Privacy Policy
Festival Hotel Conference Centre & Spa ("Festival Hotel", "we", "us") respects your privacy. This policy explains what personal data we collect when you use festivalhotellagos.com, book a room, enquire about an event or stay with us, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
We comply with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR) and the NDPA General Application and Implementation Directive 2025 (GAID). Where you are in the European Economic Area or the United Kingdom, we also comply with the General Data Protection Regulation (GDPR).
1. Who we are
Data controller: Festival Hotel Conference Centre & Spa, Festac Town, Amuwo Odofin, Lagos, Nigeria.
General enquiries: info@festivalhotellagos.com · +234 805 049 7475
Data Protection Officer: dataprotection@updcplc.com
The hotel sits within the Custodian Investment Plc / UPDC group and is managed by Premium Swiss Hotels & Resorts (PSH), which operates our reservation system.
2. What personal data we collect
You give us
- Booking details — name, e-mail address, phone number, arrival and departure dates, room type, number and ages of guests, special requests, loyalty or corporate account reference.
- Event and meeting enquiries — name, organisation, contact details, event type, dates, expected attendance, budget indication and any notes you provide.
- Payment information — where you pay online, this is handled directly by our payment provider (Paystack). We receive a confirmation and the last four digits of the card; we never see or store your full card number, expiry date or CVV. Bookings made through the availability window are completed on the reservation system operated for us by Premium Swiss Hospitality.
- Correspondence — the content of e-mails, WhatsApp messages and phone enquiries, and any feedback or complaint you send us.
- Identification at check-in — as required by Nigerian hospitality and immigration rules, a government-issued identification document, and for foreign guests passport and visa details.
- Dietary, accessibility and health-related requests — only where you volunteer them so we can accommodate you. These are sensitive personal data and we handle them accordingly.
We collect automatically
- Technical data — IP address, browser type and version, device type, operating system, referring page and the pages you view.
- Cookies and similar technologies — see our Cookie Policy for the full inventory. Non-essential cookies are set only with your consent.
We receive from others
- Travel agents and online booking platforms — booking and guest details where you booked through them.
- Corporate clients — the details of employees they book on behalf of.
3. Why we use your data and our lawful basis
We only process personal data where the NDPA (s.25) and, where applicable, GDPR Art. 6 permit it:
| What we do | Lawful basis |
|---|---|
| Take, confirm and manage your reservation; provide the room, meeting space, dining, spa and fitness services you booked | Performance of a contract with you |
| Process payment, deposits, refunds and chargebacks | Performance of a contract; legal obligation |
| Answer enquiries you send us by form, e-mail, phone or WhatsApp | Steps taken at your request before entering a contract; legitimate interests |
| Guest registration and identification at check-in; reporting to the authorities where required | Legal obligation |
| Accounting, tax, audit and record-keeping | Legal obligation |
| Site security, fraud prevention and protecting the booking system from abuse | Legitimate interests in operating a safe hotel and website |
| Improving the website and understanding how it is used | Your consent (analytics cookies) |
| Sending offers, newsletters and promotions | Your consent, which you may withdraw at any time |
| Accommodating dietary, accessibility or health-related requests | Your explicit consent |
| Establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
We do not sell your personal data, and we do not make decisions producing legal or similarly significant effects about you by automated means alone.
4. Who we share it with
- Premium Swiss Hotels & Resorts (PSH) — our management company, which operates the reservation system.
- Paystack — payment processing.
- Cloudflare — website security and delivery.
- Google — the embedded location map, and analytics where you consent.
- IT, hosting, e-mail and maintenance suppliers — under written contracts that restrict them to our instructions.
- Professional advisers — auditors, lawyers and insurers, where necessary.
- Regulators, law enforcement and courts — where we are legally required to disclose.
- Group companies — Custodian Investment Plc and UPDC Plc, for governance and audit purposes only.
Every processor acts on our documented instructions under a written agreement that meets NDPA s.29 and GDPR Art. 28.
5. International transfers
Some of the providers above are outside Nigeria — in particular our management company is based in Switzerland, and infrastructure providers may store data in the European Union or the United States.
We transfer personal data abroad only where NDPA ss.41–43 permit it: the recipient country provides an adequate level of protection, or appropriate contractual safeguards are in place, or the transfer is necessary to perform our contract with you. For transfers out of the EEA or UK we rely on adequacy decisions or Standard Contractual Clauses. You can request details of the safeguards used by writing to our DPO.
6. How long we keep it
| Data | Retention period |
|---|---|
| Booking and guest records | 7 years after the stay, to meet accounting and tax obligations |
| Payment and financial records | 7 years (Companies and Allied Matters Act and tax rules) |
| Guest registration and identification records | As required by applicable hospitality and immigration rules, then deleted |
| Event and meeting enquiries that do not become bookings | 12 months from the last contact |
| General correspondence | 24 months from the last contact |
| Marketing consents and preferences | Until you withdraw consent, plus 12 months to evidence the withdrawal |
| Cookie consent records | 6 months, then we ask you again |
| Website technical logs | 90 days |
When a retention period ends, we securely delete or irreversibly anonymise the data.
7. How we protect your data
As required by NDPA s.24(1)(f) and GDPR Art. 32 we apply technical and organisational measures appropriate to the risk, including encryption of data in transit (HTTPS), access controls on a need-to-know basis, restriction of payment card data to our PCI-DSS compliant provider, staff confidentiality obligations and data protection training, supplier due diligence and written processing agreements, and logging and monitoring of our systems.
If a breach occurs that is likely to result in a risk to your rights, we will notify the Nigeria Data Protection Commission within 72 hours and inform you without undue delay where the risk is high.
8. Children
Under the NDPA (s.31) a child is anyone under 18 years of age. Our website, booking form and enquiry forms are intended for adults, and we ask you to confirm that you are 18 or older before you submit them.
We knowingly collect a child's personal data only where a young guest is travelling as part of a booking. In that case:
- the booking must be made by a parent, legal guardian or another responsible adult, who provides consent on the child's behalf;
- we collect only what we need — first name and age — to allocate rooms, beds, meals and age-appropriate facilities;
- we verify age and guardianship at check-in against a government-issued identification document, which the NDPA expressly treats as an appropriate verification mechanism; and
- we never send marketing to a child and never place analytics or marketing cookies on a device we know belongs to a child.
If you believe a child has given us personal data without a parent or guardian's consent, contact dataprotection@updcplc.com and we will delete it.
9. Cookies
We use cookies and similar technologies as set out in our Cookie Policy. Only strictly necessary cookies are set before you choose. You can change or withdraw your choices at any time through the Cookie settings link in the footer of every page.
10. Your rights
Under NDPA ss.34–37 and GDPR Arts. 15–22 you have the right to:
- be informed about how we use your data — this policy;
- access the personal data we hold about you, and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data where we no longer have grounds to keep it;
- restrict processing while a concern is being resolved;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- portability — receive your data in a structured, machine-readable format, or have it sent to another controller;
- withdraw consent at any time, as easily as you gave it. Withdrawal does not affect processing carried out before you withdrew.
To exercise any of these, write to dataprotection@updcplc.com. We respond within 30 days and may ask you to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
11. Complaints
Please raise any concern with our DPO first — we would rather resolve it directly. If you remain dissatisfied you may complain to the Nigeria Data Protection Commission (NDPC), No. 5 Zambezi Crescent, Maitama, Abuja · info@ndpc.gov.ng · ndpc.gov.ng.
If you are in the EEA or the UK, you may instead complain to the supervisory authority in your country of residence.
12. Changes to this policy
We review this policy at least annually and whenever our processing changes. We will tell you about material changes by notice on the website and, where appropriate, by e-mail.