Privacy Policy

1. Introduction and Scope

This Privacy Policy explains how United Nigeria Airlines (“UNA”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects the personal data of passengers, website and app users, agents, corporate clients, job applicants, and other individuals (“you”) who interact with our website, mobile app, booking channels, airport, and in-flight services (together, our “Services”).

This Policy is written to comply with the Nigeria Data Protection Act (NDPA) 2023 and any other applicable Nigerian data protection law and regulations and any amendment to such legislation and regulations.

This Policy applies wherever you engage with us — our website, mobile app, call centre, airport counters, travel agents, and social media pages. It does not apply to third-party websites we do not control, even where we link to them.

2. Definitions

  • “Personal Data” means any information that can identify you, directly or indirectly, such as your name, phone number, email address, or an online identifier.

  • “Data Controller” means UNA, the entity that decides why and how your personal data is processed.

  • “Data Processor” means a third party that processes personal data on our behalf and under our instructions.

  • “Processing” means anything done with personal data, including collecting, storing, using, sharing, or deleting it.

  • “NDPC” means the Nigeria Data Protection Commission, Nigeria’s data protection regulator.

3. Our Data Protection Principles

We handle personal data according to the following principles. Everything we do with your data is:

  • Lawful, fair, and transparent.

  • Collected for clear, specific purposes, and not used for anything incompatible with those purposes.

  • Limited to what we actually need for those purposes.

  • Kept accurate and up to date, and corrected or removed promptly if it isn’t.

  • Kept only for as long as we need it.

  • Protected with appropriate security.

  • Our responsibility — we can demonstrate that we follow these principles.

4. Personal Data We Collect

We collect personal data you give us directly, data generated through your use of our Services, and, occasionally, data given to us by a third party (such as a travel agent booking on your behalf).

4.1 Categories of Personal Data

UNA currently collects:

  • Identity and contact data: first name, last name, phone number, and email address.

  • Booking and travel data: reservation details and itinerary (flight number, date, and booking reference) linked to your name, phone number, and email address, needed to provide your flight.

  • Payment data: when you pay online, your card details go directly to our payment processing partner. UNA does not receive or store your full card number (see section 8).

  • Technical and usage data: IP address, device information, browser type, and information from cookies when you use our website or app.

If you join our Unity Rewards loyalty programme, we also collect further information needed to manage your membership and tier status, including your date of birth, passport number, and flight history. Joining Unity Rewards is voluntary, but this information is needed to credit points and award tier benefits. This is covered by our separate Unity Rewards Privacy Notice.

As our Services grow, we may in future need to collect further categories of personal data. Before we start collecting any new category, we will update this Policy and, where needed, ask for your consent.

4.2 Sensitive Personal Data

UNA does not collect or process sensitive personal data. This includes health data, biometric data, genetic data, and data about religion, ethnicity, trade union membership, political opinion, sex life, or sexual orientation. If this changes in future, we will update this Policy first and apply appropriate safeguards before any such collection begins.

4.3 Data From Third Parties

Sometimes we receive your personal data from someone else or a third-party entity — for example, a travel agent/agency or another passenger or a legal or corporate entity booking on your behalf. We treat this as done with your permission. If you believe your data was given to us without your consent, contact our Data Protection Officer (section 13) and we will look into it.

5. Our Basis for Using Your Data

Every use of your personal data is supported by one of the following bases:

  • Consent — where you have clearly agreed, for example to marketing messages or non-essential cookies.

  • Contract — to set up and manage your booking and fly you to your destination.

  • Legal obligation — to meet aviation security, customs, immigration, and tax requirements.

  • Vital interest — to protect someone’s life or safety in an emergency.

  • Public interest — for aviation safety or security screening.

  • Legitimate interest — for things like fraud prevention and improving our Services, balanced against your rights.

6. How We Use Your Personal Data

We tell you, when we collect your data, what we’re collecting it for. We use your personal data to:

  • Verify your identity.

  • Set up and manage your booking and travel documents.

  • Respond to customer service enquiries and complaints.

  • Process payments and prevent fraud.

  • Meet aviation safety and security requirements.

  • Improve our Services through statistical analysis.

  • Personalise offers, where you’ve agreed to this.

  • Meet our regulatory and reporting obligations.

  • Let you know about changes that may affect you.

  • Send marketing communications, where you’ve opted in — you can opt out any time.

We won’t use your personal data for a new purpose that doesn’t fit with why we originally collected it, without telling you first and, where needed, asking for your consent.

7. Consent

Except as otherwise required by operation of law or principles of law. You have the right to give, withhold or otherwise withdraw your consent to data processing.

Where we rely on your consent, it will be freely given, specific, informed, and clear — for example, ticking a box that isn’t pre-ticked, or clicking to accept.

You can withdraw consent any time by contacting our Data Protection Officer, updating your account or cookie preferences, or using the unsubscribe link in any marketing message. Withdrawing consent won’t affect anything we did before, or any data processing we carry out on a different basis (for example, completing an existing booking).

8. How We Share Your Personal Data

We don’t sell your personal data, and we don’t share it outside our organisation without good reason. We share it only where necessary, with the categories of recipients below, and always under confidentiality obligations.

8.1 Who We Share Data With

  • Payment processing partners — to process your payment securely.

  • Flight status and notification providers — SMS, email, and push-notification services, to send booking confirmations, check-in reminders, and flight updates like delays or gate changes.

  • Ground handling agents and airport authorities — to check you in and handle your baggage.

  • Codeshare and partner airlines — where your trip involves a connecting flight with another carrier.

  • IT and hosting providers — who run our website, app, and booking systems.

  • Government authorities — aviation, customs, immigration, and tax authorities, where required by law.

  • Professional advisers — lawyers, auditors, and insurers, where needed.

  • Travel agents — where you booked, or someone booked on your behalf, through them.

Any third party that handles data on our behalf must protect it under a written agreement, use it only for the purpose we’ve agreed, and not keep it longer than necessary.

8.2 International Transfers

As an airline operating internationally, and as a business that works with service providers in other countries, we sometimes transfer personal data outside Nigeria. Whenever this happens, we apply appropriate safeguards to protect your data to a standard consistent with the provisions of the Nigeria Data Protection Act (NDPA) currently in force, and, where a transfer requires it, we will ask for your consent and explain any relevant risks beforehand.

8.2.1 Transfers Within Our Own Operations

Where we have our own offices outside Nigeria, personal data shared between those offices and our Nigeria head office is an internal transfer within UNA’s own operations. We apply internal safeguards to make sure this data is protected to the same standard wherever it’s held.

8.2.2 Transfers to Other Parties Outside Nigeria

We also share personal data with independent parties outside Nigeria — for example, government authorities, local service providers, ground handling agents, and service providers that support our Unity Rewards loyalty programme — as needed to operate our Services. These transfers are covered by appropriate contractual and security safeguards. See our separate Unity Rewards Privacy Notice for programme-specific details.

9. How Long We Keep Your Data

We keep your personal data, and records of your activity, only for as long as we need it for the purpose it was collected — taking into account our own retention schedule and any legal, regulatory, tax, or aviation record-keeping requirements. If you haven’t used our Services for a long time, we may delete or anonymise your data, and you may need to re-supply it once you again have the need for our services.

10. Your Rights

You have the right to:

  • Know what personal data we hold about you and how we use it.

  • Access a copy of your personal data.

  • Ask us to correct inaccurate or incomplete data.

  • Ask us to delete your data, where applicable.

  • Object to, or ask us to restrict, how we use your data — including for marketing.

  • Ask us to transfer your data to you or someone else, where feasible.

  • Withdraw consent at any time.

  • Not be subject to a decision based solely on automated processing that significantly affects you, without appropriate safeguards.

  • Complain to the Nigeria Data Protection Commission.

To exercise any of these rights, contact our Data Protection Officer (section 13). We’ll respond promptly. Opting out of certain processing may limit our ability to provide some Services.

11. Keeping Your Data Secure

We use appropriate technical and organisational measures to protect your personal data, including encryption for data in transit, access controls, and staff training.

All card payments are handled by our accredited payment processing partner; UNA does not store your full card details. While we take reasonable steps to protect your data, no method of transmission over the internet is completely secure, so we recommend using strong passwords and a secure, updated browser.

11.1 If a Data Breach Happens

If a personal data breach is likely to put your rights at risk, we will notify the NDPC without undue delay. If it’s likely to put you at high risk, we’ll also notify you directly.

12. Children’s Data

Our Services aren’t directed at children. We don’t knowingly collect personal data from a child, except with a parent or guardian’s consent, or as needed to provide travel services to a minor accompanied or authorised by a parent or guardian. If we learn we’ve collected a child’s data without proper consent, we’ll delete it promptly.

13. Data Protection Officer and Complaints

UNA has a Data Protection Officer (“DPO”) who oversees our data protection practices and acts as your contact point for any questions or concerns.

  • Email: dpo@flyunitednigeria.com

  • General enquiries: info@flyunitednigeria.com

If you’re not satisfied with our response, you can complain directly to the Nigeria Data Protection Commission (NDPC) through its official complaints channel.

14. Cookies and Similar Technologies

Our website and app use cookies to run essential functions, remember your preferences, and, where you consent, understand usage and personalise marketing. You can manage or withdraw your cookie preferences any time through our cookie preference centre or your browser settings. See our separate Cookie Policy for details.

15. Links to Other Websites

Our website may link to third-party websites. This Policy covers only UNA’s own website and Services. We’re not responsible for the privacy practices of any third-party site, so we recommend reviewing their policies before you engage with them.

16. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or Services or in compliance with the lawful directives of our Regulator, the Nigeria Civil Aviation Authority (NCAA) or the Federal Government of Nigeria– in line with the safeguards under the Nigeria Data Protection Act (NDPA) and the 1999 Constitution of the Federal Republic of Nigeria and such amendment thereto. If a change is significant, we’ll take reasonable steps to let you know, such as posting a notice on our website, before it takes effect. We encourage you to check back periodically.

17. Contact Us

Questions or concerns about this Policy or our data practices? Contact us at info@flyunitednigeria.com, or our Data Protection Officer at dpo@flyunitednigeria.com