Privacy Policy
Last updated: June 2025
This Privacy Policy explains how (hereinafter referred to as "we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you visit or interact with our website located at www.elvorohotelretreat.com (the "Website"), make a reservation, use our hotel-casino services, or communicate with us in any way.
We are committed to protecting your privacy and handling your personal data in a transparent, fair, and lawful manner, in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), and all other applicable data protection legislation.
Please read this Privacy Policy carefully before using our Website or services. By accessing our Website, making a reservation, or engaging with our services, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for processing your personal data (the "Data Controller") is:
| Company Name | |
|---|---|
| Trading Name | Elvorohotel Retreat |
| Registration Country | Canada |
| Company Registration Number | 1525565 |
| VAT Number | 135984276 RT0001 |
| Registered Legal Address | |
| Website | www.elvorohotelretreat.com |
| Privacy Contact Email | info@elvorohotelretreat.com |
If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact us at any time using the contact details provided in Section 11 of this Privacy Policy.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing compliance with data protection legislation and serving as a point of contact for all data protection matters.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Contact Address | |
| info@elvorohotelretreat.com |
You have the right to contact our Data Protection Officer directly regarding any matter relating to the processing of your personal data or the exercise of your rights under applicable data protection law.
3. Personal Data We Collect
We collect and process various categories of personal data about you, depending on your interaction with us. The personal data we collect may include, but is not limited to, the following:
3.1 Identity and Contact Data
- Full name (first name and surname)
- Date of birth
- Gender
- Nationality and country of residence
- Passport number, national identification number, or other government-issued identification document details (where required by law or for check-in purposes)
- Email address
- Telephone number(s)
- Postal address (home or billing address)
3.2 Reservation and Stay Data
- Booking reference numbers and reservation history
- Check-in and check-out dates
- Room type preferences and special requests
- Number of guests and guest details (including accompanying minors)
- Dietary requirements and accessibility needs
- Loyalty programme membership details
- Length of stay and past stay history
3.3 Financial and Payment Data
- Payment card type, last four digits, and expiry date
- Billing address
- Transaction history, invoices, and receipts
- Bank account details (where applicable for refunds or direct billing arrangements)
Please note: Full payment card numbers are not stored by us. Payment processing is carried out by PCI-DSS compliant third-party payment processors, and we only retain tokenised or partial card data necessary for legitimate business purposes.
3.4 Casino and Gaming Data
- Gaming activity records, including games played, wagers placed, wins, and losses
- Casino account registration data
- Player identification information as required under applicable gaming regulations
- Self-exclusion requests and responsible gambling preferences
- Anti-money laundering (AML) and know-your-customer (KYC) verification data, including identity documents and source of funds information
- Gaming session timestamps and duration
3.5 Technical and Usage Data
- IP address
- Browser type and version
- Device type, operating system, and hardware model
- Pages visited on our Website and navigation patterns
- Date and time of access
- Referring URLs and exit pages
- Cookie identifiers and similar tracking technologies (see our Cookie Policy)
- Session duration and interaction data
3.6 Communications Data
- Content of email, telephone, live chat, and written correspondence with us
- Feedback, reviews, survey responses, and complaints submitted to us
- Records of your marketing preferences and opt-in/opt-out history
3.7 Special Categories of Personal Data
In certain limited circumstances, we may collect and process special categories of personal data as defined under Article 9 of the GDPR. This may include:
- Health information (e.g., dietary requirements, disability or accessibility needs, medical emergencies during your stay)
- Biometric data (e.g., where used in security access control systems on our premises)
We will only process such special category data where we have an explicit legal basis to do so, such as your explicit consent, where processing is necessary to protect your vital interests, or where required by law. We apply heightened safeguards to all special category data.
3.8 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies (OTAs) and booking platforms through which you make a reservation
- Corporate clients or travel managers making bookings on your behalf
- Credit reference and fraud prevention agencies
- Regulatory and licensing authorities in connection with our gaming operations
- Social media platforms, where you interact with our social media profiles or connect your social media account to our services
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so in accordance with Article 6 of the GDPR. The legal bases upon which we rely are set out below:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process personal data where such processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing your reservation and managing your stay at our hotel
- Creating and managing a casino account
- Processing payments for hotel and casino services
- Responding to enquiries and pre-booking communications
- Managing loyalty programme memberships and associated benefits
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where processing is necessary for compliance with a legal obligation to which we are subject. This includes:
- Verifying your identity as required under anti-money laundering (AML), counter-terrorism financing (CTF), and gaming regulatory obligations
- Maintaining financial and accounting records as required under tax law
- Retaining records related to guest check-in as required by applicable immigration or security legislation
- Complying with court orders, regulatory investigations, or requests from competent authorities
- Meeting responsible gambling obligations under applicable gaming regulations
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process personal data where it is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, provided such interests are not overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include:
- Improving and optimising our Website, products, and services
- Ensuring the security and integrity of our premises, systems, and operations (including CCTV monitoring)
- Preventing and detecting fraud, theft, cheating, and other unlawful activities
- Managing and administering our business operations efficiently
- Conducting direct marketing of our own similar services to existing customers (subject to your right to opt out)
- Analysing usage patterns and customer behaviour to enhance user experience
- Establishing, exercising, or defending legal claims
Where we rely on legitimate interests, we have conducted and documented a Legitimate Interests Assessment (LIA) to ensure that our interests are balanced against your rights and interests. You may request a summary of this assessment from our Data Protection Officer.
4.4 Consent (Article 6(1)(a) GDPR)
In certain circumstances, we process your personal data based on your freely given, specific, informed, and unambiguous consent. This includes:
- Sending you marketing communications, newsletters, and promotional offers where you have opted in to receive such communications
- Placing non-essential cookies and similar tracking technologies on your device (see our Cookie Policy)
- Processing special category data, such as detailed health or dietary information beyond what is strictly necessary
Where we rely on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. You may withdraw consent by contacting us at info@elvorohotelretreat.com or by using the unsubscribe link included in any marketing communications.
4.5 Protection of Vital Interests (Article 6(1)(d) GDPR)
We may process personal data where such processing is necessary to protect the vital interests of you or another natural person. This may occur in emergency situations, such as a medical emergency during your stay, where we may need to share your health information with emergency medical services.
4.6 Public Interest or Official Authority (Article 6(1)(e) GDPR)
In limited circumstances, we may process personal data where such processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, including cooperation with regulatory and law enforcement bodies in connection with our licensed gaming activities.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Providing Hotel Services
- Processing and managing hotel reservations, check-in, and check-out
- Allocating rooms and fulfilling special requests and preferences
- Providing concierge, housekeeping, dining, spa, and other ancillary services during your stay
- Managing cancellations, amendments, and refunds
- Communicating with you before, during, and after your stay
5.2 Providing Casino and Gaming Services
- Creating and managing your casino account
- Administering gaming sessions and transactions
- Fulfilling our legal obligations under gaming licensing and regulatory requirements
- Implementing responsible gambling measures, including self-exclusion programmes and spending limits
- Conducting KYC and AML checks as required by law
- Detecting and preventing fraud, cheating, and money laundering
5.3 Payment Processing
- Processing and verifying payments for hotel and casino services
- Handling refunds, disputes, and chargebacks
- Maintaining financial records and complying with accounting and tax obligations
5.4 Security and Safety
- Operating CCTV surveillance systems on our premises for the safety and security of guests, staff, and property
- Monitoring access to restricted areas
- Investigating incidents, complaints, and potential breaches of our terms and conditions
- Preventing and detecting criminal activity
5.5 Marketing and Communications
- Sending you promotional offers, newsletters, and personalised recommendations for hotel and casino services (subject to your consent or opt-out preference)
- Administering competitions, prize draws, and special promotions
- Conducting customer satisfaction surveys and collecting feedback
- Personalising your experience on our Website and in our services
5.6 Website and Service Improvement
- Analysing Website traffic and user behaviour to improve functionality and user experience
- Conducting research and analytics to develop new services and improve existing ones
- Testing, maintaining, and securing our IT systems and infrastructure
5.7 Legal and Compliance Purposes
- Complying with all applicable legal and regulatory obligations
- Establishing, exercising, or defending legal claims
- Responding to requests from regulatory, law enforcement, and governmental authorities
- Maintaining accurate business records for audit and governance purposes
6. Sharing Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients only where necessary and in accordance with applicable data protection law:
6.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions as data processors. These include:
- Payment processing and fraud prevention service providers
- IT infrastructure, cloud hosting, and cybersecurity providers
- Property Management System (PMS) and hotel management software providers
- Casino management system operators
- Email marketing and customer communications platforms
- Customer relationship management (CRM) system providers
- Online booking and reservation platform providers
- Website analytics providers (e.g., anonymised or pseudonymised usage data)
- Legal, accounting, and professional advisory firms
All service providers are bound by contractual obligations (including Data Processing Agreements where required) to process personal data only in accordance with our instructions and to implement appropriate technical and organisational security measures.
6.2 Business Partners
We may share personal data with carefully selected business partners where this is necessary to provide you with a service you have requested, such as:
- Travel agencies and online booking platforms through which you made your reservation
- Partner restaurants, spas, entertainment venues, and activity providers whose services you access through us
- Loyalty programme partners
6.3 Regulatory and Gaming Authorities
As a licensed casino operator, we are required to share certain personal data with gaming regulatory and licensing authorities as mandated by law. We also cooperate fully with financial intelligence units and other competent authorities in connection with our AML and CTF obligations.
6.4 Law Enforcement and Competent Authorities
We may disclose personal data to law enforcement agencies, courts, regulatory bodies, or other competent public authorities where we are legally required or permitted to do so, or where such disclosure is necessary to protect the rights, property, or safety of our business, our guests, our staff, or the public.
6.5 Corporate Transactions
In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceedings involving , personal data may be transferred to the relevant third parties as part of such a transaction. We will take reasonable steps to ensure that your data remains protected and that you are notified of any material change in its use.
6.6 International Transfers
Where we transfer your personal data outside of the European Economic Area (EEA) or Canada, we ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection law. Such safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions issued by the European Commission or the relevant Canadian authority
- Binding Corporate Rules (BCRs) where applicable
- Other appropriate legal mechanisms as permitted by applicable law
You may request further information about international transfer safeguards by contacting our Data Protection Officer at info@elvorohotelretreat.com.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria used to determine our retention periods include:
- The nature and purpose of the personal data
- The duration of our contractual or business relationship with you
- Legal and regulatory retention obligations applicable to hotel operators and licensed casino operators in Canada and under applicable gaming legislation
- Applicable limitation periods for legal claims
- The potential risk of harm from unauthorised use or disclosure
As a general guide, we apply the following retention periods:
| Category of Personal Data | Retention Period |
|---|---|
| Hotel reservation and guest stay records | 7 years from the date of your stay, or as required by applicable law |
| Financial and payment transaction records | 7 years from the date of transaction, as required under applicable tax and accounting legislation |
| Casino account and gaming records | 5–10 years from account closure or last gaming activity, as required under applicable gaming regulations |
| AML/KYC verification documents | 5 years from the end of the business relationship or as required by applicable AML legislation |
| Marketing preference records | Until you withdraw consent or opt out, plus a reasonable period thereafter to evidence compliance |
| Website usage and technical data | Up to 24 months, depending on the type of data and applicable cookie consent |
| CCTV footage | Up to 30 days, unless retained longer in connection with an incident, investigation, or legal claim |
| Correspondence and complaints records | 3–7 years from the date of resolution, depending on the nature of the matter |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data retention and disposal procedures. Where anonymisation is not possible, the data is securely destroyed.
8. Your Rights Under Data Protection Law
Subject to applicable data protection legislation, you have the following rights in relation to your personal data. We will respond to all verified requests within one month of receipt, though this period may be extended by up to two further months in complex or numerous cases, in which case we will notify you.
8.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation from us as to whether we are processing personal data about you, and, where we are, to receive a copy of that personal data together with supplementary information about our processing activities.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to require us to correct any inaccurate personal data we hold about you, and to have incomplete personal data completed, having regard to the purposes of the processing.
8.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request the deletion or removal of your personal data where there is no compelling reason for its continued processing. This right applies in certain circumstances, such as where:
- The personal data is no longer necessary for the purposes for which it was collected
- You withdraw your consent and there is no other legal basis for processing
- You object to the processing and there are no overriding legitimate interests
- The personal data has been unlawfully processed
Please note that this right is not absolute and may be limited by our legal and regulatory obligations to retain certain data (for example, gaming records, AML documentation, and financial records).
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you do not want erasure, or where we no longer need the data but you require it for legal claims.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.
8.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests or the performance of a public task as our legal basis. You also have the absolute right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing, at any time.
8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for the performance of a contract, permitted by applicable law, or based on your explicit consent.
Where we engage in automated decision-making that may significantly affect you (including in the context of responsible gambling monitoring or fraud prevention), we will notify you and provide you with the opportunity to request human review of the decision.
8.8 Right to Withdraw Consent
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal. You may withdraw consent by contacting us at info@elvorohotelretreat.com or by using the unsubscribe mechanism in any marketing communications.
8.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada:
- Website: www.priv.gc.ca
- Telephone: 1-800-282-1376
- Address: 30 Victoria Street, Gatineau, Quebec, K1A 1H3, Canada
You also have the right to complain to the Information and Privacy Commissioner of Ontario:
- Website: www.ipc.on.ca
- Telephone: 416-326-3333 or 1-800-387-0073
- Address: 2 Bloor Street East, Suite 1400, Toronto, Ontario, M4W 1A8, Canada
We would, however, welcome the opportunity to address your concerns directly before you approach a supervisory authority, and we encourage you to contact us in the first instance.
8.10 Exercising Your Rights
To exercise any of the rights set out above, please submit a written request to our Data Protection Officer using the contact details provided in Section 11 of this Privacy Policy. We may need to verify your identity before processing your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.
10. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit using SSL/TLS protocols
- Encryption of sensitive data at rest
- Access controls and role-based permissions restricting access to personal data to authorised personnel only
- Regular security assessments, vulnerability scanning, and penetration testing
- Staff training on data protection and information security
- Incident response and data breach notification procedures
- Physical security measures at our premises
- PCI-DSS compliant payment processing systems
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authorities in accordance with our legal obligations and within the timeframes required by applicable law.
11. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or to the processing of your personal data, please contact us using the details below:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Postal Address | |
| Email Address | info@elvorohotelretreat.com |
| Website | www.elvorohotelretreat.com |
We are committed to working with you to resolve any concerns about our privacy practices and to respond to all legitimate requests in a timely and transparent manner.
12. Updates to This Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons. When we make material changes to this Privacy Policy, we will notify you by posting the updated policy on our Website with a new "Last Updated" date at the top of this page. Where required by law, we will seek your consent to any material changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our Website or services following the posting of changes constitutes your acknowledgement of the updated Privacy Policy.
If you have any questions about any changes to this Privacy Policy, please contact our Data Protection Officer using the details set out in Section 11 above.