Legal · Privacy

Privacy policy.

Effective 22 September 2026 · Compliant with the Kenya Data Protection Act, 2019

We collect only the personal information we need to respond to your enquiry, confirm your booking, and fulfil our obligations as a hotel. This page explains what we collect, why we collect it, and the rights you have under the Kenya Data Protection Act, 2019 (the “Act”) and the Regulations made under it.

1. Who is the data controller

The data controller responsible for your personal information is Serenity Fort Hotel & Conferencing Ltd, registered in Kenya, with its principal place of business at Taheri Arcade, Mariakani, Kilifi County, Kenya.

If you have any questions about this Policy or how we handle your data, please contact us using the details in section 14 below.

2. What personal information we collect

We collect personal information in three ways: (a) what you give us directly, (b) what is generated when you use our Site, and (c) what is generated when you stay at the Hotel.

(a) Information you give us directly

  • Name, email address, phone number, country of residence
  • Booking details: arrival and departure dates, room preference, meal plan, number of guests, special requests (e.g. dietary needs, accessibility)
  • Event enquiries: organisation name, expected number of delegates, event type, event date(s), contact preference
  • Any free-text information you include in the contact form message field
  • Correspondence between you and us (emails, phone notes, written letters)

(b) Information collected automatically when you use the Site

  • IP address, browser type and version, operating system, device type, screen resolution
  • Pages visited on the Site, time spent on each page, referring URL
  • Approximate geographic location (country / city level, derived from IP address)

See our Cookies Policy for the full details on cookies and similar technologies used on this Site.

(c) Information generated when you stay at the Hotel

  • Check-in records: identification document type and number (passport, national ID, driving licence), date of birth, nationality
  • Stay history: dates of stay, room number, charges incurred, payment method
  • Restaurant and room service orders
  • CCTV footage from public areas of the property for safety and security purposes

We do not knowingly collect sensitive personal data such as health, biometric, or genetic data. Where you choose to share a specific need (e.g. a dietary requirement, an accessibility request), we treat that as the minimum information needed to serve you, and only retain it for the duration of your booking unless you ask us to retain it.

3. Why we collect it

We use your personal information for the following purposes:

  • To respond to your enquiries and confirm bookings
  • To deliver the services you have booked (accommodation, meals, conferences, activities)
  • To meet our legal and regulatory obligations (immigration registration, anti-money-laundering checks, tax records)
  • To process payments and prevent fraud
  • To send you service-related communications (booking confirmation, pre-arrival information, post-stay follow-up if you have raised an issue)
  • To improve the Site and our services through aggregated, non-identifying analytics
  • To maintain the safety and security of our guests, staff, and property

4. Lawful basis

Under the Kenya Data Protection Act, 2019, we rely on the following lawful bases for processing your personal information:

  • Performance of a contract — to take steps at your request before entering into a contract, and to perform the contract we have with you (your booking).
  • Legal obligation — to comply with immigration, tax, anti-money-laundering, and tourism regulations.
  • Legitimate interests — for the proper administration of our business, the security of our property and guests, and the improvement of our services, where your rights and freedoms do not override those interests.
  • Consent — for any marketing communications, for optional cookies, and for any use of your data beyond the purposes above. You can withdraw consent at any time.

5. Who we share your information with

We do not sell or rent your personal information. We share it only with the following categories of recipients, and only the minimum information needed for the purpose:

  • Payment processors — to authorise and process card payments.
  • Immigration authorities — to comply with guest registration requirements under the Tourism Act and immigration regulations.
  • Tax authorities — to comply with VAT and tourism levy obligations.
  • IT and cloud service providers — to host our website, email, and booking records. These providers are contractually bound to protect your data.
  • Professional advisers — lawyers, accountants, and insurers, where necessary.
  • Law enforcement — where we are legally required to do so.

6. How long we keep your information

We retain personal information only for as long as needed for the purposes described in this Policy, or as required by law. Indicative retention periods:

  • Enquiries that do not result in a booking: up to 12 months, then deleted.
  • Booking records (guest registration, payment, stay history): 7 years from the date of stay, in line with tax and anti-money-laundering obligations.
  • CCTV footage from public areas: up to 30 days, unless needed for an incident investigation.
  • Marketing consent records: until you withdraw consent, plus 2 years for proof.

7. Cookies and tracking

Our Site uses a small number of essential cookies (for example, to remember the date you set in the booking form). It does not use marketing or advertising cookies, and does not embed third-party tracking pixels. See our Cookies Policy for the full list.

8. International transfers

Some of our service providers (such as cloud hosting) may store or process your personal information outside Kenya. Where this happens, we take steps to ensure that your data is protected to a standard equivalent to the Kenya Data Protection Act, 2019 — either through contractual safeguards, the use of jurisdictions with adequate protection, or your explicit consent.

9. Security

We take the security of your personal information seriously. We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (HTTPS / TLS), access controls, and staff training. No system is perfectly secure, but we work continuously to reduce risk.

10. Your rights under the Act

Subject to the conditions and exceptions set out in the Kenya Data Protection Act, 2019, you have the following rights:

Your data subject rights

  • Right to be informed — of how your data is being processed (this Policy).
  • Right of access — to request a copy of the personal information we hold about you.
  • Right to rectification — to correct inaccurate or incomplete information.
  • Right to erasure — to ask us to delete your data, where applicable.
  • Right to restriction of processing — to limit how we use your data in certain circumstances.
  • Right to data portability — to receive your data in a structured, commonly used format.
  • Right to object — to processing carried out under our legitimate interests.
  • Right to withdraw consent — at any time, where processing is based on consent.
  • Right not to be subject to automated decision-making — we do not make automated decisions about you.

To exercise any of these rights, contact us using the details below. We will respond within the time limits set by the Act (generally within 30 days). We may need to verify your identity before acting on your request.

11. Children’s data

Our Site is not directed at children under 18, and we do not knowingly collect personal information from children through this Site. Where a child stays at the Hotel, we collect only the minimum identification information required for guest registration, and only from the accompanying adult.

12. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Effective” date. Material changes that affect existing guests will be communicated by email where we hold a valid address.

13. Complaints to the Office of the Data Protection Commissioner

If you believe that we have not handled your personal information in accordance with the Act, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):

  • Website: odpc.go.ke
  • Email: info@odpc.go.ke
  • Telephone: +254 (0)20 780 6000
  • Postal address: P.O. Box 30920 – 00100, Nairobi, Kenya

We would, however, appreciate the chance to deal with your concerns before you approach the ODPC — please contact us first.

14. Contact our data team

For any privacy-related request — access, correction, deletion, objection, or just a question — please contact our Data team:

Serenity Fort Hotel & Conferencing Ltd — Data Team

Taheri Arcade, Mariakani, Kilifi County, Kenya
Email: admin@serenityforthotel.co.ke
Phone: +254 111 898 540

Office of the Data Protection Commissioner: odpc.go.ke