Privacy Policy
Last updated: June 2025
This Privacy Policy describes how Aldermeadow Partners (hereinafter referred to as "we", "us", or "our") collects, uses, stores, discloses, and protects the personal data of users (hereinafter referred to as "you" or "the data subject") who visit or interact with our website located at aldermeadowpartners.com (hereinafter the "Website"), as well as guests and customers of our hotel-casino facilities in Burnaby, Canada.
We are committed to protecting your privacy and processing your personal data in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Canadian privacy legislation including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (PIPA), and any other applicable data protection laws.
Please read this Privacy Policy carefully before using our Website or services. By accessing our Website or providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The data controller responsible for the processing of your personal data is:
| Legal Entity Name | Aldermeadow Partners |
| Registration Country | Canada |
| Registration Number | BC-2024-078192 |
| VAT Number | 129876543 |
| Legal Address | 4400 Dominion Street, Suite 310, Burnaby, BC V5G 4G3, Canada |
| Website | aldermeadowpartners.com |
| Privacy Contact Email | info@aldermeadowpartners.com |
As the data controller, Aldermeadow Partners determines the purposes and means of processing your personal data. We are accountable for ensuring that all personal data we collect is processed lawfully, fairly, and transparently in accordance with applicable data protection legislation.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing matters related to this Privacy Policy and the protection of your personal data. If you have any questions, concerns, or requests relating to the processing of your personal data, you may contact our Data Protection Officer directly:
| Name / Title | The Data Protection Officer |
| Organisation | Aldermeadow Partners |
| Address | 4400 Dominion Street, Suite 310, Burnaby, BC V5G 4G3, Canada |
| info@aldermeadowpartners.com |
3. Personal Data We Collect
Depending on the nature of your interaction with our Website and our hotel-casino services, we may collect and process the following categories of personal data:
3.1 Identity and Contact Information
- Full name (first name and surname)
- Date of birth and age verification data
- Gender
- Nationality and country of residence
- Passport, national identity card, or government-issued identification details (required for hotel check-in and gaming regulatory compliance)
- Postal address (home and/or billing address)
- Email address
- Telephone number(s)
3.2 Reservation and Booking Information
- Hotel room preferences and booking details
- Check-in and check-out dates
- Number and age of guests
- Special requests, accessibility requirements, or dietary preferences
- Loyalty programme membership numbers and related account data
3.3 Financial and Payment Information
- Credit card or debit card details (card type, last four digits, expiry date — full card numbers are processed by our PCI-DSS compliant payment processors and are not stored by us)
- Bank account information where applicable
- Transaction history and receipts related to hotel, restaurant, spa, and gaming services
- Financial information required for anti-money laundering (AML) and Know Your Customer (KYC) compliance in connection with gaming activities
3.4 Gaming and Casino-Specific Data
- Gaming activity records, including types of games played, wagers placed, and session durations
- Winnings and losses data required for regulatory reporting
- Responsible gambling self-exclusion requests and related records
- Player account information and loyalty points within casino programmes
- Identity verification documents required under gaming regulatory obligations
3.5 Technical and Usage Data
- IP address and approximate geolocation data derived therefrom
- Browser type and version
- Operating system and device type
- Pages visited on our Website, clickstream data, and time spent on pages
- Referring URLs and exit pages
- Cookie identifiers and similar tracking technologies (please refer to our Cookie Policy for further details)
- Log files and access records
3.6 Communication Data
- Correspondence and messages sent to us via email, contact forms, or live chat
- Records of telephone calls (where permitted by law and with appropriate notice)
- Feedback, reviews, survey responses, and complaints
3.7 Marketing Preferences
- Your preferences and choices regarding marketing communications
- Subscription status for newsletters or promotional emails
- Interests and preferences inferred from your interactions with our services
3.8 Special Categories of Personal Data
In certain circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. These include:
- Health data: Accessibility or dietary requirements you voluntarily disclose when making reservations or requesting special accommodations.
- Responsible gambling data: Information related to self-exclusion programmes or problem gambling support, which may indirectly reveal health-related information.
We will only process special categories of personal data where we have a lawful basis to do so as set out in Article 9(2) of the GDPR, such as your explicit consent, or where processing is necessary to protect your vital interests or comply with legal obligations.
3.9 Data Collected from Third Parties
In addition to data you provide directly, we may receive personal data about you from the following third-party sources:
- Online travel agencies (OTAs) and booking platforms (e.g., Booking.com, Expedia) when you make a reservation through their platforms
- Credit reference agencies and fraud prevention organisations
- Regulatory authorities and government bodies in connection with AML/KYC obligations
- Social media platforms, if you interact with our social media pages or log in using social media credentials
- Business partners and corporate clients who make reservations on behalf of their employees or guests
4. Legal Basis for Processing Personal Data
We process your personal data only where we have a valid legal basis under Article 6 of the GDPR. The applicable legal bases are set out below:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary to enter into or perform a contract with you. This includes:
- Processing your hotel room or restaurant reservations
- Managing your check-in and check-out procedures
- Processing payments for services rendered
- Administering your casino player account and gaming activities
- Fulfilling special service requests made by you
- Managing loyalty programme memberships
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where we are required to do so by applicable law. This includes:
- Compliance with gaming and casino regulatory requirements imposed by Canadian federal and provincial authorities
- Anti-money laundering (AML) and Know Your Customer (KYC) obligations
- Tax reporting and financial record-keeping obligations
- Identity verification requirements for age-restricted services (gaming, alcohol service)
- Mandatory reporting obligations to law enforcement or regulatory bodies
- Data retention obligations prescribed by law
- Compliance with court orders or legal process
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and interests. Our legitimate interests include:
- Ensuring the security of our Website, IT systems, hotel premises, and casino facilities (including CCTV surveillance for safety and fraud prevention)
- Fraud detection, prevention, and investigation
- Improving and optimising our Website and services through analytics
- Conducting market research and customer satisfaction surveys
- Direct marketing to existing customers in relation to similar products and services (subject to your right to object)
- Managing and defending legal claims
- Internal administrative and reporting purposes within our corporate group
- Preventing and detecting cheating or dishonest activity in our casino
Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 9 below).
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will ask for your explicit and informed agreement before processing your personal data. Consent-based processing includes:
- Sending you marketing emails, newsletters, or promotional offers where you are not an existing customer
- Placing non-essential cookies and similar tracking technologies on your device
- Processing special categories of personal data (e.g., health information for accessibility purposes) where no other legal basis applies
- Sharing your personal data with selected third-party partners for their own marketing purposes (where applicable)
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at info@aldermeadowpartners.com or use the unsubscribe mechanism provided in any marketing communications.
4.5 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect your vital interests or those of another person. This may arise, for example, in a medical emergency involving a guest on our premises.
4.6 Public Task (Article 6(1)(e) GDPR)
In certain limited circumstances, we may process personal data where it is necessary for the performance of a task carried out in the public interest, or in the exercise of official authority vested in us. This may apply in the context of regulated gaming activities conducted under public licensing frameworks.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Provision of Hotel and Accommodation Services
- Processing and confirming your reservations
- Managing check-in, check-out, and room allocation
- Providing in-room services, housekeeping, concierge, and other hotel amenities
- Accommodating dietary requirements, accessibility needs, and other special requests
- Sending confirmation emails, pre-arrival information, and post-stay communications
5.2 Provision of Casino and Gaming Services
- Verifying your identity and age eligibility for participation in gaming activities
- Administering your casino player account
- Processing gaming transactions, wagers, and winnings
- Implementing responsible gambling tools, including self-exclusion and spend limits
- Complying with gaming regulatory requirements and maintaining mandatory records
- Detecting and preventing cheating, fraud, and other prohibited activities
5.3 Payment Processing and Financial Administration
- Processing payments for all hotel, restaurant, spa, casino, and ancillary services
- Issuing invoices and receipts
- Conducting financial record-keeping for accounting and tax purposes
- Implementing AML and KYC procedures
- Processing refunds where applicable
5.4 Customer Relationship Management
- Managing your account and profile information
- Administering our loyalty and rewards programme
- Responding to your enquiries, complaints, and feedback
- Providing customer support services
- Conducting customer satisfaction surveys and market research
5.5 Marketing and Promotional Communications
- Sending you information about our hotel, casino, restaurant, spa, and event offerings
- Personalising offers and promotions based on your preferences and history with us
- Delivering targeted advertisements on our Website and third-party platforms
- Conducting prize draws, competitions, and promotional campaigns
You can opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email, by updating your account preferences, or by contacting us at info@aldermeadowpartners.com.
5.6 Website and Service Improvement
- Analysing usage patterns and behaviour on our Website through analytics tools
- Testing and developing new features and services
- Conducting internal research and business intelligence activities
- Monitoring Website performance and technical operation
5.7 Security and Fraud Prevention
- Monitoring for and preventing fraud, money laundering, and other financial crimes
- Operating CCTV surveillance on our premises for security purposes
- Detecting and investigating suspected cheating or dishonest activity in our casino
- Protecting the safety of guests, employees, and our physical and digital assets
- Cybersecurity monitoring and incident response
5.8 Legal and Regulatory Compliance
- Fulfilling our obligations under applicable Canadian and international law
- Responding to lawful requests from regulatory authorities, law enforcement agencies, or courts
- Establishing, exercising, or defending legal claims
- Maintaining records as required by gaming, financial, or other regulatory frameworks
6. Sharing of Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes without your explicit consent. However, we may share your personal data with the following categories of recipients where necessary and lawful:
6.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions as data processors. These include:
- Payment processors: PCI-DSS compliant payment gateway and card processing providers
- IT and cloud service providers: Hosting, database management, software-as-a-service (SaaS) providers, and cybersecurity services
- Reservation and property management systems: Hotel management software and booking engine providers
- Gaming technology providers: Casino management system vendors and gaming software suppliers
- Email and marketing platforms: Email service providers and marketing automation tools
- Analytics providers: Website analytics and business intelligence platforms (e.g., Google Analytics)
- Customer support tools: CRM and helpdesk software providers
- Identity verification providers: Third-party AML/KYC verification services
All data processors are bound by contractual obligations (including Data Processing Agreements where required by GDPR Article 28) to process personal data only on our instructions and to implement appropriate technical and organisational security measures.
6.2 Online Travel Agencies and Booking Partners
Where you make a reservation through a third-party booking platform or travel agency, we may exchange necessary booking and guest information with that platform in order to fulfil your reservation and provide our services.
6.3 Regulatory Authorities and Government Bodies
We may disclose your personal data to relevant regulatory authorities, law enforcement agencies, tax authorities, or courts where we are required or permitted to do so by law, including:
- British Columbia gaming regulatory authorities
- Canada Revenue Agency (CRA) and applicable tax authorities
- Financial intelligence units in connection with AML obligations (e.g., FINTRAC)
- Law enforcement agencies pursuant to lawful requests
- Courts and tribunals in connection with legal proceedings
6.4 Professional Advisers
We may share personal data with our legal advisers, auditors, accountants, and other professional advisers where necessary for the provision of their services to us, subject to professional confidentiality obligations.
6.5 Business Transfers
In the event of a merger, acquisition, corporate restructuring, sale of assets, or similar transaction, your personal data may be transferred to the acquiring or successor entity. We will notify you of any such transfer and any changes to this Privacy Policy where required by law.
6.6 With Your Consent
We may share your personal data with third parties for purposes not described in this Privacy Policy where we have obtained your explicit prior consent to do so.
6.7 International Transfers of Personal Data
Some of our service providers and partners may be located outside of Canada, the European Economic Area (EEA), or your country of residence. Where personal data is transferred to a country that does not provide an equivalent level of data protection, we will implement appropriate safeguards in accordance with applicable data protection law, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission (where applicable)
- Binding Corporate Rules (BCRs) where applicable
- Adequacy decisions recognising the recipient country as providing an adequate level of protection
- Other lawful transfer mechanisms as permitted under applicable law
You may request further information about international transfers and the safeguards in place by contacting us at info@aldermeadowpartners.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law or regulation. The criteria used to determine our retention periods include:
- The duration of our contractual relationship with you and the provision of services
- Legal and regulatory obligations prescribing minimum retention periods (for example, financial and gaming records may be required to be retained for a minimum of seven years under Canadian law)
- Applicable statutes of limitation for the purposes of establishing, exercising, or defending legal claims
- Industry standards and best practices
- The sensitivity of the personal data and the risks associated with its retention
The following indicative retention periods apply:
| Category of Data | Indicative Retention Period |
|---|---|
| Hotel reservation and guest records | 7 years from the date of stay or last interaction |
| Gaming and casino records (regulatory) | 7 years from the date of transaction, or as required by applicable gaming regulations |
| Financial and payment records | 7 years from the date of transaction (in accordance with tax and accounting requirements) |
| AML/KYC identity verification records | 5–7 years from the end of the business relationship, as required by FINTRAC and applicable regulations |
| Website usage and analytics data | Up to 26 months from the date of collection |
| Marketing preferences and opt-out records | Duration of the relationship, plus 3 years after the last interaction or opt-out |
| CCTV footage | Up to 31 days, unless retained longer for security investigations or regulatory requirements |
| Customer correspondence and complaints | 3 years from the date of resolution |
| Responsible gambling / self-exclusion records | Duration of the self-exclusion period plus 5 years, as required by gaming regulations |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data disposal procedures and applicable legal requirements.
8. Cookies and Similar Technologies
Our Website uses cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance your browsing experience, analyse Website traffic, and deliver relevant content and advertising.
Cookies are small text files placed on your device when you visit our Website. They enable the Website to remember your actions and preferences over a period of time. We use the following types of cookies:
- Strictly necessary cookies: Essential for the operation of our Website and cannot be disabled. They include cookies required for navigation, security, and access to restricted areas.
- Performance and analytics cookies: These help us understand how visitors interact with our Website by collecting aggregated data. We use tools such as Google Analytics for this purpose.
- Functionality cookies: These enable enhanced functionality and personalisation, such as remembering your language preferences or login details.
- Targeting and advertising cookies: These are used to deliver advertisements relevant to your interests, both on our Website and on third-party platforms.
Non-essential cookies are placed on your device only with your prior consent, which you may provide or withdraw at any time through our cookie consent tool available on our Website. You may also manage cookie preferences through your browser settings; however, disabling certain cookies may affect the functionality of our Website.
For detailed information about the specific cookies we use, their purposes, and their durations, please refer to our separate Cookie Policy available on our Website.
9. Your Rights as a Data Subject
Subject to applicable data protection law, you have the following rights with respect to the personal data we hold about you. We will respond to all valid requests within one calendar month of receipt, or notify you of an extension where the request is complex or numerous (up to a maximum of three months in total), free of charge, unless requests are manifestly unfounded or excessive.
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that data together with information about how and why we process it, the categories of data concerned, the recipients or categories of recipients, the envisaged retention periods, and your other rights in relation to that data.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you, and to have incomplete personal data completed, without undue delay.
9.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances, including where:
- The personal data is no longer necessary for the purposes for which it was collected
- You withdraw your consent and there is no other legal basis for processing
- You object to the processing and there are no overriding legitimate interests
- The personal data has been unlawfully processed
- Erasure is required to comply with a legal obligation
Please note that this right is not absolute and may be subject to exceptions, for example where we are required to retain data for legal, regulatory, or compliance purposes.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you do not wish us to delete the data, or where we no longer need the data but you require it for legal claims.
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object, at any time, to the processing of your personal data:
- Where processing is based on our legitimate interests (Article 6(1)(f) GDPR), we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for legal claims.
- Where your personal data is processed for direct marketing purposes, you have an unconditional right to object, and we will cease processing your data for such purposes without delay.
9.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such automated decision-making is necessary for the performance of a contract, authorised by law, or based on your explicit consent. Where we engage in automated decision-making, you have the right to request human review, to express your point of view, and to contest the decision.
9.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to the withdrawal.
9.9 How to Exercise Your Rights
To exercise any of your rights listed above, please submit a written request to our Data Protection Officer:
- By email: info@aldermeadowpartners.com
- By post: The Data Protection Officer, Aldermeadow Partners, 4400 Dominion Street, Suite 310, Burnaby, BC V5G 4G3, Canada
We may ask you to verify your identity before processing your request. This is to ensure that we do not disclose personal data to unauthorised persons. We will respond to your request within one calendar month unless an extension is required, in which case we will inform you accordingly.
9.10 Right to Lodge a Complaint
If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Canada, this is:
- Office of the Privacy Commissioner of Canada
Website: www.priv.gc.ca
Telephone: 1-800-282-1376 - Office of the Information and Privacy Commissioner for British Columbia
Website: www.oipc.bc.ca
Telephone: 1-250-387-5629
If you are located within the European Economic Area (EEA), you also have the right to lodge a complaint with the relevant data protection supervisory authority in your Member State.
We encourage you to contact us in the first instance before lodging a complaint with a supervisory authority so that we have the opportunity to address your concerns directly.
10. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include, but are not limited to:
- Encryption of data in transit using Secure Sockets Layer (SSL/TLS) technology
- Encryption of sensitive data at rest
- Access controls and role-based permissions to limit access to personal data on a need-to-know basis
- Regular security assessments, penetration testing, and vulnerability management
- Employee training on data protection and information security
- PCI-DSS compliant payment processing
- Physical security measures at our hotel-casino premises, including CCTV and access controls
- Incident response procedures for managing personal data breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and where required, we will notify you directly without undue delay.
Please note that no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
11. Children's Privacy
Our hotel-casino services, including online gaming and casino activities, are strictly intended for adults aged 19 years and over (or such higher age as required by applicable provincial law). We do not knowingly collect, use, or process personal data from individuals under the age of 19 in connection with gaming activities.
While our hotel may accommodate families and minor guests in non-gaming areas, we do not intentionally collect personal data from children under the age of 16 through our Website without the consent of a parent or legal guardian, as required by applicable law including Article 8 of the GDPR.
If you believe that we have inadvertently collected personal data from a child without appropriate consent, please contact us immediately at info@aldermeadowpartners.com so that we can take appropriate action, including deletion of such data.
12. Third-Party Websites and Links
Our Website may contain links to third-party websites, social media platforms, or partner services. This Privacy Policy applies solely to our Website and our processing activities. We are not responsible for the privacy practices, content, or data protection standards of any third-party websites. We encourage you to review the privacy policies of any third-party websites you visit before providing your personal data to them.
13. Responsible Gambling and Data Processing
As a licensed casino operator, we are committed to promoting responsible gambling and protecting the welfare of our guests. In this context, we may process personal data in order to:
- Operate and administer voluntary and mandatory self-exclusion programmes
- Monitor gaming activity for indicators of problem gambling and intervene appropriately
- Comply with regulatory requirements relating to the identification and protection of vulnerable persons
- Maintain records of self-exclusion or exclusion orders to prevent excluded individuals from accessing gaming facilities
The processing of personal data for responsible gambling purposes is carried out in compliance with our legal obligations under applicable gaming regulations and, where applicable, with your explicit consent. Such data is treated with the highest degree of confidentiality and sensitivity.
14. Changes to This Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes, we will notify you by posting the updated Privacy Policy on our Website with a revised "Last updated" date, and, where appropriate, by sending you a direct notification via email.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website or services following the publication of any changes constitutes your acknowledgement of the updated Privacy Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, the processing of your personal data, or the exercise of your data subject rights, please do not hesitate to contact us:
| Contact Person | The Data Protection Officer |
| Organisation | Aldermeadow Partners |
| Postal Address | 4400 Dominion Street, Suite 310, Burnaby, BC V5G 4G3, Canada |
| Email Address | info@aldermeadowpartners.com |
| Website | aldermeadowpartners.com |
We are committed to resolving any concerns you may have about our use of your personal data promptly and effectively. We will acknowledge receipt of your enquiry and aim to provide a substantive response within one calendar month.