Privacy policy
Last updated 26 September 2026
Draft awaiting review by a Nigerian lawyer. It describes how Innix intends to work and is not yet in force.
Innix Technologies Limited (“Innix”, “we”) makes software for hotels, bars and restaurants. This policy explains how we handle personal data, in line with the Nigeria Data Protection Act 2023 (NDPA).
Two different roles
When you use this website or become a customer, Innix decides how your data is used. We are the data controller for it.
When a hotel, bar or restaurant uses Innix to record its guests, the property decides how its guests’ data is used and is the controller. Innix processes that data on the property’s behalf, under a written data processing agreement. Guests with questions about their own data should contact the property first. We will help the property answer.
What we collect on this website
- When you book a demo: your name, phone number, email if you give it, your property’s name, type, size and city, what you use today, how you would like to be contacted and anything you write to us. We also record which page you first arrived on and any campaign tags in the link, so we know which of our efforts work.
- When you browse: we count visits with Plausible Analytics, which does not use cookies, does not collect personal data and does not track you across other websites.
Why we use it
- To arrange and hold your demo, and to follow up about it. Our lawful basis is your consent, given when you send the form, and our legitimate interest in answering enquiries.
- To understand which pages and campaigns bring enquiries, using counts that do not identify you.
We do not sell personal data and we do not use it for advertising.
Who we share it with
Only the service providers we need, each bound by a contract to protect it. They are listed on our security page. This website’s demo requests are passed to our customer relationship management system. We may disclose data where the law requires it.
Where it is stored
Customer and guest data is stored on Amazon Web Services in the Cape Town region, South Africa. Some providers, such as our messaging and error-monitoring services, may process data in other countries. Where data leaves Nigeria we rely on the safeguards the NDPA allows, such as contractual protections.
How long we keep it
Demo requests are kept for as long as we need to respond and follow up, and no longer than 24 months unless you become a customer. Customer and guest data is kept for as long as the customer’s contract requires, then deleted. Guest ID photos are deleted 90 days after departure by default.
Your rights
Under the NDPA you can ask us to:
- tell you what personal data we hold about you and give you a copy
- correct it if it is wrong
- delete it
- send it to you or another organisation in a usable format
- stop using it, or stop using it for a particular purpose
- withdraw your consent at any time, without affecting what we did before
Email privacy@innix.africa. We reply within 30 days. If you are not satisfied, you can complain to the Nigeria Data Protection Commission.
Security
How we protect data is described in detail on our security page. If a breach puts your data at risk, we will tell you and the Commission within 72 hours of becoming aware.
Changes
If we change this policy we will update the date at the top and, for significant changes, tell customers directly.
Contact
Innix Technologies Limited. Email privacy@innix.africa.