Who we are and what this notice covers
TERNOPIL DEW HOTEL & SUITE LIMITED, trading as Ternopil Dew, is responsible for personal data processed through this hotel website. This notice applies when you browse the website, submit a stay, group, corporate or event enquiry, contact the hotel through a published channel, or exercise a privacy right. A separate notice will apply to the future booking and QR-code platforms before those services begin collecting data.
Personal data we collect
We collect only information reasonably needed for the interaction you choose. Depending on your enquiry, this may include:
- your name, email address, telephone or WhatsApp number and preferred contact method;
- requested arrival and departure dates, guest numbers, room preference, enquiry subject and message;
- event, group or corporate requirements you choose to provide;
- the time and version of the privacy consent or acknowledgement presented with a form;
- correspondence, enquiry status, assignment and internal follow-up notes; and
- limited technical and security data such as IP address, browser or device information, request time, pages requested, session identifiers and signals used to prevent abuse.
This website does not currently take accommodation payments, collect payment-card details or confirm reservations. Please do not place identity documents, financial account details, medical information or other highly sensitive data in a free-text enquiry. Contact the hotel directly if special arrangements require a more appropriate channel.
How and why we use personal data
We process personal data only where we have a lawful basis under applicable Nigerian data-protection law.
- To receive, route and respond to an enquiry, take steps requested before a possible reservation, and continue the conversation with you.
- To provide customer support, maintain an accurate service history, manage group or event discussions, and improve our enquiry process where our legitimate interests do not override your rights.
- To secure the website, prevent spam, investigate misuse, maintain audit evidence and protect guests, staff and systems.
- To comply with legal obligations, establish or defend legal claims, or respond to a lawful request from a competent authority.
- Where consent is the appropriate basis, for the specific optional purpose explained at the point of collection. You may withdraw that consent at any time without affecting earlier lawful processing.
We do not sell personal data. We do not currently use website enquiry data for automated decisions that produce legal or similarly significant effects, and we do not use it for direct marketing unless a separate, valid choice has been offered.
Where the information comes from
Most information comes directly from you. We may also receive information from a person arranging a stay or event on your behalf, from your organisation for a corporate enquiry, or from the communication provider you choose. If you provide another person’s data, you should have authority to do so and make this notice available to them.
Who may receive personal data
Access is limited to authorised hotel administrators and team members who need the information for their role. We may use vetted service providers for website hosting, secure data storage, email, SMS or WhatsApp delivery, operational monitoring, backups and technical support. They may process data only for the contracted service and subject to appropriate confidentiality, security and data-processing obligations.
We may disclose information to professional advisers, insurers, law-enforcement bodies, regulators or courts where necessary and legally permitted. A future booking or payment provider will not receive data from this website unless that integration is separately introduced and disclosed.
International transfers
Some technology or communication providers may process data outside Nigeria. Before such a transfer, we require an applicable lawful transfer basis and safeguards that provide an adequate level of protection, and we document the basis used. You may contact us for information about the safeguard relevant to your data, subject to lawful confidentiality restrictions.
How long we keep information
We keep personal data only for as long as reasonably necessary for the stated purpose, legal obligations, disputes and security. Resolved enquiry records and their internal notes are scheduled for deletion after 24 months unless a longer period is required for an active reservation discussion, complaint, legal obligation or claim. Delivery logs are kept for up to 12 months and store masked destination details rather than reusable provider credentials. Deleted records may remain in protected rolling backups until those backups expire, currently after 30 days.
Active enquiries are reviewed and closed when no longer needed. Legal, security and administration records may have different documented schedules where necessary for accountability, fraud prevention or legal claims.
Security
We use organisational and technical safeguards appropriate to the risk, including access controls, role-based administration, multi-factor authentication for administrators, encryption in transit, secure cookies, protected credentials, logging, backups, software maintenance and incident procedures. No internet service can guarantee absolute security. If a personal-data breach creates a legally reportable risk, we will notify the regulator and affected people as required.
Your rights
Subject to the conditions and exemptions in applicable law, you may ask us to:
- confirm whether we process your personal data and provide access to it;
- correct inaccurate or incomplete information;
- erase information that is no longer needed or was processed unlawfully;
- restrict processing in qualifying circumstances;
- provide eligible information in a portable format;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent where processing relies on consent; and
- explain and seek human review of a qualifying solely automated decision, if one is introduced.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission. We will not treat you unfairly for exercising a privacy right. We may need proportionate information to verify your identity and locate the relevant record before responding.
Children
This website is intended for adults arranging hotel services. We do not knowingly invite children to submit enquiries themselves. An adult arranging a family stay should provide only the minimum child information needed, such as the number of children, and should not place a child’s identity documents or sensitive details in the form.
Changes and contact
We review this notice at least annually and before introducing material new uses such as analytics, advertising, online booking, payments or QR-code guest services. Material changes will be published here with a new date and version. Use the privacy contact shown below for a question, complaint or rights request.