Privacy Policy
How we look after the information you give us.
This policy explains what personal information Mwiko Lodge collects when you use this website, why we collect it, who we share it with, and the rights you have over it. It is written to meet Rwanda’s Law N° 058/2021 relating to the protection of personal data and privacy.
Who is responsible for your data
The data controller is Dolfin Rwanda Ltd, trading as Mwiko Lodge, [110372133 / TIN], of Lake Ruhondo, Northern Province, Rwanda.
For any question about this policy, or to exercise any of the rights described below, write to hello@mwikolodge.com or call +250 799 538 770.
What we collect and why
When you book a room
We collect your first and last name, email address, phone number, nationality, your chosen dates and room, the number of guests, and any special requests you write. We need this to hold your reservation, prepare for your stay, and contact you about it. Without it we cannot accept a booking.
When you pay
Payments are handled on DPO Network own secure pages. We never see or store your full card number, expiry date or security code. We receive only the outcome of the payment, the amount, and a gateway reference so we can reconcile your booking.
When you reserve a table
We collect your name, contact details, the date and time you want, and your party size, so we can hold the table.
When you write to us
The contact form collects your name, email address, subject and message, so we can reply.
When you subscribe to the journal
We store your email address and the page you subscribed from, so we can send you our occasional journal letter. You can unsubscribe at any time using the link at the bottom of every letter.
When you leave feedback after your stay
Our post-stay survey collects your name, your email address, six star ratings, and anything you choose to write. We publish your first name, your overall rating and your words on this website only if you tick the consent box on the survey. If you do not tick it, your feedback is read only by our team and is never published. You can withdraw that consent at any time by writing to us.
Our legal basis for using your information
- Performance of a contract — to take and honour your booking, and to serve you during your stay.
- Consent — for the journal newsletter, and for publishing your feedback on this website. You may withdraw consent at any time.
- Legal obligation — to keep accounting, tax and tourism records that Rwandan law requires us to keep.
- Legitimate interests — to secure our website, prevent fraud, and improve the lodge, balanced against your rights.
Who we share it with
We do not sell your personal information, and we do not share it for anyone else’s marketing. We do rely on a small number of service providers who process data on our instructions:
- Supabase — the database that stores bookings, guests, reservations and feedback.
- Railway — hosting for this website and our booking system.
- Cloudinary — storage and delivery of photographs used on the site.
- Resend — sending booking confirmations, check-out notes and the journal letter.
- RSwitch — Rwanda’s national payment switch, which processes your card or mobile money payment.
We also disclose information where the law requires it, for example to the Rwanda Revenue Authority, the Rwanda Development Board, or a competent court or authority.
Where your information is stored
Our database and hosting are currently operated from data centres in the European Union (Ireland), which is outside Rwanda. Rwandan law permits storing personal data abroad only where the controller holds a valid registration certificate from the National Cyber Security Authority authorising it, and where appropriate safeguards are in place. [CONFIRM NCSA REGISTRATION AND OFFSHORE STORAGE AUTHORISATION STATUS BEFORE PUBLISHING THIS PAGE.]
How long we keep it
- Booking, guest and payment records — [7] years after your stay, to satisfy accounting and tax obligations.
- Restaurant reservations — [24] months.
- Contact form messages — [24] months after the conversation ends.
- Newsletter subscriptions — until you unsubscribe.
- Feedback — [3] years, or until you ask us to erase it. Published feedback is removed from the site as soon as you withdraw consent.
Your rights
Under Rwandan data protection law you may ask us to:
- Give you a copy of the personal information we hold about you.
- Correct anything that is wrong or incomplete.
- Erase your information where we no longer have a reason to keep it.
- Restrict or object to how we use it.
- Withdraw consent you previously gave, including for the newsletter and for published feedback.
- Receive your information in a portable, machine-readable form.
Write to hello@mwikolodge.com and we will respond within the period the law allows. If you are not satisfied with our answer, you may complain to Rwanda’s National Cyber Security Authority (NCSA), which supervises data protection.
Cookies
This website does not use advertising cookies, analytics cookies, or any third-party tracking. The only cookie we set is a session cookie for staff signing in to our private administration area. Because it is strictly necessary for that service to work, it does not require your consent.
Security
Access to guest records is restricted to authorised staff accounts protected by passwords. Traffic between your browser and this site is encrypted. Payment card details never reach our systems. No system is perfectly secure, but we take reasonable steps to protect your information and will notify you and the authority of a breach where the law requires it.
Children
This website is not directed at children, and we do not knowingly collect personal information from a child other than the guest details a parent or guardian supplies when booking a family stay.
Changes
If we change this policy we will update the date shown at the top of this page. Material changes affecting how we use your information will be communicated to you directly where we can.