Privacy Policy

Last updated: June 2025

This Privacy Policy explains how Cedarcrestcreative Casino Hotel ("we", "us", or "our") collects, uses, discloses, and protects your personal data when you visit or use our website at cedarcrestcreative.com (the "Website"), make a reservation, stay at our hotel, use our casino facilities, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Canadian privacy legislation including the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and any other applicable data protection laws.

Please read this Privacy Policy carefully. By using our Website or our services, you acknowledge that you have read and understood this policy. If you do not agree with the terms set out herein, please discontinue use of our Website and services.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name Cedarcrestcreative Casino Hotel
Trading Name Cedarcrestcreative Casino Hotel
Registration Country Canada
Registration Number HRB 123456 B
VAT / Tax Number CA 123456789
Registered Address 4 Avenue Rd, Toronto, ON M5R 2E8, Canada
Website cedarcrestcreative.com
Privacy Contact Email privacy@cedarcrestcreative.com

1.1 Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out below:

Title The Data Protection Officer
Organisation Cedarcrestcreative Casino Hotel
Address 4 Avenue Rd, Toronto, ON M5R 2E8, Canada
Email privacy@cedarcrestcreative.com

You have the right to make a complaint at any time to the relevant supervisory authority. For individuals in Canada, the supervisory authority is the Office of the Privacy Commissioner of Canada (www.priv.gc.ca). For individuals within the European Economic Area (EEA), you may contact the supervisory authority in your country of residence. We would, however, appreciate the chance to deal with your concerns before you approach a supervisory authority, so please contact us in the first instance.

2. Personal Data We Collect

"Personal data" means any information relating to an identified or identifiable natural person. We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:

2.1 Data You Provide to Us Directly

  • Identity Data: First name, last name, username or similar identifier, title, date of birth, gender, nationality, and government-issued identification details (e.g., passport or driving licence number) where required for check-in or age verification for casino services.
  • Contact Data: Billing address, delivery address, email address, telephone numbers, and emergency contact information.
  • Reservation and Stay Data: Booking reference numbers, check-in and check-out dates, room type preferences, special requests, number of guests, loyalty programme membership details, and records of services used during your stay.
  • Financial Data: Bank account details, payment card details (card number, expiry date, CVV — processed securely and not stored in full on our systems), billing information, and transaction history.
  • Casino and Gaming Data: Player identity data, casino membership or loyalty card numbers, gaming activity records, win/loss data, responsible gambling self-exclusion requests, and age verification records as required by applicable gaming regulations.
  • Profile Data: Your username and password for any online account, preferences, feedback, and survey responses.
  • Marketing and Communications Data: Your preferences in receiving marketing communications from us and our third parties, and your communication preferences.
  • Health and Accessibility Data: Where you voluntarily provide information about dietary requirements, allergies, or accessibility needs, we process this data solely to accommodate your requests (this constitutes special category data under GDPR Article 9 and is processed with your explicit consent).

2.2 Data Collected Automatically

  • Technical Data: Internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Website.
  • Usage Data: Information about how you use our Website, products, and services, including pages visited, links clicked, time spent on pages, and referring URLs.
  • Cookie and Tracking Data: Data collected via cookies, web beacons, pixels, and similar tracking technologies. Please refer to our Cookie Policy for further details.

2.3 Data Received from Third Parties

  • Booking Platforms and Travel Agents: Personal and reservation data received from online travel agencies (OTAs), tour operators, or corporate travel managers who book on your behalf.
  • Payment Service Providers: Transaction verification and fraud detection data.
  • Identity Verification Services: Data used to verify your identity for casino access and compliance with anti-money laundering (AML) regulations.
  • Social Media Platforms: If you interact with us via social media or use social login features, we may receive limited profile data from those platforms in accordance with your privacy settings on those platforms.
  • Analytics Providers: Aggregated and anonymised data to help us understand Website traffic and usage patterns.
  • Regulatory and Law Enforcement Authorities: Where legally required, we may receive data to comply with legal obligations.

2.4 Data We Do Not Collect

We do not knowingly collect personal data from children under the age of 18. Our casino services are strictly restricted to adults. If you are under 18, please do not use our Website or provide any personal data to us. If we learn we have inadvertently collected personal data from a child under 18, we will delete it promptly.

Unless specifically required by applicable gaming or AML regulations or provided by you voluntarily (e.g., dietary needs), we do not intentionally collect special categories of personal data such as data relating to racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or biometric data for identification purposes.

4. How We Use Your Personal Data

We use your personal data for the following specific purposes. For each purpose, we have identified the type(s) of data processed and the legal basis on which we rely:

4.1 Hotel Reservations and Guest Services

  • To process, confirm, and manage your hotel reservations;
  • To facilitate your check-in and check-out;
  • To accommodate special requests, preferences, and accessibility needs;
  • To provide room service, concierge, and other hotel amenities;
  • To communicate with you before, during, and after your stay regarding your reservation.

Legal Basis: Performance of a Contract; Legitimate Interests; Consent (for special category health data).

4.2 Casino and Gaming Operations

  • To verify your identity and age for casino access;
  • To manage your casino membership or player loyalty account;
  • To comply with AML, CTF, and responsible gambling obligations;
  • To process gaming transactions and maintain accurate gaming records;
  • To implement self-exclusion and responsible gambling measures.

Legal Basis: Performance of a Contract; Legal Obligation; Legitimate Interests.

4.3 Payment Processing

  • To process payments for hotel stays, dining, spa, casino, and other services;
  • To manage refunds, chargebacks, and billing disputes;
  • To detect and prevent payment fraud.

Legal Basis: Performance of a Contract; Legal Obligation; Legitimate Interests.

4.4 Marketing and Promotional Communications

  • To send you information about our offers, packages, events, and services that may be of interest to you;
  • To personalise our communications and offers based on your preferences and stay history;
  • To administer prize draws, competitions, and promotional events.

Legal Basis: Consent; Legitimate Interests (for existing customers receiving communications about similar services).

You can opt out of receiving marketing communications at any time by clicking "unsubscribe" in any marketing email, by updating your preferences in your online account, or by contacting us at privacy@cedarcrestcreative.com.

4.5 Website Operation and Improvement

  • To operate, maintain, and improve our Website;
  • To analyse Website usage patterns and user behaviour;
  • To diagnose technical problems and ensure the security of our Website;
  • To personalise your Website experience.

Legal Basis: Legitimate Interests; Consent (for non-essential cookies).

4.6 Security and Fraud Prevention

  • To operate CCTV surveillance systems on our premises for the safety of guests, staff, and assets;
  • To prevent and detect crime, fraud, and other illegal activities;
  • To protect our property and ensure the safety of all persons on our premises.

Legal Basis: Legitimate Interests; Legal Obligation.

4.7 Legal and Regulatory Compliance

  • To comply with applicable laws and regulations, including gaming, AML, tax, and employment laws;
  • To respond to legal processes, court orders, and regulatory requests;
  • To establish, exercise, or defend legal claims.

Legal Basis: Legal Obligation; Legitimate Interests.

4.8 Customer Support and Feedback

  • To respond to your enquiries, complaints, and feedback;
  • To conduct customer satisfaction surveys;
  • To improve our products and services based on your feedback.

Legal Basis: Performance of a Contract; Legitimate Interests; Consent.

5. Sharing Your Personal Data

We do not sell your personal data to third parties. We may share your personal data with the categories of recipients listed below, and only for the purposes described in this Privacy Policy:

5.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instructions. These include:

  • IT and Technology Providers: Cloud hosting providers, website management, property management systems, and cybersecurity services;
  • Payment Processors: Payment gateway and card processing providers who facilitate secure transactions;
  • Booking and Reservation Platforms: Online travel agencies and global distribution systems through which reservations are made;
  • Marketing and Communications Providers: Email marketing platforms, CRM systems, and advertising networks;
  • Analytics Providers: Web analytics services to help us understand Website usage;
  • Identity Verification Services: Third-party providers assisting with age verification and AML compliance;
  • Customer Support Tools: Helpdesk software and live chat providers;
  • CCTV and Security Companies: Physical security providers who assist in monitoring our premises.

All our data processors are required to process your personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to comply with applicable data protection laws.

5.2 Group Companies

We may share your personal data with any subsidiary, parent company, or affiliated company within our corporate group, where relevant for the purposes described in this Privacy Policy.

5.3 Business Partners

We may share your data with trusted business partners, such as dining and spa concession operators within our hotel, loyalty programme partners, and event organisers. Any data sharing with such partners will be conducted in accordance with this Privacy Policy and applicable law.

5.4 Regulatory and Law Enforcement Authorities

We may disclose your personal data to governmental authorities, regulatory bodies, law enforcement agencies, courts, or other third parties where we are legally required or permitted to do so. This includes, for example, disclosure to:

  • The Alcohol and Gaming Commission of Ontario (AGCO);
  • Financial Intelligence Units and AML regulatory bodies;
  • The Canada Revenue Agency (CRA);
  • Police and law enforcement agencies investigating criminal offences;
  • Courts and tribunals in connection with legal proceedings.

5.5 Professional Advisors

We may share your personal data with our lawyers, auditors, insurers, and other professional advisors where necessary in connection with the services they provide to us.

5.6 Business Transfers

If we are involved in a merger, acquisition, restructuring, sale of assets, or similar corporate transaction, your personal data may be transferred as part of that transaction. We will ensure that any such transfer is subject to appropriate confidentiality and data protection obligations.

5.7 International Transfers of Personal Data

Our primary operations are based in Canada. However, some of our service providers may be located in countries outside Canada and outside the European Economic Area (EEA). When we transfer your personal data internationally, we ensure that appropriate safeguards are in place, including:

  • Transfers to countries that have been deemed to provide an adequate level of data protection by the relevant authorities;
  • Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Binding Corporate Rules where applicable;
  • Other legally recognised transfer mechanisms under applicable law.

You may request further information about the safeguards we have in place for international data transfers by contacting our DPO at privacy@cedarcrestcreative.com.

6. Data Retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.

The following general retention periods apply:

Category of Data Retention Period Rationale
Hotel reservation and guest stay records 7 years from the date of your most recent stay Legal obligation (tax and accounting requirements); Legitimate interests (dispute resolution)
Financial and payment records 7 years from the date of the transaction Legal obligation under Canadian tax and financial reporting laws
Casino gaming records and AML documentation Minimum 5 years, and up to 10 years as required by gaming regulations Legal obligation under gaming and AML legislation
Identity verification documents 5 years from the end of the business relationship Legal obligation under AML regulations
Marketing preferences and consent records Until you withdraw consent or opt out, plus 3 years Legitimate interests (proof of consent); Legal obligation
Website usage and cookie data Up to 13 months from collection Legitimate interests (analytics and security)
CCTV footage 30 days, unless required for investigation or legal proceedings Legitimate interests (security); Legal obligation
Customer complaints and correspondence 6 years from resolution of the complaint Legitimate interests (legal claims); Legal obligation
Self-exclusion records (responsible gambling) Duration of self-exclusion plus 5 years Legal obligation under gaming regulations

When your personal data is no longer required, we will securely delete or anonymise it. In some circumstances, we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this anonymised data indefinitely without further notice to you.

7. Your Data Protection Rights

Under applicable data protection law, including the GDPR, you have a number of important rights in relation to your personal data. We will respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests, in which case we will notify you and keep you updated.

We will not charge a fee to exercise your rights unless your request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse to comply. We may need to request specific information from you to verify your identity before fulfilling your request.

Your rights are as follows:

7.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you and supplementary information about how we process it. This is commonly known as a "data subject access request" (DSAR). We will provide you with a copy of your personal data free of charge, subject to limited exceptions.

7.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate personal data we hold about you and to have any incomplete personal data completed. You may also update your personal information directly through your online account where applicable.

7.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request that we delete or remove your personal data where there is no good reason for us to continue processing it. This right is not absolute and applies only in certain circumstances, including where:

  • The personal data is no longer necessary for the purpose for which it was collected;
  • You withdraw your consent and there is no other legal basis for processing;
  • You object to processing and there are no overriding legitimate interests;
  • The personal data has been unlawfully processed;
  • The personal data must be erased to comply with a legal obligation.

We may refuse your erasure request where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defence of legal claims, or for other reasons permitted under applicable law.

7.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we suspend or restrict the processing of your personal data in certain circumstances, including where:

  • You contest the accuracy of your personal data while we verify it;
  • Our processing is unlawful but you do not want us to erase the data;
  • We no longer need the data but you need us to retain it for the establishment, exercise, or defence of legal claims;
  • You have objected to our processing and we are considering whether our legitimate interests override your rights.

7.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or the performance of a contract and carried out by automated means, you have the right to request that we provide you with your personal data in a structured, commonly used, machine-readable format, or to request that we transmit it directly to another data controller where technically feasible.

7.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data:

  • Direct Marketing: Where we process your personal data for direct marketing purposes (including profiling for marketing), you have an absolute right to object at any time. We will cease processing your data for this purpose upon receipt of your objection.
  • Legitimate Interests: Where we process your data based on our legitimate interests or for the performance of a public task, you may object where you believe your interests, rights, and freedoms override our legitimate interests. We will then assess your objection and cease processing unless we can demonstrate compelling legitimate grounds that override your rights, or where processing is necessary for legal claims.

7.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where we use automated decision-making processes, you have the right to:

  • Obtain human intervention;
  • Express your point of view;
  • Obtain an explanation of the decision;
  • Contest the decision.

We currently do not make solely automated decisions that produce legal or significant effects without human review, but will notify you if this changes.

7.8 Right to Withdraw Consent

Where we process your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@cedarcrestcreative.com.

7.9 Right to Lodge a Complaint

You have the right to lodge a complaint with the relevant supervisory authority if you believe we have not complied with applicable data protection law:

  • Canada: Office of the Privacy Commissioner of Canada — www.priv.gc.ca
  • Ontario: Information and Privacy Commissioner of Ontario — www.ipc.on.ca
  • European Union / EEA: The data protection supervisory authority in your country of residence or place of work.

We would, however, appreciate the opportunity to address your concerns before you contact a supervisory authority. Please contact our DPO at privacy@cedarcrestcreative.com in the first instance.

7.10 How to Exercise Your Rights

To exercise any of the rights described in this section, please submit a written request to our DPO by:

Please include your full name, contact details, and a clear description of your request. We may ask you to verify your identity before processing your request to ensure we do not disclose your personal data to an unauthorised person.

8. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies to distinguish you from other users of our Website, enhance your browsing experience, and provide personalised content. Cookies are small text files that are placed on your device when you visit our Website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our Website, including enabling you to navigate the site and use its features. These cannot be disabled without impairing Website functionality.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our Website by collecting and reporting information anonymously. Used to improve Website performance.
  • Functionality Cookies: Allow the Website to remember your preferences (such as language or region) to provide enhanced features.
  • Targeting and Advertising Cookies: Used to deliver advertisements relevant to you and your interests, and to measure the effectiveness of advertising campaigns.

Non-essential cookies are only placed on your device with your consent, which you can provide or withdraw at any time via our cookie consent tool available on our Website. For further information on the cookies we use and how to manage them, please refer to our full Cookie Policy available on our Website.

9. Data Security

We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of data in transit using Secure Socket Layer (SSL) / Transport Layer Security (TLS) technology;
  • Encryption of sensitive data at rest;
  • Access controls and user authentication measures, including multi-factor authentication where applicable;
  • Regular security assessments, penetration testing, and vulnerability management;
  • Staff training on data protection and information security;
  • Physical security measures at our premises, including CCTV and access controls;
  • Data breach detection, response, and notification procedures.

While we take all reasonable steps to protect your personal data, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee the absolute security of your data transmitted to our Website. Any such transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to prevent unauthorised access.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay, and where required, notify you directly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or for other operational, legal, or regulatory reasons. When we make material changes to this Privacy Policy, we will notify you by updating the "Last updated" date at the top of this policy and, where appropriate, by prominently posting a notice on our Website or sending you a direct notification.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our Website and services after any changes have been made constitutes your acknowledgement of the updated Privacy Policy.

Previous versions of this Privacy Policy are available upon request from our DPO.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our personal data processing practices, please do not hesitate to contact our Data Protection Officer:

Contact The Data Protection Officer
Organisation Cedarcrestcreative Casino Hotel
Address 4 Avenue Rd, Toronto, ON M5R 2E8, Canada
Email privacy@cedarcrestcreative.com
Website cedarcrestcreative.com

We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, and you are located in Canada, you have the right to contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or the Information and Privacy Commissioner of Ontario at www.ipc.on.ca. If you are located within the EEA, you may contact the data protection authority in your country of residence.