Privacy Policy
Last updated: June 2025
This Privacy Policy describes how (hereinafter referred to as "we", "us", or "our") collects, uses, stores, and shares personal data in connection with the operation of Qalane Grand Resort, accessible at www.qalanegrandresort.com (the "Website"), as well as through our hotel, casino, and related services. We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), Canadian privacy legislation including the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and all other applicable data protection laws.
Please read this Privacy Policy carefully before using our Website or services. By accessing our Website or engaging with our services, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy.
1. Data Controller
The entity responsible for the processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
| Trading Name | Qalane Grand Resort |
| Registration Country | Canada |
| Registration Number | 1692748-3 |
| VAT Number | 731845926RT0001 |
| Legal Address | 1055 West Hastings Street, Suite 1700, Vancouver, BC V6E 2E9, Canada |
| Website | www.qalanegrandresort.com |
| Privacy Contact Email | info@qalanegrandresort.com |
If you have any questions, concerns, or requests regarding the processing of your personal data, please contact us using the details provided in the "Contact Information" section at the end of this Privacy Policy.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing and advising on matters related to data protection within our organisation. You may contact our DPO directly at any time:
| DPO Title | The Data Protection Officer |
| Organisation | |
| Address | 1055 West Hastings Street, Suite 1700, Vancouver, BC V6E 2E9, Canada |
| info@qalanegrandresort.com |
3. Personal Data We Collect
We collect various categories of personal data depending on how you interact with us — whether through our Website, during a stay at our hotel, participation in casino activities, use of ancillary services, or through communications with our staff. The categories of personal data we may collect include, but are not limited to, the following:
3.1 Identity and Contact Data
- Full name (first name and surname)
- Date of birth
- Gender
- Nationality and country of residence
- Government-issued identification number (e.g., passport number, national ID) — where required by law
- Postal address (home and/or billing address)
- Email address
- Telephone number(s)
3.2 Reservation and Booking Data
- Booking reference numbers and confirmation codes
- Check-in and check-out dates
- Room type preferences and special requests
- Number of guests and accompanying persons
- Dietary requirements and accessibility needs
- Travel itinerary details where provided
3.3 Payment and Financial Data
- Payment card details (card number, expiry date, CVV — processed securely via PCI-DSS compliant systems)
- Billing address
- Transaction history and invoices
- Bank account details (where applicable for refunds or direct debits)
3.4 Casino and Gaming Data
- Player loyalty programme membership details
- Gaming activity records (games played, duration, wagers, wins, losses)
- Casino account registration data
- Identity verification documents required under anti-money laundering (AML) and responsible gambling obligations
- Self-exclusion or responsible gambling preferences and restrictions
- Source of funds documentation where legally required
3.5 Technical and Usage Data
- IP address
- Browser type and version
- Operating system
- Device identifiers
- Pages visited on our Website and time spent on each page
- Referring URLs
- Clickstream data and navigation patterns
- Cookie identifiers and similar tracking technology data (see Section 11 on Cookies)
3.6 Loyalty Programme Data
- Loyalty programme membership number
- Points balance and redemption history
- Tier status and associated benefits
- Purchase and stay history linked to loyalty accounts
3.7 Communications Data
- Records of correspondence with us (emails, live chat transcripts, telephone call logs)
- Feedback, survey responses, and reviews submitted by you
- Complaints and dispute records
3.8 Special Categories of Personal Data
In limited circumstances, we may collect and process special categories of personal data as defined under Article 9 of the GDPR. These may include:
- Health and medical information — where you disclose a disability, allergy, or dietary requirement that requires special accommodation
- Data concerning gambling habits — which may be processed in connection with responsible gambling programmes and regulatory obligations
We will only process special category data where we have a valid legal basis to do so, such as your explicit consent, or where processing is necessary for reasons of substantial public interest or to protect vital interests, in accordance with Article 9(2) of the GDPR.
3.9 Data Collected from Third Parties
We may also receive personal data about you from third-party sources, including:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia, Hotels.com)
- Corporate travel management companies
- Regulatory authorities and identity verification service providers
- Credit reference and fraud prevention agencies
- Marketing and analytics partners
4. Legal Basis for Processing Personal Data
In accordance with Article 6 of the GDPR, we rely on one or more of the following legal bases when processing your personal data:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
Processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This applies, for example, when we process your data to manage your hotel reservation, provide accommodation and hospitality services, administer your casino account, process payments, and fulfil your bookings for dining, spa, and entertainment services.
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
Processing is necessary for compliance with a legal obligation to which we are subject. This includes obligations arising under:
- Anti-money laundering (AML) and counter-terrorism financing legislation
- Know Your Customer (KYC) requirements under gaming and financial regulations
- Tax and accounting obligations
- Regulatory reporting requirements imposed by gaming authorities
- Health and safety laws
- Immigration and guest registration requirements
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Fraud prevention and detection, and ensuring the security of our premises and systems
- Direct marketing of our own similar products and services to existing customers (subject to your right to object)
- Improving and personalising our Website, hotel, and casino services
- Conducting customer satisfaction surveys and analytics
- Managing and administering our loyalty programme
- Defending legal claims and protecting our business interests
- Network and information security, including monitoring for cyber threats
- Business reporting, management, and operational efficiency
Where we rely on legitimate interests, we carry out a balancing test to ensure our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 8).
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will obtain your consent separately and clearly at the relevant time. Processing based on consent includes:
- Sending you marketing communications (newsletters, promotional offers, event invitations) via email, SMS, or other electronic means where you are not an existing customer
- Setting non-essential cookies and similar tracking technologies on your device
- Processing special category data where explicit consent is required
You have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us using the details in Section 10 or use the unsubscribe link in any marketing email.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person — for example, in a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e) GDPR)
In limited circumstances, processing may be necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, for example in connection with regulatory inspections or cooperation with law enforcement.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Hotel and Accommodation Services
- Processing and managing your accommodation reservations
- Communicating booking confirmations, modifications, and cancellations
- Facilitating check-in and check-out procedures
- Providing personalised in-room and guest services
- Managing special requests including accessibility accommodations and dietary requirements
- Handling complaints and resolving service issues
5.2 Casino and Gaming Services
- Registering and managing your casino player account
- Verifying your identity and age in compliance with gaming regulations
- Conducting anti-money laundering (AML) and Know Your Customer (KYC) checks
- Administering responsible gambling tools, including self-exclusion schemes and deposit limits
- Processing gaming transactions and maintaining gaming records
- Complying with gaming licence conditions and regulatory reporting obligations
5.3 Payment Processing
- Processing payments for accommodation, dining, casino, spa, and other services
- Issuing invoices and receipts
- Processing refunds and managing billing disputes
- Detecting and preventing fraudulent transactions
5.4 Marketing and Communications
- Sending you promotional offers, special packages, and event invitations where you have given consent or where we have a legitimate interest to do so
- Personalising marketing communications based on your preferences and stay history
- Conducting customer satisfaction surveys and collecting feedback
- Communicating updates to our services, policies, and terms
5.5 Loyalty Programme Administration
- Managing your enrolment and participation in the Qalane Grand Resort loyalty programme
- Tracking and updating your points balance and tier status
- Delivering personalised rewards and benefits
5.6 Security, Safety, and Fraud Prevention
- Operating CCTV surveillance systems on our premises for the safety and security of guests, staff, and property
- Preventing, detecting, and investigating fraud, theft, and other criminal activity
- Ensuring the security of our digital systems and Website
- Complying with legal obligations relating to the safety of persons on our premises
5.7 Legal and Regulatory Compliance
- Meeting our obligations under applicable laws and regulations
- Cooperating with regulatory authorities, law enforcement agencies, and courts
- Establishing, exercising, or defending legal claims
- Maintaining records as required by law
5.8 Business Operations and Improvement
- Analysing Website and service usage to improve our offerings
- Conducting internal business reporting and management
- Carrying out business planning, financial management, and audits
- Training staff and improving service quality
6. How We Share Your Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients where necessary and permitted by law:
6.1 Service Providers and Data Processors
We engage carefully selected third-party service providers who process personal data on our behalf and under our instructions. These include:
- Payment processing companies and banking institutions
- Reservation and property management system (PMS) providers
- Cloud hosting and IT infrastructure providers
- Email marketing and CRM platform providers
- Casino gaming software and platform providers
- Customer support and live chat software providers
- Market research and analytics companies
- Identity verification and KYC service providers
- Fraud detection and prevention service providers
- CCTV and physical security service providers
- Printing and mailing services for physical correspondence
All third-party processors are bound by data processing agreements requiring them to maintain appropriate technical and organisational security measures and to process data only in accordance with our instructions.
6.2 Online Travel Agencies and Booking Platforms
Where you make a reservation through a third-party booking platform (such as Booking.com, Expedia, or Hotels.com), we may receive and share booking-related data with such platforms to the extent necessary to fulfil your reservation.
6.3 Regulatory Authorities and Law Enforcement
We may disclose your personal data to regulatory authorities, gaming commissions, tax authorities, law enforcement agencies, or courts where we are legally required or permitted to do so — for example, in connection with AML obligations, gaming licence compliance, or a lawful request from a competent authority.
6.4 Professional Advisers
We may share your personal data with our legal advisers, accountants, auditors, and insurers where necessary for the provision of professional services, subject to professional confidentiality obligations.
6.5 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or similar business transaction, your personal data may be transferred to the prospective or actual buyer or successor entity. We will notify you of any such transfer and the applicable privacy rights.
6.6 With Your Consent
In circumstances not covered above, we will share your personal data with third parties only with your explicit consent.
6.7 International Transfers
Some of our service providers and partners are located outside of Canada and the European Economic Area (EEA). Where we transfer personal data to countries that do not provide an equivalent level of data protection, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- Binding Corporate Rules (BCRs) where applicable
- Adequacy decisions recognised by the relevant supervisory authority
- Other lawful transfer mechanisms as permitted under applicable data protection law
You may request a copy of the relevant safeguards by contacting our DPO using the details in Section 10.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, and to resolve disputes or enforce our agreements. The specific retention periods depend on the type of data and the purpose for which it is processed.
7.1 Retention Periods
| Category of Personal Data | Retention Period | Basis for Retention |
|---|---|---|
| Hotel reservation and guest records | 7 years after the date of stay | Legal obligation (tax and accounting), legitimate interests (dispute resolution) |
| Payment and financial transaction records | 7 years from the date of transaction | Legal obligation (tax legislation, financial regulations) |
| Casino account and gaming records | 5–7 years from account closure or last activity, in accordance with gaming regulations | Legal obligation (gaming licence conditions, AML regulations) |
| AML and KYC identity verification records | 5 years from the end of the business relationship | Legal obligation (AML legislation) |
| Loyalty programme data | Duration of membership plus 3 years after account closure | Contract performance, legitimate interests |
| Marketing consent records and communications | 3 years from the date of last interaction or consent withdrawal | Legal obligation (consent record-keeping), legitimate interests |
| CCTV footage | 30 days, unless required for an investigation or legal proceedings | Legitimate interests (security), legal obligation |
| Website usage data and cookies | As specified in our Cookie Policy (typically up to 13 months) | Consent, legitimate interests |
| Customer correspondence and complaints | 3 years from resolution of the correspondence or complaint | Legitimate interests (dispute resolution) |
| Employee records (if applicable) | As required by Canadian employment law | Legal obligation |
Upon expiry of the applicable retention period, personal data is securely deleted, anonymised, or destroyed in accordance with our data retention and disposal procedures. Where data is anonymised (i.e., all identifying information is irreversibly removed), it may be retained for statistical or research purposes without further limitation.
8. Your Rights Under Data Protection Law
Subject to applicable legal conditions and exemptions, you have the following rights in relation to your personal data. We will respond to all valid requests within one month of receipt. Where a request is complex or we receive a large number of requests, we may extend this period by a further two months, in which case we will notify you accordingly.
8.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that data along with information about the purposes of processing, the categories of data, the recipients, the retention period, and your rights. The first copy is provided free of charge; further copies may be subject to a reasonable administrative fee.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate personal data we hold about you, and to have incomplete personal data completed, including by providing a supplementary statement.
8.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, or where you object to processing and there are no overriding legitimate grounds. This right is subject to our legal obligations to retain certain data (e.g., for AML compliance or accounting purposes).
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, while we verify the accuracy of data you have contested, or while we assess your objection to processing based on legitimate interests.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transmitted directly to another controller where technically feasible.
8.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- For direct marketing purposes: If you object to processing for direct marketing (including profiling for marketing purposes), we will cease such processing immediately and without requiring justification.
- Based on legitimate interests or public task: If you object on grounds relating to your particular situation, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.
8.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you, unless such processing is necessary for entering into or performing a contract, authorised by law, or based on your explicit consent. Where automated decision-making applies, you have the right to request human intervention, to express your point of view, and to contest the decision.
8.8 Right to Withdraw Consent
Where we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. To withdraw consent, please contact us using the details in Section 10, or click "unsubscribe" in any marketing communication.
8.9 Right to Lodge a Complaint
You have the right to lodge a complaint with the relevant supervisory authority if you believe that our processing of your personal data infringes applicable data protection law. In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada:
- Office of the Privacy Commissioner of Canada
- Website: www.priv.gc.ca
- Telephone: 1-800-282-1376
- Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada
If you are located in the European Economic Area, you may also have the right to lodge a complaint with your local data protection authority in your country of residence.
We encourage you to contact us in the first instance so that we may address your concern directly and promptly.
8.10 Exercising Your Rights
To exercise any of the rights described above, please submit a written request to our Data Protection Officer using the contact details provided in Section 10. We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to act on the request.
9. Security of Personal Data
We take the security of your personal data very seriously and implement appropriate technical and organisational measures to protect your data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include, but are not limited to:
- Encryption of personal data in transit using industry-standard TLS/SSL protocols
- Encryption of sensitive data at rest using AES-256 or equivalent encryption standards
- Strict access controls and role-based permissions to limit access to personal data on a need-to-know basis
- Multi-factor authentication for access to sensitive systems and databases
- Regular security testing, vulnerability assessments, and penetration testing
- Employee training on data protection and information security
- Secure disposal of physical and digital records at the end of the retention period
- Payment Card Industry Data Security Standard (PCI-DSS) compliance for payment data processing
- Incident response procedures and data breach notification processes in accordance with applicable law
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under Article 34 of the GDPR. We will also notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach, in accordance with Article 33 of the GDPR.
Notwithstanding the foregoing, no method of electronic transmission or storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.
11. Children and Minors
Our Website and casino services are not directed at, nor intended for use by, persons under the age of 19 (or the applicable age of majority in the relevant jurisdiction). We do not knowingly collect personal data from minors. Access to casino and gaming areas and online casino accounts is strictly restricted to adults of legal gambling age in accordance with applicable law.
If we become aware that we have inadvertently collected personal data from a minor without appropriate parental or guardian consent, we will take immediate steps to delete such data. If you believe we may have collected data from a minor, please contact us immediately using the details in Section 12.
12. Responsible Gambling and Data Processing
As part of our commitment to responsible gambling, we may collect and process certain personal data to identify and support guests who may be experiencing gambling-related harm. This may include:
- Monitoring gaming patterns and behaviour indicators associated with problem gambling
- Processing self-exclusion requests and enforcing exclusion periods
- Communicating with self-excluded individuals solely for the purposes of administering their exclusion
- Sharing data with responsible gambling agencies, regulators, or multi-venue exclusion schemes where required by law or licence conditions
The processing of data for responsible gambling purposes is carried out on the basis of our legal obligations under applicable gaming regulations and, where applicable, substantial public interest under Article 9(2)(g) of the GDPR.
13. Third-Party Websites and Links
Our Website may contain links to third-party websites, social media platforms, and other online services. This Privacy Policy applies solely to information collected by us through our Website and services. We are not responsible for the privacy practices or content of third-party websites, and we encourage you to review the privacy policies of any third-party sites you visit.
14. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or regulatory requirements. Any changes will be published on this page with an updated "Last updated" date at the top of the policy. Where changes are material, we may notify you by email or by placing a prominent notice on our Website.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services following the publication of changes constitutes your acknowledgement of the updated policy.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we process your personal data, or if you wish to exercise any of your data subject rights, please contact us using the following details:
| Data Controller | |
| Attention | The Data Protection Officer |
| Postal Address | 1055 West Hastings Street, Suite 1700, Vancouver, BC V6E 2E9, Canada |
| Email Address | info@qalanegrandresort.com |
| Website | www.qalanegrandresort.com |
We are committed to addressing your privacy concerns promptly and effectively. You will receive an acknowledgement of your request within five (5) business days, and a substantive response within the timeframe prescribed by applicable law (generally one calendar month).