Privacy Policy
Last updated: June 2025
This Privacy Policy describes how (hereinafter referred to as "we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you visit and use our website located at savecreststudio.com (hereinafter referred to as the "Website") or when you use any services we offer, including hotel accommodation and casino-related services. This Privacy Policy is drafted in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), as well as applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act ("PIPEDA") and the Privacy Act.
We are committed to protecting your personal data and your right to privacy. Please read this Privacy Policy carefully before using our Website or services. By accessing or using our Website, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy.
1. Data Controller
The entity responsible for the collection and processing of your personal data (the "Data Controller") is:
| Legal Entity Name | |
| Registration Country | Canada |
| Legal Address | 110 Laurier Avenue West, Ottawa, ON K1P 1J1, Canada |
| Website | savecreststudio.com |
| Privacy Contact Email | privacy@savecreststudio.com |
If you have any questions about this Privacy Policy or how we handle your personal data, please do not hesitate to contact us using the contact information provided above or in Section 12 of this document.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection laws. You may contact our DPO directly regarding any matters related to the processing of your personal data or to exercise your data subject rights:
| DPO Name | The Data Protection Officer |
| Contact Email | privacy@savecreststudio.com |
| Postal Address | 110 Laurier Avenue West, Ottawa, ON K1P 1J1, Canada |
3. Personal Data We Collect
We collect various categories of personal data depending on how you interact with us. Personal data means any information that can directly or indirectly identify you as a natural person. The categories of personal data we may collect include:
3.1 Data You Provide Directly to Us
- Identity Data: Full name, date of birth, gender, government-issued identification details (e.g., passport number, driver's licence number) where required for legal compliance or age verification.
- Contact Data: Email address, telephone number, postal address, city, province/state, postal code, and country of residence.
- Reservation and Booking Data: Check-in and check-out dates, room preferences, number of guests, special accommodation requests, and booking history.
- Payment Data: Credit or debit card details, billing address, and transaction information. Note that full payment card data is processed securely by our PCI-DSS compliant payment service providers and is not stored by us directly in a readable format.
- Account Data: Username, password (stored in hashed format), account preferences, and loyalty programme information.
- Casino and Gaming Data: Player account details, gaming history, wagers placed, winnings and losses, responsible gaming preferences, self-exclusion requests, and identity verification documents required under applicable gambling regulations.
- Communications Data: Messages, inquiries, complaints, or feedback you send us through contact forms, emails, live chat, or telephone calls.
- Survey and Feedback Data: Responses to questionnaires, satisfaction surveys, or reviews you choose to submit.
3.2 Data We Collect Automatically
- Technical Data: IP address, browser type and version, operating system, device type and identifiers, time zone setting, screen resolution, and referring URL.
- Usage Data: Pages visited, links clicked, search queries entered on our Website, time spent on pages, session duration, and navigation paths.
- Cookie and Tracking Data: Information collected via cookies, web beacons, pixels, and similar tracking technologies. Please refer to our Cookie Policy for more detailed information.
- Log Data: Server logs recording your access to and use of our Website, including timestamps, error logs, and security event logs.
3.3 Data We Receive from Third Parties
- Third-Party Booking Platforms: Reservation information received from third-party booking aggregators, travel agencies, or online travel agencies (OTAs) when you make a booking through those platforms.
- Identity Verification Providers: Results of identity checks conducted by third-party Know Your Customer (KYC) and Anti-Money Laundering (AML) service providers, as required by gambling and financial legislation.
- Payment Processors: Transaction confirmation and fraud prevention signals from our payment service providers.
- Marketing and Analytics Partners: Aggregated or pseudonymised information about your online behaviour to help us understand the effectiveness of our marketing campaigns.
- Social Media Platforms: If you choose to connect a social media account or interact with our social media pages, we may receive certain profile information in accordance with the privacy settings of those platforms.
- Public Registers and Sanctions Lists: Information from publicly available registers or sanctions screening databases, where we are required to conduct such checks under applicable law.
3.4 Special Categories of Personal Data
We do not routinely seek to collect special categories of personal data (as defined under Article 9 GDPR), such as data concerning health, racial or ethnic origin, political opinions, religious beliefs, or biometric data. However, in limited circumstances, we may process such data where:
- You have provided explicit consent (e.g., you disclose a disability or dietary requirement for the purpose of obtaining adapted services);
- Processing is necessary for reasons of substantial public interest under applicable law (e.g., responsible gambling obligations);
- Processing is necessary to protect your vital interests where you are incapable of giving consent.
Where we process special category data, we will inform you at the point of collection and will only do so in accordance with the additional safeguards required by the GDPR and applicable national law.
3.5 Data Relating to Children
Our Website and casino services are strictly intended for adults aged 19 years or older (or the applicable legal age in your jurisdiction). We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete such data. If you believe a minor has provided us with personal data, please contact us immediately at privacy@savecreststudio.com.
4. Legal Basis for Processing Your Personal Data
In accordance with Article 6 of the GDPR, we rely on the following legal bases for processing your personal data. We will always ensure that at least one valid legal basis applies before processing your data:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary to enter into or perform a contract with you, or to take pre-contractual steps at your request. This includes:
- Processing hotel reservation and check-in/check-out procedures;
- Managing your casino player account and processing gaming activities;
- Processing payments for services rendered;
- Communicating with you regarding your bookings or account.
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where it is necessary to comply with a legal obligation to which we are subject. This includes:
- Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) obligations, including customer due diligence and transaction monitoring;
- Identity verification and age verification requirements under gambling legislation;
- Tax reporting and accounting obligations;
- Responding to lawful requests from regulatory authorities, law enforcement agencies, or courts;
- Implementing responsible gambling measures, including self-exclusion registers;
- Compliance with data retention obligations under applicable law.
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include:
- Preventing, detecting, and investigating fraud, cheating, and other unlawful activities;
- Ensuring the security and integrity of our Website, IT systems, and network infrastructure;
- Improving and personalising our website and services based on user behaviour analysis;
- Conducting analytics and research to better understand our customers and improve our offerings;
- Sending direct marketing communications about similar products and services to existing customers (subject to your right to opt out);
- Managing and defending legal claims;
- Operating our loyalty programme and customer retention activities.
When we rely on legitimate interests, we conduct a balancing test to ensure that our interests do not outweigh your rights and freedoms. You may request information about this balancing test by contacting us at privacy@savecreststudio.com.
4.4 Consent (Article 6(1)(a) GDPR)
Where we have obtained your explicit consent, we will process your personal data for the specific purpose(s) for which consent was given. This may include:
- Sending marketing emails, newsletters, or promotional offers where you are a new subscriber who has not previously engaged with our services;
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special categories of personal data where permitted by your explicit consent.
Where we rely on consent as a legal basis, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent, please contact us at privacy@savecreststudio.com or use the unsubscribe link provided in our marketing communications.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person. This would apply, for example, in emergency medical situations involving a guest on our premises.
4.6 Public Task (Article 6(1)(e) GDPR)
We may process personal data where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, to the extent applicable to our operations under governing law.
5. How We Use Your Personal Data
We use your personal data for the following purposes, always in accordance with the legal basis identified in Section 4:
5.1 Providing Hotel and Accommodation Services
- Processing, confirming, and managing hotel reservations;
- Facilitating check-in and check-out processes;
- Accommodating special requests and preferences;
- Managing room assignments and housekeeping services;
- Processing payments and issuing invoices and receipts;
- Handling cancellations, modifications, and refunds.
5.2 Providing Casino and Gaming Services
- Creating, maintaining, and managing your casino player account;
- Verifying your identity and age in accordance with legal requirements;
- Processing gaming transactions, bets, and payouts;
- Conducting AML and fraud screening as required by law;
- Implementing responsible gambling tools, including deposit limits, cool-off periods, and self-exclusion;
- Monitoring gaming activity for signs of problem gambling and taking appropriate action in accordance with regulatory obligations.
5.3 Customer Account Management
- Creating and maintaining your user account on our Website;
- Managing your loyalty programme membership and points balance;
- Providing customer support and responding to your inquiries and complaints;
- Sending transactional and service-related notifications (e.g., booking confirmations, account alerts).
5.4 Marketing and Promotional Activities
- Sending you promotional emails, newsletters, and special offers relating to our hotel and casino services, where you have provided consent or where we have a legitimate interest to do so;
- Personalising marketing content based on your preferences, booking history, and gaming activity;
- Conducting customer satisfaction surveys and market research;
- Managing promotional competitions, prize draws, and bonus programmes.
5.5 Website and Service Improvement
- Analysing Website usage patterns to improve user experience and functionality;
- Conducting A/B testing and performance optimisation;
- Troubleshooting technical issues and maintaining Website security;
- Developing new products, services, and features.
5.6 Security, Fraud Prevention, and Legal Compliance
- Detecting, investigating, and preventing fraudulent activity, money laundering, and other illegal conduct;
- Monitoring and enforcing our Terms and Conditions and other applicable policies;
- Cooperating with law enforcement, regulatory authorities, and judicial proceedings where required;
- Maintaining audit trails and records for compliance purposes;
- Protecting the safety and security of our guests, staff, and premises, including through CCTV surveillance where applicable.
6. Sharing of Your Personal Data
We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate safeguards:
6.1 Service Providers and Data Processors
We engage trusted third-party service providers to perform functions on our behalf. These providers process your data only under our instructions and in accordance with data processing agreements that comply with GDPR requirements. Categories of service providers include:
- Payment processing and fraud prevention service providers;
- Cloud hosting, IT infrastructure, and cybersecurity providers;
- Identity verification and KYC/AML compliance providers;
- Email, SMS, and marketing communication platforms;
- Customer relationship management (CRM) system providers;
- Analytics and website performance monitoring providers;
- Booking and reservation management system providers;
- Legal, accounting, and auditing firms;
- Responsible gambling monitoring service providers.
6.2 Regulatory and Law Enforcement Authorities
We may disclose your personal data to competent authorities where we are required to do so by applicable law or upon lawful request, including:
- Gambling regulatory authorities and licensing bodies;
- Financial intelligence units and AML supervisory authorities;
- Tax authorities and government agencies;
- Law enforcement agencies and judicial authorities.
6.3 Business Partners
In certain circumstances, we may share your data with business partners, such as co-promotional partners, affiliated hotels, or event organisers, where you have provided consent or where it is necessary to provide you with a service you have requested.
6.4 Corporate Transactions
In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction, your personal data may be transferred to the relevant acquiring or successor entity. We will notify you of any such transfer and ensure that appropriate protections are in place.
6.5 International Data Transfers
is based in Canada. Some of our service providers may be located in countries outside Canada and the European Economic Area (EEA). Where personal data is transferred to countries that have not been recognised as providing an adequate level of data protection by the European Commission, we will ensure that appropriate safeguards are implemented, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Adequacy decisions where the destination country has been recognised as providing adequate protection;
- Other legally recognised transfer mechanisms under applicable data protection law.
You may request a copy of the relevant safeguards applicable to cross-border transfers by contacting us at privacy@savecreststudio.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purpose of satisfying any legal, regulatory, accounting, or reporting requirements. The specific retention periods we apply are determined based on:
- The nature of the personal data and the sensitivity of its content;
- The purpose for which the data was originally collected;
- Applicable statutory and regulatory retention requirements;
- Our legitimate business interests in maintaining certain records.
7.1 General Retention Periods
| Category of Data | Retention Period | Legal Basis for Retention |
|---|---|---|
| Hotel guest reservation data | 7 years from the date of stay | Legal obligation (tax and accounting requirements) |
| Casino player account data | 5–7 years from account closure or last activity | Legal obligation (AML/gambling regulation) |
| Payment and transaction records | 7 years | Legal obligation (tax and financial regulation) |
| Identity verification documents (KYC) | 5 years from end of business relationship | Legal obligation (AML legislation) |
| Marketing preferences and consent records | 3 years from last interaction or until withdrawal of consent | Legitimate interest / Consent |
| Website analytics and cookies data | Up to 26 months from collection | Legitimate interest / Consent |
| Customer support communications | 3 years from closure of the inquiry | Legitimate interest / Legal obligation |
| Self-exclusion and responsible gambling records | Duration of self-exclusion plus 5 years | Legal obligation (gambling regulation) |
| CCTV footage | Up to 30 days, unless required for an investigation | Legitimate interest / Legal obligation |
Upon expiry of the applicable retention period, your personal data will be securely deleted, anonymised, or pseudonymised in accordance with our internal data disposal procedures. Where data has been anonymised in such a way that you can no longer be identified, we may retain and use such anonymised data without further notice.
8. Your Rights as a Data Subject
Under the GDPR and applicable Canadian privacy legislation, you have a number of rights in relation to your personal data. These rights are described below. Please note that some rights are subject to limitations and exceptions under applicable law.
8.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, together with information about how and why we process it. We will provide this information free of charge, normally within 30 days of receiving your request.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will rectify such data without undue delay upon receipt of a valid request.
8.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The data is no longer necessary for the purpose for which it was collected;
- You withdraw consent and there is no other legal basis for processing;
- You object to processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed;
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute and may not apply where we are required to retain your data to comply with legal obligations (e.g., AML or gambling regulation), or to establish, exercise, or defend legal claims.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing pending our verification of legitimate grounds.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or on a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us.
8.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where we rely on our legitimate interests as the legal basis for processing. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.
You also have the absolute right to object to the processing of your personal data for direct marketing purposes at any time. Upon receipt of such an objection, we will immediately cease all direct marketing activities in relation to you.
8.7 Right to Withdraw Consent
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at privacy@savecreststudio.com.
8.8 Right Not to be Subject to Automated Decision-Making (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects on you. Where we engage in automated decision-making, we will inform you of this, provide you with information about the logic involved, and allow you to request human review of such decisions.
8.9 Right to Lodge a Complaint
You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that our processing of your personal data infringes applicable data protection law. If you are located in Canada, you may contact:
-
Office of the Privacy Commissioner of Canada (OPC):
30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada
Website: www.priv.gc.ca
If you are located within the European Union or European Economic Area, you may also contact the relevant supervisory authority in your country of residence.
We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority. Please contact us first at privacy@savecreststudio.com.
8.10 Exercising Your Rights
To exercise any of the rights described above, please submit a written request to us using the contact details provided in Section 12. We will respond to your request within 30 calendar days of receipt. In complex or multiple cases, this period may be extended by a further two months, in which case we will notify you of the extension and the reasons for it within the initial 30-day period. There is no charge for making a request; however, we reserve the right to charge a reasonable administrative fee for manifestly unfounded or excessive requests.
To protect your personal data, we may need to verify your identity before processing your request. We may ask you to provide proof of identity and, where applicable, proof of your authority to act on behalf of another individual.
10. Security of Your Personal Data
We take the security of your personal data very seriously and implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit using Secure Socket Layer (SSL) / Transport Layer Security (TLS) technology;
- Encryption of sensitive data at rest;
- Access controls and role-based permissions limiting data access to authorised personnel only;
- Multi-factor authentication for access to sensitive systems;
- Regular penetration testing and vulnerability assessments;
- Firewalls, intrusion detection and prevention systems;
- Secure disposal procedures for data and hardware;
- Regular staff training on data protection and information security;
- Incident response and data breach notification procedures.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, we will also notify you directly.
While we implement all reasonable security measures, no method of data transmission over the internet or method of electronic storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for notifying us immediately if you suspect any unauthorised access to your account.
11. Third-Party Websites and Links
Our Website may contain links to third-party websites, plugins, or applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices or content. We encourage you to read the privacy policy of every website you visit before providing any personal data.
12. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our processing of your personal data, please do not hesitate to contact us using the following details:
| Data Controller | |
| Data Protection Officer | The Data Protection Officer |
| Email Address | privacy@savecreststudio.com |
| Postal Address | 110 Laurier Avenue West, Ottawa, ON K1P 1J1, Canada |
| Website | savecreststudio.com |
We aim to respond to all legitimate inquiries within 30 calendar days of receipt. If the matter is complex or we have received a high volume of requests, we may take up to three months in total to respond, and we will notify you of any such extension within the initial 30-day period.
13. Changes to This Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our data processing activities, applicable laws, or our business practices. When we make material changes, we will notify you by posting the updated Privacy Policy on our Website with a revised "Last Updated" date, and, where appropriate, by sending you a direct notification via email.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website and services following the posting of a revised Privacy Policy constitutes your acknowledgement of the changes.
If any changes significantly affect your rights or how we process your personal data, we will take additional steps to bring them to your attention, including requesting fresh consent where required by law.