LakoweLakesLiving by House of Iredia, LTD
- Effective date: 23 July 2026
- Last updated: 23 July 2026
1. About this policy
This Privacy Policy explains how House of Iredia, LTD, operating the LakoweLakesLiving brand (referred to as "LakoweLakesLiving," "we," "us," or "our"), collects, uses, shares, stores, and protects personal data when you:
- visit www.lakowelakesliving.com or another page that links to this policy;
- ask about a stay, dining, golf, wedding, meeting, retreat, activity, property, or related service;
- submit an availability or booking request;
- communicate with us by email, telephone, WhatsApp, a website form, or live chat where available;
- use a booking-detail, invoice, or confirmation link that we provide; or
- otherwise interact with LakoweLakesLiving.
This policy is intended to comply with the Nigeria Data Protection Act 2023 (the "NDP Act"), the Nigeria Data Protection Act General Application and Implementation Directive 2025 (the "GAID"), and other applicable privacy laws.
2. Who is responsible for your personal data
House of Iredia, LTD, operating as LakoweLakesLiving, is the data controller for the personal data described in this policy when it decides why and how that data is processed.
LakoweLakesLiving is an independent assisted-booking and guest-support service. It is not the owner of Lakowe Lakes Golf & Country Estate, the hotel owner, or the final reservation authority. When we send your booking details to the relevant accommodation, estate, restaurant, activity, event, or other service provider (each a "Service Provider"), that Service Provider may process your personal data as a separate data controller under its own privacy notice.
Controller contact details
- Legal/business name: House of Iredia, LTD, operating as LakoweLakesLiving
- Company registration number: 8155972
- Place of business: Lagos, Nigeria
- Business address: Lakowe Lakes Golf and Country Estate, Km 40, Lekki-Epe Expressway, Ibeju-Lekki, Lagos State, Nigeria
- Email: houseofiredia@gmail.com
3. Personal data we collect
3.1 Data you provide
Depending on how you interact with us, we may collect:
- Identity and contact data: your name, email address, telephone or WhatsApp number, billing address, and the contact details of the person making a group booking.
- Stay and service-request data: proposed check-in and check-out dates, accommodation or room preference, number of adults and children, meal plan, event or activity preferences, budget, special requests, accessibility needs, and related planning details.
- Booking data: booking-request identifiers, invoice and confirmation details, amendments, cancellations, check-in information, and communications with you and the relevant Service Provider.
- Payment and transaction data: amount, currency, bank deposit or transfer reference, payment status, payment method, invoice, receipt, and refund or dispute information. Customers arrange bank deposits or transfers outside the website. We confirm whether the expected funds have been received; the website does not process or store card details, online-banking credentials, or payment security codes.
- Communications data: messages and attachments you send through forms, email, WhatsApp, telephone, live chat, or social media, and records of our responses.
- Marketing-preference data: whether you have asked to receive or stop receiving promotional communications.
- Verification and compliance data: identification or other information reasonably required to prevent fraud, verify a transaction, comply with law, or resolve a complaint. We will request only what is necessary for the relevant purpose.
Please avoid including health information, government identification numbers, financial credentials, or other sensitive personal data in a general enquiry unless we specifically request it through an appropriate channel and explain why it is needed.
3.2 Data collected automatically
When you use the website, we and our technology providers may collect:
- internet protocol address, device and browser type, operating system, language, and approximate location derived from your network information;
- pages viewed, referring page, links and buttons selected, dates and times, session duration, and navigation paths;
- website performance, web-vitals, diagnostic, error, and exception data;
- cookie, device, advertising, session, and analytics identifiers;
- conversion events, such as submitting a booking request or selecting a WhatsApp link; and
- session-replay data showing how a visitor interacts with the website. Input fields are configured to be masked, but you should still avoid entering sensitive information into an unexpected field.
Page addresses and referral data can contain query parameters or reference values. We configure analytics tools to avoid collecting booking references, access tokens, or other unnecessary identifiers.
3.3 Data received from others
We may receive personal data from:
- the person organising a booking or event for you;
- the relevant Service Provider or its reservations team;
- RediaOS, which supports our customer relationship, booking, communication, invoicing, and payment workflow;
- our bank or financial institution, which provides deposit or transfer records used to confirm receipt;
- WhatsApp, social-media platforms, advertising networks, analytics providers, and referral partners; and
- fraud-prevention, professional-advisory, regulatory, or law-enforcement sources where permitted by law.
If you give us another person's data, you must be authorised to do so and should direct that person to this Privacy Policy.
4. Why we use personal data and our lawful bases
We process personal data only where we have a recognised lawful basis.
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Respond to an enquiry and recommend suitable options | Identity, contact, request, and communications data | Steps at your request before a contract; legitimate interests in providing responsive guest support |
| Check availability and prepare a quote | Identity, contact, stay, service-request, and communications data | Steps at your request before a contract |
| Arrange and administer a confirmed booking or service | Identity, contact, booking, transaction, and communications data | Performance of a contract |
| Create invoices, process and reconcile payments, refunds, or disputes | Identity, contact, booking, transaction, and verification data | Performance of a contract; compliance with legal and accounting obligations; legitimate interests in preventing fraud and reconciling payments |
| Communicate with you about a request, booking, payment, arrival, change, or support issue | Identity, contact, booking, and communications data | Steps before a contract; performance of a contract; legitimate interests in customer service |
| Protect the website, users, transactions, and our rights | Technical, usage, verification, booking, transaction, and communications data | Legal obligations; legitimate interests in security, fraud prevention, record integrity, and legal claims |
| Maintain business, tax, accounting, audit, and compliance records | Identity, booking, transaction, and communications data | Compliance with legal obligations; legitimate interests in accountable business administration |
| Measure website use, diagnose errors, record sessions, and improve the service | Technical, usage, analytics, and session-replay data | Consent for non-essential cookies and tracking tools |
| Measure advertising conversions and campaign performance | Technical, usage, advertising identifier, referral, and conversion data | Consent |
| Send promotional messages | Identity, contact, and marketing-preference data | Consent |
| Comply with lawful requests and protect vital interests | Data relevant to the request or emergency | Legal obligation, public interest, or vital interests, as applicable |
Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights and reasonable expectations override those interests. You may object as described in section 10.
We do not currently use solely automated decision-making that produces legal or similarly significant effects about you. If that changes, we will provide the information and safeguards required by law.
5. Cookies, analytics, advertising, and local storage
The website may use cookies, pixels, tags, local storage, and similar technologies.
- Necessary technologies support security, network stability, accessibility, and core functions. These may operate without consent where permitted by law.
- PostHog helps us understand website use, performance, errors, conversions, and user journeys and may provide masked session replay.
- Google Ads and Google tags help us measure advertising conversions, including booking requests and WhatsApp-link selections.
- Local storage may remember a live-chat session or another user-requested preference on the device.
Before we use a non-essential cookie or tracking tool, we will display a conspicuous choice that explains its purpose and lets you expressly accept or reject it. Rejecting non-essential tracking will not prevent access to the website's basic functions. You can later withdraw consent through the cookie settings made available on the website. You can also clear cookies or local storage through your browser, although doing so may remove saved preferences or chat access.
Our service providers may also process data under their own privacy notices. Their choices do not replace the consent controls we are required to provide on our website.
6. How we share personal data
We may disclose only the data reasonably required to:
- House of Iredia, LTD personnel and authorised contractors who manage enquiries, bookings, support, finance, compliance, or technology;
- RediaOS and related workflow providers that support customer relationship management, booking requests, messages, invoices, payment records, and audit records;
- relevant Service Providers, including the Lakowe Lakes reservations team, accommodation managers or owners, restaurants, golf or activity operators, event providers, and other suppliers needed to answer or fulfil your request;
- our bank or financial institution as needed to receive, verify, reconcile, or return a customer-arranged bank deposit or transfer;
- hosting, infrastructure, security, analytics, session-replay, advertising, email, and communications providers, including PostHog, Google, WhatsApp/Meta, and any email-delivery provider used for booking communications;
- professional advisers and insurers, including lawyers, accountants, auditors, data-protection advisers, and insurers;
- regulators, courts, law-enforcement bodies, tax authorities, or other public authorities where disclosure is required or permitted by law; and
- a buyer, investor, successor, or restructuring participant in connection with a proposed or completed sale, merger, financing, or transfer of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.
Some recipients act only on our documented instructions. Others, such as a Service Provider, bank, social platform, or regulator, may decide independently how to process data for their own lawful purposes.
We do not sell personal data for money.
7. International transfers
Some technology, analytics, advertising, communications, or hosting providers may store or access personal data outside Nigeria. Where a transfer is subject to the NDP Act, we will use a lawful transfer mechanism, assess the destination and recipient where required, and apply appropriate contractual, organisational, and technical safeguards. Where the law requires your consent for a particular transfer, we will request it before the transfer.
You may contact us for available information about the safeguards used for a transfer of your data.
8. Retention
We keep personal data only for as long as necessary for the stated purpose, to meet legal obligations, or to establish, exercise, or defend legal claims. The periods below describe our current retention approach; a shorter period applies where our operational needs or vendor settings allow it.
| Record | Retention period |
|---|---|
| Availability or booking enquiry that does not become a contract | Up to 6 months after the request is closed, unless a legal claim or another lawful ground requires limited retention |
| General contact or support enquiry unrelated to a transaction | Up to 12 months after the last substantive interaction |
| Confirmed booking, invoice, payment, refund, and accounting record | Through the end of the sixth year after the relevant financial or assessment year, or longer where an audit, dispute, court order, or law requires it |
| Booking-related messages and operational audit trail | For the related booking-record period, or a shorter period where the content is no longer needed |
| Analytics event data and technical logs | Up to 12 months, after which data should be deleted or irreversibly de-identified unless a shorter vendor setting applies |
| Session recordings | Up to 90 days, subject to consent and a shorter period where practical |
| Marketing data | Until consent is withdrawn or the data is no longer needed; a minimal suppression record may be kept to honour an opt-out |
| Consent and privacy-choice records | While the relevant processing continues and for up to 6 years afterwards where needed to demonstrate compliance or resolve a claim |
When a retention period ends, we will delete, securely destroy, or irreversibly de-identify the data unless continued retention is lawfully required. Backup copies may remain for a limited recovery cycle and will not be restored for ordinary use after deletion.
9. Security
We use proportionate technical and organisational measures designed to protect personal data, including access controls, authenticated internal connections, input masking for session replay, manual verification of bank deposits or transfers against financial records, record minimisation, and security monitoring. We also require relevant service providers to protect personal data appropriately.
No internet transmission or storage system is completely secure. Please protect links, access tokens, payment references, and messages we send to you, and contact us promptly if you believe a booking or communication has been compromised.
If a personal-data breach creates a risk requiring notice under applicable law, we will notify the Nigeria Data Protection Commission and affected individuals as required.
10. Your rights
Subject to applicable law and any lawful limitations, you may have the right to:
- be informed about our processing;
- ask whether we process your personal data and obtain access to it;
- receive a copy in a commonly used electronic format and, where applicable, request portability;
- correct inaccurate, incomplete, out-of-date, or misleading data;
- request deletion where the data is no longer necessary or there is no lawful basis to retain it;
- request restriction while a request, objection, or legal claim is being resolved;
- withdraw consent at any time, as easily as it was given, without affecting earlier lawful processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing, after which we will stop using your data for that purpose;
- object to and challenge qualifying solely automated decisions and request human intervention; and
- lodge a complaint with the Nigeria Data Protection Commission.
To exercise a right, email houseofiredia@gmail.com with the subject "Privacy request" or contact us using section 15. Tell us which right you wish to exercise and provide enough information for us to locate the relevant records. We may request proportionate proof of identity or authority to protect you and others from unauthorised disclosure.
For step-by-step instructions, see our User Data Deletion page.
We will respond without unreasonable delay and aim to resolve a complete request within 30 days, subject to any period or extension permitted by law. We will explain if we cannot fulfil all or part of a request.
11. Direct marketing
We will send promotional email, SMS, or WhatsApp messages only where you have given the consent required by law. A service message about an enquiry, payment, booking, safety issue, or requested support is not a promotional message.
You can opt out of marketing at any time by using the unsubscribe method in the message or by contacting us. We will not make an existing booking conditional on consent to unrelated marketing.
12. Children
The website and booking service are intended for adults aged 18 or older. A booking must be made by an adult with legal capacity to contract. We may need limited information about children included in a family or group request, such as the number of children and age ranges relevant to occupancy or pricing. The responsible adult must be authorised to provide that information.
We do not knowingly ask a child to submit a booking request or consent to non-essential processing. If we learn that we collected a child's personal data without appropriate authorisation or another lawful basis, we will delete or otherwise remediate it as required by law.
13. Third-party websites and services
Our website links to services we do not control, including Service Provider sites, maps, social-media platforms, and WhatsApp. Their privacy notices govern their independent processing. Review those notices before giving them personal data. A link does not make us responsible for another party's privacy or security practices.
14. Complaints
Please contact us first so that we can investigate and try to resolve your concern promptly. You also have the right to complain directly to the Nigeria Data Protection Commission:
- Website: www.ndpc.gov.ng
- Email: info@ndpc.gov.ng
- Telephone: +234 (0) 916 061 5551
- Address: No. 12 Dr Clement Isong Street, Asokoro, Abuja, Nigeria
This right is not conditional on contacting us first.
15. Contact us
For privacy questions, requests, or complaints, contact:
House of Iredia, LTD / LakoweLakesLiving Privacy Contact
- Company registration number: 8155972
- Place of business: Lagos, Nigeria
- Business address: Lakowe Lakes Golf and Country Estate, Km 40, Lekki-Epe Expressway, Ibeju-Lekki, Lagos State, Nigeria
- Email: houseofiredia@gmail.com
16. Changes to this policy
We may update this policy to reflect changes in our services, providers, practices, or legal obligations. We will publish the updated version with a new "Last updated" date and give additional notice where a change materially affects your rights or requires renewed consent.
Related policies