Privacy Policy
Last updated: June 2025
This Privacy Policy explains how Cedarcrestcreative Casino Hotel ("we", "us", or "our") collects, uses, discloses, and protects your personal data when you visit or use our website at cedarcrestcreative.com (the "Website"), make a reservation, stay at our hotel, use our casino facilities, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Canadian privacy legislation including the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and any other applicable data protection laws.
Please read this Privacy Policy carefully. By using our Website or our services, you acknowledge that you have read and understood this policy. If you do not agree with the terms set out herein, please discontinue use of our Website and services.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Legal Entity Name | Cedarcrestcreative Casino Hotel |
|---|---|
| Trading Name | Cedarcrestcreative Casino Hotel |
| Registration Country | Canada |
| Registration Number | HRB 123456 B |
| VAT / Tax Number | CA 123456789 |
| Registered Address | 4 Avenue Rd, Toronto, ON M5R 2E8, Canada |
| Website | cedarcrestcreative.com |
| Privacy Contact Email | privacy@cedarcrestcreative.com |
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact our DPO using the details set out below:
| Title | The Data Protection Officer |
|---|---|
| Organisation | Cedarcrestcreative Casino Hotel |
| Address | 4 Avenue Rd, Toronto, ON M5R 2E8, Canada |
| privacy@cedarcrestcreative.com |
You have the right to make a complaint at any time to the relevant supervisory authority. For individuals in Canada, the supervisory authority is the Office of the Privacy Commissioner of Canada (www.priv.gc.ca). For individuals within the European Economic Area (EEA), you may contact the supervisory authority in your country of residence. We would, however, appreciate the chance to deal with your concerns before you approach a supervisory authority, so please contact us in the first instance.
2. Personal Data We Collect
"Personal data" means any information relating to an identified or identifiable natural person. We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:
2.1 Data You Provide to Us Directly
- Identity Data: First name, last name, username or similar identifier, title, date of birth, gender, nationality, and government-issued identification details (e.g., passport or driving licence number) where required for check-in or age verification for casino services.
- Contact Data: Billing address, delivery address, email address, telephone numbers, and emergency contact information.
- Reservation and Stay Data: Booking reference numbers, check-in and check-out dates, room type preferences, special requests, number of guests, loyalty programme membership details, and records of services used during your stay.
- Financial Data: Bank account details, payment card details (card number, expiry date, CVV — processed securely and not stored in full on our systems), billing information, and transaction history.
- Casino and Gaming Data: Player identity data, casino membership or loyalty card numbers, gaming activity records, win/loss data, responsible gambling self-exclusion requests, and age verification records as required by applicable gaming regulations.
- Profile Data: Your username and password for any online account, preferences, feedback, and survey responses.
- Marketing and Communications Data: Your preferences in receiving marketing communications from us and our third parties, and your communication preferences.
- Health and Accessibility Data: Where you voluntarily provide information about dietary requirements, allergies, or accessibility needs, we process this data solely to accommodate your requests (this constitutes special category data under GDPR Article 9 and is processed with your explicit consent).
2.2 Data Collected Automatically
- Technical Data: Internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our Website.
- Usage Data: Information about how you use our Website, products, and services, including pages visited, links clicked, time spent on pages, and referring URLs.
- Cookie and Tracking Data: Data collected via cookies, web beacons, pixels, and similar tracking technologies. Please refer to our Cookie Policy for further details.
2.3 Data Received from Third Parties
- Booking Platforms and Travel Agents: Personal and reservation data received from online travel agencies (OTAs), tour operators, or corporate travel managers who book on your behalf.
- Payment Service Providers: Transaction verification and fraud detection data.
- Identity Verification Services: Data used to verify your identity for casino access and compliance with anti-money laundering (AML) regulations.
- Social Media Platforms: If you interact with us via social media or use social login features, we may receive limited profile data from those platforms in accordance with your privacy settings on those platforms.
- Analytics Providers: Aggregated and anonymised data to help us understand Website traffic and usage patterns.
- Regulatory and Law Enforcement Authorities: Where legally required, we may receive data to comply with legal obligations.
2.4 Data We Do Not Collect
We do not knowingly collect personal data from children under the age of 18. Our casino services are strictly restricted to adults. If you are under 18, please do not use our Website or provide any personal data to us. If we learn we have inadvertently collected personal data from a child under 18, we will delete it promptly.
Unless specifically required by applicable gaming or AML regulations or provided by you voluntarily (e.g., dietary needs), we do not intentionally collect special categories of personal data such as data relating to racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or biometric data for identification purposes.
3. Legal Basis for Processing Your Personal Data
In accordance with GDPR Article 6, we will only process your personal data where we have a lawful basis to do so. The legal bases we rely upon are as follows:
3.1 Performance of a Contract (Article 6(1)(b))
We process your personal data where processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation, check-in, and check-out;
- Providing the hotel room, amenities, and services you have booked;
- Processing payments for your stay and services consumed;
- Managing your casino membership or player account;
- Responding to your pre-booking inquiries.
3.2 Compliance with a Legal Obligation (Article 6(1)(c))
We process your personal data where processing is necessary for compliance with a legal obligation to which we are subject. This includes:
- Verifying your age and identity as required by gaming and alcohol licensing regulations;
- Anti-money laundering (AML) and counter-terrorism financing (CTF) checks and reporting obligations;
- Tax record-keeping and financial reporting obligations;
- Complying with court orders, law enforcement requests, and regulatory demands;
- Maintaining records required by health and safety legislation;
- Responsible gambling obligations, including processing self-exclusion requests.
3.3 Legitimate Interests (Article 6(1)(f))
We process your personal data where it is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Preventing and detecting fraud, theft, and other criminal activity, including the use of CCTV surveillance within our premises;
- Ensuring the security of our IT systems, networks, and information;
- Improving and developing our Website, services, and customer experience;
- Analysing how our Website and services are used to make them more relevant and useful;
- Sending you direct marketing communications about services similar to those you have already used (where you have not opted out);
- Managing and administering our business operations efficiently;
- Protecting and defending our legal rights and interests.
We carry out a balancing test to ensure our legitimate interests are not overridden by your rights. You may request further information on this balancing test by contacting our DPO.
3.4 Consent (Article 6(1)(a))
Where we rely on your consent as the legal basis for processing, we will make this clear to you at the point of collection. Processing based on consent includes:
- Sending you marketing communications where you are a new contact and have opted in;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special category personal data such as dietary or health information where voluntarily provided;
- Sending personalised promotional offers based on your preferences.
Where we process your data based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@cedarcrestcreative.com or use the unsubscribe mechanism in any marketing email we send.
3.5 Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process your personal data where processing is necessary to protect your vital interests or the vital interests of another person. For example, we may share your information with emergency services in the event of a medical emergency on our premises.
3.6 Public Task (Article 6(1)(e))
In limited circumstances, we may process your personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority. This may include cooperation with regulatory investigations related to gaming compliance.
3.7 Special Category Data
Where we process special categories of personal data (as defined under GDPR Article 9), we rely on one of the following additional conditions:
- Explicit Consent (Article 9(2)(a)): For dietary, health, or accessibility information voluntarily provided by you;
- Vital Interests (Article 9(2)(c)): In medical emergency situations;
- Legal Claims (Article 9(2)(f)): Where processing is necessary for the establishment, exercise, or defence of legal claims;
- Substantial Public Interest (Article 9(2)(g)): Where required by applicable law, such as AML obligations involving biometric or identity verification data.
4. How We Use Your Personal Data
We use your personal data for the following specific purposes. For each purpose, we have identified the type(s) of data processed and the legal basis on which we rely:
4.1 Hotel Reservations and Guest Services
- To process, confirm, and manage your hotel reservations;
- To facilitate your check-in and check-out;
- To accommodate special requests, preferences, and accessibility needs;
- To provide room service, concierge, and other hotel amenities;
- To communicate with you before, during, and after your stay regarding your reservation.
Legal Basis: Performance of a Contract; Legitimate Interests; Consent (for special category health data).
4.2 Casino and Gaming Operations
- To verify your identity and age for casino access;
- To manage your casino membership or player loyalty account;
- To comply with AML, CTF, and responsible gambling obligations;
- To process gaming transactions and maintain accurate gaming records;
- To implement self-exclusion and responsible gambling measures.
Legal Basis: Performance of a Contract; Legal Obligation; Legitimate Interests.
4.3 Payment Processing
- To process payments for hotel stays, dining, spa, casino, and other services;
- To manage refunds, chargebacks, and billing disputes;
- To detect and prevent payment fraud.
Legal Basis: Performance of a Contract; Legal Obligation; Legitimate Interests.
4.4 Marketing and Promotional Communications
- To send you information about our offers, packages, events, and services that may be of interest to you;
- To personalise our communications and offers based on your preferences and stay history;
- To administer prize draws, competitions, and promotional events.
Legal Basis: Consent; Legitimate Interests (for existing customers receiving communications about similar services).
You can opt out of receiving marketing communications at any time by clicking "unsubscribe" in any marketing email, by updating your preferences in your online account, or by contacting us at privacy@cedarcrestcreative.com.
4.5 Website Operation and Improvement
- To operate, maintain, and improve our Website;
- To analyse Website usage patterns and user behaviour;
- To diagnose technical problems and ensure the security of our Website;
- To personalise your Website experience.
Legal Basis: Legitimate Interests; Consent (for non-essential cookies).
4.6 Security and Fraud Prevention
- To operate CCTV surveillance systems on our premises for the safety of guests, staff, and assets;
- To prevent and detect crime, fraud, and other illegal activities;
- To protect our property and ensure the safety of all persons on our premises.
Legal Basis: Legitimate Interests; Legal Obligation.
4.7 Legal and Regulatory Compliance
- To comply with applicable laws and regulations, including gaming, AML, tax, and employment laws;
- To respond to legal processes, court orders, and regulatory requests;
- To establish, exercise, or defend legal claims.
Legal Basis: Legal Obligation; Legitimate Interests.
4.8 Customer Support and Feedback
- To respond to your enquiries, complaints, and feedback;
- To conduct customer satisfaction surveys;
- To improve our products and services based on your feedback.
Legal Basis: Performance of a Contract; Legitimate Interests; Consent.
5. Sharing Your Personal Data
We do not sell your personal data to third parties. We may share your personal data with the categories of recipients listed below, and only for the purposes described in this Privacy Policy:
5.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions. These include:
- IT and Technology Providers: Cloud hosting providers, website management, property management systems, and cybersecurity services;
- Payment Processors: Payment gateway and card processing providers who facilitate secure transactions;
- Booking and Reservation Platforms: Online travel agencies and global distribution systems through which reservations are made;
- Marketing and Communications Providers: Email marketing platforms, CRM systems, and advertising networks;
- Analytics Providers: Web analytics services to help us understand Website usage;
- Identity Verification Services: Third-party providers assisting with age verification and AML compliance;
- Customer Support Tools: Helpdesk software and live chat providers;
- CCTV and Security Companies: Physical security providers who assist in monitoring our premises.
All our data processors are required to process your personal data only on our documented instructions, to implement appropriate technical and organisational security measures, and to comply with applicable data protection laws.
5.2 Group Companies
We may share your personal data with any subsidiary, parent company, or affiliated company within our corporate group, where relevant for the purposes described in this Privacy Policy.
5.3 Business Partners
We may share your data with trusted business partners, such as dining and spa concession operators within our hotel, loyalty programme partners, and event organisers. Any data sharing with such partners will be conducted in accordance with this Privacy Policy and applicable law.
5.4 Regulatory and Law Enforcement Authorities
We may disclose your personal data to governmental authorities, regulatory bodies, law enforcement agencies, courts, or other third parties where we are legally required or permitted to do so. This includes, for example, disclosure to:
- The Alcohol and Gaming Commission of Ontario (AGCO);
- Financial Intelligence Units and AML regulatory bodies;
- The Canada Revenue Agency (CRA);
- Police and law enforcement agencies investigating criminal offences;
- Courts and tribunals in connection with legal proceedings.
5.5 Professional Advisors
We may share your personal data with our lawyers, auditors, insurers, and other professional advisors where necessary in connection with the services they provide to us.
5.6 Business Transfers
If we are involved in a merger, acquisition, restructuring, sale of assets, or similar corporate transaction, your personal data may be transferred as part of that transaction. We will ensure that any such transfer is subject to appropriate confidentiality and data protection obligations.
5.7 International Transfers of Personal Data
Our primary operations are based in Canada. However, some of our service providers may be located in countries outside Canada and outside the European Economic Area (EEA). When we transfer your personal data internationally, we ensure that appropriate safeguards are in place, including:
- Transfers to countries that have been deemed to provide an adequate level of data protection by the relevant authorities;
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules where applicable;
- Other legally recognised transfer mechanisms under applicable law.
You may request further information about the safeguards we have in place for international data transfers by contacting our DPO at privacy@cedarcrestcreative.com.
6. Data Retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.
The following general retention periods apply:
| Category of Data | Retention Period | Rationale |
|---|---|---|
| Hotel reservation and guest stay records | 7 years from the date of your most recent stay | Legal obligation (tax and accounting requirements); Legitimate interests (dispute resolution) |
| Financial and payment records | 7 years from the date of the transaction | Legal obligation under Canadian tax and financial reporting laws |
| Casino gaming records and AML documentation | Minimum 5 years, and up to 10 years as required by gaming regulations | Legal obligation under gaming and AML legislation |
| Identity verification documents | 5 years from the end of the business relationship | Legal obligation under AML regulations |
| Marketing preferences and consent records | Until you withdraw consent or opt out, plus 3 years | Legitimate interests (proof of consent); Legal obligation |
| Website usage and cookie data | Up to 13 months from collection | Legitimate interests (analytics and security) |
| CCTV footage | 30 days, unless required for investigation or legal proceedings | Legitimate interests (security); Legal obligation |
| Customer complaints and correspondence | 6 years from resolution of the complaint | Legitimate interests (legal claims); Legal obligation |
| Self-exclusion records (responsible gambling) | Duration of self-exclusion plus 5 years | Legal obligation under gaming regulations |
When your personal data is no longer required, we will securely delete or anonymise it. In some circumstances, we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this anonymised data indefinitely without further notice to you.
7. Your Data Protection Rights
Under applicable data protection law, including the GDPR, you have a number of important rights in relation to your personal data. We will respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests, in which case we will notify you and keep you updated.
We will not charge a fee to exercise your rights unless your request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse to comply. We may need to request specific information from you to verify your identity before fulfilling your request.
Your rights are as follows:
7.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you and supplementary information about how we process it. This is commonly known as a "data subject access request" (DSAR). We will provide you with a copy of your personal data free of charge, subject to limited exceptions.
7.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you and to have any incomplete personal data completed. You may also update your personal information directly through your online account where applicable.
7.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)
You have the right to request that we delete or remove your personal data where there is no good reason for us to continue processing it. This right is not absolute and applies only in certain circumstances, including where:
- The personal data is no longer necessary for the purpose for which it was collected;
- You withdraw your consent and there is no other legal basis for processing;
- You object to processing and there are no overriding legitimate interests;
- The personal data has been unlawfully processed;
- The personal data must be erased to comply with a legal obligation.
We may refuse your erasure request where processing is necessary for compliance with a legal obligation, for the establishment, exercise, or defence of legal claims, or for other reasons permitted under applicable law.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we suspend or restrict the processing of your personal data in certain circumstances, including where:
- You contest the accuracy of your personal data while we verify it;
- Our processing is unlawful but you do not want us to erase the data;
- We no longer need the data but you need us to retain it for the establishment, exercise, or defence of legal claims;
- You have objected to our processing and we are considering whether our legitimate interests override your rights.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract and carried out by automated means, you have the right to request that we provide you with your personal data in a structured, commonly used, machine-readable format, or to request that we transmit it directly to another data controller where technically feasible.
7.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- Direct Marketing: Where we process your personal data for direct marketing purposes (including profiling for marketing), you have an absolute right to object at any time. We will cease processing your data for this purpose upon receipt of your objection.
- Legitimate Interests: Where we process your data based on our legitimate interests or for the performance of a public task, you may object where you believe your interests, rights, and freedoms override our legitimate interests. We will then assess your objection and cease processing unless we can demonstrate compelling legitimate grounds that override your rights, or where processing is necessary for legal claims.
7.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where we use automated decision-making processes, you have the right to:
- Obtain human intervention;
- Express your point of view;
- Obtain an explanation of the decision;
- Contest the decision.
We currently do not make solely automated decisions that produce legal or significant effects without human review, but will notify you if this changes.
7.8 Right to Withdraw Consent
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@cedarcrestcreative.com.
7.9 Right to Lodge a Complaint
You have the right to lodge a complaint with the relevant supervisory authority if you believe we have not complied with applicable data protection law:
- Canada: Office of the Privacy Commissioner of Canada — www.priv.gc.ca
- Ontario: Information and Privacy Commissioner of Ontario — www.ipc.on.ca
- European Union / EEA: The data protection supervisory authority in your country of residence or place of work.
We would, however, appreciate the opportunity to address your concerns before you contact a supervisory authority. Please contact our DPO at privacy@cedarcrestcreative.com in the first instance.
7.10 How to Exercise Your Rights
To exercise any of the rights described in this section, please submit a written request to our DPO by:
- Email: privacy@cedarcrestcreative.com
- Post: The Data Protection Officer, Cedarcrestcreative Casino Hotel, 4 Avenue Rd, Toronto, ON M5R 2E8, Canada
Please include your full name, contact details, and a clear description of your request. We may ask you to verify your identity before processing your request to ensure we do not disclose your personal data to an unauthorised person.
9. Data Security
We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit using Secure Socket Layer (SSL) / Transport Layer Security (TLS) technology;
- Encryption of sensitive data at rest;
- Access controls and user authentication measures, including multi-factor authentication where applicable;
- Regular security assessments, penetration testing, and vulnerability management;
- Staff training on data protection and information security;
- Physical security measures at our premises, including CCTV and access controls;
- Data breach detection, response, and notification procedures.
While we take all reasonable steps to protect your personal data, no method of transmission over the internet or electronic storage is entirely secure. We cannot guarantee the absolute security of your data transmitted to our Website. Any such transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to prevent unauthorised access.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay, and where required, notify you directly.
10. Third-Party Links and Services
Our Website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements or data processing practices. When you leave our Website, we encourage you to read the privacy policy of every website you visit.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or for other operational, legal, or regulatory reasons. When we make material changes to this Privacy Policy, we will notify you by updating the "Last updated" date at the top of this policy and, where appropriate, by prominently posting a notice on our Website or sending you a direct notification.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our Website and services after any changes have been made constitutes your acknowledgement of the updated Privacy Policy.
Previous versions of this Privacy Policy are available upon request from our DPO.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our personal data processing practices, please do not hesitate to contact our Data Protection Officer:
| Contact | The Data Protection Officer |
|---|---|
| Organisation | Cedarcrestcreative Casino Hotel |
| Address | 4 Avenue Rd, Toronto, ON M5R 2E8, Canada |
| privacy@cedarcrestcreative.com | |
| Website | cedarcrestcreative.com |
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, and you are located in Canada, you have the right to contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or the Information and Privacy Commissioner of Ontario at www.ipc.on.ca. If you are located within the EEA, you may contact the data protection authority in your country of residence.