Privacy Policy

Last updated: June 2025

This Privacy Policy explains how (“we”, “us”, or “our”) collects, uses, stores, and shares personal data when you visit or use our website rivercrestatelier.com (the “Website”), make a reservation, use our hotel or casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all applicable data protection legislation.

Please read this Privacy Policy carefully. By accessing our Website or using our services, you acknowledge that you have read and understood this document.

1. Data Controller

The entity responsible for the processing of your personal data (the “Data Controller”) is:

Legal Entity Name
Registration Country European Union (EU)
Legal Address
Website rivercrestatelier.com
Privacy Contact Email privacy@rivercrestatelier.com

If you have any questions or concerns about how we process your personal data, you may contact us at any time at the contact details provided above or in Section 11 of this Policy.

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing matters relating to this Privacy Policy and our compliance with applicable data protection law.

DPO Title The Data Protection Officer
Organisation
Contact Email privacy@rivercrestatelier.com
Postal Address

You have the right to contact our DPO directly at any time regarding the processing of your personal data, the exercise of your rights, or any complaints you may have.

3. Scope and Applicability

This Privacy Policy applies to:

  • Visitors to our Website (rivercrestatelier.com), including persons who browse, make enquiries, or use any online features;
  • Guests who make hotel reservations, check in, or stay at our hotel premises in Toronto;
  • Patrons who access or use our casino facilities, participate in gaming activities, or enroll in loyalty or gaming programmes;
  • Individuals who contact us by telephone, email, live chat, social media, or any other communication channel;
  • Job applicants and prospective employees who submit applications or CVs;
  • Business partners, vendors, and contractors whose personal data we process in the course of managing commercial relationships.

This Policy does not apply to third-party websites, applications, or services that may be linked to or from our Website. We encourage you to review the privacy policies of any third-party sites you visit.

4. Personal Data We Collect

We collect personal data that you voluntarily provide to us, personal data that is generated automatically when you use our Website or services, and personal data that we may lawfully receive from third parties. The categories of personal data we process are described below.

4.1 Identity and Contact Data

  • Full name, title, and date of birth;
  • Nationality and passport or government-issued identity document details;
  • Postal address, email address, and telephone number;
  • Billing and payment information (credit or debit card details, bank account information);
  • Signature (where required for check-in or contractual purposes).

4.2 Reservation and Stay Data

  • Check-in and check-out dates, room type and preferences;
  • Special requests and accessibility requirements;
  • Number of guests and, where relevant, details of accompanying minors;
  • Details of services consumed during a stay (restaurant, spa, room service, minibar);
  • Loyalty programme membership number and history.

4.3 Casino and Gaming Data

  • Identity verification data required under Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations (government-issued ID, proof of address, source of funds);
  • Gaming activity records, including game participation, bet amounts, wins, and losses;
  • Casino loyalty programme enrolment and activity data;
  • Responsible gambling self-exclusion declarations and interaction records;
  • Video surveillance footage captured in gaming areas in accordance with applicable regulatory requirements.

4.4 Technical and Usage Data

  • IP address, browser type and version, operating system;
  • Device identifiers and connection data;
  • Pages visited, time spent on pages, links clicked, referral URLs;
  • Cookie identifiers and similar tracking technology data (see Section 10);
  • Log files and error reports.

4.5 Communications Data

  • Content of emails, live-chat messages, and online enquiry forms you send us;
  • Records of telephone calls (where calls are recorded for training or legal purposes);
  • Feedback, reviews, and survey responses;
  • Social media interactions where you tag or message us through official channels.

4.6 Marketing and Preferences Data

  • Marketing communication preferences and opt-in or opt-out records;
  • Interests and preferences inferred from your interactions with us;
  • Participation in competitions, promotions, or events.

4.7 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under Article 9 GDPR. This may include:

  • Health data: information about dietary requirements, allergies, or physical accessibility needs that you voluntarily share with us to enable us to tailor our services;
  • Health data related to responsible gambling: where you voluntarily disclose information about a gambling-related problem to access our responsible gambling support services or self-exclusion programme.

We process special category data only where you have given your explicit consent (Article 9(2)(a) GDPR) or where processing is necessary to protect your vital interests or comply with legal obligations.

4.8 Data Relating to Children

Our casino services are strictly restricted to individuals aged 19 years or over (in accordance with Ontario provincial law) and, in any event, to individuals who are at least 18 years of age under applicable GDPR standards. We do not knowingly collect personal data from children under the age of 16 for any marketing or profiling purpose. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@rivercrestatelier.com.

6. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

6.1 Provision of Hotel Services

  • Processing and confirming reservations, managing check-in and check-out;
  • Allocating rooms, accommodating special requests and accessibility needs;
  • Processing payments and issuing invoices or receipts;
  • Managing guest accounts, stays, and related hotel services.

6.2 Provision of Casino Services

  • Verifying your identity and age before permitting access to gaming areas;
  • Maintaining gaming records as required by casino licensing law;
  • Administering gaming loyalty programmes and promotional offers;
  • Implementing responsible gambling measures and self-exclusion requests;
  • Detecting and preventing fraud, money laundering, and cheating.

6.3 Communication and Customer Support

  • Responding to your enquiries, complaints, and feedback;
  • Sending service-related communications (booking confirmations, receipt emails);
  • Notifying you of changes to our services, terms, or this Privacy Policy.

6.4 Marketing and Personalisation

  • Sending you promotional communications about our hotel, casino, restaurant, spa, and event offerings, subject to your marketing preferences and applicable law;
  • Personalising your experience on our Website and tailoring offers to your preferences;
  • Conducting competitions, prize draws, and promotional events.

6.5 Security, Fraud Prevention, and Legal Compliance

  • Monitoring and securing our premises through CCTV surveillance;
  • Detecting, investigating, and preventing fraudulent transactions and criminal activity;
  • Complying with AML, KYC, tax, and other regulatory obligations;
  • Cooperating with law enforcement, courts, and regulatory authorities;
  • Establishing, exercising, and defending legal claims.

6.6 Analytics and Business Improvement

  • Analysing Website traffic, usage patterns, and user behaviour;
  • Conducting market research and guest satisfaction surveys;
  • Improving our products, services, Website functionality, and guest experience;
  • Preparing internal business reports and performance analytics.

6.7 Recruitment and HR

  • Reviewing job applications, conducting interviews, and making employment decisions;
  • Maintaining records of employment applications for a reasonable period in case a suitable role becomes available.

7. Data Sharing and Disclosure

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients only where necessary and in accordance with applicable law:

7.1 Service Providers and Data Processors

We engage trusted third-party service providers to perform functions on our behalf. These include:

  • IT and cloud services: hosting providers, database management, cybersecurity, and technical support vendors;
  • Payment processors: payment gateway and card processing companies that handle financial transactions securely;
  • Property Management System (PMS) providers: hotel reservation and guest management platform operators;
  • Casino management system providers: operators of gaming management and compliance software;
  • Marketing and communications platforms: email marketing, CRM, and analytics service providers;
  • Security and surveillance providers: companies managing CCTV and access control systems;
  • Professional advisors: lawyers, auditors, accountants, and insurers who require access to data to provide their services.

All data processors are bound by written data processing agreements that require them to process personal data only on our documented instructions and to implement appropriate technical and organisational security measures.

7.2 Regulatory and Law Enforcement Authorities

We may disclose personal data to government bodies, regulatory agencies, law enforcement authorities, courts, or other public authorities where we are required to do so by law or where such disclosure is necessary to:

  • Comply with a legal obligation (e.g., AML reporting to financial intelligence units);
  • Respond to lawful requests, court orders, or legal process;
  • Protect our rights, property, or the safety of our guests and staff.

7.3 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or part of our business or assets, your personal data may be transferred to the successor entity. We will notify you of any such transfer and any changes to privacy arrangements as required by applicable law.

7.4 Online Booking and Distribution Partners

Where you make a reservation through an online travel agency (OTA) or third-party booking platform, that platform acts as an independent data controller. We receive your booking details from that platform and process them to fulfil your reservation. Please review the privacy policy of any third-party booking platform you use.

7.5 International Data Transfers

Because is registered in the EU and operates premises in Canada, your personal data may be transferred between the European Economic Area (EEA) and Canada, and to other countries where our service providers operate. We ensure that all international transfers of personal data are protected by appropriate safeguards, including:

  • Transfers to Canada: the European Commission has recognised Canada (for organisations subject to the Personal Information Protection and Electronic Documents Act, PIPEDA) as providing an adequate level of data protection under Article 45 GDPR;
  • Transfers to other third countries: we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Article 46(2)(c) GDPR), Binding Corporate Rules (BCRs) where applicable, or other appropriate safeguards;
  • Where no adequacy decision or other safeguard applies, we rely on derogations permitted by Article 49 GDPR, such as your explicit consent or the performance of a contract with you, on a case-by-case basis.

You may request a copy of the applicable transfer mechanism by contacting our DPO at privacy@rivercrestatelier.com.

8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal, regulatory, accounting, or reporting obligations, or to resolve disputes and enforce agreements. Our general retention principles are as follows:

Category of Data Retention Period Basis
Hotel reservation and guest stay records 7 years from the date of checkout Legal obligation (tax and accounting law); legitimate interests (dispute resolution)
Payment and financial transaction records 7 years from the date of transaction Legal obligation (tax and financial regulations)
Casino AML/KYC identity verification records 5 years from the end of the business relationship or individual transaction Legal obligation (AML Directive; casino licensing law)
Gaming activity records 5 years from the date of activity Legal obligation (gaming regulatory requirements)
CCTV surveillance footage Up to 90 days unless required for investigation or legal proceedings Legitimate interests (security); legal obligation
Responsible gambling and self-exclusion records Duration of self-exclusion plus 5 years Legal obligation; vital interests; legitimate interests
Marketing preferences and consent records 3 years from your last interaction with us, or until consent is withdrawn Legitimate interests; consent
Website usage and cookie data Up to 24 months (varies by cookie type; see Section 10) Legitimate interests; consent
Job application records (unsuccessful applicants) 12 months from the date of the decision Legitimate interests; consent (where provided)
Correspondence and communications records 3 years from the date of the last communication Legitimate interests (dispute resolution and business records)

Upon expiry of the applicable retention period, we securely delete or anonymise your personal data so that it can no longer be associated with you. Where anonymisation is not feasible, we apply appropriate access restrictions to the data pending its deletion.

9. Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights with respect to your personal data. These rights apply subject to the conditions and limitations set out in applicable data protection law.

9.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you and to receive information about how we process it, including the purposes of processing, categories of data, recipients, retention periods, and the existence of automated decision-making.

9.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.

9.3 Right to Erasure (“Right to be Forgotten”) (Article 17 GDPR)

You have the right to request that we delete your personal data where:

  • The data is no longer necessary for the purpose for which it was collected;
  • You withdraw your consent and there is no other legal basis for processing;
  • You object to the processing and there are no overriding legitimate grounds;
  • The data has been unlawfully processed;
  • Erasure is required to comply with a legal obligation.

Please note that this right is not absolute. We may be unable to delete certain data where we are required to retain it by law (e.g., AML records, tax records) or where processing is necessary for the establishment, exercise, or defence of legal claims.

9.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including:

  • While we verify the accuracy of data you have contested;
  • Where processing is unlawful but you prefer restriction over erasure;
  • Where we no longer need the data but you require it for the establishment, exercise, or defence of legal claims;
  • Where you have objected to processing and we are considering whether our legitimate interests override your objection.

9.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

9.6 Right to Object (Article 21 GDPR)

You have the right to object to the processing of your personal data on grounds related to your particular situation where processing is based on legitimate interests (Article 6(1)(f) GDPR). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defence of legal claims.

You have an unconditional right to object to the processing of your personal data for direct marketing purposes at any time, including profiling related to direct marketing. Upon receipt of your objection, we will immediately stop using your data for direct marketing.

9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we engage in such processing, we will inform you and provide you with the right to obtain human intervention, to express your point of view, and to contest the decision.

We use limited profiling for personalised marketing communications and for fraud detection. Where such profiling may produce significant effects, we will rely on explicit consent or other appropriate safeguards.

9.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that took place before the withdrawal.

9.9 How to Exercise Your Rights

To exercise any of the rights listed above, please submit a written request to our Data Protection Officer:

We will respond to your request within 30 calendar days of receipt. In complex or multiple cases, we may extend this period by a further two months, in which case we will notify you of the extension and the reasons for it within the initial 30-day period. We may need to verify your identity before processing your request.

Exercising your rights is free of charge. However, where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable administrative fee or refuse to act on the request, in accordance with Article 12(5) GDPR.

9.10 Right to Lodge a Complaint

If you believe that we have processed your personal data in breach of applicable data protection law, you have the right to lodge a complaint with a supervisory authority. As is registered in the EU, the lead supervisory authority will be determined based on our EU establishment. You may also lodge a complaint with the data protection authority in the EU Member State of your habitual residence or place of work.

A list of EU data protection supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

We encourage you to contact us first at privacy@rivercrestatelier.com so that we may attempt to resolve your concern directly.

10. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies (such as web beacons, pixels, and local storage objects) to enhance your browsing experience, analyse Website traffic, and deliver personalised content and advertising. Below is a summary of the types of cookies we use:

Cookie Type Purpose Legal Basis Duration
Strictly Necessary Essential for the Website to function; enable core features such as page navigation, secure login, and shopping basket functionality. The Website cannot function properly without these cookies. Legitimate interests (no consent required) Session or up to 12 months
Performance / Analytics Collect information about how visitors use our Website (e.g., pages visited, errors encountered) to help us improve Website performance and user experience. Consent Up to 24 months
Functionality Remember your preferences and settings (e.g., language, region, accessibility settings) to personalise your experience. Consent Up to 12 months
Marketing / Targeting Track your browsing behaviour across websites to deliver targeted advertising and measure the effectiveness of advertising campaigns. Consent Up to 24 months

When you first visit our Website, a cookie consent banner will be displayed allowing you to accept, reject, or customise your cookie preferences. You may change your preferences at any time by clicking the “Cookie Settings” link in the footer of our Website.

You may also control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our Website. For more information about cookies and how to manage them, visit www.allaboutcookies.org .

11. Security of Your Personal Data

We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of personal data in transit (TLS/SSL) and, where appropriate, at rest;
  • Access controls and role-based permissions ensuring that only authorised personnel can access personal data on a need-to-know basis;
  • Regular security assessments, penetration testing, and vulnerability management;
  • Data minimisation practices to limit the volume of personal data collected and processed;
  • Pseudonymisation of data where feasible;
  • Documented procedures for responding to personal data breaches, including notification to the supervisory authority within 72 hours where required under Article 33 GDPR and notification to affected individuals where required under Article 34 GDPR;
  • Regular staff training on data protection and information security.

Despite our best efforts, no method of transmission over the internet or electronic storage is 100% secure. You are responsible for maintaining the confidentiality of any account credentials you use to access our services.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please do not hesitate to contact us:

Data Controller
Data Protection Officer The Data Protection Officer
Postal Address
Email Address privacy@rivercrestatelier.com
Website rivercrestatelier.com

We will endeavour to respond to all privacy-related enquiries promptly and in any event within the timeframes prescribed by applicable data protection law.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing activities, legal requirements, or business practices. When we make material changes, we will notify you by:

  • Posting the updated Privacy Policy on our Website with a revised “Last updated” date;
  • Sending a notification to the email address associated with your account (where applicable);
  • Displaying a prominent notice on our Website home page for a reasonable period.

We encourage you to review this Privacy Policy periodically. Your continued use of our Website or services after the effective date of any updated Privacy Policy constitutes your acknowledgment of the changes. Where required by law, we will obtain your renewed consent before applying material changes that affect the processing of your personal data.

14. Glossary of Key Terms

For the purposes of this Privacy Policy, the following terms have the meanings set out below:

  • Personal Data: Any information relating to an identified or identifiable natural person (“data subject”), as defined in Article 4(1) GDPR.
  • Processing: Any operation or set of operations performed on personal data, including collection, storage, use, disclosure, erasure, or destruction, as defined in Article 4(2) GDPR.
  • Data Controller: The natural or legal person that determines the purposes and means of processing personal data, as defined in Article 4(7) GDPR.
  • Data Processor: A natural or legal person that processes personal data on behalf of the Data Controller, as defined in Article 4(8) GDPR.
  • Data Protection Officer (DPO): An individual designated to oversee data protection strategy and compliance, as required under Articles 37–39 GDPR.
  • Special Categories of Personal Data: Sensitive data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person’s sex life or sexual orientation, as defined in Article 9 GDPR.
  • GDPR: The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  • Supervisory Authority: An independent public authority responsible for monitoring the application of the GDPR in each EU Member State, as defined in Article 4(21) GDPR.
  • Standard Contractual Clauses (SCCs): Standardised data protection clauses adopted by the European Commission to ensure appropriate safeguards for international data transfers, as referenced in Article 46(2)(c) GDPR.