first — we would rather resolve it directly. If you remain dissatisfied you may complain to the Nigeria Data Protection Commission (NDPC), No. 5 Zambezi Crescent, Maitama, Abuja · info@ndpc.gov.ng · ndpc.gov.ng.

If you are in the EEA or the UK, you may instead complain to the supervisory authority in your country of residence.

12. Changes to this policy

We review this policy at least annually and whenever our processing changes. We will tell you about material changes by notice on the website and, where appropriate, by e-mail.