Privacy Policy

Last updated: June 2025

This Privacy Policy describes how (hereinafter referred to as "we", "us", "our", or the "Company") collects, uses, discloses, and protects the personal data of individuals ("you", "your", "data subject") who interact with our website located at www.qalexagrandlodge.com (the "Website"), as well as in the context of our hotel and casino services offered at Qalexagrand Lodge in Edmonton, Canada.

We are committed to protecting your privacy and processing your personal data in a transparent, lawful, and secure manner, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta's Personal Information Protection Act (PIPA), and all other applicable data protection legislation.

Please read this Privacy Policy carefully before using our Website or engaging with our services. By using our Website, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The entity responsible for the processing of your personal data is:

Legal Entity Name
Trading Name Qalexagrand Lodge
Registration Country Canada
Company Registration Number BC1369427
VAT / Business Number 849271638RT0001
Registered Address
Website www.qalexagrandlodge.com
Contact Email info@qalexagrandlodge.com

As a data controller, we determine the purposes and means of processing your personal data. We are accountable for all personal data we collect, use, retain, and disclose in connection with our activities.

2. Data Protection Officer (DPO)

We have designated a Data Protection Officer responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws. If you have any questions, concerns, or requests regarding the processing of your personal data, you may contact our DPO at:

DPO Title The Data Protection Officer
Organisation
Address
Email info@qalexagrandlodge.com

3. Scope and Applicability

This Privacy Policy applies to:

  • All visitors and users of our Website ( www.qalexagrandlodge.com );
  • Guests who book accommodation, dining, or event services through our Website or third-party platforms;
  • Individuals who participate in our casino activities and loyalty programmes;
  • Individuals who contact us via email, telephone, online forms, or in person;
  • Business partners, suppliers, and other third parties whose representatives interact with us;
  • Any person whose personal data we process in connection with our business operations.

This Policy does not apply to third-party websites linked from our Website. We are not responsible for the privacy practices of external websites and encourage you to review their respective privacy policies.

4. Personal Data We Collect

We collect various categories of personal data depending on the nature of your interaction with us. We only collect personal data that is adequate, relevant, and limited to what is necessary for the specified purposes.

4.1 Data You Provide Directly to Us

  • Identity and Contact Data: Full name, date of birth, nationality, gender, postal address, email address, telephone number, and government-issued identification details (e.g., passport or driver's licence number) where required by law;
  • Reservation and Booking Data: Arrival and departure dates, room type preferences, number of guests, special requests, and service preferences;
  • Payment Data: Credit or debit card details, billing address, and transaction history (note: full card data is processed securely by our PCI-DSS compliant payment processors and is not stored on our systems);
  • Account and Profile Data: Login credentials, loyalty programme membership details, account settings, and communication preferences;
  • Casino and Gaming Data: Player registration details, gaming activity records, winnings, losses, wager amounts, responsible gaming self-exclusion requests, and identity verification documents required under anti-money laundering regulations;
  • Communications Data: Messages, enquiries, complaints, feedback, and survey responses submitted to us;
  • Marketing Preferences: Consents and opt-in or opt-out preferences for direct marketing communications.

4.2 Data Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device identifiers, time zone settings, and browser plug-in types;
  • Usage Data: Pages visited, links clicked, referring URLs, session duration, and navigation paths within our Website;
  • Cookie and Tracking Data: Information collected through cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy.

4.3 Data Received from Third Parties

  • Booking Platform Data: Reservation data transmitted by online travel agencies (OTAs) and booking platforms through which you made a reservation;
  • Social Media Data: Public profile information when you interact with our social media pages or log in via a social media account;
  • Fraud Prevention and Credit Reference Agencies: Data to verify your identity and protect against fraud;
  • Regulatory and Law Enforcement Bodies: Data shared pursuant to legal obligations, particularly in relation to anti-money laundering (AML) compliance.

4.4 Special Categories of Personal Data

We may, in limited circumstances, process special categories of personal data as defined under Article 9 of the GDPR, including:

  • Health and Disability Information: Where you inform us of accessibility requirements or dietary needs for medical reasons, in order to provide appropriate accommodations;
  • Data relating to criminal convictions or offences: As required for regulatory compliance under gaming and anti-money laundering legislation.

We process special category data only where a specific legal basis under Article 9(2) GDPR applies, including your explicit consent, the performance of obligations in the field of employment law, or reasons of substantial public interest.

6. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

6.1 Service Delivery and Guest Experience

  • Processing and managing hotel reservations, room assignments, and guest check-in and check-out procedures;
  • Providing and personalising accommodation, dining, entertainment, spa, and casino services;
  • Managing your online account, loyalty programme membership, and reward points;
  • Responding to your enquiries, requests, and feedback;
  • Facilitating event bookings, conference arrangements, and group reservations.

6.2 Payment Processing and Financial Administration

  • Processing payments for services rendered and issuing receipts, invoices, and tax documents;
  • Detecting and preventing fraudulent transactions and chargebacks;
  • Maintaining financial records in compliance with applicable accounting and tax laws.

6.3 Legal and Regulatory Compliance

  • Conducting identity verification and KYC checks in accordance with AML and CTF legislation;
  • Implementing responsible gambling measures, including age verification, self-exclusion processing, and problem gambling monitoring;
  • Complying with gaming regulatory requirements and reporting obligations;
  • Responding to requests from courts, regulators, law enforcement, and other competent authorities.

6.4 Security and Safety

  • Operating CCTV surveillance systems throughout our premises for the safety and security of guests, staff, and property;
  • Monitoring access control systems and preventing unauthorised access;
  • Investigating incidents, accidents, and security breaches;
  • Protecting the integrity of our gaming operations and preventing cheating or collusion.

6.5 Marketing and Communications

  • Sending you promotional offers, newsletters, and information about our services, events, and loyalty programme benefits, where you have consented or where we have a legitimate interest to do so;
  • Conducting surveys, feedback programmes, and market research to improve our services;
  • Personalising marketing communications based on your preferences and stay history.

6.6 Website and Technology Management

  • Maintaining and improving our Website's functionality, performance, and user experience;
  • Analysing traffic patterns, user behaviour, and engagement metrics through web analytics tools;
  • Administering our IT systems and ensuring network security.

6.7 Business Operations and Development

  • Managing our relationships with suppliers, partners, and contractors;
  • Conducting business planning, internal audits, and financial reporting;
  • Exercising and defending legal rights and claims.

7. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share your personal data only in the circumstances described below, and only to the extent necessary for the relevant purpose.

7.1 Service Providers and Data Processors

We engage trusted third-party service providers to assist us in operating our business and delivering our services. These providers act as data processors on our behalf and are contractually bound to process your data only on our instructions and in compliance with applicable data protection law. They include:

  • Payment Processors: To securely process credit and debit card payments;
  • IT and Cloud Service Providers: To host our Website, manage our databases, and provide cybersecurity services;
  • Property Management System (PMS) Providers: To manage hotel reservations, room assignments, and guest profiles;
  • Casino Management System (CMS) Providers: To administer gaming accounts and transaction records;
  • Email and Marketing Platforms: To send marketing communications and manage subscriber lists;
  • Analytics Providers: To provide website analytics and reporting services;
  • Loyalty Programme Administrators: To manage reward points, redemptions, and member communications;
  • CCTV and Security System Operators;
  • Legal, Accounting, and Auditing Firms: To provide professional advisory services.

7.2 Online Travel Agencies and Booking Platforms

Where you make a reservation through a third-party online travel agency (OTA) or booking platform, we may receive your personal data from that platform and share confirmation and operational data with them as necessary to fulfil your booking.

7.3 Regulatory Authorities and Law Enforcement

We may disclose your personal data to regulatory bodies, law enforcement agencies, courts, or other public authorities where we are legally required to do so, including:

  • Gaming and liquor regulatory authorities in Alberta and Canada;
  • The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) and other financial intelligence units;
  • Canada Revenue Agency (CRA) and other tax authorities;
  • Law enforcement agencies in connection with criminal investigations;
  • Courts and tribunals in connection with legal proceedings.

7.4 Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding involving our Company, your personal data may be disclosed or transferred to the relevant parties (e.g., prospective purchaser, administrators, or successors in interest) as part of that transaction. We will notify you of any such transfer and any changes to this Privacy Policy as required by law.

7.5 Professional Advisers

We may share your personal data with our lawyers, auditors, accountants, and insurers where necessary in connection with the provision of their professional services to us, subject to applicable professional confidentiality obligations.

7.6 International Transfers

Where we transfer your personal data to recipients located outside the European Economic Area (EEA) or outside Canada, we ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Transfers to countries recognised as providing an adequate level of data protection by the European Commission;
  • Binding Corporate Rules (BCRs) where applicable;
  • Compliance with PIPEDA's requirements for cross-border data transfers.

You may request further information about the safeguards we have in place for international transfers by contacting our DPO.

8. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance your browsing experience, analyse Website usage, and deliver relevant content and advertising.

8.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the Website to function correctly. These cookies do not require your consent and cannot be disabled through our cookie banner;
  • Performance and Analytics Cookies: Help us understand how visitors interact with our Website by collecting anonymous statistical data (e.g., Google Analytics);
  • Functionality Cookies: Remember your preferences (such as language settings) to provide a more personalised experience;
  • Marketing and Targeting Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns.

When you first visit our Website, you will be presented with a cookie consent banner enabling you to accept or manage your cookie preferences. You can withdraw or change your consent at any time through the cookie settings link available in our Website footer.

You may also control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our Website.

9. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The retention periods we apply are determined by the following criteria:

  • The nature and sensitivity of the personal data;
  • The purposes for which we process the data and whether those purposes can be achieved in a shorter time;
  • Applicable statutory and regulatory retention obligations;
  • The potential risk of harm from unauthorised use or disclosure of the data;
  • The need to retain data for the establishment, exercise, or defence of legal claims.

9.1 Indicative Retention Periods

Category of Data Retention Period Basis
Guest reservation and stay records 7 years after the date of stay Legal obligation / Legitimate interests
Financial and payment records 7 years from the date of transaction Legal obligation (tax and accounting law)
Casino gaming records and AML/KYC data 5–10 years as required by applicable AML legislation Legal obligation (FINTRAC / PCMLTFA)
Online account and loyalty programme data Duration of membership plus 3 years after account closure Contract / Legitimate interests
Marketing consent records Until consent is withdrawn, plus 3 years thereafter Consent / Legal obligation
CCTV footage Up to 31 days, unless retained for incident investigation Legitimate interests / Legal obligation
Customer correspondence and complaints 3 years from date of resolution Legitimate interests
Website usage and analytics data Up to 26 months Legitimate interests / Consent
Cookie consent records 2 years from date of consent Legal obligation

At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data retention and disposal procedures.

10. Your Rights as a Data Subject

Subject to applicable law, you have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month of receipt, unless the request is particularly complex or numerous, in which case we may extend this period by a further two months. We will notify you of any such extension.

10.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether we process personal data about you, and if so, to receive a copy of that data along with information about the purposes of processing, the categories of data processed, recipients, retention periods, and your other rights.

10.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete data completed, taking into account the purposes of the processing.

10.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal basis applies, or where you object to processing and there are no overriding legitimate grounds. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

10.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in the following circumstances:

  • Where you contest the accuracy of the data, for a period enabling us to verify its accuracy;
  • Where the processing is unlawful but you oppose erasure and request restriction instead;
  • Where we no longer need the data but you require it for the establishment, exercise, or defence of legal claims;
  • Where you have objected to processing pursuant to Article 21, pending verification of whether our legitimate grounds override yours.

10.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.

10.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data:

  • Where processing is based on legitimate interests (Article 6(1)(f)), on grounds relating to your particular situation. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims;
  • Where personal data is processed for direct marketing purposes, including profiling related to direct marketing. You have an absolute right to object to such processing at any time, and we will cease processing your data for that purpose without requiring you to provide grounds.

10.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we carry out such automated decision-making, we will inform you and provide you with the right to obtain human intervention, to express your point of view, and to contest the decision.

10.8 Right to Withdraw Consent

Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. To withdraw your consent, please contact us using the details provided in Section 13 below or use the unsubscribe link contained in our marketing communications.

10.9 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority. Depending on your jurisdiction, this may include:

  • For individuals in the EEA: The supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement. A full list of EEA supervisory authorities is available at https://edpb.europa.eu ;
  • For individuals in Canada: The Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca , or the Office of the Information and Privacy Commissioner of Alberta (OIPC) at www.oipc.ab.ca .

We encourage you to contact us first before lodging a complaint so that we have the opportunity to address your concerns directly.

10.10 How to Exercise Your Rights

To exercise any of your rights listed above, please submit a written request to our DPO using the contact details set out in Section 13 of this Privacy Policy. In order to process your request, we may ask you to verify your identity by providing appropriate identification. This is to ensure we do not disclose your personal data to any unauthorised person.

We will not charge a fee for handling your request unless it is manifestly unfounded, repetitive, or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

11. Children's Privacy

Our casino services are restricted to individuals aged 18 years or older, as required by applicable gaming laws and regulations. Our Website and services are not directed at children under the age of 16 years, and we do not knowingly collect personal data from children under this age.

If we become aware that we have inadvertently collected personal data from a child under the applicable minimum age, we will take prompt steps to delete such data from our records. If you believe we may have collected personal data from a child, please contact us immediately at info@qalexagrandlodge.com .

12. Data Security

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:

  • Encryption of personal data in transit using Transport Layer Security (TLS) protocols;
  • Encryption of personal data at rest where appropriate;
  • Access controls and role-based permissions restricting data access to authorised personnel only;
  • Regular security assessments, vulnerability scanning, and penetration testing;
  • Staff training on data protection and information security;
  • Incident response and data breach notification procedures;
  • Physical security controls at our premises, including access control systems and CCTV surveillance;
  • PCI-DSS compliant payment processing infrastructure.

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and in accordance with our obligations under Article 34 of the GDPR and applicable Canadian privacy legislation.

Please note that the transmission of data over the internet is never completely secure. While we take every reasonable step to protect your personal data, we cannot guarantee the absolute security of data transmitted to our Website.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our processing of your personal data, please contact us using the following details:

Data Controller
Attention The Data Protection Officer
Postal Address
Email Address info@qalexagrandlodge.com
Website www.qalexagrandlodge.com

We aim to acknowledge all privacy-related enquiries within 5 business days and to resolve requests within the statutory timeframes prescribed under applicable data protection law.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or regulatory guidance. When we make material changes to this Privacy Policy, we will notify you by posting the updated Policy on our Website and, where appropriate, by sending you a notification via email or other means.

The date of the most recent revision will always be displayed at the top of this Privacy Policy. We encourage you to review this Policy periodically to stay informed about how we are protecting your personal data.

Your continued use of our Website or services following the posting of changes constitutes your acknowledgment of the updated Privacy Policy. Where we are required by law to obtain your renewed consent, we will do so.