Privacy Policy

Last updated: June 2025

This Privacy Policy describes how (hereinafter referred to as "we", "us", or "our") collects, uses, stores, and shares personal data in connection with the operation of Qalane Grand Resort, accessible at www.qalanegrandresort.com (the "Website"), as well as through our hotel, casino, and related services. We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), Canadian privacy legislation including the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and all other applicable data protection laws.

Please read this Privacy Policy carefully before using our Website or services. By accessing our Website or engaging with our services, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name
Trading Name Qalane Grand Resort
Registration Country Canada
Registration Number 1692748-3
VAT Number 731845926RT0001
Legal Address 1055 West Hastings Street, Suite 1700, Vancouver, BC V6E 2E9, Canada
Website www.qalanegrandresort.com
Privacy Contact Email info@qalanegrandresort.com

If you have any questions, concerns, or requests regarding the processing of your personal data, please contact us using the details provided in the "Contact Information" section at the end of this Privacy Policy.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing and advising on matters related to data protection within our organisation. You may contact our DPO directly at any time:

DPO Title The Data Protection Officer
Organisation
Address 1055 West Hastings Street, Suite 1700, Vancouver, BC V6E 2E9, Canada
Email info@qalanegrandresort.com

3. Personal Data We Collect

We collect various categories of personal data depending on how you interact with us — whether through our Website, during a stay at our hotel, participation in casino activities, use of ancillary services, or through communications with our staff. The categories of personal data we may collect include, but are not limited to, the following:

3.1 Identity and Contact Data

  • Full name (first name and surname)
  • Date of birth
  • Gender
  • Nationality and country of residence
  • Government-issued identification number (e.g., passport number, national ID) — where required by law
  • Postal address (home and/or billing address)
  • Email address
  • Telephone number(s)

3.2 Reservation and Booking Data

  • Booking reference numbers and confirmation codes
  • Check-in and check-out dates
  • Room type preferences and special requests
  • Number of guests and accompanying persons
  • Dietary requirements and accessibility needs
  • Travel itinerary details where provided

3.3 Payment and Financial Data

  • Payment card details (card number, expiry date, CVV — processed securely via PCI-DSS compliant systems)
  • Billing address
  • Transaction history and invoices
  • Bank account details (where applicable for refunds or direct debits)

3.4 Casino and Gaming Data

  • Player loyalty programme membership details
  • Gaming activity records (games played, duration, wagers, wins, losses)
  • Casino account registration data
  • Identity verification documents required under anti-money laundering (AML) and responsible gambling obligations
  • Self-exclusion or responsible gambling preferences and restrictions
  • Source of funds documentation where legally required

3.5 Technical and Usage Data

  • IP address
  • Browser type and version
  • Operating system
  • Device identifiers
  • Pages visited on our Website and time spent on each page
  • Referring URLs
  • Clickstream data and navigation patterns
  • Cookie identifiers and similar tracking technology data (see Section 11 on Cookies)

3.6 Loyalty Programme Data

  • Loyalty programme membership number
  • Points balance and redemption history
  • Tier status and associated benefits
  • Purchase and stay history linked to loyalty accounts

3.7 Communications Data

  • Records of correspondence with us (emails, live chat transcripts, telephone call logs)
  • Feedback, survey responses, and reviews submitted by you
  • Complaints and dispute records

3.8 Special Categories of Personal Data

In limited circumstances, we may collect and process special categories of personal data as defined under Article 9 of the GDPR. These may include:

  • Health and medical information — where you disclose a disability, allergy, or dietary requirement that requires special accommodation
  • Data concerning gambling habits — which may be processed in connection with responsible gambling programmes and regulatory obligations

We will only process special category data where we have a valid legal basis to do so, such as your explicit consent, or where processing is necessary for reasons of substantial public interest or to protect vital interests, in accordance with Article 9(2) of the GDPR.

3.9 Data Collected from Third Parties

We may also receive personal data about you from third-party sources, including:

  • Online travel agencies and booking platforms (e.g., Booking.com, Expedia, Hotels.com)
  • Corporate travel management companies
  • Regulatory authorities and identity verification service providers
  • Credit reference and fraud prevention agencies
  • Marketing and analytics partners

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Hotel and Accommodation Services

  • Processing and managing your accommodation reservations
  • Communicating booking confirmations, modifications, and cancellations
  • Facilitating check-in and check-out procedures
  • Providing personalised in-room and guest services
  • Managing special requests including accessibility accommodations and dietary requirements
  • Handling complaints and resolving service issues

5.2 Casino and Gaming Services

  • Registering and managing your casino player account
  • Verifying your identity and age in compliance with gaming regulations
  • Conducting anti-money laundering (AML) and Know Your Customer (KYC) checks
  • Administering responsible gambling tools, including self-exclusion schemes and deposit limits
  • Processing gaming transactions and maintaining gaming records
  • Complying with gaming licence conditions and regulatory reporting obligations

5.3 Payment Processing

  • Processing payments for accommodation, dining, casino, spa, and other services
  • Issuing invoices and receipts
  • Processing refunds and managing billing disputes
  • Detecting and preventing fraudulent transactions

5.4 Marketing and Communications

  • Sending you promotional offers, special packages, and event invitations where you have given consent or where we have a legitimate interest to do so
  • Personalising marketing communications based on your preferences and stay history
  • Conducting customer satisfaction surveys and collecting feedback
  • Communicating updates to our services, policies, and terms

5.5 Loyalty Programme Administration

  • Managing your enrolment and participation in the Qalane Grand Resort loyalty programme
  • Tracking and updating your points balance and tier status
  • Delivering personalised rewards and benefits

5.6 Security, Safety, and Fraud Prevention

  • Operating CCTV surveillance systems on our premises for the safety and security of guests, staff, and property
  • Preventing, detecting, and investigating fraud, theft, and other criminal activity
  • Ensuring the security of our digital systems and Website
  • Complying with legal obligations relating to the safety of persons on our premises

5.7 Legal and Regulatory Compliance

  • Meeting our obligations under applicable laws and regulations
  • Cooperating with regulatory authorities, law enforcement agencies, and courts
  • Establishing, exercising, or defending legal claims
  • Maintaining records as required by law

5.8 Business Operations and Improvement

  • Analysing Website and service usage to improve our offerings
  • Conducting internal business reporting and management
  • Carrying out business planning, financial management, and audits
  • Training staff and improving service quality

6. How We Share Your Personal Data

We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients where necessary and permitted by law:

6.1 Service Providers and Data Processors

We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions. These include:

  • Payment processing companies and banking institutions
  • Reservation and property management system (PMS) providers
  • Cloud hosting and IT infrastructure providers
  • Email marketing and CRM platform providers
  • Casino gaming software and platform providers
  • Customer support and live chat software providers
  • Market research and analytics companies
  • Identity verification and KYC service providers
  • Fraud detection and prevention service providers
  • CCTV and physical security service providers
  • Printing and mailing services for physical correspondence

All third-party processors are bound by data processing agreements requiring them to maintain appropriate technical and organisational security measures and to process data only in accordance with our instructions.

6.2 Online Travel Agencies and Booking Platforms

Where you make a reservation through a third-party booking platform (such as Booking.com, Expedia, or Hotels.com), we may receive and share booking-related data with such platforms to the extent necessary to fulfil your reservation.

6.3 Regulatory Authorities and Law Enforcement

We may disclose your personal data to regulatory authorities, gaming commissions, tax authorities, law enforcement agencies, or courts where we are legally required or permitted to do so — for example, in connection with AML obligations, gaming licence compliance, or a lawful request from a competent authority.

6.4 Professional Advisers

We may share your personal data with our legal advisers, accountants, auditors, and insurers where necessary for the provision of professional services, subject to professional confidentiality obligations.

6.5 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or similar business transaction, your personal data may be transferred to the prospective or actual buyer or successor entity. We will notify you of any such transfer and the applicable privacy rights.

6.6 With Your Consent

In circumstances not covered above, we will share your personal data with third parties only with your explicit consent.

6.7 International Transfers

Some of our service providers and partners are located outside of Canada and the European Economic Area (EEA). Where we transfer personal data to countries that do not provide an equivalent level of data protection, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) as approved by the European Commission
  • Binding Corporate Rules (BCRs) where applicable
  • Adequacy decisions recognised by the relevant supervisory authority
  • Other lawful transfer mechanisms as permitted under applicable data protection law

You may request a copy of the relevant safeguards by contacting our DPO using the details in Section 10.

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, and to resolve disputes or enforce our agreements. The specific retention periods depend on the type of data and the purpose for which it is processed.

7.1 Retention Periods

Category of Personal Data Retention Period Basis for Retention
Hotel reservation and guest records 7 years after the date of stay Legal obligation (tax and accounting), legitimate interests (dispute resolution)
Payment and financial transaction records 7 years from the date of transaction Legal obligation (tax legislation, financial regulations)
Casino account and gaming records 5–7 years from account closure or last activity, in accordance with gaming regulations Legal obligation (gaming licence conditions, AML regulations)
AML and KYC identity verification records 5 years from the end of the business relationship Legal obligation (AML legislation)
Loyalty programme data Duration of membership plus 3 years after account closure Contract performance, legitimate interests
Marketing consent records and communications 3 years from the date of last interaction or consent withdrawal Legal obligation (consent record-keeping), legitimate interests
CCTV footage 30 days, unless required for an investigation or legal proceedings Legitimate interests (security), legal obligation
Website usage data and cookies As specified in our Cookie Policy (typically up to 13 months) Consent, legitimate interests
Customer correspondence and complaints 3 years from resolution of the correspondence or complaint Legitimate interests (dispute resolution)
Employee records (if applicable) As required by Canadian employment law Legal obligation

Upon expiry of the applicable retention period, personal data is securely deleted, anonymised, or destroyed in accordance with our data retention and disposal procedures. Where data is anonymised (i.e., all identifying information is irreversibly removed), it may be retained for statistical or research purposes without further limitation.

8. Your Rights Under Data Protection Law

Subject to applicable legal conditions and exemptions, you have the following rights in relation to your personal data. We will respond to all valid requests within one month of receipt. Where a request is complex or we receive a large number of requests, we may extend this period by a further two months, in which case we will notify you accordingly.

8.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that data along with information about the purposes of processing, the categories of data, the recipients, the retention period, and your rights. The first copy is provided free of charge; further copies may be subject to a reasonable administrative fee.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to request the correction of inaccurate personal data we hold about you, and to have incomplete personal data completed, including by providing a supplementary statement.

8.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, or where you object to processing and there are no overriding legitimate grounds. This right is subject to our legal obligations to retain certain data (e.g., for AML compliance or accounting purposes).

8.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, while we verify the accuracy of data you have contested, or while we assess your objection to processing based on legitimate interests.

8.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transmitted directly to another controller where technically feasible.

8.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data:

  • For direct marketing purposes: If you object to processing for direct marketing (including profiling for marketing purposes), we will cease such processing immediately and without requiring justification.
  • Based on legitimate interests or public task: If you object on grounds relating to your particular situation, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.

8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you, unless such processing is necessary for entering into or performing a contract, authorised by law, or based on your explicit consent. Where automated decision-making applies, you have the right to request human intervention, to express your point of view, and to contest the decision.

8.8 Right to Withdraw Consent

Where we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. To withdraw consent, please contact us using the details in Section 10, or click "unsubscribe" in any marketing communication.

8.9 Right to Lodge a Complaint

You have the right to lodge a complaint with the relevant supervisory authority if you believe that our processing of your personal data infringes applicable data protection law. In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada:

  • Office of the Privacy Commissioner of Canada
  • Website: www.priv.gc.ca
  • Telephone: 1-800-282-1376
  • Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada

If you are located in the European Economic Area, you may also have the right to lodge a complaint with your local data protection authority in your country of residence.

We encourage you to contact us in the first instance so that we may address your concern directly and promptly.

8.10 Exercising Your Rights

To exercise any of the rights described above, please submit a written request to our Data Protection Officer using the contact details provided in Section 10. We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to act on the request.

9. Security of Personal Data

We take the security of your personal data very seriously and implement appropriate technical and organisational measures to protect your data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include, but are not limited to:

  • Encryption of personal data in transit using industry-standard TLS/SSL protocols
  • Encryption of sensitive data at rest using AES-256 or equivalent encryption standards
  • Strict access controls and role-based permissions to limit access to personal data on a need-to-know basis
  • Multi-factor authentication for access to sensitive systems and databases
  • Regular security testing, vulnerability assessments, and penetration testing
  • Employee training on data protection and information security
  • Secure disposal of physical and digital records at the end of the retention period
  • Payment Card Industry Data Security Standard (PCI-DSS) compliance for payment data processing
  • Incident response procedures and data breach notification processes in accordance with applicable law

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under Article 34 of the GDPR. We will also notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach, in accordance with Article 33 of the GDPR.

Notwithstanding the foregoing, no method of electronic transmission or storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.

10. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance your browsing experience, analyse usage, and deliver relevant content and advertising. A cookie is a small text file placed on your device by a website you visit.

10.1 Types of Cookies We Use

  • Strictly Necessary Cookies: These cookies are essential for the operation of our Website and cannot be switched off. They enable core functionality such as security, session management, and network management. No consent is required for these cookies.
  • Performance and Analytics Cookies: These cookies collect information about how visitors use our Website, including which pages are visited most frequently and any error messages encountered. We use this data to improve Website performance. These cookies require your consent.
  • Functionality Cookies: These cookies allow our Website to remember your preferences (such as language and region) and provide enhanced, personalised features. These cookies require your consent.
  • Targeting and Advertising Cookies: These cookies are used to deliver advertisements that are more relevant to you and your interests, and to measure the effectiveness of advertising campaigns. These cookies require your consent and may be set by third-party advertising partners.

10.2 Managing Cookies

When you first visit our Website, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our Website.

You can also manage cookies through your browser settings. Most browsers allow you to refuse, delete, or control cookies. Please note that disabling certain cookies may affect the functionality and user experience of our Website. For guidance on managing cookies in your specific browser, please refer to the browser's help documentation or visit www.allaboutcookies.org.

11. Children and Minors

Our Website and casino services are not directed at, nor intended for use by, persons under the age of 19 (or the applicable age of majority in the relevant jurisdiction). We do not knowingly collect personal data from minors. Access to casino and gaming areas and online casino accounts is strictly restricted to adults of legal gambling age in accordance with applicable law.

If we become aware that we have inadvertently collected personal data from a minor without appropriate parental or guardian consent, we will take immediate steps to delete such data. If you believe we may have collected data from a minor, please contact us immediately using the details in Section 12.

12. Responsible Gambling and Data Processing

As part of our commitment to responsible gambling, we may collect and process certain personal data to identify and support guests who may be experiencing gambling-related harm. This may include:

  • Monitoring gaming patterns and behaviour indicators associated with problem gambling
  • Processing self-exclusion requests and enforcing exclusion periods
  • Communicating with self-excluded individuals solely for the purposes of administering their exclusion
  • Sharing data with responsible gambling agencies, regulators, or multi-venue exclusion schemes where required by law or licence conditions

The processing of data for responsible gambling purposes is carried out on the basis of our legal obligations under applicable gaming regulations and, where applicable, substantial public interest under Article 9(2)(g) of the GDPR.

14. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or regulatory requirements. Any changes will be published on this page with an updated "Last updated" date at the top of the policy. Where changes are material, we may notify you by email or by placing a prominent notice on our Website.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services following the publication of changes constitutes your acknowledgement of the updated policy.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we process your personal data, or if you wish to exercise any of your data subject rights, please contact us using the following details:

Data Controller
Attention The Data Protection Officer
Postal Address 1055 West Hastings Street, Suite 1700, Vancouver, BC V6E 2E9, Canada
Email Address info@qalanegrandresort.com
Website www.qalanegrandresort.com

We are committed to addressing your privacy concerns promptly and effectively. You will receive an acknowledgement of your request within five (5) business days, and a substantive response within the timeframe prescribed by applicable law (generally one calendar month).