Privacy Policy

Last updated: June 2025

This Privacy Policy explains how Greentonecreative ("we", "us", "our") collects, uses, discloses, and protects personal data of visitors and guests of our hotel-casino website located at greentonecreative.com (the "Website"). We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Canadian privacy legislation including the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and all other applicable data protection laws.

Please read this Privacy Policy carefully before using our Website or providing us with any personal information. By accessing or using our Website, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Legal Entity Name Greentonecreative
Registered Address Wollaston Lake, SK S0J 3C0, Canada
Registration Country Canada
Registration Number HRB 144455 B
VAT Number DE 144455789
Website greentonecreative.com
Privacy Contact Email info@greentonecreative.com

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding your personal data or this Privacy Policy, you may contact our DPO at:

Name / Title The Data Protection Officer
Organisation Greentonecreative
Address Wollaston Lake, SK S0J 3C0, Canada
Email info@greentonecreative.com

3. Personal Data We Collect

Depending on how you interact with our Website and services, we may collect and process the following categories of personal data about you. "Personal data" means any information that identifies or could reasonably be used to identify you as an individual.

3.1 Data You Provide Directly

  • Identity Data: Full name, date of birth, gender, nationality, and a copy of government-issued identification (where required for casino regulatory compliance or age verification).
  • Contact Data: Email address, telephone number, postal address, city, country, and postal/ZIP code.
  • Reservation and Booking Data: Check-in and check-out dates, room type preferences, number of guests, special requests, loyalty programme membership numbers, and booking history.
  • Account Data: Username, password (stored in hashed form), security questions and answers, and account preferences when you create a profile on our Website.
  • Payment and Financial Data: Credit or debit card details (card number, expiry date, CVV — processed via PCI-DSS compliant payment processors), billing address, and transaction history. We do not store full card numbers on our own servers.
  • Casino and Gaming Data: Gaming preferences, wager history, winnings and losses, gaming account balance, self-exclusion preferences, and responsible gambling settings, where applicable and required by law.
  • Communications Data: Messages, feedback, reviews, complaints, and other communications you send us via contact forms, email, or live chat.
  • Marketing Preferences: Your opt-in or opt-out choices for receiving promotional communications, newsletters, and special offers.

3.2 Data Collected Automatically

  • Technical Data: IP address, browser type and version, operating system, device type and identifiers, time zone setting, and browser plug-in types and versions.
  • Usage Data: Pages visited, links clicked, referring URLs, session duration, traffic sources, and navigation paths on our Website.
  • Cookie and Tracking Data: Information collected through cookies, web beacons, pixel tags, and similar tracking technologies. Please refer to our Cookie Policy for further details.
  • Log Data: Server logs including access timestamps, error logs, and security event logs.

3.3 Data Received from Third Parties

  • Online Travel Agencies and Booking Platforms: Reservation details and contact information forwarded to us when you book through a third-party platform.
  • Identity Verification Providers: Results of identity and age verification checks conducted for casino regulatory compliance purposes.
  • Analytics Providers: Aggregated and anonymised statistical data about Website usage.
  • Social Media Platforms: If you choose to connect a social media account or log in via a social media provider, we may receive profile information permitted by your social media settings.
  • Fraud Prevention and Credit Reference Agencies: Information used to verify your identity, prevent fraud, and comply with anti-money laundering obligations.

3.4 Special Categories of Personal Data

We do not intentionally collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sexual orientation) unless we are required to do so by law (for example, accessibility requirements), or you explicitly provide such information (for example, dietary requirements relating to a health condition). Where we process such data, we do so on the basis of your explicit consent or as otherwise permitted under applicable law.

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes. Each purpose is linked to the applicable legal basis described in Section 4 above.

  • To process and manage reservations and bookings: We use your identity, contact, and booking data to confirm your reservation, manage your stay, and provide the hotel and casino services you have requested. (Legal basis: Contract performance)
  • To process payments: We use your payment and financial data to collect fees for accommodation, casino services, dining, and other amenities, and to issue receipts or invoices. (Legal basis: Contract performance; Legal obligation)
  • To manage your online account: We use your account data to authenticate you, maintain your profile, and enable access to personalised features and booking history. (Legal basis: Contract performance)
  • To comply with legal and regulatory obligations: We use identity and gaming data to verify your age and identity, comply with casino licensing regulations, conduct AML/CTF checks, and fulfil mandatory reporting requirements. (Legal basis: Legal obligation; Public task)
  • To provide customer support: We use your communications and contact data to respond to your enquiries, resolve complaints, and provide after-stay support. (Legal basis: Contract performance; Legitimate interests)
  • To send you marketing and promotional communications: With your consent, we may send you emails, SMS messages, or other communications about special offers, events, promotions, and news about Greentonecreative . (Legal basis: Consent)
  • To personalise your experience: We use your preferences, usage data, and booking history to tailor our Website content, recommendations, and offers to your interests. (Legal basis: Legitimate interests; Consent)
  • To improve our Website and services: We analyse technical and usage data to identify issues, monitor performance, and make improvements to our Website and services. (Legal basis: Legitimate interests)
  • To ensure security and prevent fraud: We process technical, identity, and payment data to detect and prevent fraudulent activity, unauthorised access, and security incidents. (Legal basis: Legitimate interests; Legal obligation)
  • To administer responsible gambling measures: We process gaming data and self-exclusion preferences to implement responsible gambling tools and comply with applicable gaming regulations. (Legal basis: Legal obligation; Legitimate interests)
  • To conduct internal business administration: We use personal data for internal record-keeping, financial reporting, auditing, and business management purposes. (Legal basis: Legal obligation; Legitimate interests)
  • To enforce our terms and protect our legal rights: We may process personal data as necessary to enforce our terms and conditions, defend or bring legal claims, and protect our rights, property, and safety. (Legal basis: Legitimate interests; Legal obligation)

6. Sharing Your Personal Data

We do not sell, rent, or trade your personal data to third parties for their own commercial purposes. We may share your personal data with the following categories of recipients only where necessary and proportionate to the relevant purpose, and subject to appropriate safeguards.

6.1 Service Providers and Data Processors

We engage trusted third-party companies and individuals to perform services on our behalf. These processors act only on our instructions and are contractually bound to protect your personal data. They include:

  • Payment processors: To securely process credit/debit card transactions and handle financial transfers.
  • IT and cloud hosting providers: To host our Website, databases, email systems, and other IT infrastructure.
  • Booking and reservation management platforms: To manage hotel reservations and guest records.
  • Email and marketing platforms: To send transactional and marketing communications to guests who have consented to receive them.
  • Analytics providers: To analyse Website traffic and usage patterns (such as Google Analytics or similar tools).
  • Customer support and live chat providers: To assist with handling guest enquiries and complaints.
  • Identity verification and fraud prevention services: To verify guest identities and conduct AML/CTF compliance checks.

6.2 Regulatory and Law Enforcement Authorities

We may disclose your personal data to regulatory bodies, law enforcement agencies, gaming commissions, tax authorities, or courts where we are required to do so by applicable law, court order, or regulatory requirement. This includes disclosures necessary to comply with casino licensing obligations, AML/CTF reporting duties, and responses to lawful legal process.

6.3 Business Partners

We may share personal data with carefully selected business partners (for example, online travel agencies, concierge service providers, or affiliated hospitality businesses) where necessary to fulfil your booking or provide a service you have requested. Such sharing is subject to appropriate data sharing agreements.

6.4 Professional Advisers

We may share personal data with lawyers, auditors, accountants, insurers, and other professional advisers where necessary for the provision of their services to us, subject to confidentiality obligations.

6.5 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction involving Greentonecreative , personal data held by us may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer and any material changes to this Privacy Policy in such circumstances.

6.6 International Data Transfers

As an organisation registered in Canada and serving guests from various countries, including those within the European Economic Area (EEA), your personal data may be transferred to and processed in countries outside the EEA. Whenever we transfer personal data to a country that does not provide an equivalent level of data protection, we ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (Article 46(2)(c) GDPR).
  • Adequacy decisions by the European Commission recognising the destination country as providing adequate data protection.
  • Binding Corporate Rules (BCRs) or other approved transfer mechanisms where applicable.

You may request a copy of the relevant safeguards by contacting our DPO at the details provided in Section 2.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria we use to determine the appropriate retention period include:

  • The nature of the personal data and the sensitivity of the information concerned.
  • The purposes for which we process the data and whether we can achieve those purposes through other means.
  • Applicable legal or regulatory obligations that require us to retain data for a minimum period (for example, financial records required to be kept for a defined number of years under tax law).
  • Potential need to retain data for the establishment, exercise, or defence of legal claims.

7.1 Indicative Retention Periods

Category of Data Indicative Retention Period Reason
Booking and reservation records 7 years from the date of the stay Legal, financial, and contractual obligations
Payment and transactional data 7 years from the date of transaction Tax and accounting legal obligations
Identity verification records (casino) 5 years from the end of the business relationship AML/CTF regulatory requirements
Guest account data 3 years from last account activity or account closure Legitimate interests; contract performance
Marketing preferences and consent records Until consent is withdrawn or 3 years from last interaction Consent management and legal accountability
Website usage and analytics data Up to 26 months from collection Analytics and Website improvement
Customer support communications 3 years from resolution of the matter Legitimate interests; legal claims
Security logs and access records 12 months from date of record Security and fraud prevention

When personal data is no longer required, we will securely delete or anonymise it in accordance with our internal data retention and destruction procedures. Anonymised data may be retained indefinitely for statistical and analytical purposes.

8. Your Rights as a Data Subject

Under the GDPR and other applicable data protection laws, you have the following rights in relation to your personal data. We will respond to your request within one calendar month of receipt, although this period may be extended by a further two months in cases of complexity or volume, in which case we will inform you. We will not charge a fee for exercising your rights, unless your request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline to act.

8.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you, together with information about how we process it, the purposes of processing, the categories of data processed, any recipients with whom the data has been shared, and the envisaged retention period.

8.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay. You may also update your information directly through your account profile where applicable.

8.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)

You have the right to request the deletion of your personal data where:

  • The personal data is no longer necessary for the purposes for which it was collected.
  • You withdraw consent and there is no other legal basis for processing.
  • You object to processing and there are no overriding legitimate grounds.
  • The personal data has been unlawfully processed.
  • Erasure is required to comply with a legal obligation.

Please note that this right is not absolute and may not apply where we are required to retain data to comply with a legal obligation, or where processing is necessary for the establishment, exercise, or defence of legal claims.

8.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, where processing is unlawful but you prefer restriction over erasure, or where we no longer need the data but you require it for legal claims.

8.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

8.6 Right to Object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless processing is necessary for the establishment, exercise, or defence of legal claims.

You have an unconditional right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing. If you object to direct marketing, we will stop processing your data for this purpose immediately.

8.7 Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal. You may withdraw your consent by contacting us at info@greentonecreative.com or by following the unsubscribe link in any marketing email we send you.

8.8 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you, unless such processing is necessary for a contract, authorised by law, or based on your explicit consent. We do not currently use fully automated decision-making processes that produce legal or similarly significant effects. If this changes, we will update this Privacy Policy and notify you accordingly.

8.9 Right to Lodge a Complaint (Article 77 GDPR)

If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority. If you are located in the European Union or EEA, you may contact the data protection authority of the EU member state where you reside, work, or where the alleged infringement occurred. A list of EU supervisory authorities is available at edpb.europa.eu .

If you are located in Canada, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca .

We would, however, appreciate the opportunity to address your concerns directly before you approach any supervisory authority. Please contact our DPO in the first instance.

8.10 How to Exercise Your Rights

To exercise any of the rights listed above, please submit a written request to us by email at info@greentonecreative.com , clearly stating your name, the right you wish to exercise, and relevant details to help us identify and locate your personal data. We may need to verify your identity before processing your request in order to protect the security of your information.

9. Cookies and Tracking Technologies

Our Website uses cookies and similar tracking technologies (such as web beacons, pixel tags, and local storage) to enhance your browsing experience, analyse Website traffic, and deliver relevant content and advertising. Cookies are small text files placed on your device when you visit a website.

We use the following types of cookies:

  • Strictly Necessary Cookies: Essential for the operation of our Website, including enabling you to navigate the site and use its features. These cookies cannot be disabled.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our Website by collecting information about page views, traffic sources, and user behaviour, so we can improve our Website.
  • Functional Cookies: Allow our Website to remember your preferences (such as language, region, or login status) to provide a more personalised experience.
  • Targeting and Advertising Cookies: Used to deliver advertisements relevant to you and your interests, and to measure the effectiveness of advertising campaigns. These cookies are only placed with your consent.

When you first visit our Website, you will be presented with a cookie consent banner enabling you to accept or reject non-essential cookies. You can also manage your cookie preferences at any time by adjusting your browser settings or accessing our cookie preference centre. Please note that disabling certain cookies may affect the functionality of our Website.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include, but are not limited to:

  • Encryption of personal data in transit using TLS/SSL technology.
  • Encryption of personal data at rest where appropriate.
  • Access controls and authentication measures to restrict access to personal data to authorised personnel only.
  • Regular security assessments, penetration testing, and vulnerability scanning.
  • Staff training on data protection and information security.
  • Incident response procedures to detect, investigate, and respond to personal data breaches.
  • PCI-DSS compliant payment processing systems.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by Article 34 GDPR.

While we take all reasonable steps to protect your personal data, please note that no method of transmission over the internet or electronic storage is completely secure. We therefore cannot guarantee absolute security.

11. Children and Minors

Our hotel and casino services are intended for individuals who are at least 18 years of age (or the minimum legal age for gambling in the applicable jurisdiction, if higher). We do not knowingly collect personal data from children under the age of 16 without verifiable parental or guardian consent. If you are under 18, you must not use the casino-related sections of our Website or attempt to make a gambling-related transaction.

If we become aware that we have inadvertently collected personal data from a child under 16 without appropriate consent, we will take immediate steps to delete that information. If you believe we may have collected data from a child, please contact us immediately at info@greentonecreative.com .

13. Changes to This Privacy Policy

We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, legal requirements, or for other operational, legal, or regulatory reasons. When we make material changes to this Privacy Policy, we will notify you by posting the updated policy on this page with a revised "Last updated" date and, where appropriate, by sending you an email notification or displaying a prominent notice on our Website.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website following the posting of changes constitutes your acknowledgment of those changes.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or our data protection practices, please do not hesitate to contact us using the following details:

Data Controller Greentonecreative
Data Protection Officer The Data Protection Officer
Address Wollaston Lake, SK S0J 3C0, Canada
Email info@greentonecreative.com
Website greentonecreative.com

We will endeavour to respond to all legitimate requests within one calendar month. Occasionally, it may take us longer if your request is particularly complex or if you have made multiple requests. In such circumstances, we will notify you and keep you updated throughout the process.