Privacy Policy

Last updated: June 2025

This Privacy Policy describes how ("we", "us", "our") collects, uses, stores, and protects your personal data when you visit or interact with our website kiryrahotelretreat.com (the "Website"), make reservations, use our hotel and casino services, or otherwise engage with us. We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Canadian federal and provincial privacy legislation, including the Personal Information Protection and Electronic Documents Act ("PIPEDA") and the British Columbia Personal Information Protection Act ("PIPA"), and all other applicable data protection laws.

Please read this Privacy Policy carefully. By using the Website or our services, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please discontinue use of the Website and our services immediately.

1. Data Controller

The entity responsible for your personal data (the "Data Controller") is:

Legal Entity Name
Trading Name Kiryra Hotel Retreat
Registration Country Canada
Registration Number 1478329-6
VAT / Business Number 829471653 RT0001
Registered Address
Website kiryrahotelretreat.com
Privacy Contact Email info@kiryrahotelretreat.com

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and ensuring ongoing compliance with applicable data protection legislation. If you have any questions about this Privacy Policy, your personal data, or wish to exercise any of your rights, please contact our DPO:

Title The Data Protection Officer
Organisation
Address
Email info@kiryrahotelretreat.com

3. Personal Data We Collect

We collect personal data about you from a variety of sources, including directly from you, automatically through your use of our Website, and from third parties. The categories of personal data we collect include, but are not limited to, the following:

3.1 Identity and Contact Data

  • Full name (first name, last name)
  • Date of birth and age verification information
  • Gender
  • Nationality and country of residence
  • Passport, national identity card, or other government-issued identification details (required for hotel check-in and casino regulatory compliance)
  • Email address
  • Telephone and mobile number
  • Postal address (home, billing, or business)

3.2 Reservation and Booking Data

  • Check-in and check-out dates
  • Room type and preferences
  • Number of guests
  • Special requests, accessibility requirements, and dietary preferences
  • Booking reference numbers and confirmation details
  • Loyalty or rewards programme membership details

3.3 Payment and Financial Data

  • Credit, debit, or prepaid card details (card number, expiry date, CVV — processed securely via PCI DSS-compliant payment processors)
  • Bank account information (where applicable for refunds or pre-authorisations)
  • Billing address
  • Transaction history and receipts
  • Currency and payment method preferences

3.4 Casino and Gaming Data

  • Player registration and account information
  • Age and identity verification documentation
  • Gaming activity, session history, and transaction records
  • Betting patterns, wagering history, and game preferences
  • Responsible gambling assessments, self-exclusion requests, and deposit limit settings
  • Anti-money laundering (AML) and know-your-customer (KYC) documentation and screening results
  • Source of funds and wealth declarations where required by regulation

3.5 Technical and Usage Data

  • IP address and approximate geolocation data
  • Browser type, version, and language settings
  • Operating system and device information
  • Referring website URLs
  • Pages visited, links clicked, and time spent on the Website
  • Session identifiers and cookie data (see our Cookie Policy for further details)
  • Log files and access logs

3.6 Profile and Preference Data

  • Account username and password (stored in encrypted form)
  • Interests, preferences, and feedback provided voluntarily
  • Survey responses and competition entries
  • Communication preferences (e.g., opt-in or opt-out of marketing)
  • Complaints and correspondence records

3.7 CCTV and Physical Security Data

  • CCTV footage and images recorded on our premises for security, fraud prevention, and regulatory compliance purposes
  • Access control records (entry and exit logs for restricted areas)

3.8 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under GDPR Article 9. This may include:

  • Health-related information (e.g., accessibility needs, dietary requirements related to medical conditions, or responsible gambling health assessments)
  • Biometric data (where applicable for identity verification in compliance with regulatory obligations)

We will only process special categories of personal data where we have a valid legal basis to do so, such as your explicit consent, or where processing is necessary to protect your vital interests or for the exercise of legal claims. Where we rely on explicit consent, you may withdraw it at any time without prejudice to processing already carried out.

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

5.1 Hotel Services

  • Processing and confirming hotel reservations, modifications, and cancellations
  • Facilitating check-in and check-out procedures
  • Managing in-room services, housekeeping preferences, and special requests
  • Processing payments, deposits, and refunds
  • Sending booking confirmation emails, pre-arrival information, and post-stay satisfaction surveys
  • Administering loyalty rewards and recognising returning guests

5.2 Casino and Gaming Services

  • Creating and managing casino player accounts
  • Verifying your identity and age in compliance with applicable gaming regulations
  • Processing gaming transactions, deposits, and withdrawals
  • Monitoring gaming activity for regulatory compliance and responsible gambling purposes
  • Conducting AML and KYC screening in accordance with legal obligations
  • Administering self-exclusion programmes, cooling-off periods, and deposit limits
  • Providing customer support related to gaming services

5.3 Customer Communication

  • Responding to your enquiries, complaints, and feedback
  • Providing customer support via telephone, email, and live chat
  • Sending transactional and service-related communications
  • Sending marketing and promotional communications (where you have consented or where permitted under legitimate interests)

5.4 Website Operation and Improvement

  • Operating, maintaining, and improving the functionality of the Website
  • Analysing Website traffic and user behaviour to enhance user experience
  • Diagnosing technical problems and resolving Website errors
  • Personalising content and recommendations based on your preferences and browsing history
  • Testing new features and Website updates

5.5 Security and Fraud Prevention

  • Monitoring and detecting fraudulent, unauthorised, or illegal activities
  • Investigating suspected fraud, misuse, or breaches of our terms and conditions
  • Operating CCTV surveillance systems on our premises
  • Maintaining the physical and cyber security of our facilities and systems

5.6 Legal and Regulatory Compliance

  • Meeting obligations under gambling, financial services, and hospitality regulations
  • Maintaining required records and audit trails
  • Responding to lawful requests from regulatory authorities, law enforcement, and courts
  • Defending or pursuing legal claims

5.7 Business Operations and Analytics

  • Internal reporting and business performance analysis
  • Staff training and quality assurance
  • Strategic planning and service development
  • Market research and customer satisfaction measurement

6. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own commercial purposes. We may, however, share your personal data with the following categories of recipients in the circumstances described below:

6.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and only in accordance with our written instructions. These include:

  • Payment processors and banking partners (for secure transaction processing)
  • Cloud hosting, IT infrastructure, and cybersecurity providers
  • Email marketing and customer relationship management (CRM) platform providers
  • Analytics and business intelligence providers
  • Identity verification and KYC service providers
  • AML screening and compliance software providers
  • Customer support and live chat software providers
  • Online booking and reservation platform providers
  • Casino gaming software and platform providers
  • CCTV and physical security technology providers

All service providers are subject to appropriate data processing agreements and are required to implement adequate technical and organisational security measures to protect your personal data.

6.2 Regulatory and Law Enforcement Authorities

We may share your personal data with competent regulatory bodies, law enforcement agencies, courts, or other public authorities where we are legally required or permitted to do so. This includes:

  • Gaming and casino regulatory authorities in the relevant jurisdiction
  • Financial intelligence units and tax authorities
  • Police and law enforcement agencies investigating criminal offences
  • Courts and tribunals in connection with legal proceedings

6.3 Professional Advisors

We may share your personal data with our legal advisors, auditors, accountants, and insurance providers where necessary for the provision of professional services to us, subject to duties of confidentiality.

6.4 Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or other similar transaction involving , your personal data may be transferred to the relevant successor entity. We will notify you of any such transfer that materially affects your privacy rights.

6.5 Third-Party Partners (With Your Consent)

Where you have given your explicit consent, we may share your data with selected third-party partners (such as travel agencies, entertainment partners, or affiliate hospitality providers) for their own marketing purposes. You may withdraw this consent at any time.

6.6 International Transfers

Our primary operations are based in Canada. However, some of our service providers and processors may be located outside Canada and the European Economic Area (EEA). Where we transfer personal data internationally, we ensure adequate safeguards are in place, which may include:

  • Transfers to countries recognised by the European Commission as providing an adequate level of data protection
  • Use of Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs) where applicable
  • Other lawful transfer mechanisms as required under applicable data protection legislation

You may request a copy of the relevant safeguards by contacting us at info@kiryrahotelretreat.com .

7. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria we use to determine appropriate retention periods include:

  • The nature and sensitivity of the personal data
  • The purposes for which we collected the data and whether those purposes have been fulfilled
  • Applicable legal and regulatory minimum retention requirements
  • Whether there are ongoing or reasonably foreseeable legal disputes or claims
  • Any instructions from supervisory or regulatory authorities

The following indicative retention periods apply to the main categories of data we hold:

Category of Data Indicative Retention Period Basis
Hotel booking and reservation records 7 years from date of stay Legal obligation (tax and accounting records); contract
Guest identity and check-in records 5 years from date of stay Legal obligation (hotel registration regulations)
Payment and financial transaction records 7 years from date of transaction Legal obligation (financial and tax regulations)
Casino player account and gaming records 5–7 years from account closure or last activity Legal obligation (gambling regulation, AML legislation)
AML/KYC documentation 5 years from end of business relationship Legal obligation (anti-money laundering legislation)
Responsible gambling records 5 years from date of assessment or exclusion Legal obligation; vital interests
Marketing communications and consent records Until consent is withdrawn, plus 3 years Consent; legitimate interests (proof of consent)
Website analytics and log data Up to 26 months Legitimate interests
CCTV recordings Up to 31 days, unless required for an investigation Legitimate interests; legal obligation
Customer correspondence and complaints 3 years from resolution Legitimate interests; legal claims

Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our internal data retention and disposal procedures. Where data is anonymised, it may be retained indefinitely for statistical and analytical purposes as it no longer constitutes personal data.

8. Cookies and Similar Tracking Technologies

Our Website uses cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance your browsing experience, analyse Website usage, and deliver relevant content and advertising.

The types of cookies we use include:

  • Strictly Necessary Cookies: Essential for the Website to function properly. These cannot be disabled as they are required for core functionality such as session management, security, and load balancing.
  • Performance and Analytics Cookies: Help us understand how visitors interact with the Website by collecting aggregated, anonymous information. We use this data to improve Website performance and user experience.
  • Functional Cookies: Allow the Website to remember your preferences and settings (such as language, currency, and login status) to provide a more personalised experience.
  • Targeting and Advertising Cookies: Used to deliver advertisements relevant to your interests on our Website and third-party platforms. These are placed by us and our advertising partners.

When you first visit the Website, you will be presented with a cookie consent banner allowing you to accept or decline non-essential cookies. You can manage or withdraw your cookie preferences at any time through our Cookie Settings tool or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of the Website.

For further details about the specific cookies we use, their purposes, and how to manage them, please refer to our Cookie Policy available on our Website.

9. Your Rights Under GDPR and Applicable Privacy Law

Subject to applicable law and certain legal exceptions, you have the following rights in relation to your personal data:

9.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you, together with information about how we use it, who we share it with, how long we retain it, and the rights available to you. This is commonly known as a "Subject Access Request" (SAR).

9.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete personal data, without undue delay.

9.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where you have withdrawn consent, or where the data has been unlawfully processed. This right is not absolute and may be subject to legal retention obligations.

9.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or have objected to processing, pending verification by us.

9.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.

9.6 Right to Object (Article 21 GDPR)

You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where we rely on legitimate interests as our legal basis. You also have an unconditional right to object to the processing of your personal data for direct marketing purposes, including profiling to the extent that it relates to such direct marketing.

9.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Where we engage in such processing, we will inform you and provide you with the opportunity to request human review, express your point of view, and contest the decision.

9.8 Right to Withdraw Consent

Where we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

9.9 Right to Lodge a Complaint

You have the right to lodge a complaint with a competent supervisory authority if you believe that our processing of your personal data infringes applicable data protection law. In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada (OPC):

  • Website: www.priv.gc.ca
  • Telephone: 1-800-282-1376

In British Columbia, complaints regarding PIPA may also be directed to the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC):

  • Website: www.oipc.bc.ca
  • Telephone: 250-387-5629

Where GDPR applies (for example, in respect of data subjects located in the European Economic Area), complaints may be directed to the relevant EU member state data protection supervisory authority.

9.10 How to Exercise Your Rights

To exercise any of your rights listed above, please submit a written request to our Data Protection Officer using the contact details provided in Section 2 of this Privacy Policy. We will respond to all legitimate requests within one calendar month of receipt. Where requests are complex or numerous, we may extend this period by a further two months, in which case we will notify you accordingly.

We may need to verify your identity before processing your request. We will not charge a fee for responding to your request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to respond.

10. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include, but are not limited to:

  • SSL/TLS encryption for data transmitted via the Website
  • Encryption of sensitive data at rest (including payment card data in compliance with PCI DSS standards)
  • Access controls, role-based permissions, and multi-factor authentication for internal systems
  • Regular security audits, vulnerability assessments, and penetration testing
  • Staff training on data protection and information security best practices
  • Incident response and data breach notification procedures
  • Physical security measures at our premises, including access controls and CCTV

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, will inform you directly.

While we employ stringent security measures, no method of data transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of your personal data and encourage you to take steps to protect your own information, such as keeping your account password confidential and logging out of your account when using shared devices.

11. Children and Minors

Our hotel and casino services are strictly intended for adults aged 19 years or older (or the legal gambling age applicable in the relevant jurisdiction). We do not knowingly collect personal data from individuals under the age of 19. Our Website is not directed at, nor intended for use by, minors.

If you believe that we have inadvertently collected personal data from a minor, please contact us immediately at info@kiryrahotelretreat.com and we will take prompt steps to delete such data from our records.

13. Automated Decision-Making and Profiling

We may use automated processing and profiling technologies in connection with certain activities, including fraud detection, responsible gambling monitoring, and personalised marketing. Where any such automated processing produces decisions that have legal or similarly significant effects on you, we will inform you of the existence of such processing, provide you with meaningful information about the logic involved, and ensure that you have the right to request human review of the decision, to express your point of view, and to contest the outcome.

14. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes, we will notify you by updating the "Last updated" date at the top of this policy and, where appropriate, by sending you a direct notification via email or a prominent notice on the Website.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of the Website or our services following the posting of changes constitutes your acknowledgement of the updated policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or the exercise of your rights, please do not hesitate to contact us:

Data Controller
Contact Person The Data Protection Officer
Postal Address
Email Address info@kiryrahotelretreat.com
Website kiryrahotelretreat.com

We are committed to addressing your concerns promptly and transparently. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 9.9 of this Privacy Policy.