Privacy Policy
Last updated: June 2025
Welcome to Xelmoriaregalstay ("we", "us", "our"). We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA"), and all other applicable data protection legislation. This Privacy Policy explains who we are, what personal data we collect about you, why we collect it, how we use it, with whom we share it, how long we retain it, and what rights you have in relation to your data.
Please read this policy carefully before using our website at xelmoriaregalstay.com (the "Website") or making use of any of the services we provide. By accessing our Website or providing us with your personal data, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for the collection and processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
|---|---|
| Trading Name | Xelmoriaregalstay |
| Registration Country | Canada |
| Registration Number | Corporation No. 8529471 |
| VAT / Tax Number | GST/HST No. 852 947 163 RT0001 |
| Registered Address | |
| Website | xelmoriaregalstay.com |
| Privacy Contact Email | privacy@xelmoriaregalstay.com |
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws. If you have any questions, concerns, or requests relating to your personal data, you may contact our DPO at:
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| Email Address | privacy@xelmoriaregalstay.com |
3. Scope and Application of This Policy
This Privacy Policy applies to all personal data collected through:
- Our Website at xelmoriaregalstay.com and any subdomains thereof;
- Online reservations, booking forms, and enquiry submissions;
- Our hotel and casino facilities located in Picton, Canada;
- Loyalty and rewards programme enrolment and management;
- Direct communications via email, telephone, or post;
- Social media pages and channels operated by us;
- Third-party platforms and booking aggregators through which you make a reservation with us;
- In-person interactions, including casino floor activities, check-in, check-out, dining, and event attendance.
This policy does not apply to websites of third parties to which our Website may link. We encourage you to review the privacy policies of any third-party websites you visit.
4. Personal Data We Collect
We collect and process various categories of personal data, depending on the nature of your interaction with us. The categories of personal data we may collect include the following:
4.1 Identity and Contact Data
- Full name (first name, middle name, surname);
- Date of birth and, where legally required, proof of age;
- Gender;
- Nationality and country of residence;
- Passport number, national identity card number, or other government-issued identification;
- Postal address (home and/or billing address);
- Email address;
- Telephone and mobile numbers;
- Emergency contact details.
4.2 Reservation and Stay Data
- Reservation reference numbers and booking history;
- Check-in and check-out dates;
- Room type, preferences, and special requests;
- Number and relationship of accompanying guests;
- Details of services used during your stay (dining, spa, entertainment, casino);
- Complaints, feedback, and satisfaction survey responses.
4.3 Financial and Payment Data
- Credit or debit card details (processed securely via PCI-DSS compliant payment processors);
- Bank account information where applicable;
- Billing address;
- Transaction history and spend records;
- Invoice and receipt data.
4.4 Casino and Gaming Data
- Gaming activity, play history, and wagering records;
- Casino account registration details;
- Player card or loyalty number;
- Self-exclusion requests and responsible gaming records;
- Identity verification data required under anti-money laundering (AML) and know-your-customer (KYC) obligations, including copies of government-issued identification;
- Source of funds declarations where required by law;
- Winnings, cashouts, and chip purchase records.
4.5 Technical and Usage Data
- IP address and approximate geolocation derived from IP;
- Browser type and version;
- Operating system and device type;
- Pages viewed, links clicked, and time spent on each page;
- Referral URL and search terms used to find our Website;
- Cookie identifiers and session tokens (see our Cookie Policy for further details);
- Log files and server access records.
4.6 Marketing and Communications Data
- Marketing preferences and consent records;
- Communication history (emails opened, links clicked);
- Loyalty programme tier, points balance, and redemption history;
- Responses to promotions, competitions, and surveys.
4.7 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health and dietary information: when you notify us of allergies, dietary requirements, or accessibility needs in relation to your stay or dining experience;
- Responsible gambling indicators: information relating to problem gambling behaviour or self-exclusion status, which may indirectly reveal health-related information.
We process such data only where you have given explicit consent, or where processing is necessary to protect your vital interests or those of another person, or where processing is required by applicable law. We apply enhanced safeguards to all special category data.
4.8 CCTV and Security Data
- CCTV footage captured within our hotel and casino premises for security and fraud prevention purposes;
- Incident reports and security logs.
4.9 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia);
- Corporate travel agents and event organisers;
- Credit reference and fraud prevention agencies;
- Regulatory authorities in connection with AML/KYC obligations;
- Social media platforms, where you interact with us through those channels.
5. Legal Basis for Processing
We only process your personal data when we have a lawful basis to do so. In accordance with Article 6 of the GDPR, the legal bases on which we rely are as follows:
5.1 Performance of a Contract (Article 6(1)(b))
Processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes:
- Processing your reservation, check-in, and check-out;
- Managing your casino account and gaming activity;
- Processing payments for services rendered;
- Administering your loyalty programme membership;
- Responding to service requests and customer enquiries.
5.2 Legal Obligation (Article 6(1)(c))
Processing is necessary to comply with a legal obligation to which we are subject. This includes:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations under Canadian federal and provincial law;
- Know-your-customer (KYC) and identity verification requirements;
- Gaming regulatory reporting and record-keeping obligations;
- Tax and accounting obligations under the Income Tax Act and GST/HST legislation;
- Compliance with court orders, law enforcement requests, and regulatory investigations.
5.3 Legitimate Interests (Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where those interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Fraud prevention and detection, and protecting the security of our premises and systems;
- Operating CCTV surveillance for the safety and security of guests and staff;
- Improving and optimising our Website, services, and guest experience;
- Sending direct marketing communications to existing customers (subject to opt-out rights);
- Enforcing our terms and conditions and exercising or defending legal claims;
- Business analytics, internal reporting, and performance monitoring;
- Managing network and information security.
Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests are not overridden by your rights. You may request details of this assessment by contacting us at the details provided in Section 13.
5.4 Consent (Article 6(1)(a))
Where you have given us your clear, freely given, specific, informed, and unambiguous consent to process your personal data for a specific purpose. This includes:
- Sending you marketing communications where you are not an existing customer;
- Placing non-essential cookies on your device;
- Processing special categories of personal data (e.g., health or dietary information);
- Sharing your data with selected third-party partners for their own marketing purposes.
Where we rely on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@xelmoriaregalstay.com.
5.5 Vital Interests (Article 6(1)(d))
Processing is necessary in order to protect your vital interests or those of another natural person. This may apply in medical emergencies or where your safety or the safety of others is at immediate risk on our premises.
5.6 Public Task (Article 6(1)(e))
Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, for example in connection with gaming regulatory compliance or cooperation with governmental authorities.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Hotel Operations
- To process, manage, and confirm your accommodation reservations;
- To facilitate check-in and check-out procedures;
- To deliver the services you have requested during your stay;
- To process payments and issue invoices and receipts;
- To communicate with you about your reservation, including modifications and cancellations;
- To accommodate dietary requirements, accessibility needs, and other special requests you have communicated to us.
6.2 Casino and Gaming Operations
- To register and administer your casino account;
- To verify your identity and age in accordance with applicable gaming regulations;
- To record and report gaming transactions as required by law;
- To identify and support guests who may be experiencing problem gambling;
- To enforce self-exclusion requests and responsible gaming measures;
- To detect and prevent cheating, fraud, and money laundering on the casino floor.
6.3 Marketing and Personalisation
- To send you promotional offers, news, special packages, and event invitations relating to Xelmoriaregalstay, subject to your marketing preferences;
- To personalise your experience on our Website and tailor content to your interests;
- To administer loyalty programmes, rewards, and exclusive member benefits;
- To conduct surveys and collect feedback to improve our services.
6.4 Security and Fraud Prevention
- To operate CCTV systems throughout our hotel and casino premises;
- To detect, investigate, and prevent fraudulent transactions and activities;
- To verify the identity of guests and staff;
- To protect the safety and security of all guests, employees, and visitors.
6.5 Legal and Regulatory Compliance
- To comply with our obligations under AML, KYC, and gaming regulatory frameworks;
- To respond to lawful requests from law enforcement and regulatory authorities;
- To exercise or defend legal claims;
- To maintain statutory records and fulfil tax reporting obligations.
6.6 Business Operations and Improvement
- To analyse Website traffic and improve our online presence;
- To conduct internal research and business analytics;
- To train staff and maintain service quality standards;
- To manage and develop our IT systems and infrastructure.
7. Sharing Your Personal Data
We do not sell your personal data to third parties. We may, however, share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate safeguards:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instruction. These include:
- Payment processing companies and financial institutions;
- Cloud computing, hosting, and IT infrastructure providers;
- Email marketing and customer relationship management (CRM) platforms;
- Reservation and property management system (PMS) providers;
- Casino management system (CMS) and gaming technology providers;
- Website analytics and performance monitoring tools;
- Printing, mailing, and communication service providers;
- Legal, audit, and professional advisory firms.
All our data processors are bound by written data processing agreements that require them to process personal data only as instructed, implement appropriate security measures, and not engage sub-processors without our prior written authorisation.
7.2 Regulatory and Law Enforcement Authorities
We may disclose personal data to:
- The AGCO, Ontario's gaming regulator and other gaming regulatory bodies, as required by our gaming licence obligations;
- The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) and other AML reporting bodies;
- Canada Revenue Agency (CRA) for tax compliance purposes;
- Law enforcement agencies, courts, or other governmental authorities where required by law or court order, or where necessary to protect our legal rights.
7.3 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy, your personal data may be transferred to a successor or affiliated entity. We will notify you of any such transfer and any material changes to this Privacy Policy.
7.4 Marketing Partners (with Consent)
With your explicit consent, we may share your contact information with carefully selected partners for joint promotional activities. You may withdraw this consent at any time.
7.5 International Transfers
Xelmoriaregalstay is based in Canada. Some of our service providers may be located outside Canada or the European Economic Area (EEA). Where personal data is transferred internationally, we ensure that adequate safeguards are in place, including:
- Transfers to countries that have been deemed to provide an adequate level of data protection by the European Commission or the relevant Canadian authority;
- Use of Standard Contractual Clauses (SCCs) approved by the European Commission, where transfers are governed by GDPR;
- Binding Corporate Rules or other recognised transfer mechanisms, where applicable.
You may request a copy of the safeguards we have in place for international transfers by contacting our DPO at privacy@xelmoriaregalstay.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Our data retention periods are guided by the following principles:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years from the date of departure | Legal obligation (tax and accounting records) |
| Payment and financial transaction records | 7 years from the date of transaction | Legal obligation (tax and financial regulation) |
| Casino gaming and wagering records | 7 years from the date of activity | Legal obligation (gaming regulatory requirements) |
| AML/KYC identity verification records | 7 years from the end of the business relationship | Legal obligation (FINTRAC / PCMLTFA) |
| Self-exclusion and responsible gaming records | Duration of exclusion plus 10 years | Legal obligation and legitimate interests |
| CCTV footage | 30 days, unless required for an ongoing investigation | Legitimate interests (security) |
| Marketing consent records | Until consent is withdrawn, plus 3 years | Consent / legal obligation (proof of consent) |
| Website analytics and cookie data | Up to 26 months from collection | Legitimate interests / consent |
| Customer complaints and correspondence | 3 years from resolution | Legitimate interests (legal claims) |
| Employment application records (unsuccessful) | 12 months from application date | Legitimate interests |
At the end of the applicable retention period, personal data is securely deleted, anonymised, or archived in accordance with our internal data destruction procedures. Where data is anonymised, it may be retained indefinitely for statistical and analytical purposes.
9. Your Rights Under GDPR and Applicable Data Protection Law
Depending on your location and the applicable law, you have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month of receipt, and will not charge a fee unless your request is manifestly unfounded or excessive.
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether or not we process personal data concerning you and, if so, to receive a copy of that data together with information about how it is processed, the purposes of processing, the recipients to whom it has been disclosed, and the envisaged retention period.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to require us to correct any inaccurate personal data we hold about you and to have any incomplete personal data completed, taking into account the purposes of the processing.
9.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data where there is no longer a legitimate reason for us to continue processing it, where you have withdrawn your consent and there is no other legal basis for processing, or where you have objected to processing and there are no overriding legitimate grounds. This right may be limited where processing is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you oppose erasure, or where you need us to retain the data for the establishment, exercise, or defence of legal claims.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests or is carried out for direct marketing purposes. Where you object to direct marketing, we will cease processing your data for that purpose immediately. Where you object on the basis of legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
9.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for a contract, authorised by law, or based on your explicit consent. We do not currently make decisions based solely on automated processing that have legal or similarly significant effects on individuals without human involvement. If this changes, we will update this policy and notify you accordingly.
9.8 Right to Withdraw Consent
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at privacy@xelmoriaregalstay.com or use the unsubscribe link in any marketing email we send you.
9.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority:
- In Canada: The Office of the Privacy Commissioner of Canada (OPC), 30 Victoria Street, Gatineau, QC K1A 1H3. Website: www.priv.gc.ca
- In the EU/EEA (for GDPR purposes): The data protection supervisory authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority. We encourage you to contact us in the first instance.
9.10 Exercising Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer at:
- Email: privacy@xelmoriaregalstay.com
- Post: The Data Protection Officer, ,
We may need to verify your identity before processing your request. We will respond within one month of receiving a valid request. If your request is complex or we receive a large number of requests, we may extend this period by a further two months, and we will inform you of this extension within the initial one-month period.
11. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption of personal data in transit using Transport Layer Security (TLS) and at rest using industry-standard encryption protocols;
- Payment card data processed in accordance with the Payment Card Industry Data Security Standard (PCI-DSS);
- Access controls and role-based permissions restricting data access to authorised personnel;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Staff training on data protection and information security;
- Incident response procedures for identifying, managing, and reporting data breaches;
- Physical security measures at our hotel and casino premises.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 of the GDPR.
12. Children's Privacy
Our casino services are strictly restricted to individuals aged 19 years and over (or the applicable legal minimum age in the relevant jurisdiction). Our Website is not directed at children under the age of 16, and we do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at privacy@xelmoriaregalstay.com and we will take prompt steps to delete such data.
We may collect limited personal data relating to children accompanying guests who are staying at the hotel (e.g., number of children in a room), but we do not use such data for marketing purposes, and we apply additional protective measures to any data relating to minors.
13. How to Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our processing of your personal data, please do not hesitate to contact us:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| privacy@xelmoriaregalstay.com | |
| Postal Address | |
| Website | xelmoriaregalstay.com |
We are committed to resolving any privacy-related concerns promptly and transparently. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada or the relevant EU/EEA supervisory authority, as described in Section 9.9 above.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or our business operations. When we make material changes to this policy, we will notify you by posting the updated policy on our Website with a revised "Last updated" date at the top of the page. Where required by law, or where changes are material and likely to affect your rights, we will also notify you by email or through a prominent notice on our Website.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services after the posting of any changes constitutes your acknowledgement of the updated Privacy Policy.
Previous versions of this Privacy Policy are available upon request by contacting our DPO at privacy@xelmoriaregalstay.com.