Book now

Privacy

Privacy Policy

How House of Iredia, LTD collects, uses, shares, stores, and protects personal data when you use LakoweLakesLiving.

On this page

LakoweLakesLiving by House of Iredia, LTD

  • Effective date: 23 July 2026
  • Last updated: 23 July 2026

1. About this policy

This Privacy Policy explains how House of Iredia, LTD, operating the LakoweLakesLiving brand (referred to as "LakoweLakesLiving," "we," "us," or "our"), collects, uses, shares, stores, and protects personal data when you:

  • visit www.lakowelakesliving.com or another page that links to this policy;
  • ask about a stay, dining, golf, wedding, meeting, retreat, activity, property, or related service;
  • submit an availability or booking request;
  • communicate with us by email, telephone, WhatsApp, a website form, or live chat where available;
  • use a booking-detail, invoice, or confirmation link that we provide; or
  • otherwise interact with LakoweLakesLiving.

This policy is intended to comply with the Nigeria Data Protection Act 2023 (the "NDP Act"), the Nigeria Data Protection Act General Application and Implementation Directive 2025 (the "GAID"), and other applicable privacy laws.

2. Who is responsible for your personal data

House of Iredia, LTD, operating as LakoweLakesLiving, is the data controller for the personal data described in this policy when it decides why and how that data is processed.

LakoweLakesLiving is an independent assisted-booking and guest-support service. It is not the owner of Lakowe Lakes Golf & Country Estate, the hotel owner, or the final reservation authority. When we send your booking details to the relevant accommodation, estate, restaurant, activity, event, or other service provider (each a "Service Provider"), that Service Provider may process your personal data as a separate data controller under its own privacy notice.

Controller contact details

  • Legal/business name: House of Iredia, LTD, operating as LakoweLakesLiving
  • Company registration number: 8155972
  • Place of business: Lagos, Nigeria
  • Business address: Lakowe Lakes Golf and Country Estate, Km 40, Lekki-Epe Expressway, Ibeju-Lekki, Lagos State, Nigeria
  • Email: houseofiredia@gmail.com

3. Personal data we collect

3.1 Data you provide

Depending on how you interact with us, we may collect:

  • Identity and contact data: your name, email address, telephone or WhatsApp number, billing address, and the contact details of the person making a group booking.
  • Stay and service-request data: proposed check-in and check-out dates, accommodation or room preference, number of adults and children, meal plan, event or activity preferences, budget, special requests, accessibility needs, and related planning details.
  • Booking data: booking-request identifiers, invoice and confirmation details, amendments, cancellations, check-in information, and communications with you and the relevant Service Provider.
  • Payment and transaction data: amount, currency, bank deposit or transfer reference, payment status, payment method, invoice, receipt, and refund or dispute information. Customers arrange bank deposits or transfers outside the website. We confirm whether the expected funds have been received; the website does not process or store card details, online-banking credentials, or payment security codes.
  • Communications data: messages and attachments you send through forms, email, WhatsApp, telephone, live chat, or social media, and records of our responses.
  • Marketing-preference data: whether you have asked to receive or stop receiving promotional communications.
  • Verification and compliance data: identification or other information reasonably required to prevent fraud, verify a transaction, comply with law, or resolve a complaint. We will request only what is necessary for the relevant purpose.

Please avoid including health information, government identification numbers, financial credentials, or other sensitive personal data in a general enquiry unless we specifically request it through an appropriate channel and explain why it is needed.

3.2 Data collected automatically

When you use the website, we and our technology providers may collect:

  • internet protocol address, device and browser type, operating system, language, and approximate location derived from your network information;
  • pages viewed, referring page, links and buttons selected, dates and times, session duration, and navigation paths;
  • website performance, web-vitals, diagnostic, error, and exception data;
  • cookie, device, advertising, session, and analytics identifiers;
  • conversion events, such as submitting a booking request or selecting a WhatsApp link; and
  • session-replay data showing how a visitor interacts with the website. Input fields are configured to be masked, but you should still avoid entering sensitive information into an unexpected field.

Page addresses and referral data can contain query parameters or reference values. We configure analytics tools to avoid collecting booking references, access tokens, or other unnecessary identifiers.

3.3 Data received from others

We may receive personal data from:

  • the person organising a booking or event for you;
  • the relevant Service Provider or its reservations team;
  • RediaOS, which supports our customer relationship, booking, communication, invoicing, and payment workflow;
  • our bank or financial institution, which provides deposit or transfer records used to confirm receipt;
  • WhatsApp, social-media platforms, advertising networks, analytics providers, and referral partners; and
  • fraud-prevention, professional-advisory, regulatory, or law-enforcement sources where permitted by law.

If you give us another person's data, you must be authorised to do so and should direct that person to this Privacy Policy.

4. Why we use personal data and our lawful bases

We process personal data only where we have a recognised lawful basis.

PurposeTypical dataLawful basis
Respond to an enquiry and recommend suitable optionsIdentity, contact, request, and communications dataSteps at your request before a contract; legitimate interests in providing responsive guest support
Check availability and prepare a quoteIdentity, contact, stay, service-request, and communications dataSteps at your request before a contract
Arrange and administer a confirmed booking or serviceIdentity, contact, booking, transaction, and communications dataPerformance of a contract
Create invoices, process and reconcile payments, refunds, or disputesIdentity, contact, booking, transaction, and verification dataPerformance of a contract; compliance with legal and accounting obligations; legitimate interests in preventing fraud and reconciling payments
Communicate with you about a request, booking, payment, arrival, change, or support issueIdentity, contact, booking, and communications dataSteps before a contract; performance of a contract; legitimate interests in customer service
Protect the website, users, transactions, and our rightsTechnical, usage, verification, booking, transaction, and communications dataLegal obligations; legitimate interests in security, fraud prevention, record integrity, and legal claims
Maintain business, tax, accounting, audit, and compliance recordsIdentity, booking, transaction, and communications dataCompliance with legal obligations; legitimate interests in accountable business administration
Measure website use, diagnose errors, record sessions, and improve the serviceTechnical, usage, analytics, and session-replay dataConsent for non-essential cookies and tracking tools
Measure advertising conversions and campaign performanceTechnical, usage, advertising identifier, referral, and conversion dataConsent
Send promotional messagesIdentity, contact, and marketing-preference dataConsent
Comply with lawful requests and protect vital interestsData relevant to the request or emergencyLegal obligation, public interest, or vital interests, as applicable

Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights and reasonable expectations override those interests. You may object as described in section 10.

We do not currently use solely automated decision-making that produces legal or similarly significant effects about you. If that changes, we will provide the information and safeguards required by law.

5. Cookies, analytics, advertising, and local storage

The website may use cookies, pixels, tags, local storage, and similar technologies.

  • Necessary technologies support security, network stability, accessibility, and core functions. These may operate without consent where permitted by law.
  • PostHog helps us understand website use, performance, errors, conversions, and user journeys and may provide masked session replay.
  • Google Ads and Google tags help us measure advertising conversions, including booking requests and WhatsApp-link selections.
  • Local storage may remember a live-chat session or another user-requested preference on the device.

Before we use a non-essential cookie or tracking tool, we will display a conspicuous choice that explains its purpose and lets you expressly accept or reject it. Rejecting non-essential tracking will not prevent access to the website's basic functions. You can later withdraw consent through the cookie settings made available on the website. You can also clear cookies or local storage through your browser, although doing so may remove saved preferences or chat access.

Our service providers may also process data under their own privacy notices. Their choices do not replace the consent controls we are required to provide on our website.

6. How we share personal data

We may disclose only the data reasonably required to:

  • House of Iredia, LTD personnel and authorised contractors who manage enquiries, bookings, support, finance, compliance, or technology;
  • RediaOS and related workflow providers that support customer relationship management, booking requests, messages, invoices, payment records, and audit records;
  • relevant Service Providers, including the Lakowe Lakes reservations team, accommodation managers or owners, restaurants, golf or activity operators, event providers, and other suppliers needed to answer or fulfil your request;
  • our bank or financial institution as needed to receive, verify, reconcile, or return a customer-arranged bank deposit or transfer;
  • hosting, infrastructure, security, analytics, session-replay, advertising, email, and communications providers, including PostHog, Google, WhatsApp/Meta, and any email-delivery provider used for booking communications;
  • professional advisers and insurers, including lawyers, accountants, auditors, data-protection advisers, and insurers;
  • regulators, courts, law-enforcement bodies, tax authorities, or other public authorities where disclosure is required or permitted by law; and
  • a buyer, investor, successor, or restructuring participant in connection with a proposed or completed sale, merger, financing, or transfer of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.

Some recipients act only on our documented instructions. Others, such as a Service Provider, bank, social platform, or regulator, may decide independently how to process data for their own lawful purposes.

We do not sell personal data for money.

7. International transfers

Some technology, analytics, advertising, communications, or hosting providers may store or access personal data outside Nigeria. Where a transfer is subject to the NDP Act, we will use a lawful transfer mechanism, assess the destination and recipient where required, and apply appropriate contractual, organisational, and technical safeguards. Where the law requires your consent for a particular transfer, we will request it before the transfer.

You may contact us for available information about the safeguards used for a transfer of your data.

8. Retention

We keep personal data only for as long as necessary for the stated purpose, to meet legal obligations, or to establish, exercise, or defend legal claims. The periods below describe our current retention approach; a shorter period applies where our operational needs or vendor settings allow it.

RecordRetention period
Availability or booking enquiry that does not become a contractUp to 6 months after the request is closed, unless a legal claim or another lawful ground requires limited retention
General contact or support enquiry unrelated to a transactionUp to 12 months after the last substantive interaction
Confirmed booking, invoice, payment, refund, and accounting recordThrough the end of the sixth year after the relevant financial or assessment year, or longer where an audit, dispute, court order, or law requires it
Booking-related messages and operational audit trailFor the related booking-record period, or a shorter period where the content is no longer needed
Analytics event data and technical logsUp to 12 months, after which data should be deleted or irreversibly de-identified unless a shorter vendor setting applies
Session recordingsUp to 90 days, subject to consent and a shorter period where practical
Marketing dataUntil consent is withdrawn or the data is no longer needed; a minimal suppression record may be kept to honour an opt-out
Consent and privacy-choice recordsWhile the relevant processing continues and for up to 6 years afterwards where needed to demonstrate compliance or resolve a claim

When a retention period ends, we will delete, securely destroy, or irreversibly de-identify the data unless continued retention is lawfully required. Backup copies may remain for a limited recovery cycle and will not be restored for ordinary use after deletion.

9. Security

We use proportionate technical and organisational measures designed to protect personal data, including access controls, authenticated internal connections, input masking for session replay, manual verification of bank deposits or transfers against financial records, record minimisation, and security monitoring. We also require relevant service providers to protect personal data appropriately.

No internet transmission or storage system is completely secure. Please protect links, access tokens, payment references, and messages we send to you, and contact us promptly if you believe a booking or communication has been compromised.

If a personal-data breach creates a risk requiring notice under applicable law, we will notify the Nigeria Data Protection Commission and affected individuals as required.

10. Your rights

Subject to applicable law and any lawful limitations, you may have the right to:

  • be informed about our processing;
  • ask whether we process your personal data and obtain access to it;
  • receive a copy in a commonly used electronic format and, where applicable, request portability;
  • correct inaccurate, incomplete, out-of-date, or misleading data;
  • request deletion where the data is no longer necessary or there is no lawful basis to retain it;
  • request restriction while a request, objection, or legal claim is being resolved;
  • withdraw consent at any time, as easily as it was given, without affecting earlier lawful processing;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing, after which we will stop using your data for that purpose;
  • object to and challenge qualifying solely automated decisions and request human intervention; and
  • lodge a complaint with the Nigeria Data Protection Commission.

To exercise a right, email houseofiredia@gmail.com with the subject "Privacy request" or contact us using section 15. Tell us which right you wish to exercise and provide enough information for us to locate the relevant records. We may request proportionate proof of identity or authority to protect you and others from unauthorised disclosure.

For step-by-step instructions, see our User Data Deletion page.

We will respond without unreasonable delay and aim to resolve a complete request within 30 days, subject to any period or extension permitted by law. We will explain if we cannot fulfil all or part of a request.

11. Direct marketing

We will send promotional email, SMS, or WhatsApp messages only where you have given the consent required by law. A service message about an enquiry, payment, booking, safety issue, or requested support is not a promotional message.

You can opt out of marketing at any time by using the unsubscribe method in the message or by contacting us. We will not make an existing booking conditional on consent to unrelated marketing.

12. Children

The website and booking service are intended for adults aged 18 or older. A booking must be made by an adult with legal capacity to contract. We may need limited information about children included in a family or group request, such as the number of children and age ranges relevant to occupancy or pricing. The responsible adult must be authorised to provide that information.

We do not knowingly ask a child to submit a booking request or consent to non-essential processing. If we learn that we collected a child's personal data without appropriate authorisation or another lawful basis, we will delete or otherwise remediate it as required by law.

13. Third-party websites and services

Our website links to services we do not control, including Service Provider sites, maps, social-media platforms, and WhatsApp. Their privacy notices govern their independent processing. Review those notices before giving them personal data. A link does not make us responsible for another party's privacy or security practices.

14. Complaints

Please contact us first so that we can investigate and try to resolve your concern promptly. You also have the right to complain directly to the Nigeria Data Protection Commission:

This right is not conditional on contacting us first.

15. Contact us

For privacy questions, requests, or complaints, contact:

House of Iredia, LTD / LakoweLakesLiving Privacy Contact

  • Company registration number: 8155972
  • Place of business: Lagos, Nigeria
  • Business address: Lakowe Lakes Golf and Country Estate, Km 40, Lekki-Epe Expressway, Ibeju-Lekki, Lagos State, Nigeria
  • Email: houseofiredia@gmail.com

16. Changes to this policy

We may update this policy to reflect changes in our services, providers, practices, or legal obligations. We will publish the updated version with a new "Last updated" date and give additional notice where a change materially affects your rights or requires renewed consent.

Related policies