Privacy Policy

Last updated: June 2025

Welcome to Nexoriahotelhouse. We are committed to protecting your personal data and respecting your privacy in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Personal Information Protection and Electronic Documents Act (PIPEDA), and all other applicable data protection legislation. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website at nexoriahotelhouse.com, make a reservation, use our hotel-casino services, or otherwise interact with us.

Please read this Policy carefully before using our website or services. By accessing our website or providing us with your personal data, you acknowledge that you have read and understood the practices described herein.

1. Data Controller

The entity responsible for the processing of your personal data (the "Data Controller") is:

Company Name Nexoriahotelhouse Inc.
Trading Name Nexoriahotelhouse
Registration Country Canada
Registration Number Corporation No. 7926841
VAT / Tax Number GST/HST No. 862 947 315 RT0001
Registered Legal Address 72 Water Street, Charlottetown, PE C1A 1A8, Canada
Website nexoriahotelhouse.com
Privacy Contact Email privacy@nexoriahotelhouse.com

2. Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you have any questions, concerns, or requests regarding your personal data or this Policy, you may contact our DPO directly:

Title The Data Protection Officer
Organisation Nexoriahotelhouse Inc.
Address 72 Water Street, Charlottetown, PE C1A 1A8, Canada
Email privacy@nexoriahotelhouse.com

We will respond to all legitimate requests within 30 days. Occasionally, it may take us longer if your request is particularly complex or if you have made several requests; in such cases, we will notify you and keep you updated.

3. Scope and Applicability

This Privacy Policy applies to:

  • Visitors to our website nexoriahotelhouse.com and any related subdomains;
  • Guests who make reservations or bookings for hotel accommodation;
  • Patrons who use our casino, entertainment, dining, spa, and other on-site facilities;
  • Individuals who contact us by email, telephone, or through our online contact forms;
  • Participants in our loyalty programmes, promotions, surveys, or competitions;
  • Business partners, suppliers, and their respective representatives;
  • Job applicants and prospective employees.

This Policy does not apply to third-party websites, applications, or services that may be linked from our website. We encourage you to review the privacy policies of any third-party services you access through links on our website.

4. Personal Data We Collect

Depending on your relationship with us and the services you use, we may collect and process the following categories of personal data:

4.1 Identity and Contact Information

  • Full name (first name, last name, title or honorific);
  • Date of birth and age verification data;
  • Gender;
  • Nationality and country of residence;
  • Passport, national ID card, or driver's licence number (where required by law);
  • Postal address (billing and correspondence);
  • Email address;
  • Telephone and mobile numbers.

4.2 Reservation and Stay Information

  • Booking reference number and booking history;
  • Check-in and check-out dates;
  • Room type preferences and special requests;
  • Number and age of accompanying guests;
  • Accessibility requirements and disability-related needs;
  • Dietary requirements and food allergy information;
  • Loyalty programme membership number and tier status.

4.3 Financial and Payment Information

  • Credit or debit card details (card number, expiry date, CVV — processed securely via PCI-DSS compliant payment processors);
  • Bank account information (where applicable for direct transfers);
  • Billing address;
  • Transaction history and folio details;
  • Currency and payment preferences.

4.4 Casino and Gaming Information

  • Gaming activity records and transaction logs;
  • Wagers placed, wins, and losses;
  • Self-exclusion and responsible gambling declarations;
  • Identity and age verification documents (required by law for gaming activities);
  • Anti-money laundering (AML) compliance records, including source of funds declarations;
  • Player account details and gaming preferences.

4.5 Technical and Usage Data

  • IP address and approximate geolocation;
  • Browser type, version, and operating system;
  • Device identifiers (device type, model, operating system);
  • Pages viewed, links clicked, and time spent on each page;
  • Referral source (how you arrived at our website);
  • Cookie identifiers and similar tracking technologies (see our Cookie Policy);
  • Session logs and access timestamps.

4.6 Communications Data

  • Records of correspondence and enquiries submitted via email, phone, or our contact forms;
  • Feedback, complaints, and review content;
  • Recordings of telephone calls (where you have been notified);
  • Chat transcripts and messaging records.

4.7 Marketing and Preference Data

  • Marketing preferences and subscription status;
  • Survey responses and event participation records;
  • Interests and preferences inferred from your interaction with our services.

4.8 Special Categories of Personal Data

In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These may include:

  • Health data: such as disability or accessibility requirements, dietary restrictions related to medical conditions, or medication storage needs — collected solely to provide appropriate accommodations;
  • Biometric data: where facial recognition or fingerprint systems are used for secure access control or identity verification (subject to explicit consent and separate notice);
  • Data relating to criminal convictions: required for regulatory compliance in casino operations (e.g., exclusion from gaming premises pursuant to applicable gaming regulations).

We process such data only where we have a valid legal basis to do so, including your explicit consent or where processing is necessary for reasons of substantial public interest under applicable law.

4.9 Data We Collect from Third Parties

We may also receive personal data about you from the following third-party sources:

  • Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia);
  • Travel agents and corporate travel management companies;
  • Payment processing providers and fraud prevention agencies;
  • Credit reference and identity verification agencies;
  • Social media platforms (where you interact with our social media pages);
  • Analytics and advertising partners;
  • Regulatory bodies and law enforcement agencies (where required).

6. How We Use Your Personal Data

We use your personal data for the following purposes:

6.1 Providing Hotel Services

  • Processing and confirming your reservation;
  • Managing check-in and check-out procedures;
  • Assigning and preparing your accommodation;
  • Coordinating housekeeping, room service, and concierge requests;
  • Processing payments and managing your account folio;
  • Providing accessibility and dietary accommodations;
  • Issuing tax invoices and receipts.

6.2 Providing Casino and Gaming Services

  • Registering and managing your player account;
  • Processing gaming transactions and maintaining gaming records;
  • Verifying your identity and age as required by law;
  • Administering responsible gambling programmes, including self-exclusion;
  • Monitoring gaming activity for AML and regulatory compliance;
  • Investigating suspicious transactions or activities.

6.3 Customer Relationship Management

  • Managing your loyalty programme membership and rewards;
  • Responding to your enquiries, complaints, and feedback;
  • Sending booking confirmations, pre-arrival information, and post-stay follow-ups;
  • Conducting customer satisfaction surveys;
  • Personalising your experience based on your preferences and history.

6.4 Marketing and Promotions

  • Sending you marketing communications, special offers, and promotional materials (where you have provided consent or where we have a legitimate interest as an existing customer);
  • Administering competitions, prize draws, and promotional events;
  • Conducting targeted advertising on our website and third-party platforms (where consent has been obtained);
  • Measuring the effectiveness of our marketing campaigns.

6.5 Security and Fraud Prevention

  • Operating CCTV systems on our premises for the safety of guests, staff, and property;
  • Detecting and preventing fraud, theft, and other criminal activities;
  • Monitoring online transactions for suspicious activity;
  • Conducting identity and credit checks where necessary;
  • Maintaining premises access control systems.

6.6 Legal and Regulatory Compliance

  • Meeting our obligations under Canadian gaming, financial, tax, and hospitality legislation;
  • Cooperating with regulatory authorities, law enforcement agencies, and courts;
  • Maintaining records required by applicable laws and regulations;
  • Defending or pursuing legal claims;
  • Conducting internal audits and compliance reviews.

6.7 Business Operations and Improvement

  • Analysing website traffic and user behaviour to improve our online services;
  • Conducting business analytics and performance reporting;
  • Training staff and improving service quality;
  • Managing IT infrastructure and ensuring information security;
  • Facilitating business transactions, including mergers, acquisitions, or asset sales.

7. Disclosure and Sharing of Personal Data

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate data protection safeguards:

7.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and under our instructions as data processors. These include:

  • Payment processing and financial transaction service providers;
  • Property Management System (PMS) and hotel software providers;
  • Casino management system providers;
  • IT services, cloud hosting, and cybersecurity providers;
  • Email delivery and marketing automation platforms;
  • Customer relationship management (CRM) software providers;
  • Online booking and reservation platform providers;
  • Analytics and data intelligence providers;
  • Printing, document management, and mailing service providers;
  • Legal, accounting, and auditing firms.

All data processors are bound by written data processing agreements that require them to process your data only as instructed and in accordance with applicable data protection law.

7.2 Regulatory and Government Authorities

We may disclose your personal data to regulatory bodies, law enforcement agencies, government authorities, or courts where required by law, including:

  • Gaming regulatory authorities and licensing bodies;
  • Financial intelligence units and AML/CTF supervisory authorities;
  • Tax authorities (Canada Revenue Agency and other applicable tax bodies);
  • Police and other law enforcement agencies (pursuant to lawful requests);
  • Courts and judicial bodies (in connection with legal proceedings).

7.3 Business Partners

With your consent or on the basis of our legitimate interests, we may share your data with:

  • Online travel agencies and booking platforms through which you made your reservation;
  • Corporate clients and travel management companies acting on your behalf;
  • Partner restaurants, spas, entertainment venues, or event organisers (where you have specifically requested or booked such services);
  • Our loyalty programme partners.

7.4 Professional Advisors

We may share your data with our professional advisors, including lawyers, auditors, accountants, and insurers, where necessary for the provision of professional services.

7.5 Corporate Transactions

In the event of a merger, acquisition, reorganisation, bankruptcy, or sale of all or part of our assets, your personal data may be transferred to the acquiring entity. We will notify you of any such change and the applicable privacy protections that will continue to apply.

7.6 International Transfers of Personal Data

Your personal data is primarily stored and processed in Canada. However, some of our service providers may process personal data in countries outside Canada and the European Economic Area (EEA). Where we transfer personal data internationally, we ensure that appropriate safeguards are in place to protect your data, including:

  • Transfers to countries that have been recognised as providing an adequate level of data protection by the relevant authority (e.g., the European Commission);
  • Use of Standard Contractual Clauses (SCCs) approved by the European Commission;
  • Binding Corporate Rules where applicable;
  • Other lawful transfer mechanisms available under applicable data protection law.

You may request a copy of the safeguards we have put in place for international transfers by contacting our DPO at privacy@nexoriahotelhouse.com.

8. Data Retention

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means, as well as the applicable legal requirements.

8.1 Retention Periods by Category

Category of Data Retention Period Reason
Guest reservation and stay records 7 years from the date of departure Legal obligation (tax and accounting records)
Payment and financial transaction records 7 years from the date of transaction Tax legislation and financial record-keeping requirements
Casino gaming records and player account data 7 years from the date of the gaming activity or account closure Gaming regulatory obligations and AML requirements
AML/KYC identity verification documents 7 years from the end of the business relationship Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA)
CCTV footage 30 days, unless required for an ongoing investigation Security and fraud prevention; overwritten on a rolling basis
Website usage and cookie data Up to 13 months from the date of collection Analytics and website performance improvement
Marketing consent records 3 years from the date of last interaction or withdrawal of consent Demonstrating compliance with consent requirements
Customer complaints and correspondence 3 years from the date of resolution Dispute resolution and legitimate interests
Self-exclusion and responsible gambling records Duration of self-exclusion plus 7 years Legal obligation and responsible gambling compliance
Job application records (unsuccessful candidates) 12 months from the date of the recruitment decision Legitimate interests (potential future vacancies, legal claims)
Loyalty programme data 3 years from the date of last activity or programme termination Contract performance and legitimate interests

Upon expiry of the applicable retention period, we will securely delete or anonymise your personal data. Where complete deletion is not immediately possible (for example, because your data has been archived in backup systems), we will isolate your data from further processing until deletion is possible.

9. Your Rights Under GDPR and Applicable Data Protection Law

Subject to applicable law, you have the following rights in relation to your personal data. Please note that certain rights may be subject to limitations and exceptions under applicable law.

9.1 Right of Access (Article 15 GDPR)

You have the right to request a copy of the personal data we hold about you, together with information about how we process it. We will provide this information in a commonly used, machine-readable format where possible.

9.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you without undue delay.

9.3 Right to Erasure / Right to Be Forgotten (Article 17 GDPR)

You have the right to request the deletion of your personal data in certain circumstances, including where:

  • The data is no longer necessary for the purposes for which it was collected;
  • You withdraw your consent and there is no other legal basis for processing;
  • You object to processing and there are no overriding legitimate grounds;
  • The data has been unlawfully processed;
  • The data must be erased to comply with a legal obligation.

Please note that this right does not apply where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

9.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while we verify the accuracy of the data or consider your objection to processing.

9.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or on a contract, and processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

9.6 Right to Object (Article 21 GDPR)

You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defence of legal claims.

You also have the absolute right to object at any time to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing. If you object, we will stop processing your data for this purpose immediately.

9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such decision is necessary for the performance of a contract, authorised by law, or based on your explicit consent.

Where we use automated decision-making or profiling (for example, for personalised marketing or fraud detection), we will provide you with information about the logic involved and the significance of such processing, and you may request human review of the decision.

9.8 Right to Withdraw Consent (Article 7(3) GDPR)

Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal.

9.9 How to Exercise Your Rights

To exercise any of the rights listed above, please submit a written request to our Data Protection Officer:

  • Email: privacy@nexoriahotelhouse.com
  • Post: The Data Protection Officer, Nexoriahotelhouse Inc., 72 Water Street, Charlottetown, PE C1A 1A8, Canada

We may need to verify your identity before processing your request. We will respond to all requests within 30 days of receipt. In cases of complexity or multiple requests, we may extend this period by a further two months, but will inform you of the extension and the reasons within the initial 30-day period.

We will not charge a fee for responding to your requests unless they are manifestly unfounded or excessive. In such cases, we may charge a reasonable administrative fee or refuse to comply with the request.

9.10 Right to Lodge a Complaint with a Supervisory Authority

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority. In Canada, the relevant authority is:

  • Office of the Privacy Commissioner of Canada
    30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada
    Website: www.priv.gc.ca
    Toll-free: 1-800-282-1376

If you are located in the European Economic Area (EEA), you also have the right to lodge a complaint with the supervisory authority in your country of habitual residence, place of work, or the place of the alleged infringement.

10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies (such as pixels, web beacons, and local storage) to enhance your browsing experience, analyse website traffic, and deliver relevant content and advertising.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the website to function correctly. These cannot be disabled without affecting website functionality (legal basis: legitimate interests);
  • Performance and Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous statistical information (legal basis: consent);
  • Functionality Cookies: Remember your preferences and personalise your experience (legal basis: consent);
  • Targeting and Advertising Cookies: Used to deliver relevant advertisements and track campaign effectiveness (legal basis: consent).

You can manage your cookie preferences at any time through our cookie consent banner or by adjusting your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

For detailed information about the cookies we use, their purposes, and how to manage them, please refer to our full Cookie Policy available on our website.

11. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your data against accidental loss, destruction, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of personal data in transit (SSL/TLS) and at rest where appropriate;
  • Access controls and authentication requirements to limit access to personal data;
  • Regular security testing, vulnerability assessments, and penetration testing;
  • Staff training and awareness programmes on data protection and information security;
  • Physical security measures at our premises, including restricted access and CCTV;
  • Payment card processing compliant with PCI-DSS standards;
  • Incident response and data breach notification procedures;
  • Regular review and update of security policies and procedures.

Despite these measures, no data transmission over the internet or data storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@nexoriahotelhouse.com.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 of the GDPR.

12. Children and Minors

Our website and services are not directed at children under the age of 18. We do not knowingly collect personal data from children under 18 without verifiable parental or guardian consent.

Casino and gaming services are strictly restricted to individuals who are 19 years of age or older (or the applicable legal minimum age in the relevant jurisdiction). We conduct age verification checks as required by applicable gaming legislation.

If you believe that we have inadvertently collected personal data from a minor without appropriate consent, please contact our DPO at privacy@nexoriahotelhouse.com and we will take steps to delete such information as quickly as possible.

13. Automated Decision-Making and Profiling

We may use automated processing and profiling in the following contexts:

  • Fraud and AML detection: Automated systems monitor transactions for patterns indicative of fraud or money laundering. Where a transaction is flagged, a human review will take place before any significant action is taken;
  • Personalised marketing: We may use profiling to tailor marketing communications to your interests and preferences based on your interaction history with us;
  • Responsible gambling: Automated systems may flag gaming behaviour that may indicate problem gambling, triggering proactive outreach from our responsible gambling team.

Where any automated decision produces legal or similarly significant effects, you have the right to request human review. Please contact us at privacy@nexoriahotelhouse.com to exercise this right.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities, applicable law, or regulatory requirements. When we make material changes, we will notify you by:

  • Posting a prominent notice on our website homepage;
  • Sending an email notification to the address we hold on file for you (where applicable);
  • Updating the "Last Updated" date at the top of this Policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services after the effective date of any changes constitutes your acknowledgement of the updated Policy.

Previous versions of this Privacy Policy are available upon request from our DPO.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please do not hesitate to contact us:

Data Protection Officer The Data Protection Officer, Nexoriahotelhouse Inc.
Email privacy@nexoriahotelhouse.com
Postal Address 72 Water Street, Charlottetown, PE C1A 1A8, Canada
Website nexoriahotelhouse.com

We are committed to working with you to resolve any concerns regarding your privacy. If, however, you feel that your concerns have not been adequately addressed, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada or the supervisory authority in your jurisdiction of residence.