BookSyr Legal

Data Protection

Effective Date: 9 August 2026

Data protection compliance summary for BookSyr — Serious customers. Confirmed bookings.

Regulatory Alignment

BookSyr operates a structured data protection model aligned with the Nigeria Data Protection Act (NDPA) and internationally recognized principles including GDPR (EU/EEA) and UK GDPR concepts where they inform good practice, plus cross-border transfer safeguards for infrastructure providers.

Data Architecture

The platform processes data within its operational workflow: discover vendor → select offering → provide booking details → deposit checkout → confirmation. Only confirmed bookings trigger necessary data sharing with the fulfilling vendor.

Security Controls

Encrypted payment processing via third-party gateways, secure hosting infrastructure, role-based administrative access, transaction references for audit, and controlled vendor visibility into customer booking data.

Data Minimization

Only necessary booking and account data is collected. No storage of full payment card data on BookSyr systems. Limited retention policies. Anonymization or deletion where applicable when data is no longer needed.

Risk Mitigation

Structured vendor data-sharing only after confirmation, secure third-party integrations, clear terms limiting liability exposure for provider-side fulfilment, and transparent cancellation and payment policies shown before checkout.

Strategic Approach

BookSyr is built as a legally structured, regulation-aware platform designed for reliable local growth: controlled data flows, reduced unnecessary collection, and compliance-first operational architecture.