Privacy Policy
Last updated: June 2025
This Privacy Policy describes how (hereinafter referred to as "we", "us", "our", or the "Company") collects, uses, discloses, and protects the personal data of individuals ("you", "your", "data subject") who interact with our website located at www.qalexagrandlodge.com (the "Website"), as well as in the context of our hotel and casino services offered at Qalexagrand Lodge in Edmonton, Canada.
We are committed to protecting your privacy and processing your personal data in a transparent, lawful, and secure manner, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta's Personal Information Protection Act (PIPA), and all other applicable data protection legislation.
Please read this Privacy Policy carefully before using our Website or engaging with our services. By using our Website, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for the processing of your personal data is:
| Legal Entity Name | |
|---|---|
| Trading Name | Qalexagrand Lodge |
| Registration Country | Canada |
| Company Registration Number | BC1369427 |
| VAT / Business Number | 849271638RT0001 |
| Registered Address | |
| Website | www.qalexagrandlodge.com |
| Contact Email | info@qalexagrandlodge.com |
As a data controller, we determine the purposes and means of processing your personal data. We are accountable for all personal data we collect, use, retain, and disclose in connection with our activities.
2. Data Protection Officer (DPO)
We have designated a Data Protection Officer responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO at:
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@qalexagrandlodge.com |
3. Scope and Applicability
This Privacy Policy applies to:
- All visitors and users of our Website ( www.qalexagrandlodge.com );
- Guests who book accommodation, dining, or event services through our Website or third-party platforms;
- Individuals who participate in our casino activities and loyalty programmes;
- Individuals who contact us via email, telephone, online forms, or in person;
- Business partners, suppliers, and other third parties whose representatives interact with us;
- Any person whose personal data we process in connection with our business operations.
This Policy does not apply to third-party websites linked from our Website. We are not responsible for the privacy practices of external websites and encourage you to review their respective privacy policies.
4. Personal Data We Collect
We collect various categories of personal data depending on the nature of your interaction with us. We only collect personal data that is adequate, relevant, and limited to what is necessary for the specified purposes.
4.1 Data You Provide Directly to Us
- Identity and Contact Data: Full name, date of birth, nationality, gender, postal address, email address, telephone number, and government-issued identification details (e.g., passport or driver's licence number) where required by law;
- Reservation and Booking Data: Arrival and departure dates, room type preferences, number of guests, special requests, and service preferences;
- Payment Data: Credit or debit card details, billing address, and transaction history (note: full card data is processed securely by our PCI-DSS compliant payment processors and is not stored on our systems);
- Account and Profile Data: Login credentials, loyalty programme membership details, account settings, and communication preferences;
- Casino and Gaming Data: Player registration details, gaming activity records, winnings, losses, wager amounts, responsible gaming self-exclusion requests, and identity verification documents required under anti-money laundering regulations;
- Communications Data: Messages, enquiries, complaints, feedback, and survey responses submitted to us;
- Marketing Preferences: Consents and opt-in or opt-out preferences for direct marketing communications.
4.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device identifiers, time zone settings, and browser plug-in types;
- Usage Data: Pages visited, links clicked, referring URLs, session duration, and navigation paths within our Website;
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy.
4.3 Data Received from Third Parties
- Booking Platform Data: Reservation data transmitted by online travel agencies (OTAs) and booking platforms through which you made a reservation;
- Social Media Data: Public profile information when you interact with our social media pages or log in via a social media account;
- Fraud Prevention and Credit Reference Agencies: Data to verify your identity and protect against fraud;
- Regulatory and Law Enforcement Bodies: Data shared pursuant to legal obligations, particularly in relation to anti-money laundering (AML) compliance.
4.4 Special Categories of Personal Data
We may, in limited circumstances, process special categories of personal data as defined under Article 9 of the GDPR, including:
- Health and Disability Information: Where you inform us of accessibility requirements or dietary needs for medical reasons, in order to provide appropriate accommodations;
- Data relating to criminal convictions or offences: As required for regulatory compliance under gaming and anti-money laundering legislation.
We process special category data only where a specific legal basis under Article 9(2) GDPR applies, including your explicit consent, the performance of obligations in the field of employment law, or reasons of substantial public interest.
5. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your personal data only where we have a lawful basis to do so. The legal bases we rely upon are as follows:
5.1 Article 6(1)(a) — Consent
We process your personal data on the basis of your freely given, specific, informed, and unambiguous consent in the following circumstances:
- Sending you direct marketing emails, SMS messages, or newsletters about our services, promotions, and offers where you have opted in;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special category personal data for which no other legal basis applies.
You have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
5.2 Article 6(1)(b) — Performance of a Contract
We process your personal data where it is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract:
- Processing hotel reservations, check-ins, and check-outs;
- Managing your casino player account and processing gaming transactions;
- Providing dining, event, spa, and concierge services you have requested;
- Processing payments and issuing invoices and receipts;
- Managing your loyalty programme membership and associated benefits.
5.3 Article 6(1)(c) — Compliance with a Legal Obligation
We process your personal data where necessary to comply with legal obligations to which we are subject, including:
- Anti-money laundering (AML) and counter-terrorist financing (CTF) obligations, including customer due diligence and Know Your Customer (KYC) verification;
- Responsible gambling obligations, including processing self-exclusion requests and age verification;
- Tax and accounting obligations, including record-keeping for financial transactions;
- Reporting obligations to regulatory authorities, including gaming regulators and financial intelligence units;
- Compliance with court orders, subpoenas, or other mandatory legal processes.
5.4 Article 6(1)(d) — Protection of Vital Interests
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, such as in the event of a medical emergency on our premises.
5.5 Article 6(1)(e) — Public Task
Where applicable, we may process personal data in the exercise of official authority or in the public interest, particularly in the context of compliance with gaming regulatory requirements imposed by public authorities.
5.6 Article 6(1)(f) — Legitimate Interests
We process your personal data on the basis of our legitimate interests or those of a third party, provided that such interests are not overridden by your interests or fundamental rights and freedoms. We rely on this legal basis for the following purposes:
- Fraud detection, prevention, and investigation;
- Improving and optimising the functionality and performance of our Website;
- Conducting internal analytics to understand how guests use our services;
- Administering and protecting our business and IT infrastructure;
- Sending direct marketing to existing customers about similar products and services (subject to your right to object);
- Monitoring CCTV footage for the security of our premises, guests, staff, and assets;
- Managing and resolving disputes, complaints, and legal claims.
We conduct a legitimate interests assessment (LIA) for each processing activity relying on this basis and document our findings. You may request further information about these assessments by contacting our DPO.
6. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
6.1 Service Delivery and Guest Experience
- Processing and managing hotel reservations, room assignments, and guest check-in and check-out procedures;
- Providing and personalising accommodation, dining, entertainment, spa, and casino services;
- Managing your online account, loyalty programme membership, and reward points;
- Responding to your enquiries, requests, and feedback;
- Facilitating event bookings, conference arrangements, and group reservations.
6.2 Payment Processing and Financial Administration
- Processing payments for services rendered and issuing receipts, invoices, and tax documents;
- Detecting and preventing fraudulent transactions and chargebacks;
- Maintaining financial records in compliance with applicable accounting and tax laws.
6.3 Legal and Regulatory Compliance
- Conducting identity verification and KYC checks in accordance with AML and CTF legislation;
- Implementing responsible gambling measures, including age verification, self-exclusion processing, and problem gambling monitoring;
- Complying with gaming regulatory requirements and reporting obligations;
- Responding to requests from courts, regulators, law enforcement, and other competent authorities.
6.4 Security and Safety
- Operating CCTV surveillance systems throughout our premises for the safety and security of guests, staff, and property;
- Monitoring access control systems and preventing unauthorised access;
- Investigating incidents, accidents, and security breaches;
- Protecting the integrity of our gaming operations and preventing cheating or collusion.
6.5 Marketing and Communications
- Sending you promotional offers, newsletters, and information about our services, events, and loyalty programme benefits, where you have consented or where we have a legitimate interest to do so;
- Conducting surveys, feedback programmes, and market research to improve our services;
- Personalising marketing communications based on your preferences and stay history.
6.6 Website and Technology Management
- Maintaining and improving our Website's functionality, performance, and user experience;
- Analysing traffic patterns, user behaviour, and engagement metrics through web analytics tools;
- Administering our IT systems and ensuring network security.
6.7 Business Operations and Development
- Managing our relationships with suppliers, partners, and contractors;
- Conducting business planning, internal audits, and financial reporting;
- Exercising and defending legal rights and claims.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share your personal data only in the circumstances described below, and only to the extent necessary for the relevant purpose.
7.1 Service Providers and Data Processors
We engage trusted third-party service providers to assist us in operating our business and delivering our services. These providers act as data processors on our behalf and are contractually bound to process your data only on our instructions and in compliance with applicable data protection law. They include:
- Payment Processors: To securely process credit and debit card payments;
- IT and Cloud Service Providers: To host our Website, manage our databases, and provide cybersecurity services;
- Property Management System (PMS) Providers: To manage hotel reservations, room assignments, and guest profiles;
- Casino Management System (CMS) Providers: To administer gaming accounts and transaction records;
- Email and Marketing Platforms: To send marketing communications and manage subscriber lists;
- Analytics Providers: To provide website analytics and reporting services;
- Loyalty Programme Administrators: To manage reward points, redemptions, and member communications;
- CCTV and Security System Operators;
- Legal, Accounting, and Auditing Firms: To provide professional advisory services.
7.2 Online Travel Agencies and Booking Platforms
Where you make a reservation through a third-party online travel agency (OTA) or booking platform, we may receive your personal data from that platform and share confirmation and operational data with them as necessary to fulfil your booking.
7.3 Regulatory Authorities and Law Enforcement
We may disclose your personal data to regulatory bodies, law enforcement agencies, courts, or other public authorities where we are legally required to do so, including:
- Gaming and liquor regulatory authorities in Alberta and Canada;
- The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) and other financial intelligence units;
- Canada Revenue Agency (CRA) and other tax authorities;
- Law enforcement agencies in connection with criminal investigations;
- Courts and tribunals in connection with legal proceedings.
7.4 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding involving our Company, your personal data may be disclosed or transferred to the relevant parties (e.g., prospective purchaser, administrators, or successors in interest) as part of that transaction. We will notify you of any such transfer and any changes to this Privacy Policy as required by law.
7.5 Professional Advisers
We may share your personal data with our lawyers, auditors, accountants, and insurers where necessary in connection with the provision of their professional services to us, subject to applicable professional confidentiality obligations.
7.6 International Transfers
Where we transfer your personal data to recipients located outside the European Economic Area (EEA) or outside Canada, we ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Transfers to countries recognised as providing an adequate level of data protection by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Compliance with PIPEDA's requirements for cross-border data transfers.
You may request further information about the safeguards we have in place for international transfers by contacting our DPO.
9. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The retention periods we apply are determined by the following criteria:
- The nature and sensitivity of the personal data;
- The purposes for which we process the data and whether those purposes can be achieved in a shorter time;
- Applicable statutory and regulatory retention obligations;
- The potential risk of harm from unauthorised use or disclosure of the data;
- The need to retain data for the establishment, exercise, or defence of legal claims.
9.1 Indicative Retention Periods
| Category of Data | Retention Period | Basis |
|---|---|---|
| Guest reservation and stay records | 7 years after the date of stay | Legal obligation / Legitimate interests |
| Financial and payment records | 7 years from the date of transaction | Legal obligation (tax and accounting law) |
| Casino gaming records and AML/KYC data | 5–10 years as required by applicable AML legislation | Legal obligation (FINTRAC / PCMLTFA) |
| Online account and loyalty programme data | Duration of membership plus 3 years after account closure | Contract / Legitimate interests |
| Marketing consent records | Until consent is withdrawn, plus 3 years thereafter | Consent / Legal obligation |
| CCTV footage | Up to 31 days, unless retained for incident investigation | Legitimate interests / Legal obligation |
| Customer correspondence and complaints | 3 years from date of resolution | Legitimate interests |
| Website usage and analytics data | Up to 26 months | Legitimate interests / Consent |
| Cookie consent records | 2 years from date of consent | Legal obligation |
At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data retention and disposal procedures.
10. Your Rights as a Data Subject
Subject to applicable law, you have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month of receipt, unless the request is particularly complex or numerous, in which case we may extend this period by a further two months. We will notify you of any such extension.
10.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process personal data about you, and if so, to receive a copy of that data along with information about the purposes of processing, the categories of data processed, recipients, retention periods, and your other rights.
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete data completed, taking into account the purposes of the processing.
10.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, or where you object to processing and there are no overriding legitimate grounds. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in the following circumstances:
- Where you contest the accuracy of the data, for a period enabling us to verify its accuracy;
- Where the processing is unlawful but you oppose erasure and request restriction instead;
- Where we no longer need the data but you require it for the establishment, exercise, or defence of legal claims;
- Where you have objected to processing pursuant to Article 21, pending verification of whether our legitimate grounds override yours.
10.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.
10.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data:
- Where processing is based on legitimate interests (Article 6(1)(f)), on grounds relating to your particular situation. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims;
- Where personal data is processed for direct marketing purposes, including profiling related to direct marketing. You have an absolute right to object to such processing at any time, and we will cease processing your data for that purpose without requiring you to provide grounds.
10.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we carry out such automated decision-making, we will inform you and provide you with the right to obtain human intervention, to express your point of view, and to contest the decision.
10.8 Right to Withdraw Consent
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. To withdraw your consent, please contact us using the details provided in Section 13 below or use the unsubscribe link contained in our marketing communications.
10.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority. Depending on your jurisdiction, this may include:
- For individuals in the EEA: The supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement. A full list of EEA supervisory authorities is available at https://edpb.europa.eu ;
- For individuals in Canada: The Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca , or the Office of the Information and Privacy Commissioner of Alberta (OIPC) at www.oipc.ab.ca .
We encourage you to contact us first before lodging a complaint so that we have the opportunity to address your concerns directly.
10.10 How to Exercise Your Rights
To exercise any of your rights listed above, please submit a written request to our DPO using the contact details set out in Section 13 of this Privacy Policy. In order to process your request, we may ask you to verify your identity by providing appropriate identification. This is to ensure we do not disclose your personal data to any unauthorised person.
We will not charge a fee for handling your request unless it is manifestly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
11. Children's Privacy
Our casino services are restricted to individuals aged 18 years or older, as required by applicable gaming laws and regulations. Our Website and services are not directed at children under the age of 16 years, and we do not knowingly collect personal data from children under this age.
If we become aware that we have inadvertently collected personal data from a child under the applicable minimum age, we will take prompt steps to delete such data from our records. If you believe we may have collected personal data from a child, please contact us immediately at info@qalexagrandlodge.com .
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:
- Encryption of personal data in transit using Transport Layer Security (TLS) protocols;
- Encryption of personal data at rest where appropriate;
- Access controls and role-based permissions restricting data access to authorised personnel only;
- Regular security assessments, vulnerability scanning, and penetration testing;
- Staff training on data protection and information security;
- Incident response and data breach notification procedures;
- Physical security controls at our premises, including access control systems and CCTV surveillance;
- PCI-DSS compliant payment processing infrastructure.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and in accordance with our obligations under Article 34 of the GDPR and applicable Canadian privacy legislation.
Please note that the transmission of data over the internet is never completely secure. While we take every reasonable step to protect your personal data, we cannot guarantee the absolute security of data transmitted to our Website.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our processing of your personal data, please contact us using the following details:
| Data Controller | |
|---|---|
| Attention | The Data Protection Officer |
| Postal Address | |
| Email Address | info@qalexagrandlodge.com |
| Website | www.qalexagrandlodge.com |
We aim to acknowledge all privacy-related enquiries within 5 business days and to resolve requests within the statutory timeframes prescribed under applicable data protection law.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or regulatory guidance. When we make material changes to this Privacy Policy, we will notify you by posting the updated Policy on our Website and, where appropriate, by sending you a notification via email or other means.
The date of the most recent revision will always be displayed at the top of this Privacy Policy. We encourage you to review this Policy periodically to stay informed about how we are protecting your personal data.
Your continued use of our Website or services following the posting of changes constitutes your acknowledgment of the updated Privacy Policy. Where we are required by law to obtain your renewed consent, we will do so.