NDPR Compliance
What is the NDPR?
UseLodger is NDPR compliant.
This page explains exactly how we meet our obligations under Nigerian data protection law — and what that means for property owners, staff, and guests who use our platform.
The Nigeria Data Protection Regulation (NDPR) 2019 was issued by the National Information Technology Development Agency (NITDA) under the authority of the NITDA Act 2007. It establishes rules for how organisations collect, use, store, and protect personal data belonging to Nigerian citizens and residents.
The NDPR was strengthened by the Nigeria Data Protection Act (NDPA) 2023, which established the Nigeria Data Protection Commission (NDPC) as the standalone regulatory authority. UseLodger complies with both instruments.
NDPR 2019
Issued by NITDA — foundational framework
NDPA 2023
Nigeria Data Protection Act — statutory law
NDPC
Nigeria Data Protection Commission — regulator
NITDA
National IT Development Agency
Our commitment
UseLodger was designed with data protection as a foundational principle, not an afterthought. The following commitments are built into the architecture of the platform:
Data localisation
All core platform data (users, bookings, financials) stored on Nigerian servers
Security by design
bcrypt passwords, TLS 1.3, JWT with expiry, 2FA, full audit logs
Data minimisation
We collect only what is necessary for the platform to function
Purpose limitation
Data is used only for the purpose it was collected — never sold or used for advertising
Transparency
Plain-language privacy policy, this compliance page, and email notification of any changes
Breach notification
72-hour user notification and NDPC reporting in the event of a data breach
DPO appointed
A Data Protection Officer oversees all data handling — contactable at privacy@uselodger.com
DPA available
A Data Processing Agreement is available for all property owners who require one
Lawful basis for processing
Under the NDPR and NDPA, every processing activity must have a lawful basis. UseLodger relies on the following bases:
- Processing account registration and login
- Processing bookings and payments
- Sending booking confirmation emails and SMS
- Creating Paystack subaccounts for property owners
- Generating invoices
- Platform security monitoring and fraud detection
- Improving AI pricing models using anonymised data
- Product analytics to improve user experience
- Maintaining audit logs for security purposes
- Retaining financial records for 7 years under Nigerian tax law
- Responding to lawful requests from NITDA, NDPC, or courts
- VAIDS and FIRS compliance for transaction reporting
- Marketing and promotional emails (opt-in only)
- Push notification preferences
- Optional profile information beyond minimum required
Data subject rights
Every individual whose data we process is a data subject with rights under the NDPR. UseLodger supports the exercise of all applicable rights. The response time for all requests is 30 days from receipt.
| Right | What it means | How to exercise |
|---|---|---|
| Right to access | Receive a copy of all personal data we hold | Email privacy@uselodger.com |
| Right to rectification | Correct inaccurate or incomplete data | Account Settings or email us |
| Right to erasure | Request deletion (subject to legal retention requirements) | Email privacy@uselodger.com |
| Right to portability | Receive your data in JSON or CSV format | Email privacy@uselodger.com |
| Right to object | Object to processing based on legitimate interests | Email privacy@uselodger.com |
| Right to restrict | Limit how we process your data while a dispute is resolved | Email privacy@uselodger.com |
| Withdraw consent | Withdraw consent for marketing or optional processing at any time | Account Settings → Notifications or email us |
| Right not to be profiled | Object to automated decision-making that significantly affects you | Email privacy@uselodger.com |
Data Protection Officer
UseLodger has appointed a Data Protection Officer (DPO) as required under Article 4.1(3) of the NDPR for organisations that process personal data on a large scale.
Data Processing Agreement (DPA)
Property owners who use UseLodger process guest personal data (names, contact details, stay information) as data controllers. UseLodger acts as a data processor on their behalf for this guest data.
Under Article 2.6 of the NDPR and the NDPA 2023, a written Data Processing Agreement is required between a data controller and data processor.
The DPA covers:
- Subject matter and duration of processing
- Nature and purpose of the processing
- Type of personal data and categories of data subjects
- Obligations and rights of the data controller (property owner)
- Sub-processor list (Paystack, Cloudinary, KudiSMS, Firebase)
- Data subject rights assistance obligations
- Security and breach notification obligations
- Return or deletion of data at end of agreement
Cross-border data transfers
The NDPR restricts transfer of personal data outside Nigeria to countries with adequate data protection standards. UseLodger transfers data outside Nigeria only in the following circumstances:
Cloudinary
Firebase (Google)
All other personal data — user accounts, bookings, financial records — is stored on Nigerian servers and never transferred outside Nigeria.
Third-party data processors
UseLodger uses the following third-party sub-processors. Each has been assessed for NDPR compatibility and has a data processing agreement in place with UseLodger:
| Processor | Purpose | Data location |
|---|---|---|
| Paystack | Payment processing & subaccount splits | Nigeria |
| Flutterwave | International & pan-African payments | Nigeria / Global |
| Cloudinary | Media storage and CDN delivery | Global CDN |
| KudiSMS | SMS OTP and transactional messages | Nigeria |
| Termii | SMS fallback delivery | Nigeria |
| Firebase (Google) | Push notification tokens | Global |
| SMTP provider | Transactional email delivery | Configurable |
| Groq | AI inference (anonymised data only) | United States |
Breach response procedure
UseLodger has a documented Data Breach Response Procedure. In the event of a personal data breach:
Internal breach detected, contained, and logged. Incident response team activated.
Scope of breach assessed. Affected data subjects and data categories identified.
Notification sent to Nigeria Data Protection Commission (NDPC) as required by NDPA 2023.
Affected users notified by email with: what happened, what data was involved, what we are doing about it, and what you should do.
Full incident report completed. Security measures reviewed and updated. Regulatory follow-up as required.
Audit & compliance record
- UseLodger maintains a Record of Processing Activities (ROPA) as required by NDPR Article 4.1(3)
- Annual Data Protection Impact Assessments (DPIAs) conducted for high-risk processing activities
- Staff handling personal data receive NDPR training on onboarding and annually thereafter
- Third-party processor contracts reviewed annually for continued compliance
- All data subject requests are logged with timestamps and outcomes
- Security controls reviewed quarterly by the DPO
Contact NITDA / NDPC
If you have a complaint about how UseLodger handles your personal data and are not satisfied with our response, you have the right to escalate to the Nigerian data protection authority:
Nigeria Data Protection Commission (NDPC)
Statutory data protection authority under the NDPA 2023
National Information Technology Development Agency (NITDA)
Original NDPR issuing authority
Questions about this policy? privacy@uselodger.com
Privacy Policy →