Master Service Agreement
The overarching contract between VisitorsLounge and its subscribing organizations.
- Parties & scope
- Fees & renewal
- Warranties
- Governing law: Nigeria
The contracts and policies that govern your relationship with VisitorsLounge, aligned to the Nigeria Data Protection Act, 2023.
The overarching contract between VisitorsLounge and its subscribing organizations.
Availability targets, support response times, and service credits for paid VisitorsLounge subscriptions.
How VisitorsLounge collects, processes and protects personal data under the Nigeria Data Protection Act, 2023 (NDPA).
Full text below — or grab the PDF for your records.
Updated July 2026
The overarching contract between VisitorsLounge and its subscribing organizations.
This Master Service Agreement ("MSA") is entered into between African Models GServices Ltd, trading as VisitorsLounge ("Provider"), and the organization identified on the order form or online subscription ("Customer").
The MSA governs the Customer's access to and use of the VisitorsLounge platform and any related services (collectively, the "Services"), including subsequent order forms and statements of work.
Provider grants Customer a non-exclusive, non-transferable, worldwide right to access and use the Services for its internal business operations during the subscription term.
Customer is responsible for creating and managing users, roles, and access controls within its tenant, and for the acts and omissions of its authorized users.
Fees are set out on the applicable order form or plan page. Unless stated otherwise, subscriptions renew automatically for successive periods equal to the initial term.
Invoices are payable within fifteen (15) days of the invoice date. Overdue amounts may accrue interest at 1.5% per month or the maximum rate permitted by law, whichever is lower.
As between the parties, Customer retains all right, title and interest in and to Customer Data. Customer grants Provider a limited licence to process Customer Data solely to deliver and improve the Services.
Each party will protect the other's Confidential Information using at least the same degree of care it uses to protect its own, and no less than a reasonable standard of care.
Provider warrants that the Services will perform materially in accordance with its published documentation. Provider's exclusive obligation for breach of this warranty is to use commercially reasonable efforts to correct the non-conformity.
Except as expressly provided, the Services are provided "as is" without warranties of any kind, whether express, implied, statutory or otherwise.
To the maximum extent permitted by law, each party's aggregate liability arising out of or related to this MSA will not exceed the fees paid or payable by Customer to Provider in the twelve (12) months preceding the claim.
In no event will either party be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenues, goodwill, or data.
This MSA remains in effect for the duration of any active subscription. Either party may terminate for material breach that remains uncured for thirty (30) days after written notice.
Upon termination, Customer's right to access the Services ends and Provider will make Customer Data available for export for thirty (30) days, after which it may be deleted.
This MSA is governed by the laws of the Federal Republic of Nigeria. The parties submit to the exclusive jurisdiction of the courts of Lagos State, subject to either party's right to seek injunctive relief in any court of competent jurisdiction.
Before commencing formal proceedings, the parties will attempt to resolve any dispute in good faith through senior-level discussions for at least thirty (30) days.
This MSA, together with any order form and referenced policies (including the SLA and Data Protection Policy), constitutes the entire agreement between the parties and supersedes all prior understandings on its subject matter.
No modification is effective unless in writing and signed (including electronically) by both parties. If any provision is held unenforceable, the remaining provisions will remain in full force.
Updated July 2026
Availability targets, support response times, and service credits for paid VisitorsLounge subscriptions.
Provider will use commercially reasonable efforts to make the Services available with a Monthly Uptime Percentage of at least 99.9% during each calendar month, measured at the load balancer.
"Monthly Uptime Percentage" means total minutes in the month, minus minutes of Unavailability, divided by total minutes in the month, expressed as a percentage.
The Uptime Commitment does not apply to Unavailability caused by: (a) scheduled maintenance announced at least 48 hours in advance; (b) factors outside Provider's reasonable control, including force majeure and internet access failures beyond Provider's demarcation; (c) Customer's equipment, software or third-party services; or (d) Customer's breach of the MSA or acceptable use policy.
Severity 1 — production down for all users: first response within 1 hour, 24×7.
Severity 2 — major feature impaired, workaround unavailable: first response within 4 business hours.
Severity 3 — minor feature impaired, workaround available: first response within 1 business day.
Severity 4 — questions and enhancement requests: first response within 2 business days.
If the Monthly Uptime Percentage falls below the committed level, Customer may request a service credit equal to a percentage of the monthly fee for the affected month: 10% for uptime between 99.0% and 99.9%; 25% for uptime between 95.0% and 99.0%; and 50% for uptime below 95.0%.
Service credits are Customer's sole and exclusive remedy for any failure to meet the Uptime Commitment. Credit requests must be submitted within thirty (30) days of the affected month.
Scheduled maintenance windows are typically performed outside standard business hours in West Africa Time. Emergency maintenance may be performed at any time with notice as soon as reasonably practicable.
Provider performs encrypted backups of tenant data at least daily. The Recovery Point Objective (RPO) is 24 hours; the Recovery Time Objective (RTO) for a full regional failover is 8 hours.
Updated July 2026
How VisitorsLounge collects, processes and protects personal data under the Nigeria Data Protection Act, 2023 (NDPA).
This policy documents VisitorsLounge's approach to processing Personal Data in compliance with the Nigeria Data Protection Act, 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR) where still applicable, and, where relevant, the EU General Data Protection Regulation (GDPR).
Processing is carried out on one or more of the following legal bases under section 25 of the NDPA: consent, performance of a contract, legal obligation, protection of vital interests, public interest, or legitimate interests balanced against data subject rights.
For Customer Data submitted to the platform by an organization ("Tenant"), the Tenant is the Data Controller and VisitorsLounge is the Data Processor.
For account, billing and website analytics data, VisitorsLounge is the Data Controller.
Visitor data: name, contact information, host, photograph, check-in/out times, badge tokens, NDA acceptance.
Employee/host data: name, work email, role, notification preferences.
Account data: administrator name, email, phone, organization, role, authentication tokens.
Operational data: audit logs, device and browser information, IP addresses used for rate limiting and security.
Personal Data is processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; limited to what is necessary; kept accurate and up to date; retained no longer than necessary; and processed with appropriate security (NDPA, s. 24).
Data subjects may exercise the following rights under sections 34–37 of the NDPA: access, rectification, erasure, restriction of processing, objection, portability, and the right not to be subject to solely automated decision-making with legal or similarly significant effects.
Visitors should first contact the Tenant hosting their visit. Requests may also be sent to privacy@visitorslounge.com and will be actioned within thirty (30) days.
Personal Data may be transferred outside Nigeria only where the receiving jurisdiction provides an adequate level of protection or where appropriate safeguards are in place, in accordance with sections 41–43 of the NDPA. Provider relies on Standard Contractual Clauses and comparable mechanisms where required.
Visitor records are retained for the period configured by the Tenant. Photographs and expired records are purged automatically. Account and billing records are retained as required by applicable tax, accounting and anti-money-laundering laws.
Encryption in transit (TLS 1.2+) and at rest for databases and backups.
Row-level security isolating each Tenant's data within a shared database.
Role-based access controls, least-privilege principles and multi-factor authentication for administrative access.
Continuous audit logging for check-in, check-out and administrative actions.
Regular vulnerability scanning and third-party penetration testing.
In accordance with section 40 of the NDPA, VisitorsLounge will notify the Nigeria Data Protection Commission (NDPC) within seventy-two (72) hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, and will inform affected data subjects without undue delay where the risk is high.
VisitorsLounge has designated a Data Protection Officer (DPO) responsible for monitoring compliance with the NDPA. The DPO can be reached at dpo@visitorslounge.com.
Data subjects may lodge a complaint with the Nigeria Data Protection Commission (NDPC) if they believe their rights under the NDPA have been infringed. Contact details are published at ndpc.gov.ng.
These documents are provided for information. They are not legal advice; for tailored terms please contact legal@visitorslounge.com.