Luzora Travel

Legal

Data Protection Policy

Luzora Travel's commitment to lawful, fair, and transparent processing of personal data.

Last updated: 30 June 2026Effective: 30 June 2026

1. Overview

Our Commitment

Luzora Travel is committed to processing personal data responsibly, transparently, and in full compliance with applicable data protection law. This policy applies to all personal data processed by Luzora - whether belonging to customers, property partners, employees, or other individuals whose data passes through our platform.

This Data Protection Policy supplements our Privacy Policy and Cookies Policy. It sets out our internal governance standards and obligations under applicable law.

3. Data Controller

Luzora Travel acts as the data controller for all personal data collected and processed through the luzoratravel.com platform, the customer-facing web application, the partner dashboard, and internal HR and administrative systems.

Where Luzora processes data on behalf of property partners (for example, managing guest records within the partner dashboard), Luzora also acts as a data processor on the property partner's behalf. In these cases, a Data Processing Agreement (DPA) governs the arrangement.

Data Controller Details

Company: Luzora Travel

Registration: Kenya

Contact: support@luzoratravel.com

Address: Westlands Business Park, Nairobi, Kenya

4. Data Protection Principles

All personal data processed by Luzora must comply with the following principles:

Lawfulness, Fairness & Transparency

Data is processed on a lawful basis and in a manner that is fair and transparent to the data subject.

Purpose Limitation

Data is collected for specified, explicit, and legitimate purposes and not processed in ways incompatible with those purposes.

Data Minimisation

Only the data that is necessary for the stated purpose is collected and processed.

Accuracy

Personal data is kept accurate and up to date. Inaccurate data is corrected or deleted promptly.

Storage Limitation

Data is not kept longer than necessary for the purpose for which it was collected.

Integrity & Confidentiality

Data is processed with appropriate security measures to protect against unauthorised access, loss, or destruction.

Accountability

Luzora takes responsibility for compliance and can demonstrate how compliance is maintained.

5. Categories of Data We Process

5.1 Customer Data

  • Identity data: name, date of birth, nationality, passport/national ID number
  • Contact data: email address, phone number, physical address
  • Transaction data: booking history, payment records, refund history
  • Preference data: travel preferences, dietary requirements, special assistance needs
  • Technical data: IP address, device information, session tokens
  • Loyalty data: points balance, redemption history, tier status
  • Communications data: support messages, reviews, feedback

5.2 Property Partner Data

  • Business identity data: company name, registration details, KRA PIN
  • Contact data: property address, email, phone
  • Financial data: bank account details, commission records, payout history
  • Operational data: room inventory, pricing, availability, booking records
  • Guest data processed on behalf of properties (controller-processor relationship)

5.3 Employee & HR Data

Described in detail in Section 13 below.

6. Lawful Basis for Processing

Under the Kenya DPA 2019 and GDPR, every processing activity must have a lawful basis. Luzora relies on the following bases:

  • Contract: Processing necessary to perform or prepare for a contract with you (bookings, account management, HR contracts).
  • Legal Obligation: Processing required to comply with a legal obligation (KRA tax records, anti-money laundering requirements, employment law).
  • Legitimate Interests: Processing for our legitimate business interests where those interests are not overridden by your rights (platform security, fraud prevention, analytics).
  • Consent: Processing based on your specific, informed, and freely given consent (marketing emails, optional analytics cookies). Consent may be withdrawn at any time.
  • Vital Interests: Processing necessary to protect life in emergency situations (e.g. sharing location data with emergency services during a travel incident).

7. Data Subject Rights

Individuals whose data we process ("data subjects") have the following rights under the Kenya DPA 2019:

RightWhat It MeansResponse Time
AccessObtain a copy of your personal data and information about how it is used30 days
RectificationCorrect inaccurate or incomplete data30 days
ErasureDelete your data where there is no overriding legal reason to retain it30 days
RestrictionRestrict processing while accuracy or legal basis is disputed30 days
PortabilityReceive your data in a structured, machine-readable format30 days
ObjectionObject to processing based on legitimate interests or direct marketingImmediate for marketing; 30 days otherwise
Withdraw ConsentWithdraw consent for consent-based processing at any timeImmediate

To exercise any right, email support@luzoratravel.com with your full name and the nature of your request. We will verify your identity before processing any request.

8. Data Processing Agreements

Where Luzora engages third parties to process personal data on our behalf, we enter into Data Processing Agreements (DPAs) that require those parties to:

  • Process data only on Luzora's documented instructions
  • Implement appropriate technical and organisational security measures
  • Not sub-process data without Luzora's prior consent
  • Delete or return all personal data upon termination of the agreement
  • Assist Luzora in fulfilling data subject rights requests and breach notifications

Current data processors include: Render (hosting), Vercel (frontend hosting), Cloudinary (media storage), Resend (email), Stripe, PesaPal, and Safaricom M-Pesa (payments).

9. Cross-Border Data Transfers

Luzora's infrastructure involves international data transfers. Specifically:

  • United States: Render (hosting), Vercel (frontend), Stripe (payments), Cloudinary (media)
  • European Union: Some Stripe operations are EU-based

For transfers from the EEA or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. For transfers outside Kenya, we apply equivalent safeguards in accordance with the Kenya DPA 2019 requirements.

10. Data Breach Response

In the event of a personal data breach, Luzora will:

  • Contain and assess the breach within 24 hours of discovery
  • Notify the Office of the Data Protection Commissioner (ODPC) within 72 hours where the breach poses a risk to individuals' rights and freedoms
  • Notify affected data subjects without undue delay if the breach is likely to result in a high risk to their rights
  • Document all breaches internally, including those not requiring notification
  • Take remediation steps to prevent recurrence

If you believe your personal data has been compromised, please notify us immediately at support@luzoratravel.com.

11. Data Protection Impact Assessment (DPIA)

Luzora conducts Data Protection Impact Assessments (DPIAs) before implementing new processing activities that are likely to result in a high risk to individuals. DPIAs are mandatory for:

  • Large-scale processing of special categories of data
  • Systematic monitoring of publicly accessible areas
  • New technologies involving biometric or health data
  • Processing that could result in significant financial or social consequences for individuals

12. Special Categories of Data

We treat the following as special categories requiring heightened protection:

  • Health and dietary information (collected to facilitate accessibility needs or special meal requests)
  • Passport and travel document data (required by some properties and immigration authorities)
  • Biometric data (not currently collected; will require explicit consent if introduced)

Special category data is processed only with your explicit consent or where strictly necessary to fulfil a service you have requested.

13. Employee & HR Data

Luzora processes a wide range of HR and employment data through its integrated HRMS platform, including for Luzora staff and, where applicable, property partner employees. This includes:

  • Employment records: job title, department, payroll number, contract type
  • Payroll data: salary, PAYE tax calculations (Kenya Revenue Authority), NHIF, NSSF deductions
  • Leave and attendance records
  • Performance reviews and appraisals
  • Training and certification records
  • Recruitment records (job applications, interview notes)
  • National ID and KRA PIN (for tax compliance)
  • Bank account details (for payroll payments)
  • Emergency contact information

Employee data is processed on the legal bases of contractual necessity (employment contract), legal obligation (tax and employment law), and legitimate interests (workforce management). Employee data is retained for the duration of employment plus 7 years as required by Kenyan employment and tax law.

Employees and property partner staff may exercise all data subject rights listed in Section 7 above.

14. Contact & Complaints

For any data protection queries, subject access requests, or complaints, please contact our team:

Email: support@luzoratravel.com

Address: Westlands Business Park, Nairobi, Kenya

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) Kenya at odpc.go.ke.