useLodger

Welcome to useLodger

Africa's hospitality platform

Request a demo

useLodger · Africa-first hospitality SaaS · © 2026

NDPR compliance

UseLodger
Compliance

NDPR Compliance

Effective: 1 June 2026Last updated: 11 June 2026
Privacy Policy →

What is the NDPR?

UseLodger is NDPR compliant.

This page explains exactly how we meet our obligations under Nigerian data protection law — and what that means for property owners, staff, and guests who use our platform.

The Nigeria Data Protection Regulation (NDPR) 2019 was issued by the National Information Technology Development Agency (NITDA) under the authority of the NITDA Act 2007. It establishes rules for how organisations collect, use, store, and protect personal data belonging to Nigerian citizens and residents.

The NDPR was strengthened by the Nigeria Data Protection Act (NDPA) 2023, which established the Nigeria Data Protection Commission (NDPC) as the standalone regulatory authority. UseLodger complies with both instruments.

NDPR 2019

Issued by NITDA — foundational framework

NDPA 2023

Nigeria Data Protection Act — statutory law

NDPC

Nigeria Data Protection Commission — regulator

NITDA

National IT Development Agency

Our commitment

UseLodger was designed with data protection as a foundational principle, not an afterthought. The following commitments are built into the architecture of the platform:

🇳🇬

Data localisation

All core platform data (users, bookings, financials) stored on Nigerian servers

🔐

Security by design

bcrypt passwords, TLS 1.3, JWT with expiry, 2FA, full audit logs

🗑

Data minimisation

We collect only what is necessary for the platform to function

Purpose limitation

Data is used only for the purpose it was collected — never sold or used for advertising

📋

Transparency

Plain-language privacy policy, this compliance page, and email notification of any changes

Breach notification

72-hour user notification and NDPC reporting in the event of a data breach

🧑‍💼

DPO appointed

A Data Protection Officer oversees all data handling — contactable at privacy@uselodger.com

📝

DPA available

A Data Processing Agreement is available for all property owners who require one

Lawful basis for processing

Under the NDPR and NDPA, every processing activity must have a lawful basis. UseLodger relies on the following bases:

Contractual necessity
  • Processing account registration and login
  • Processing bookings and payments
  • Sending booking confirmation emails and SMS
  • Creating Paystack subaccounts for property owners
  • Generating invoices
Legitimate interests
  • Platform security monitoring and fraud detection
  • Improving AI pricing models using anonymised data
  • Product analytics to improve user experience
  • Maintaining audit logs for security purposes
Legal obligation
  • Retaining financial records for 7 years under Nigerian tax law
  • Responding to lawful requests from NITDA, NDPC, or courts
  • VAIDS and FIRS compliance for transaction reporting
Consent
  • Marketing and promotional emails (opt-in only)
  • Push notification preferences
  • Optional profile information beyond minimum required

Data subject rights

Every individual whose data we process is a data subject with rights under the NDPR. UseLodger supports the exercise of all applicable rights. The response time for all requests is 30 days from receipt.

RightWhat it meansHow to exercise
Right to accessReceive a copy of all personal data we holdEmail privacy@uselodger.com
Right to rectificationCorrect inaccurate or incomplete dataAccount Settings or email us
Right to erasureRequest deletion (subject to legal retention requirements)Email privacy@uselodger.com
Right to portabilityReceive your data in JSON or CSV formatEmail privacy@uselodger.com
Right to objectObject to processing based on legitimate interestsEmail privacy@uselodger.com
Right to restrictLimit how we process your data while a dispute is resolvedEmail privacy@uselodger.com
Withdraw consentWithdraw consent for marketing or optional processing at any timeAccount Settings → Notifications or email us
Right not to be profiledObject to automated decision-making that significantly affects youEmail privacy@uselodger.com
We will respond to all data subject requests within 30 days. Complex requests may be extended by a further 30 days with notification. We do not charge a fee for exercising your rights unless the request is manifestly unfounded or excessive.

Data Protection Officer

UseLodger has appointed a Data Protection Officer (DPO) as required under Article 4.1(3) of the NDPR for organisations that process personal data on a large scale.

RoleData Protection Officer (DPO)
Appointment date1 June 2026
Emailprivacy@uselodger.com
Response timeWithin 30 days for data subject requests
ResponsibilitiesOversight of all data processing activities, compliance monitoring, staff training, and NDPC liaison

Data Processing Agreement (DPA)

Property owners who use UseLodger process guest personal data (names, contact details, stay information) as data controllers. UseLodger acts as a data processor on their behalf for this guest data.

Under Article 2.6 of the NDPR and the NDPA 2023, a written Data Processing Agreement is required between a data controller and data processor.

A standard Data Processing Agreement (DPA) is available to all UseLodger property owners on request. Email legal@uselodger.com with subject line "DPA Request" and we will provide the agreement within 3 business days.

The DPA covers:

  • Subject matter and duration of processing
  • Nature and purpose of the processing
  • Type of personal data and categories of data subjects
  • Obligations and rights of the data controller (property owner)
  • Sub-processor list (Paystack, Cloudinary, KudiSMS, Firebase)
  • Data subject rights assistance obligations
  • Security and breach notification obligations
  • Return or deletion of data at end of agreement

Cross-border data transfers

The NDPR restricts transfer of personal data outside Nigeria to countries with adequate data protection standards. UseLodger transfers data outside Nigeria only in the following circumstances:

Cloudinary

CountryUnited States / Global CDN
DataMedia files (property photos, room images, QR codes, videos)
BasisNecessary for platform functionality — contractual clauses in place

Firebase (Google)

CountryUnited States / Global
DataDevice push notification tokens only — no personal profile data
BasisMinimal data transfer, contractual clauses in place

All other personal data — user accounts, bookings, financial records — is stored on Nigerian servers and never transferred outside Nigeria.

Third-party data processors

UseLodger uses the following third-party sub-processors. Each has been assessed for NDPR compatibility and has a data processing agreement in place with UseLodger:

ProcessorPurposeData location
PaystackPayment processing & subaccount splitsNigeria
FlutterwaveInternational & pan-African paymentsNigeria / Global
CloudinaryMedia storage and CDN deliveryGlobal CDN
KudiSMSSMS OTP and transactional messagesNigeria
TermiiSMS fallback deliveryNigeria
Firebase (Google)Push notification tokensGlobal
SMTP providerTransactional email deliveryConfigurable
GroqAI inference (anonymised data only)United States

Breach response procedure

UseLodger has a documented Data Breach Response Procedure. In the event of a personal data breach:

Within 24 hours

Internal breach detected, contained, and logged. Incident response team activated.

Within 48 hours

Scope of breach assessed. Affected data subjects and data categories identified.

Within 72 hours

Notification sent to Nigeria Data Protection Commission (NDPC) as required by NDPA 2023.

Without undue delay

Affected users notified by email with: what happened, what data was involved, what we are doing about it, and what you should do.

Post-breach

Full incident report completed. Security measures reviewed and updated. Regulatory follow-up as required.

Audit & compliance record

  • UseLodger maintains a Record of Processing Activities (ROPA) as required by NDPR Article 4.1(3)
  • Annual Data Protection Impact Assessments (DPIAs) conducted for high-risk processing activities
  • Staff handling personal data receive NDPR training on onboarding and annually thereafter
  • Third-party processor contracts reviewed annually for continued compliance
  • All data subject requests are logged with timestamps and outcomes
  • Security controls reviewed quarterly by the DPO
Property owners who require a copy of UseLodger's compliance documentation for their own NDPR audit purposes should email legal@uselodger.com.

Contact NITDA / NDPC

If you have a complaint about how UseLodger handles your personal data and are not satisfied with our response, you have the right to escalate to the Nigerian data protection authority:

Nigeria Data Protection Commission (NDPC)

Statutory data protection authority under the NDPA 2023

Websitendpc.gov.ng
Emailinfo@ndpc.gov.ng
AddressAbuja, Federal Capital Territory, Nigeria

National Information Technology Development Agency (NITDA)

Original NDPR issuing authority

Websitenitda.gov.ng
AddressAbuja, FCT
Before escalating to the NDPC, please contact our DPO at privacy@uselodger.com — we resolve most concerns within 5 business days.

Questions about this policy? privacy@uselodger.com

Privacy Policy →

Hotel AI Assistant

Online · powered by Groq

Hello! 👋 I'm your Hotel AI Assistant. I can help with bookings, room status, pricing, operational insights and more. How can I help you today?
08:09 PM

Powered by Codequor AI · Available 24/7