Privacy Policy
Last updated 26 September 2026
The short version
We collect what we need to run Alejo OS and support you, protect it, and never sell it. For hotel guests’ data, the hotel is in charge and we only process it on the hotel’s instructions. You can access, correct or delete your data by emailing us.
1. Who we are and what this policy covers
Alejo OS is made by Consulaw Tech Services (“Consulaw Tech”, “we”, “us”). This policy explains how we handle personal data under the Nigeria Data Protection Act 2023 (the “NDPA”), the NDPC’s implementing rules, and, where it applies to you, the EU and UK GDPR.
It covers two groups of people, for whom we are the data controller:
- visitors to this website, including anyone who sends us a message; and
- hotel owners, managers and staff who have an Alejo OS account (“account holders”).
It does not describe how a hotel handles its own guests’ data. For that, each hotel is the controller and we are its processor, acting only on its instructions. See section 4, our Guest Privacy Notice and the Data Processing Agreement.
2. What we collect
| Who | What | Where it comes from |
|---|---|---|
| Website visitors | Name, email address and message if you use the contact form; your choice on our cookie notice; the technical data (IP address, browser, pages requested) that our hosting and rate limiter process to deliver the site and block abuse. | You, and your browser. |
| Account holders | Name, work email, password (stored only as a salted hash), role and hotel, two-factor authentication settings, sign-in times, actions you take in the product (audit log), support tickets and messages you send us, tutorials you have completed. | You, your hotel, and your use of the product. |
| Hotel businesses | Business name, address, country, currency, logo and colours, bank details you give us for payouts (account number, resolved account name), and payment gateway connections. Gateway secret keys are encrypted. | The hotel owner. |
| Security and abuse prevention | Failed sign-in attempts keyed to an email address or IP address, and one-time tokens for password reset and email verification. | Generated when you use sign-in and reset flows. |
3. How we use it, and our lawful bases
| Purpose | Lawful basis (NDPA) |
|---|---|
| Create and run your account, authenticate you, provide and support the product. | Performance of our contract with you or your hotel. |
| Take and route payments, send receipts, invoices and service notices. | Performance of a contract; legal obligation. |
| Secure the platform: rate limiting, fraud and abuse detection, audit logs, incident response. | Legitimate interests in keeping the service and its users safe. |
| Reply to your enquiries and support requests. | Legitimate interests; steps at your request before a contract. |
| Improve the product using aggregated, anonymised usage patterns. | Legitimate interests. |
| Comply with tax, accounting, anti-fraud and other legal obligations, and respond to lawful requests from authorities. | Legal obligation. |
| Non-essential cookies or marketing, if we ever add them. | Your consent, which you can withdraw. |
We do not sell personal data. We do not use it for advertising profiles. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
4. Guest data: our role as processor
Hotels use Alejo OS to store and use data about their guests: names, contact details, ID details, stays, orders, requests, folios and payments. The hotel decides why and how that data is used, and is responsible for telling guests about it. We process it only to provide the service to the hotel, under the Data Processing Agreement. If a guest contacts us with a privacy request about their stay, we will direct it to the hotel, which is the party able to act on it, and help the hotel respond.
6. Sending data outside Nigeria
Some of our providers are outside Nigeria, including in the European Union and the United States. Where we transfer personal data across borders we rely on a lawful mechanism under the NDPA, such as an adequacy finding, Standard Contractual Clauses, binding commitments from the provider, or your consent, so that your data keeps an equivalent level of protection.
7. How long we keep it
- Account data: while your account is active, and afterwards only as long as we need for legal, accounting and dispute reasons.
- Contact-form messages: as long as needed to deal with your enquiry and reasonably follow up.
- Security data such as sign-in attempt records and one-time tokens: a short time, then discarded.
- When a hotel ends its agreement, on request we delete or anonymise its data within 90 days, except what we must keep by law. Backups are overwritten on their normal cycle.
8. How we protect it
Passwords are stored as salted hashes. Traffic is encrypted in transit. Sessions use signed, HTTP-only cookies. Two-factor authentication is available and recommended for owners and managers. Access inside the product is role-based and important actions are audit-logged. Payment gateway secrets are encrypted at rest. Sign-in and reset flows are rate limited. Payment confirmations from gateways are signature-verified. We review our security regularly. No system is perfectly secure, so if something goes wrong we will act quickly and tell you as described below.
9. Your rights
Under the NDPA (and the GDPR where it applies), you can ask us to:
- tell you whether we hold data about you and give you a copy;
- correct data that is wrong or incomplete;
- delete data we no longer need or have no lawful basis to keep;
- restrict or stop certain processing, including objecting to processing based on legitimate interests;
- give you your data in a portable format;
- withdraw consent you gave, at any time, without affecting what was done before.
Email consulawtech@gmail.com. We may need to confirm who you are, and we will respond within 30 days, extendable where the law allows. It is free unless a request is clearly unfounded or excessive. If you are unhappy with our answer, you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng) or, if the GDPR applies, to your local supervisory authority.
11. Children
Alejo OS is for businesses and their staff, and is not directed at children. We do not knowingly collect data from anyone under 18 for our own purposes. If you think a child has given us data, contact us and we will delete it.
12. If something goes wrong
If a personal data breach is likely to put people at risk, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware, and affected people or hotels without undue delay, saying what happened, what data is involved and what we are doing about it. For a breach affecting hotel data, we notify the hotel so it can meet its own obligations.
13. Changes to this policy
We will post any update here with a new “last updated” date, and for material changes tell account holders by email or in the app.
14. Contact
Consulaw Tech Services, maker of Alejo OS. Data protection requests and questions: consulawtech@gmail.com. Supervisory authority in Nigeria: Nigeria Data Protection Commission, ndpc.gov.ng.
