Privacy Policy

Last updated: June 2025

This Privacy Policy explains how (hereinafter referred to as "we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you visit or interact with our website located at www.elvorohotelretreat.com (the "Website"), make a reservation, use our hotel-casino services, or communicate with us in any way.

We are committed to protecting your privacy and handling your personal data in a transparent, fair, and lawful manner, in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), and all other applicable data protection legislation.

Please read this Privacy Policy carefully before using our Website or services. By accessing our Website, making a reservation, or engaging with our services, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The entity responsible for processing your personal data (the "Data Controller") is:

Company Name
Trading Name Elvorohotel Retreat
Registration Country Canada
Company Registration Number 1525565
VAT Number 135984276 RT0001
Registered Legal Address
Website www.elvorohotelretreat.com
Privacy Contact Email info@elvorohotelretreat.com

If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact us at any time using the contact details provided in Section 11 of this Privacy Policy.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing compliance with data protection legislation and serving as a point of contact for all data protection matters.

DPO Title The Data Protection Officer
Organisation
Contact Address
Email info@elvorohotelretreat.com

You have the right to contact our Data Protection Officer directly regarding any matter relating to the processing of your personal data or the exercise of your rights under applicable data protection law.

3. Personal Data We Collect

We collect and process various categories of personal data about you, depending on your interaction with us. The personal data we collect may include, but is not limited to, the following:

3.1 Identity and Contact Data

  • Full name (first name and surname)
  • Date of birth
  • Gender
  • Nationality and country of residence
  • Passport number, national identification number, or other government-issued identification document details (where required by law or for check-in purposes)
  • Email address
  • Telephone number(s)
  • Postal address (home or billing address)

3.2 Reservation and Stay Data

  • Booking reference numbers and reservation history
  • Check-in and check-out dates
  • Room type preferences and special requests
  • Number of guests and guest details (including accompanying minors)
  • Dietary requirements and accessibility needs
  • Loyalty programme membership details
  • Length of stay and past stay history

3.3 Financial and Payment Data

  • Payment card type, last four digits, and expiry date
  • Billing address
  • Transaction history, invoices, and receipts
  • Bank account details (where applicable for refunds or direct billing arrangements)

Please note: Full payment card numbers are not stored by us. Payment processing is carried out by PCI-DSS compliant third-party payment processors, and we only retain tokenised or partial card data necessary for legitimate business purposes.

3.4 Casino and Gaming Data

  • Gaming activity records, including games played, wagers placed, wins, and losses
  • Casino account registration data
  • Player identification information as required under applicable gaming regulations
  • Self-exclusion requests and responsible gambling preferences
  • Anti-money laundering (AML) and know-your-customer (KYC) verification data, including identity documents and source of funds information
  • Gaming session timestamps and duration

3.5 Technical and Usage Data

  • IP address
  • Browser type and version
  • Device type, operating system, and hardware model
  • Pages visited on our Website and navigation patterns
  • Date and time of access
  • Referring URLs and exit pages
  • Cookie identifiers and similar tracking technologies (see our Cookie Policy)
  • Session duration and interaction data

3.6 Communications Data

  • Content of email, telephone, live chat, and written correspondence with us
  • Feedback, reviews, survey responses, and complaints submitted to us
  • Records of your marketing preferences and opt-in/opt-out history

3.7 Special Categories of Personal Data

In certain limited circumstances, we may collect and process special categories of personal data as defined under Article 9 of the GDPR. This may include:

  • Health information (e.g., dietary requirements, disability or accessibility needs, medical emergencies during your stay)
  • Biometric data (e.g., where used in security access control systems on our premises)

We will only process such special category data where we have an explicit legal basis to do so, such as your explicit consent, where processing is necessary to protect your vital interests, or where required by law. We apply heightened safeguards to all special category data.

3.8 Data Collected from Third Parties

We may also receive personal data about you from third parties, including:

  • Online travel agencies (OTAs) and booking platforms through which you make a reservation
  • Corporate clients or travel managers making bookings on your behalf
  • Credit reference and fraud prevention agencies
  • Regulatory and licensing authorities in connection with our gaming operations
  • Social media platforms, where you interact with our social media profiles or connect your social media account to our services

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Providing Hotel Services

  • Processing and managing hotel reservations, check-in, and check-out
  • Allocating rooms and fulfilling special requests and preferences
  • Providing concierge, housekeeping, dining, spa, and other ancillary services during your stay
  • Managing cancellations, amendments, and refunds
  • Communicating with you before, during, and after your stay

5.2 Providing Casino and Gaming Services

  • Creating and managing your casino account
  • Administering gaming sessions and transactions
  • Fulfilling our legal obligations under gaming licensing and regulatory requirements
  • Implementing responsible gambling measures, including self-exclusion programmes and spending limits
  • Conducting KYC and AML checks as required by law
  • Detecting and preventing fraud, cheating, and money laundering

5.3 Payment Processing

  • Processing and verifying payments for hotel and casino services
  • Handling refunds, disputes, and chargebacks
  • Maintaining financial records and complying with accounting and tax obligations

5.4 Security and Safety

  • Operating CCTV surveillance systems on our premises for the safety and security of guests, staff, and property
  • Monitoring access to restricted areas
  • Investigating incidents, complaints, and potential breaches of our terms and conditions
  • Preventing and detecting criminal activity

5.5 Marketing and Communications

  • Sending you promotional offers, newsletters, and personalised recommendations for hotel and casino services (subject to your consent or opt-out preference)
  • Administering competitions, prize draws, and special promotions
  • Conducting customer satisfaction surveys and collecting feedback
  • Personalising your experience on our Website and in our services

5.6 Website and Service Improvement

  • Analysing Website traffic and user behaviour to improve functionality and user experience
  • Conducting research and analytics to develop new services and improve existing ones
  • Testing, maintaining, and securing our IT systems and infrastructure

5.7 Legal and Compliance Purposes

  • Complying with all applicable legal and regulatory obligations
  • Establishing, exercising, or defending legal claims
  • Responding to requests from regulatory, law enforcement, and governmental authorities
  • Maintaining accurate business records for audit and governance purposes

6. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients only where necessary and in accordance with applicable data protection law:

6.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instructions as data processors. These include:

  • Payment processing and fraud prevention service providers
  • IT infrastructure, cloud hosting, and cybersecurity providers
  • Property Management System (PMS) and hotel management software providers
  • Casino management system operators
  • Email marketing and customer communications platforms
  • Customer relationship management (CRM) system providers
  • Online booking and reservation platform providers
  • Website analytics providers (e.g., anonymised or pseudonymised usage data)
  • Legal, accounting, and professional advisory firms

All service providers are bound by contractual obligations (including Data Processing Agreements where required) to process personal data only in accordance with our instructions and to implement appropriate technical and organisational security measures.

6.2 Business Partners

We may share personal data with carefully selected business partners where this is necessary to provide you with a service you have requested, such as:

  • Travel agencies and online booking platforms through which you made your reservation
  • Partner restaurants, spas, entertainment venues, and activity providers whose services you access through us
  • Loyalty programme partners

6.3 Regulatory and Gaming Authorities

As a licensed casino operator, we are required to share certain personal data with gaming regulatory and licensing authorities as mandated by law. We also cooperate fully with financial intelligence units and other competent authorities in connection with our AML and CTF obligations.

6.4 Law Enforcement and Competent Authorities

We may disclose personal data to law enforcement agencies, courts, regulatory bodies, or other competent public authorities where we are legally required or permitted to do so, or where such disclosure is necessary to protect the rights, property, or safety of our business, our guests, our staff, or the public.

6.5 Corporate Transactions

In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceedings involving , personal data may be transferred to the relevant third parties as part of such a transaction. We will take reasonable steps to ensure that your data remains protected and that you are notified of any material change in its use.

6.6 International Transfers

Where we transfer your personal data outside of the European Economic Area (EEA) or Canada, we ensure that appropriate safeguards are in place to protect your data in accordance with applicable data protection law. Such safeguards may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions issued by the European Commission or the relevant Canadian authority
  • Binding Corporate Rules (BCRs) where applicable
  • Other appropriate legal mechanisms as permitted by applicable law

You may request further information about international transfer safeguards by contacting our Data Protection Officer at info@elvorohotelretreat.com.

7. Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria used to determine our retention periods include:

  • The nature and purpose of the personal data
  • The duration of our contractual or business relationship with you
  • Legal and regulatory retention obligations applicable to hotel operators and licensed casino operators in Canada and under applicable gaming legislation
  • Applicable limitation periods for legal claims
  • The potential risk of harm from unauthorised use or disclosure

As a general guide, we apply the following retention periods:

Category of Personal Data Retention Period
Hotel reservation and guest stay records 7 years from the date of your stay, or as required by applicable law
Financial and payment transaction records 7 years from the date of transaction, as required under applicable tax and accounting legislation
Casino account and gaming records 5–10 years from account closure or last gaming activity, as required under applicable gaming regulations
AML/KYC verification documents 5 years from the end of the business relationship or as required by applicable AML legislation
Marketing preference records Until you withdraw consent or opt out, plus a reasonable period thereafter to evidence compliance
Website usage and technical data Up to 24 months, depending on the type of data and applicable cookie consent
CCTV footage Up to 30 days, unless retained longer in connection with an incident, investigation, or legal claim
Correspondence and complaints records 3–7 years from the date of resolution, depending on the nature of the matter

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our data retention and disposal procedures. Where anonymisation is not possible, the data is securely destroyed.

8. Your Rights Under Data Protection Law

Subject to applicable data protection legislation, you have the following rights in relation to your personal data. We will respond to all verified requests within one month of receipt, though this period may be extended by up to two further months in complex or numerous cases, in which case we will notify you.

8.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation from us as to whether we are processing personal data about you, and, where we are, to receive a copy of that personal data together with supplementary information about our processing activities.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to require us to correct any inaccurate personal data we hold about you, and to have incomplete personal data completed, having regard to the purposes of the processing.

8.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)

You have the right to request the deletion or removal of your personal data where there is no compelling reason for its continued processing. This right applies in certain circumstances, such as where:

  • The personal data is no longer necessary for the purposes for which it was collected
  • You withdraw your consent and there is no other legal basis for processing
  • You object to the processing and there are no overriding legitimate interests
  • The personal data has been unlawfully processed

Please note that this right is not absolute and may be limited by our legal and regulatory obligations to retain certain data (for example, gaming records, AML documentation, and financial records).

8.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you do not want erasure, or where we no longer need the data but you require it for legal claims.

8.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.

8.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where we rely on legitimate interests or the performance of a public task as our legal basis. You also have the absolute right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing, at any time.

8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for the performance of a contract, permitted by applicable law, or based on your explicit consent.

Where we engage in automated decision-making that may significantly affect you (including in the context of responsible gambling monitoring or fraud prevention), we will notify you and provide you with the opportunity to request human review of the decision.

8.8 Right to Withdraw Consent

Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal. You may withdraw consent by contacting us at info@elvorohotelretreat.com or by using the unsubscribe mechanism in any marketing communications.

8.9 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada:

  • Website: www.priv.gc.ca
  • Telephone: 1-800-282-1376
  • Address: 30 Victoria Street, Gatineau, Quebec, K1A 1H3, Canada

You also have the right to complain to the Information and Privacy Commissioner of Ontario:

  • Website: www.ipc.on.ca
  • Telephone: 416-326-3333 or 1-800-387-0073
  • Address: 2 Bloor Street East, Suite 1400, Toronto, Ontario, M4W 1A8, Canada

We would, however, welcome the opportunity to address your concerns directly before you approach a supervisory authority, and we encourage you to contact us in the first instance.

8.10 Exercising Your Rights

To exercise any of the rights set out above, please submit a written request to our Data Protection Officer using the contact details provided in Section 11 of this Privacy Policy. We may need to verify your identity before processing your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.

9. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to enhance your browsing experience, analyse Website traffic, and, where you have consented, to deliver personalised content and advertising. Cookies are small text files placed on your device when you visit our Website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our Website, including session management, security, and access to secure areas. These cookies do not require your consent.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our Website by collecting anonymous or pseudonymised usage information. Used with your consent.
  • Functional Cookies: Enable enhanced functionality and personalisation, such as remembering your preferences and settings. Used with your consent.
  • Targeting and Advertising Cookies: Used to deliver relevant advertisements and marketing communications based on your interests. Used with your explicit consent.

You can manage your cookie preferences at any time through our Cookie Consent tool available on our Website, or by adjusting the settings in your browser. Please note that disabling certain cookies may affect the functionality of our Website.

For full details about the cookies we use, their purposes, and how to manage them, please refer to our separate Cookie Policy available on our Website.

10. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of data in transit using SSL/TLS protocols
  • Encryption of sensitive data at rest
  • Access controls and role-based permissions restricting access to personal data to authorised personnel only
  • Regular security assessments, vulnerability scanning, and penetration testing
  • Staff training on data protection and information security
  • Incident response and data breach notification procedures
  • Physical security measures at our premises
  • PCI-DSS compliant payment processing systems

Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authorities in accordance with our legal obligations and within the timeframes required by applicable law.

11. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or to the processing of your personal data, please contact us using the details below:

Data Controller
Data Protection Officer The Data Protection Officer
Postal Address
Email Address info@elvorohotelretreat.com
Website www.elvorohotelretreat.com

We are committed to working with you to resolve any concerns about our privacy practices and to respond to all legitimate requests in a timely and transparent manner.

12. Updates to This Privacy Policy

We may update or revise this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons. When we make material changes to this Privacy Policy, we will notify you by posting the updated policy on our Website with a new "Last Updated" date at the top of this page. Where required by law, we will seek your consent to any material changes.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our Website or services following the posting of changes constitutes your acknowledgement of the updated Privacy Policy.

If you have any questions about any changes to this Privacy Policy, please contact our Data Protection Officer using the details set out in Section 11 above.