Privacy Policy
Last Updated: June 2025
(referred to herein as "we", "us", "our", or the "Hotel-Casino") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at www.xenerihotelinsight.com (the "Website"), make a reservation, visit our premises, or otherwise interact with us. This Policy also describes your rights under applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA), the Privacy Act, relevant provincial legislation, and, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR for guests and website visitors located in the European Economic Area or the United Kingdom.
Please read this Privacy Policy carefully. By accessing or using our Website, making a booking, or visiting Xeneri Hotelinsight located in Ottawa, Ontario, Canada, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our Website and services.
1. Data Controller
For the purposes of applicable data protection legislation, including the GDPR, the data controller responsible for your personal information is:
| Legal Entity Name | |
|---|---|
| Trading Name | Xeneri Hotelinsight |
| Registered Address | |
| Registration Country | Canada |
| Company Registration Number | 789456321RT0001 |
| VAT/GST Number | 789456321RC0001 |
| Website | www.xenerihotelinsight.com |
| Privacy Email | privacy@xenerihotelinsight.com |
As the data controller, we determine the purposes and means by which your personal information is processed. Where we act as a data processor on behalf of another controller (for example, a third-party booking platform), those controllers' privacy policies will govern the processing of your personal information in those contexts.
2. Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee compliance with this Privacy Policy and applicable data protection legislation. You may contact our DPO at any time regarding any matter relating to this Privacy Policy or the processing of your personal information:
| Name/Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@xenerihotelinsight.com |
3. Personal Information We Collect
We collect personal information about you in a variety of ways depending on how you interact with us. The categories of personal information we may collect are described below.
3.1 Information You Provide to Us Directly
- Identification and Contact Details: Your full name, date of birth, gender, nationality, government-issued identification number (such as passport or driver's licence number), home address, email address, and telephone number.
- Reservation and Stay Information: Check-in and check-out dates, room type and preferences, special requests, loyalty programme membership number, number and names of accompanying guests, and dietary or accessibility requirements.
- Payment Information: Credit or debit card details (card number, expiry date, CVV), billing address, and transaction history. Payment card data is processed using industry-standard encryption (PCI DSS compliant). We do not store full card numbers on our systems beyond the period necessary to complete the transaction.
- Casino and Gaming Information: Player loyalty or rewards card details, gaming transaction history, wagering activity, winnings and losses, and any self-exclusion or responsible gaming elections you make.
- Identity Verification for Casino Operations: Government-issued photo identification, age verification documents, source of funds documentation, and anti-money laundering (AML) due diligence records as required by applicable law, including the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).
- Correspondence and Communications: Messages, enquiries, complaints, or feedback you send to us via email, contact forms, telephone, or in-person interactions with our staff.
- Event and Restaurant Bookings: Details of any event, conference, spa, or dining reservations made with us, including dietary requirements and special requests.
- Account Credentials: Username and password for any online account you create on our Website.
- Marketing Preferences: Your elected preferences regarding marketing communications and loyalty programme participation.
3.2 Information We Collect Automatically
- Technical and Usage Data: IP address, browser type and version, operating system, device type and identifiers, time zone setting, pages visited, clickstream data, referral URLs, and duration of visit.
- Cookie and Tracking Data: Information collected through cookies, web beacons, pixel tags, and similar technologies as further described in our Cookie Policy (see Section 12 below).
- Location Data: General geolocation derived from your IP address. We do not collect precise GPS location data without your explicit consent.
3.3 Information We Collect From Third Parties
- Booking Platforms and Travel Agencies: Reservation details and contact information from third-party online travel agencies (OTAs), global distribution systems (GDS), or travel management companies through which you make a booking.
- Credit Reference and Fraud Prevention Agencies: Information to verify your identity, assess creditworthiness, and prevent fraud.
- Regulatory and Law Enforcement Authorities: Information provided to us pursuant to legal obligations, court orders, or official regulatory enquiries.
- Social Media Platforms: If you interact with our social media pages or log in to our Website using a social media account, we may receive certain profile information from those platforms in accordance with your privacy settings on those platforms.
- Publicly Available Sources: Publicly accessible databases, sanctions lists, and registers for AML and regulatory compliance purposes.
3.4 Special Categories of Personal Information
We may, in limited circumstances, collect special categories of personal information (also referred to as sensitive personal information) as defined under GDPR Article 9 and equivalent Canadian legislation. This includes:
- Health and Accessibility Information: Disability, mobility, or dietary requirements you voluntarily provide to us to enable us to accommodate your needs during your stay.
- Responsible Gaming and Self-Exclusion Data: Information relating to problem gambling declarations, voluntary self-exclusion programmes, or referrals to support services, which may, in certain contexts, constitute health-related data.
We process such special category data only where we have obtained your explicit consent (GDPR Article 9(2)(a)) or where processing is necessary for the establishment, exercise, or defence of legal claims, or where another lawful basis under Article 9(2) applies. We implement heightened safeguards for such data.
We do not knowingly collect personal information from individuals under the age of 18. Casino gaming services are strictly restricted to individuals who are 19 years of age or older in the Province of Ontario. If you believe we have inadvertently collected personal information from a minor, please contact us immediately at privacy@xenerihotelinsight.com.
4. Legal Basis for Processing Personal Information
Where the GDPR or equivalent legislation applies to our processing of your personal information, we are required to identify a lawful basis for each processing activity. The legal bases we rely on are set out in GDPR Article 6 and are described below. We may rely on more than one legal basis in respect of the same processing activity.
4.1 Performance of a Contract (Article 6(1)(b))
We process your personal information where it is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This includes:
- Processing your hotel reservation, check-in, and check-out;
- Managing your stay, including room assignments and service requests;
- Processing payments for accommodation, casino services, food and beverage, spa, and other hotel services;
- Administering your loyalty programme membership and associated benefits;
- Managing event, conference, and dining bookings.
4.2 Compliance With a Legal Obligation (Article 6(1)(c))
We process your personal information where it is necessary to comply with a legal obligation to which we are subject under Canadian federal or provincial law, or other applicable law. This includes:
- Anti-money laundering and counter-terrorist financing obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated regulations;
- Identity verification and age verification requirements under gaming regulations;
- Tax reporting and record-keeping obligations under the Income Tax Act and applicable provincial tax legislation;
- Reporting requirements to the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC);
- Compliance with court orders, judicial processes, and regulatory directives;
- Occupational health and safety obligations;
- Guest registration requirements under provincial innkeeper legislation.
4.3 Legitimate Interests (Article 6(1)(f))
We process your personal information where it is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include:
- Improving and personalising the services and experience we offer to guests;
- Ensuring the security of our premises, guests, staff, and assets, including through CCTV surveillance;
- Preventing and detecting fraud, theft, cheating, and other unlawful activity on our premises and Website;
- Managing and defending legal claims and disputes;
- Conducting business analytics, financial reporting, and strategic planning;
- Sending you direct marketing communications about our services where you are an existing customer (subject to your right to opt out);
- Administering and improving our Website and online services;
- Maintaining the integrity of our casino operations, including detecting advantage play and collusion;
- Sharing personal information within our corporate group for internal administrative purposes.
Where we rely on legitimate interests, you have the right to object to such processing. Please see Section 9 (Your Privacy Rights) for further information.
4.4 Consent (Article 6(1)(a))
In certain circumstances, we will ask for your consent before processing your personal information. This includes:
- Sending you marketing and promotional communications where you are not an existing customer;
- Setting non-essential cookies on your device (please see Section 12);
- Processing special categories of personal information such as health or accessibility data where no other lawful basis applies;
- Sharing your personal information with selected third-party partners for their own marketing purposes, where you have opted in.
Where we rely on consent as our lawful basis, you have the right to withdraw your consent at any time without detriment to you. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@xenerihotelinsight.com or use the unsubscribe mechanism in any marketing communication.
4.5 Vital Interests (Article 6(1)(d))
We may process your personal information where it is necessary to protect your vital interests or those of another natural person, for example in a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e))
In limited circumstances, we may process your personal information where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, for example, where we cooperate with regulators exercising statutory powers.
5. How We Use Your Personal Information
We use the personal information we collect for the following purposes, each grounded in one or more of the legal bases described in Section 4:
5.1 Hotel and Hospitality Services
- Processing, confirming, and managing your accommodation reservations;
- Facilitating your check-in, check-out, and in-stay experience;
- Fulfilling room preference and special service requests;
- Providing concierge, spa, fitness, dining, and other ancillary hotel services;
- Managing event and conference bookings;
- Sending reservation confirmations, pre-arrival communications, and post-stay follow-ups.
5.2 Casino and Gaming Services
- Verifying your identity and age for access to gaming facilities;
- Managing your player loyalty or rewards account;
- Processing gaming transactions, credits, and redemptions;
- Administering jackpot and prize notifications;
- Meeting responsible gaming obligations, including monitoring for problem gambling indicators;
- Enforcing self-exclusion agreements and voluntary exclusion programmes;
- Detecting and preventing cheating, fraud, and money laundering in gaming operations.
5.3 Payment Processing and Financial Administration
- Processing and reconciling payments for all hotel and casino services;
- Issuing invoices, receipts, and tax documentation;
- Managing credit facilities and payment disputes;
- Complying with tax reporting obligations.
5.4 Security and Safety
- Operating CCTV and surveillance systems throughout our premises for the safety and security of guests and staff;
- Controlling access to restricted areas of the hotel and casino;
- Investigating incidents, complaints, accidents, and criminal activity;
- Cooperating with law enforcement and regulatory authorities;
- Responding to emergencies and medical situations.
5.5 Legal and Regulatory Compliance
- Meeting our obligations under AML, PCMLTFA, and FINTRAC reporting requirements;
- Complying with gaming licensing and regulatory conditions;
- Responding to legal processes, court orders, and governmental requests;
- Establishing, exercising, or defending legal claims.
5.6 Marketing and Communications
- Sending you information about our offers, promotions, events, and services where you have consented or where permitted by law;
- Personalising marketing communications based on your stay history and preferences;
- Administering competitions, prize draws, and promotional campaigns;
- Conducting guest satisfaction surveys and soliciting reviews (subject to your right to opt out).
5.7 Website and Service Improvement
- Analysing how visitors use our Website to improve functionality and user experience;
- Testing and developing new features and services;
- Managing our online booking platform and digital customer experience;
- Preventing and detecting unauthorised access, technical vulnerabilities, and cybersecurity threats.
5.8 Business Operations and Analytics
- Conducting internal business analysis, revenue management, and capacity planning;
- Training and quality assurance for our staff;
- Managing supplier and partner relationships;
- Pursuing mergers, acquisitions, financing, or corporate restructuring activities.
6. Sharing Your Personal Information
We do not sell your personal information to third parties. We may share your personal information with the following categories of recipients in the circumstances described below.
6.1 Service Providers and Processors
We engage trusted third-party service providers who process personal information on our behalf under written data processing agreements. These include:
- Payment processing and card acquirer services;
- Cloud hosting, data storage, and IT infrastructure providers;
- Property management system (PMS) and casino management system (CMS) vendors;
- Central reservation system (CRS) and revenue management platform providers;
- Email marketing and customer relationship management (CRM) platform providers;
- Analytics and website optimisation service providers;
- Fraud detection and identity verification service providers;
- CCTV monitoring and physical security service providers;
- Loyalty programme technology and fulfilment providers;
- Legal, accounting, and auditing professionals acting in a service capacity.
6.2 Booking Platforms and Distribution Partners
Where you make a reservation through a third-party online travel agency, travel agent, or global distribution system, we may share confirmation and stay-related information with that platform to service your booking.
6.3 Regulatory and Law Enforcement Authorities
We may disclose your personal information to governmental bodies, law enforcement agencies, regulatory authorities, and courts where we are required or permitted to do so by applicable law, including but not limited to:
- FINTRAC and other financial intelligence bodies for AML and counter-terrorism financing reporting;
- The Alcohol and Gaming Commission of Ontario (AGCO) or other gaming regulators;
- The Canada Revenue Agency (CRA) for tax compliance purposes;
- Police services and law enforcement agencies in response to valid legal requests or in case of suspected criminal activity;
- Courts and arbitral tribunals in connection with legal proceedings.
6.4 Corporate Group
We may share your personal information with other members of our corporate group for internal administrative, operational, and compliance purposes. All intra-group transfers are governed by appropriate data sharing agreements.
6.5 Business Transfers
In the event of a merger, acquisition, amalgamation, financing, sale of assets, or other corporate reorganisation, your personal information may be disclosed to prospective or actual purchasers, investors, or successors as part of due diligence or the transaction process, subject to appropriate confidentiality obligations.
6.6 Professional Advisors
We may share your personal information with our lawyers, accountants, auditors, insurers, and other professional advisors where reasonably necessary for the provision of their professional services to us, subject to duties of professional confidentiality.
6.7 International Transfers
Our service providers may be located in jurisdictions outside Canada, including in the United States, the European Economic Area, or other countries. Where we transfer personal information outside of Canada, we take steps to ensure that appropriate safeguards are in place to protect your information, including reliance on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where GDPR applies;
- Contractual obligations requiring the recipient to provide a level of protection equivalent to Canadian privacy law;
- Adequacy findings or equivalent frameworks applicable under PIPEDA or provincial legislation.
You may request further information about international transfers and the safeguards we have in place by contacting us at privacy@xenerihotelinsight.com.
7. Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria we use to determine retention periods include:
- Contractual and Operational Data: Guest reservation records, stay history, and payment records are generally retained for a period of seven (7) years following the conclusion of your stay or the last transaction, in accordance with Canadian tax and accounting legislation.
- Casino and Gaming Records: Gaming transaction records, player loyalty account data, and AML due diligence documentation are retained for a minimum of five (5) to seven (7) years from the date of the relevant transaction or account closure, in compliance with PCMLTFA requirements and gaming regulatory obligations. FINTRAC records are retained for five (5) years as required by law.
- Marketing Data: Contact details and marketing preferences held on the basis of consent or legitimate interests are retained until you opt out or withdraw consent, or for up to three (3) years following your last interaction with us, after which we will seek refreshed consent or delete the data.
- CCTV Footage: Surveillance footage is typically retained for a period of thirty (30) to ninety (90) days, unless it is required in connection with an incident, investigation, or legal proceeding, in which case it may be retained for longer.
- Website and Technical Data: Server logs and analytical data are generally retained for a period of up to twelve (12) to twenty-four (24) months.
- Legal Claims and Disputes: Data relevant to pending or anticipated litigation, regulatory proceedings, or insurance claims will be retained until the matter is finally resolved and any applicable limitation period has expired.
- Self-Exclusion and Responsible Gaming Records: Records related to self-exclusion elections are retained in accordance with applicable gaming regulatory requirements and for the duration necessary to give effect to the exclusion.
At the end of the applicable retention period, personal information is securely deleted or anonymised. Where full deletion is not immediately practicable, we will ensure the data is restricted from active use until deletion is possible.
8. Your Privacy Rights
Depending on your location and the legislation applicable to you, you may have the following rights in relation to your personal information. We will respond to valid requests within the timeframes required by applicable law (generally within 30 days under GDPR, subject to possible extension).
8.1 Right of Access
You have the right to request confirmation of whether we process personal information about you and, if so, to receive a copy of that personal information along with certain supplementary information about how it is processed (GDPR Article 15; PIPEDA Principle 9).
8.2 Right to Rectification
You have the right to request that we correct any inaccurate personal information we hold about you and to have incomplete personal information completed (GDPR Article 16).
8.3 Right to Erasure ("Right to Be Forgotten")
In certain circumstances, you have the right to request that we delete your personal information, for example where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and no other lawful basis for processing applies (GDPR Article 17). Please note that this right is subject to limitations, including where we are required to retain data by law or for the establishment, exercise, or defence of legal claims.
8.4 Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal information in certain circumstances, for example where you contest its accuracy, while we verify the position (GDPR Article 18).
8.5 Right to Data Portability
Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to request that we transmit it directly to another controller where technically feasible (GDPR Article 20).
8.6 Right to Object
You have the right to object at any time to the processing of your personal information where that processing is based on our legitimate interests (GDPR Article 21(1)). You also have an unconditional right to object at any time to the processing of your personal information for direct marketing purposes, including profiling related to such marketing (GDPR Article 21(2)). We will cease such processing upon receipt of a valid objection, unless we can demonstrate compelling legitimate grounds that override your interests.
8.7 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out prior to withdrawal (GDPR Article 7(3)).
8.8 Rights Related to Automated Decision-Making and Profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless the automated decision is necessary for entering into or performing a contract, is authorised by applicable law, or is based on your explicit consent (GDPR Article 22). Where we engage in such processing, we will inform you and provide appropriate safeguards.
8.9 Right to Lodge a Complaint
If you believe that our processing of your personal information infringes applicable data protection legislation, you have the right to lodge a complaint with the relevant supervisory authority:
- Canada: The Office of the Privacy Commissioner of Canada (OPC), 30 Victoria Street, Gatineau, QC K1A 1H3. Website: www.priv.gc.ca. Telephone: 1-800-282-1376.
- Ontario: The Information and Privacy Commissioner of Ontario (IPC), 2 Bloor Street East, Suite 1400, Toronto, ON M4W 1A8. Website: www.ipc.on.ca.
- European Union / EEA: The supervisory authority of the EU Member State in which you reside or work, or in which the alleged infringement occurred.
- United Kingdom: The Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Website: ico.org.uk.
We encourage you to contact us in the first instance at privacy@xenerihotelinsight.com so that we have the opportunity to address your concerns directly.
8.10 Exercising Your Rights
To exercise any of the rights described above, please submit a written request to our Data Protection Officer at privacy@xenerihotelinsight.com or by post to:
The Data Protection Officer
We may need to verify your identity before processing your request. We will not charge a fee for responding to your request unless it is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to respond, in accordance with applicable law.
9. Security of Your Personal Information
We implement appropriate technical and organisational security measures to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit using Transport Layer Security (TLS) protocols;
- Encryption of sensitive data at rest;
- Payment card data processing in accordance with the Payment Card Industry Data Security Standard (PCI DSS);
- Role-based access controls and least-privilege access principles;
- Regular security assessments, penetration testing, and vulnerability management;
- Staff training on data protection and information security;
- Physical access controls at our premises and data processing facilities;
- Incident response and data breach notification procedures.
While we take all reasonable steps to protect your personal information, no method of electronic transmission or storage is completely secure. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately at privacy@xenerihotelinsight.com.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, we will notify affected individuals directly, in accordance with our obligations under applicable law (GDPR Articles 33 and 34; PIPEDA Breach of Security Safeguards Regulations).
10. Profiling and Automated Decision-Making
We may use automated processing, including profiling, for the following purposes:
- Personalisation: We may analyse your stay history, gaming activity, and preferences to personalise our services, offers, and communications. This profiling does not produce legally significant automated decisions.
- Fraud Detection: We use automated tools to detect unusual payment activity, potential money laundering, and fraudulent transactions. Where such automated screening generates an alert that may affect you, human review is conducted before any action is taken.
- Responsible Gaming Monitoring: Automated systems may flag patterns of gaming behaviour consistent with problem gambling indicators. Any resulting intervention involves human assessment by trained responsible gaming staff.
We do not make solely automated decisions that produce significant legal effects about you without human oversight. If you have questions about profiling activities, please contact our DPO.
12. Third-Party Websites and Links
Our Website may contain links to third-party websites, including booking partners, social media platforms, and other service providers. This Privacy Policy does not apply to those third-party websites. We encourage you to review the privacy policies of any third-party websites you visit, as we have no control over their data collection or processing practices and accept no responsibility for them.
13. Responsible Gaming and Self-Exclusion
Xeneri Hotelinsight is committed to promoting responsible gaming. We process personal information in the context of responsible gaming programmes, including self-exclusion registrations, voluntary spending limits, and participation in support referral programmes. Information collected for these purposes is treated with heightened confidentiality and used solely for the administration of responsible gaming measures, compliance with regulatory obligations, and, where necessary, safeguarding your wellbeing.
Self-exclusion data will not be used for marketing purposes and will be retained for the duration of the exclusion period and as required by applicable gaming regulatory requirements thereafter.
For assistance with responsible gaming, please contact our Responsible Gaming team on-site or visit the Responsible Gambling Council of Canada at www.responsiblegambling.org.
14. Children's Privacy
Our Website and casino services are not directed at individuals under the age of 18. We do not knowingly collect or process personal information from children under 18 years of age. Casino gaming is restricted to persons aged 19 years or older in Ontario. If we become aware that we have inadvertently collected personal information from a person under the age of 18, we will take immediate steps to delete such information from our records. Parents or guardians who believe their child has provided us with personal information should contact us at privacy@xenerihotelinsight.com.
15. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable legislation, or regulatory guidance. The date at the top of this Privacy Policy indicates when it was last revised. We encourage you to review this Privacy Policy periodically.
Where changes to this Privacy Policy are material, we will provide you with prominent notice, such as by posting a notice on our Website homepage or sending you a notification by email where we hold your contact details, prior to the changes taking effect.
Your continued use of our Website and services after any update to this Privacy Policy constitutes your acknowledgement of the revised Policy. If you do not agree with any changes, you should discontinue use of our Website and services and may request deletion of your personal information as described in Section 8.
16. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our handling of your personal information, or if you wish to exercise any of your privacy rights, please contact us using the details below. We are committed to responding to all legitimate enquiries promptly and in accordance with our legal obligations.
| Data Controller | |
|---|---|
| Attention | The Data Protection Officer |
| Postal Address | |
| privacy@xenerihotelinsight.com | |
| Website | www.xenerihotelinsight.com |
We will aim to acknowledge your enquiry within five (5) business days and to respond fully within thirty (30) days. Where your request is complex or where you have submitted multiple requests, we may extend this period by a further two (2) months, in which case we will notify you of the extension and the reasons for it, in accordance with GDPR Article 12(3).
If you are not satisfied with our response, you have the right to lodge a complaint with the applicable privacy supervisory authority as described in Section 8.9 of this Privacy Policy.