Privacy Policy
Last updated: June 2025
This Privacy Policy explains how (“we”, “us”, or “our”) collects, uses, stores, and shares personal data when you visit or use our website rivercrestatelier.com (the “Website”), make a reservation, use our hotel or casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all applicable data protection legislation.
Please read this Privacy Policy carefully. By accessing our Website or using our services, you acknowledge that you have read and understood this document.
1. Data Controller
The entity responsible for the processing of your personal data (the “Data Controller”) is:
| Legal Entity Name | |
|---|---|
| Registration Country | European Union (EU) |
| Legal Address | |
| Website | rivercrestatelier.com |
| Privacy Contact Email | privacy@rivercrestatelier.com |
If you have any questions or concerns about how we process your personal data, you may contact us at any time at the contact details provided above or in Section 11 of this Policy.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing matters relating to this Privacy Policy and our compliance with applicable data protection law.
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Contact Email | privacy@rivercrestatelier.com |
| Postal Address |
You have the right to contact our DPO directly at any time regarding the processing of your personal data, the exercise of your rights, or any complaints you may have.
3. Scope and Applicability
This Privacy Policy applies to:
- Visitors to our Website (rivercrestatelier.com), including persons who browse, make enquiries, or use any online features;
- Guests who make hotel reservations, check in, or stay at our hotel premises in Toronto;
- Patrons who access or use our casino facilities, participate in gaming activities, or enroll in loyalty or gaming programmes;
- Individuals who contact us by telephone, email, live chat, social media, or any other communication channel;
- Job applicants and prospective employees who submit applications or CVs;
- Business partners, vendors, and contractors whose personal data we process in the course of managing commercial relationships.
This Policy does not apply to third-party websites, applications, or services that may be linked to or from our Website. We encourage you to review the privacy policies of any third-party sites you visit.
4. Personal Data We Collect
We collect personal data that you voluntarily provide to us, personal data that is generated automatically when you use our Website or services, and personal data that we may lawfully receive from third parties. The categories of personal data we process are described below.
4.1 Identity and Contact Data
- Full name, title, and date of birth;
- Nationality and passport or government-issued identity document details;
- Postal address, email address, and telephone number;
- Billing and payment information (credit or debit card details, bank account information);
- Signature (where required for check-in or contractual purposes).
4.2 Reservation and Stay Data
- Check-in and check-out dates, room type and preferences;
- Special requests and accessibility requirements;
- Number of guests and, where relevant, details of accompanying minors;
- Details of services consumed during a stay (restaurant, spa, room service, minibar);
- Loyalty programme membership number and history.
4.3 Casino and Gaming Data
- Identity verification data required under Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations (government-issued ID, proof of address, source of funds);
- Gaming activity records, including game participation, bet amounts, wins, and losses;
- Casino loyalty programme enrolment and activity data;
- Responsible gambling self-exclusion declarations and interaction records;
- Video surveillance footage captured in gaming areas in accordance with applicable regulatory requirements.
4.4 Technical and Usage Data
- IP address, browser type and version, operating system;
- Device identifiers and connection data;
- Pages visited, time spent on pages, links clicked, referral URLs;
- Cookie identifiers and similar tracking technology data (see Section 10);
- Log files and error reports.
4.5 Communications Data
- Content of emails, live-chat messages, and online enquiry forms you send us;
- Records of telephone calls (where calls are recorded for training or legal purposes);
- Feedback, reviews, and survey responses;
- Social media interactions where you tag or message us through official channels.
4.6 Marketing and Preferences Data
- Marketing communication preferences and opt-in or opt-out records;
- Interests and preferences inferred from your interactions with us;
- Participation in competitions, promotions, or events.
4.7 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under Article 9 GDPR. This may include:
- Health data: information about dietary requirements, allergies, or physical accessibility needs that you voluntarily share with us to enable us to tailor our services;
- Health data related to responsible gambling: where you voluntarily disclose information about a gambling-related problem to access our responsible gambling support services or self-exclusion programme.
We process special category data only where you have given your explicit consent (Article 9(2)(a) GDPR) or where processing is necessary to protect your vital interests or comply with legal obligations.
4.8 Data Relating to Children
Our casino services are strictly restricted to individuals aged 19 years or over (in accordance with Ontario provincial law) and, in any event, to individuals who are at least 18 years of age under applicable GDPR standards. We do not knowingly collect personal data from children under the age of 16 for any marketing or profiling purpose. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@rivercrestatelier.com.
5. Legal Basis for Processing Your Personal Data
Under the GDPR, we are required to identify a lawful basis for every processing activity. We rely on the following legal bases set out in Article 6 GDPR:
5.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary to enter into or perform a contract with you, or to take pre-contractual steps at your request. Examples include:
- Processing hotel reservations and managing your stay;
- Processing payments for hotel, restaurant, spa, or casino services;
- Administering your loyalty programme membership;
- Responding to your enquiries about available rooms or services.
5.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process personal data where we are required to do so by law. Examples include:
- Identity verification and record-keeping obligations under Anti-Money Laundering (AML) legislation and casino licensing requirements;
- Retention of financial and tax records as required by applicable tax law;
- Disclosure to law enforcement or regulatory authorities when lawfully required;
- Guest registration obligations under hospitality and immigration regulations;
- Compliance with occupational health and safety obligations.
5.3 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, for example in the event of a medical emergency on our premises.
5.4 Legitimate Interests (Article 6(1)(f) GDPR)
We process personal data where it is necessary for the purposes of our legitimate interests or those of a third party, provided that those interests are not overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include:
- Operating, improving, and securing our Website, IT infrastructure, and business operations;
- Preventing fraud, theft, cheating, and other unlawful activity on our premises and through our services;
- Video surveillance (CCTV) of public areas on our hotel and casino premises for safety and security purposes;
- Sending direct marketing communications about products and services similar to those you have previously purchased, where you have not opted out;
- Conducting analytics and business intelligence to understand how our services are used and to improve the guest experience;
- Managing and documenting business relationships with suppliers, partners, and contractors;
- Administering and defending legal claims.
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) to ensure that our interests are balanced fairly against your rights. You may request a summary of any relevant LIA by contacting our DPO.
5.5 Consent (Article 6(1)(a) GDPR)
Where no other legal basis applies, or where required by law, we will ask for your freely given, specific, informed, and unambiguous consent before processing your personal data. We rely on consent for:
- Sending marketing emails, SMS messages, or push notifications where you have not previously purchased our services;
- Placing non-essential cookies and similar tracking technologies on your device (see Section 10);
- Processing special category data (e.g., health or dietary information) beyond what is strictly necessary for service provision;
- Profiling and personalised advertising beyond what is permitted under legitimate interests.
You have the right to withdraw your consent at any time without detriment. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw your consent, please contact us at privacy@rivercrestatelier.com or use the unsubscribe link in any marketing email.
5.6 Public Interest (Article 6(1)(e) GDPR)
In limited circumstances, we may process personal data where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, for example when cooperating with public health authorities or regulators in accordance with applicable law.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Provision of Hotel Services
- Processing and confirming reservations, managing check-in and check-out;
- Allocating rooms, accommodating special requests and accessibility needs;
- Processing payments and issuing invoices or receipts;
- Managing guest accounts, stays, and related hotel services.
6.2 Provision of Casino Services
- Verifying your identity and age before permitting access to gaming areas;
- Maintaining gaming records as required by casino licensing law;
- Administering gaming loyalty programmes and promotional offers;
- Implementing responsible gambling measures and self-exclusion requests;
- Detecting and preventing fraud, money laundering, and cheating.
6.3 Communication and Customer Support
- Responding to your enquiries, complaints, and feedback;
- Sending service-related communications (booking confirmations, receipt emails);
- Notifying you of changes to our services, terms, or this Privacy Policy.
6.4 Marketing and Personalisation
- Sending you promotional communications about our hotel, casino, restaurant, spa, and event offerings, subject to your marketing preferences and applicable law;
- Personalising your experience on our Website and tailoring offers to your preferences;
- Conducting competitions, prize draws, and promotional events.
6.5 Security, Fraud Prevention, and Legal Compliance
- Monitoring and securing our premises through CCTV surveillance;
- Detecting, investigating, and preventing fraudulent transactions and criminal activity;
- Complying with AML, KYC, tax, and other regulatory obligations;
- Cooperating with law enforcement, courts, and regulatory authorities;
- Establishing, exercising, and defending legal claims.
6.6 Analytics and Business Improvement
- Analysing Website traffic, usage patterns, and user behaviour;
- Conducting market research and guest satisfaction surveys;
- Improving our products, services, Website functionality, and guest experience;
- Preparing internal business reports and performance analytics.
6.7 Recruitment and HR
- Reviewing job applications, conducting interviews, and making employment decisions;
- Maintaining records of employment applications for a reasonable period in case a suitable role becomes available.
7. Data Sharing and Disclosure
We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients only where necessary and in accordance with applicable law:
7.1 Service Providers and Data Processors
We engage trusted third-party service providers to perform functions on our behalf. These include:
- IT and cloud services: hosting providers, database management, cybersecurity, and technical support vendors;
- Payment processors: payment gateway and card processing companies that handle financial transactions securely;
- Property Management System (PMS) providers: hotel reservation and guest management platform operators;
- Casino management system providers: operators of gaming management and compliance software;
- Marketing and communications platforms: email marketing, CRM, and analytics service providers;
- Security and surveillance providers: companies managing CCTV and access control systems;
- Professional advisors: lawyers, auditors, accountants, and insurers who require access to data to provide their services.
All data processors are bound by written data processing agreements that require them to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures.
7.2 Regulatory and Law Enforcement Authorities
We may disclose personal data to government bodies, regulatory agencies, law enforcement authorities, courts, or other public authorities where we are required to do so by law or where such disclosure is necessary to:
- Comply with a legal obligation (e.g., AML reporting to financial intelligence units);
- Respond to lawful requests, court orders, or legal process;
- Protect our rights, property, or the safety of our guests and staff.
7.3 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of all or part of our business or assets, your personal data may be transferred to the successor entity. We will notify you of any such transfer and any changes to privacy arrangements as required by applicable law.
7.4 Online Booking and Distribution Partners
Where you make a reservation through an online travel agency (OTA) or third-party booking platform, that platform acts as an independent data controller. We receive your booking details from that platform and process them to fulfil your reservation. Please review the privacy policy of any third-party booking platform you use.
7.5 International Data Transfers
Because is registered in the EU and operates premises in Canada, your personal data may be transferred between the European Economic Area (EEA) and Canada, and to other countries where our service providers operate. We ensure that all international transfers of personal data are protected by appropriate safeguards, including:
- Transfers to Canada: the European Commission has recognised Canada (for organisations subject to the Personal Information Protection and Electronic Documents Act, PIPEDA) as providing an adequate level of data protection under Article 45 GDPR;
- Transfers to other third countries: we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Article 46(2)(c) GDPR), Binding Corporate Rules (BCRs) where applicable, or other appropriate safeguards;
- Where no adequacy decision or other safeguard applies, we rely on derogations permitted by Article 49 GDPR, such as your explicit consent or the performance of a contract with you, on a case-by-case basis.
You may request a copy of the applicable transfer mechanism by contacting our DPO at privacy@rivercrestatelier.com.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal, regulatory, accounting, or reporting obligations, or to resolve disputes and enforce agreements. Our general retention principles are as follows:
| Category of Data | Retention Period | Basis |
|---|---|---|
| Hotel reservation and guest stay records | 7 years from the date of checkout | Legal obligation (tax and accounting law); legitimate interests (dispute resolution) |
| Payment and financial transaction records | 7 years from the date of transaction | Legal obligation (tax and financial regulations) |
| Casino AML/KYC identity verification records | 5 years from the end of the business relationship or individual transaction | Legal obligation (AML Directive; casino licensing law) |
| Gaming activity records | 5 years from the date of activity | Legal obligation (gaming regulatory requirements) |
| CCTV surveillance footage | Up to 90 days unless required for investigation or legal proceedings | Legitimate interests (security); legal obligation |
| Responsible gambling and self-exclusion records | Duration of self-exclusion plus 5 years | Legal obligation; vital interests; legitimate interests |
| Marketing preferences and consent records | 3 years from your last interaction with us, or until consent is withdrawn | Legitimate interests; consent |
| Website usage and cookie data | Up to 24 months (varies by cookie type; see Section 10) | Legitimate interests; consent |
| Job application records (unsuccessful applicants) | 12 months from the date of the decision | Legitimate interests; consent (where provided) |
| Correspondence and communications records | 3 years from the date of the last communication | Legitimate interests (dispute resolution and business records) |
Upon expiry of the applicable retention period, we securely delete or anonymise your personal data so that it can no longer be associated with you. Where anonymisation is not feasible, we apply appropriate access restrictions to the data pending its deletion.
9. Your Rights Under the GDPR
As a data subject under the GDPR, you have the following rights with respect to your personal data. These rights apply subject to the conditions and limitations set out in applicable data protection law.
9.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you and to receive information about how we process it, including the purposes of processing, categories of data, recipients, retention periods, and the existence of automated decision-making.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.
9.3 Right to Erasure (“Right to be Forgotten”) (Article 17 GDPR)
You have the right to request that we delete your personal data where:
- The data is no longer necessary for the purpose for which it was collected;
- You withdraw your consent and there is no other legal basis for processing;
- You object to the processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed;
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute. We may be unable to delete certain data where we are required to retain it by law (e.g., AML records, tax records) or where processing is necessary for the establishment, exercise, or defence of legal claims.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including:
- While we verify the accuracy of data you have contested;
- Where processing is unlawful but you prefer restriction over erasure;
- Where we no longer need the data but you require it for the establishment, exercise, or defence of legal claims;
- Where you have objected to processing and we are considering whether our legitimate interests override your objection.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
9.6 Right to Object (Article 21 GDPR)
You have the right to object to the processing of your personal data on grounds related to your particular situation where processing is based on legitimate interests (Article 6(1)(f) GDPR). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defence of legal claims.
You have an unconditional right to object to the processing of your personal data for direct marketing purposes at any time, including profiling related to direct marketing. Upon receipt of your objection, we will immediately stop using your data for direct marketing.
9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we engage in such processing, we will inform you and provide you with the right to obtain human intervention, to express your point of view, and to contest the decision.
We use limited profiling for personalised marketing communications and for fraud detection. Where such profiling may produce significant effects, we will rely on explicit consent or other appropriate safeguards.
9.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that took place before the withdrawal.
9.9 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer:
- By email: privacy@rivercrestatelier.com
- By post: The Data Protection Officer, ,
We will respond to your request within 30 calendar days of receipt. In complex or multiple cases, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it within the initial 30-day period. We may need to verify your identity before processing your request.
Exercising your rights is free of charge. However, where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable administrative fee or refuse to act on the request, in accordance with Article 12(5) GDPR.
9.10 Right to Lodge a Complaint
If you believe that we have processed your personal data in breach of applicable data protection law, you have the right to lodge a complaint with a supervisory authority. As is registered in the EU, the lead supervisory authority will be determined based on our EU establishment. You may also lodge a complaint with the data protection authority in the EU Member State of your habitual residence or place of work.
A list of EU data protection supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
We encourage you to contact us first at privacy@rivercrestatelier.com so that we may attempt to resolve your concern directly.
11. Security of Your Personal Data
We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of personal data in transit (TLS/SSL) and, where appropriate, at rest;
- Access controls and role-based permissions ensuring that only authorised personnel can access personal data on a need-to-know basis;
- Regular security assessments, penetration testing, and vulnerability management;
- Data minimisation practices to limit the volume of personal data collected and processed;
- Pseudonymisation of data where feasible;
- Documented procedures for responding to personal data breaches, including notification to the supervisory authority within 72 hours where required under Article 33 GDPR and notification to affected individuals where required under Article 34 GDPR;
- Regular staff training on data protection and information security.
Despite our best efforts, no method of transmission over the internet or electronic storage is 100% secure. You are responsible for maintaining the confidentiality of any account credentials you use to access our services.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please do not hesitate to contact us:
| Data Controller | |
|---|---|
| Data Protection Officer | The Data Protection Officer |
| Postal Address | |
| Email Address | privacy@rivercrestatelier.com |
| Website | rivercrestatelier.com |
We will endeavour to respond to all privacy-related enquiries promptly and in any event within the timeframes prescribed by applicable data protection law.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, legal requirements, or business practices. When we make material changes, we will notify you by:
- Posting the updated Privacy Policy on our Website with a revised “Last updated” date;
- Sending a notification to the email address associated with your account (where applicable);
- Displaying a prominent notice on our Website home page for a reasonable period.
We encourage you to review this Privacy Policy periodically. Your continued use of our Website or services after the effective date of any updated Privacy Policy constitutes your acknowledgment of the changes. Where required by law, we will obtain your renewed consent before applying material changes that affect the processing of your personal data.
14. Glossary of Key Terms
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
- Personal Data: Any information relating to an identified or identifiable natural person (“data subject”), as defined in Article 4(1) GDPR.
- Processing: Any operation or set of operations performed on personal data, including collection, storage, use, disclosure, erasure, or destruction, as defined in Article 4(2) GDPR.
- Data Controller: The natural or legal person that determines the purposes and means of processing personal data, as defined in Article 4(7) GDPR.
- Data Processor: A natural or legal person that processes personal data on behalf of the Data Controller, as defined in Article 4(8) GDPR.
- Data Protection Officer (DPO): An individual designated to oversee data protection strategy and compliance, as required under Articles 37–39 GDPR.
- Special Categories of Personal Data: Sensitive data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person’s sex life or sexual orientation, as defined in Article 9 GDPR.
- GDPR: The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- Supervisory Authority: An independent public authority responsible for monitoring the application of the GDPR in each EU Member State, as defined in Article 4(21) GDPR.
- Standard Contractual Clauses (SCCs): Standardised data protection clauses adopted by the European Commission to ensure appropriate safeguards for international data transfers, as referenced in Article 46(2)(c) GDPR.