Legal
Privacy Policy
Last updated: 23 May 2026
This Privacy Policy explains how the AMORC Booking System ("we", "us") collects, uses and protects your personal data when you visit bookings.amorcame.org or make a booking. It is written to comply with the Nigeria Data Protection Act 2023.
1. Data controller
The data controller is:
AMORC Africa
Email: rm.capetown@amorcame.org
2. What we collect
When you make a booking we collect the following personal data:
- Identification: full name, email address, optional phone number, and your AMORC membership number.
- Booking details: the event you booked, number of attendees, payment amount, donation amount.
- Attendance information: dietary requirements or allergies, and transport requirements, where you supply them.
- Payment metadata: Paystack transaction identifiers (we do not see or store card numbers).
- Technical data: the IP address and basic device information accompanying your request, retained only in standard server logs.
3. Why we use it (purposes and lawful bases)
We process your personal data for the following purposes, with the lawful bases shown:
- To process and fulfil your booking, including sending you confirmation, programme and follow-up emails — lawful basis: performance of a contract with you.
- To cater for your dietary, accessibility and transport needs at the event — lawful basis: performance of a contract with you, with dietary information that may include health data processed on the basis of your explicit consent given at booking.
- To maintain the security and integrity of the booking system — lawful basis: legitimate interests (running a secure service).
We do not send marketing email and we do not use your data for profiling or automated decision-making.
4. Who we share it with
We share personal data only with the following processors, each of which acts on our written instructions and is subject to a data processing agreement:
- Stripe — payment processing (Stripe Payments Europe Ltd., Ireland; with onward transfer to Stripe, Inc. in the United States under Standard Contractual Clauses).
- Amazon Web Services (Amazon Simple Email Service) — delivery of transactional email (processed in the London (eu-west-2) region).
- Laravel Forge / DigitalOcean — hosting infrastructure (London region).
- Cloudflare — DNS and edge network in front of the site.
We do not sell, rent or otherwise share your personal data with third parties for their own purposes.
5. International transfers
Our primary processing takes place in the United Kingdom and the European Union. Where any transfer of personal data outside the UK or EEA is necessary (for example, certain Stripe operations), the transfer is governed by the UK International Data Transfer Agreement, UK Addendum to the EU Standard Contractual Clauses, or an equivalent recognised safeguard.
6. How long we keep it
- Booking and payment records: kept for six years after the end of the financial year in which the booking was made, in accordance with HMRC accounting record-keeping requirements.
- Server logs containing IP addresses: 30 days.
- Booking-related email (e.g. enquiries by email): up to 12 months from last correspondence, unless retention is required for accounting reasons.
Where you ask us to erase data that we are legally required to retain, we will anonymise the record so that you are no longer identifiable from it, while keeping the underlying financial entry intact.
7. Your rights
Under UK GDPR you have the following rights in respect of your personal data:
- Right of access — to be told what we hold about you and receive a copy.
- Right to rectification — to have inaccurate data corrected.
- Right to erasure ("right to be forgotten") — subject to legal retention exceptions described above.
- Right to restriction or to object to processing.
- Right to data portability for data you supplied directly.
- Right to withdraw consent at any time where processing is based on consent (e.g. dietary information).
- Right to lodge a complaint with the Nigeria Data Protection Commission (NDPC). https://ndpc.gov.ng
To exercise any of these rights, email rm.capetown@amorcame.org with the request and enough detail to identify the booking. We will respond within one calendar month.
8. Cookies
We use only cookies that are strictly necessary for the booking flow to function (session and CSRF protection). We do not use analytics, advertising or tracking cookies. See our Cookie Policy for the full list.
9. Security
Connections to the site are encrypted with TLS. Card details are entered on Stripe's hosted pages and never reach our servers; we are out of scope for PCI DSS card storage and are eligible for SAQ A self-assessment. Administrative access to the booking system requires authentication with second-factor support, and all administrator actions on bookings are logged.
10. Changes to this policy
We may update this policy. The "last updated" date at the top of the page indicates the current version. Material changes that affect how we process your data will be flagged on the home page and, where appropriate, by direct email.
11. Contact
Questions about this policy or your data: rm.capetown@amorcame.org