Privacy Policy
Last updated: June 2025
At , we are deeply committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you visit our website at quietmeadowlabs.com, make a reservation, use our hotel and casino services, or otherwise interact with us. It also explains your rights under applicable data protection legislation, including the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), where applicable, as well as Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
Please read this Privacy Policy carefully. By using our website or services, you acknowledge that you have read and understood the practices described herein.
1. Data Controller
The entity responsible for collecting and processing your personal data (the "Data Controller") is:
| Legal Entity Name | |
|---|---|
| Trading Name | |
| Registered Address | |
| Country of Registration | Canada |
| Website | quietmeadowlabs.com |
| Privacy Contact Email | privacy@quietmeadowlabs.com |
If you have any questions, concerns, or requests relating to how we handle your personal data, please contact us using the details provided in the Contact Information section of this Policy.
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy and our data protection practices. If you wish to exercise any of your rights or have any concerns about our data processing activities, you may contact our DPO directly:
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| privacy@quietmeadowlabs.com |
2. Personal Data We Collect
We collect personal data in a variety of ways depending on how you interact with us. The categories of personal data we collect include, but are not limited to, the following:
2.1 Identity and Contact Information
- Full name (first name and surname)
- Date of birth and age verification data
- Gender (where provided voluntarily)
- Nationality and country of residence
- Postal address, including billing and correspondence addresses
- Email address
- Telephone number(s)
- Government-issued identification details (e.g., passport number, driver's licence number) where required for check-in or regulatory compliance
2.2 Reservation and Stay Information
- Booking reference numbers and reservation details
- Check-in and check-out dates
- Room type, preferences, and special requests
- Number and names of guests accompanying you
- Information about services used during your stay (restaurant, spa, room service, casino, etc.)
- Loyalty programme membership details and points history
- Records of complaints, compliments, and feedback provided
2.3 Financial and Payment Information
- Payment card details (processed securely via compliant payment processors; full card numbers are not stored by us)
- Billing address associated with your payment method
- Transaction history, invoices, and receipts
- Information required for anti-money laundering (AML) and Know Your Customer (KYC) compliance, including source of funds declarations where legally mandated
- Casino credit and wagering account information
2.4 Casino and Gaming Information
- Gaming account registration details
- Gambling activity records, including games played, wagers placed, and winnings
- Self-exclusion and responsible gambling declarations
- Problem gambling assessments and intervention records
- Player verification and age verification records
- Information required for gaming regulatory compliance
2.5 Technical and Usage Data
- IP address and approximate geolocation derived therefrom
- Browser type and version
- Operating system and device type
- Pages visited on our website and duration of visits
- Referring URLs and exit pages
- Date and time of website access
- Cookie identifiers and similar tracking technologies (see our Cookie Policy section)
- Wi-Fi usage data while on property
2.6 Communication and Marketing Data
- Records of communications between you and us (emails, letters, chat transcripts, phone call logs)
- Marketing preferences and opt-in/opt-out records
- Survey responses and feedback form submissions
- Social media handle or username if you interact with us on social media platforms
2.7 Special Categories of Personal Data
In certain limited circumstances, we may collect and process special categories of personal data as defined under GDPR Article 9. This includes:
- Health and dietary information (e.g., allergy requirements or disability-related accommodation needs) where voluntarily provided to ensure appropriate service delivery
- Information about gambling addiction or problem gambling where disclosed during responsible gambling interactions
We process special category data only where strictly necessary and on the basis of your explicit consent, or where processing is necessary to protect your vital interests, or as otherwise permitted under applicable law. You are under no obligation to provide special category data, though some services may be limited without it (for example, we cannot accommodate a specific dietary allergy unless you inform us of it).
2.8 Data Collected About Third Parties
If you provide us with personal data about other individuals (for example, co-guests, travel companions, or event attendees), you are responsible for ensuring that those individuals are aware of this Privacy Policy and that you have the necessary authority or consent to share their information with us.
2.9 Data We Do Not Collect Knowingly from Minors
Our services, including casino and gambling facilities, are strictly restricted to individuals who are at least 18 years of age (or the legal gambling age applicable in the relevant jurisdiction). We do not knowingly collect personal data from minors. If we discover that we have inadvertently collected personal data from a person under the applicable minimum age, we will take immediate steps to delete such data.
3. Legal Basis for Processing
We process your personal data only where we have a valid legal basis to do so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
3.1 Performance of a Contract (Article 6(1)(b))
We process personal data where processing is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing your booking or reservation details
- Facilitating your check-in and check-out
- Processing payments for hotel and casino services
- Managing your loyalty programme account
- Providing the specific hotel, dining, spa, and casino services you have requested
- Responding to pre-booking enquiries and quotations
3.2 Compliance with a Legal Obligation (Article 6(1)(c))
We process personal data where processing is necessary for compliance with a legal obligation to which we are subject under Canadian law, applicable provincial legislation, or other applicable regulations. This includes:
- Anti-money laundering (AML) and counter-terrorist financing (CTF) obligations
- Know Your Customer (KYC) verification requirements
- Gaming and casino regulatory reporting obligations
- Responsible gambling obligations, including self-exclusion register compliance
- Tax reporting and financial record-keeping obligations
- Health and safety obligations
- Responding to lawful requests from law enforcement or regulatory authorities
- Age verification requirements
3.3 Legitimate Interests (Article 6(1)(f))
We process personal data where processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Ensuring the security, safety, and integrity of our premises, guests, staff, and assets (including CCTV surveillance on property)
- Fraud detection, prevention, and investigation
- Maintaining and improving the performance and functionality of our website
- Analytics and statistical analysis to understand how our services are used and to improve them
- Direct marketing of similar products and services to existing customers (where permitted by applicable law and subject to your right to opt out)
- Managing and protecting our business and legal interests
- Communicating with you about changes to our services, terms, or policies
- Network and information security
- Debt collection and recovery
Where we rely on legitimate interests, we have balanced our interests against yours and are satisfied that our processing does not unduly override your privacy rights. You have the right to object to processing based on legitimate interests; please see the Your Rights section for further details.
3.4 Protection of Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where processing is necessary to protect the vital interests of you or another natural person. This may arise, for example, in a medical emergency on our premises.
3.5 Consent (Article 6(1)(a))
Where we rely on consent as the legal basis for processing, we will ask for your clear and affirmative consent at the time of collection. This applies to:
- Sending you marketing communications and promotional offers (where you are a new customer or where we require consent under applicable law)
- Placing non-essential cookies and similar tracking technologies on your device
- Processing special categories of personal data (e.g., health or dietary information)
- Any other processing activity for which we have specifically requested your consent
Where we rely on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. To withdraw consent, please contact us at privacy@quietmeadowlabs.com or use the unsubscribe link in our marketing emails.
3.6 Public Interest (Article 6(1)(e))
In limited circumstances, we may process personal data where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us. This may apply, for example, to certain regulatory reporting activities related to our casino operations.
4. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
4.1 Provision and Management of Hotel Services
- To process and manage room and facility bookings
- To facilitate check-in and check-out procedures
- To accommodate your special requests, preferences, and accessibility requirements
- To provide concierge, room service, dining, spa, and other on-property services
- To manage loyalty and rewards programme membership and benefits
- To handle lost property enquiries
4.2 Casino and Gaming Operations
- To register and manage gaming accounts
- To process gaming transactions and maintain accurate records
- To comply with gaming regulations, licensing requirements, and responsible gambling obligations
- To administer the self-exclusion programme and enforce exclusion decisions
- To detect and prevent fraudulent or suspicious gambling activity
- To fulfil AML/KYC compliance obligations
4.3 Payment Processing and Financial Management
- To process payments, issue invoices, and manage refunds
- To detect, investigate, and prevent fraudulent transactions
- To maintain accurate financial and accounting records as required by law
4.4 Security and Safety
- To operate CCTV surveillance systems on our premises for the safety of guests, staff, and property
- To manage access control to secure areas of our facilities
- To investigate incidents, accidents, and security breaches
- To comply with health and safety obligations
4.5 Customer Service and Communications
- To respond to your enquiries, requests, and complaints
- To notify you of changes to your booking or to our services
- To send transactional communications related to your stay or account
- To conduct satisfaction surveys and collect feedback
4.6 Marketing and Personalisation
- To send you marketing communications about our hotel, casino, promotions, events, and special offers, where you have consented or where we have a legitimate interest in doing so
- To personalise our website and communications based on your preferences and interaction history
- To invite you to participate in competitions, promotions, and loyalty scheme offers
- To conduct targeted advertising on third-party platforms (subject to your consent where required)
You may opt out of receiving marketing communications at any time by clicking the "unsubscribe" link in any marketing email, by updating your preferences in your account, or by contacting us at privacy@quietmeadowlabs.com.
4.7 Website and Service Improvement
- To analyse website traffic, usage patterns, and user behaviour to improve our online services
- To test, develop, and improve our website features and functionality
- To monitor and ensure the technical performance and security of our website
4.8 Legal and Regulatory Compliance
- To comply with our legal and regulatory obligations under Canadian federal and provincial law
- To respond to lawful requests from courts, law enforcement agencies, and regulatory bodies
- To establish, exercise, or defend legal claims
- To conduct internal audits and risk assessments
6. Sharing Your Personal Data
We do not sell your personal data. We may share your personal data with the following categories of recipients where necessary and in accordance with applicable law:
6.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf in accordance with our instructions and applicable data protection law. These include:
- Payment processing companies and financial institutions (for secure transaction handling)
- IT service providers, cloud hosting providers, and cybersecurity firms
- Reservation management and property management system providers
- Customer relationship management (CRM) platform providers
- Email marketing and communications platform providers
- Analytics and website performance service providers
- Printing, mailing, and logistics companies (for physical correspondence)
- Catering, events, and hospitality service providers engaged for specific events
- Casino operations software providers and gaming system vendors
All processors are bound by contractual obligations (Data Processing Agreements) requiring them to process data only on our documented instructions and to implement appropriate technical and organisational security measures.
6.2 Regulatory and Law Enforcement Authorities
We may disclose personal data to government bodies, regulatory authorities, law enforcement agencies, and courts where we are required or permitted to do so by law. This includes, but is not limited to:
- The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) for AML/CTF reporting
- Provincial gaming and liquor regulatory bodies
- Canada Revenue Agency (CRA) for tax compliance purposes
- Law enforcement agencies in connection with criminal investigations
- Courts or tribunals in connection with legal proceedings
6.3 Professional Advisors
We may share personal data with our legal advisors, accountants, auditors, and insurers where necessary for the provision of professional services, the defence of legal claims, or the conduct of audits.
6.4 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or other corporate transaction involving , personal data held by us may be transferred to the relevant third party as part of that transaction. We will notify you of any such transfer that materially affects the processing of your personal data.
6.5 With Your Consent
We may share your personal data with other third parties where you have given your explicit consent for us to do so.
6.6 International Data Transfers
Our primary operations are based in Canada. However, some of our third-party service providers may be located outside Canada, including in countries within the European Economic Area (EEA), the United Kingdom, or other jurisdictions. Where personal data is transferred outside Canada to countries that may not provide an equivalent level of data protection, we ensure that appropriate safeguards are in place. These safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the relevant data protection authority
- Binding Corporate Rules (BCRs) where applicable
- Transfers to countries deemed adequate by the relevant authority
- Any other mechanism approved under applicable data protection law
You may request further information about our international transfer safeguards by contacting us at privacy@quietmeadowlabs.com.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria we use to determine appropriate retention periods include:
- The nature and sensitivity of the personal data concerned
- The purposes for which it was collected and whether those purposes have been fulfilled
- Legal or regulatory obligations requiring us to retain data for a minimum period
- Whether there is an ongoing contractual relationship between us
- The potential risk of harm from unauthorised disclosure or use of the data
- Whether retention is necessary for the establishment, exercise, or defence of legal claims
7.1 Indicative Retention Periods
| Category of Data | Indicative Retention Period | Basis |
|---|---|---|
| Hotel reservation and stay records | 7 years from the date of stay | Legal obligation (tax/accounting) and legitimate interests |
| Financial and payment transaction records | 7 years from the date of transaction | Legal obligation (Canadian tax and accounting law) |
| Casino gaming and wagering records | 5–7 years from the date of activity, or as required by gaming regulations | Legal obligation (gaming regulatory requirements) |
| AML/KYC identification records | 7 years from the end of the business relationship | Legal obligation (FINTRAC / PCMLTFA) |
| Self-exclusion and responsible gambling records | Duration of exclusion period plus 7 years | Legal obligation and legitimate interests |
| CCTV footage | 30 days, unless required for an investigation | Legitimate interests (security) |
| Marketing consent records | 3 years after last interaction or until consent is withdrawn | Consent / legitimate interests |
| Customer service and complaint records | 3 years from resolution of the matter | Legitimate interests / legal claims |
| Website usage and analytics data (anonymised) | 26 months | Legitimate interests |
Upon expiry of the relevant retention period, personal data will be securely deleted, anonymised, or destroyed in accordance with our data retention and disposal procedures. In some circumstances, we may anonymise your personal data so that it can no longer be associated with you, in which case we may use such information without further notice to you.
8. Your Rights
Depending on your location and the applicable law, you may have a number of rights in relation to the personal data we hold about you. Under the GDPR and, where applicable, Canadian privacy law, these rights include:
8.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, along with information about how we use it, who we share it with, how long we retain it, and the safeguards in place for international transfers. This is commonly known as a "Subject Access Request" (SAR).
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will use reasonable efforts to rectify such data promptly.
8.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
In certain circumstances, you have the right to request that we delete your personal data. This right applies where:
- The personal data is no longer necessary for the purposes for which it was collected
- You withdraw your consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The personal data has been unlawfully processed
- Deletion is required to comply with a legal obligation
This right is not absolute; we may retain personal data where required by law, for the exercise or defence of legal claims, or for other legitimate purposes.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while the accuracy of your data is being verified, or where you have objected to processing and we are assessing whether our legitimate interests override yours.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract, and processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, machine-readable format, and to transmit that data to another controller.
8.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to processing of your personal data where we rely on legitimate interests as the legal basis. You also have the absolute right to object to the use of your personal data for direct marketing purposes, including profiling related to direct marketing, at any time without giving any reason.
8.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for the conclusion or performance of a contract, is authorised by law, or is based on your explicit consent. We will inform you if we engage in any such automated decision-making.
8.8 Right to Withdraw Consent
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal.
8.9 How to Exercise Your Rights
To exercise any of the rights described above, please submit a written request to:
- Email: privacy@quietmeadowlabs.com
- Post: The Data Protection Officer, ,
We may need to verify your identity before we can respond to your request. We will respond to your request within 30 days of receipt (or such other period as required by applicable law). In complex cases or where we receive a high volume of requests, we may extend this period by a further two months and will notify you accordingly.
We will not charge a fee for handling your rights request unless the request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act on the request.
8.10 Right to Lodge a Complaint
If you are not satisfied with how we handle your personal data or your rights request, you have the right to lodge a complaint with a supervisory authority. In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada (OPC):
- Website: www.priv.gc.ca
- Telephone: 1-800-282-1376
- Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada
If you are located in the European Economic Area, you also have the right to lodge a complaint with the data protection authority in your country of residence or place of work.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, so we encourage you to contact us in the first instance.
9. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption of personal data in transit (TLS/SSL) and at rest where appropriate
- Access controls and role-based permissions limiting access to personal data to authorised personnel only
- Regular security assessments, vulnerability scanning, and penetration testing
- Staff training on data protection and information security
- Physical security controls at our premises
- Incident response procedures and data breach notification protocols
- PCI DSS compliant payment processing
While we take all reasonable steps to protect your data, no method of electronic transmission or storage is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law.
10. Third-Party Links and Services
Our website may contain links to third-party websites, social media platforms, or services that are not operated by us. This Privacy Policy applies solely to our website and services. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites. We encourage you to review the privacy policy of any third-party website you visit.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or for other operational, legal, or regulatory reasons. When we make material changes, we will notify you by posting the updated policy on our website with a revised "Last Updated" date, and, where appropriate, by sending you a notification by email.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. Your continued use of our website or services after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy.
12. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, our data processing practices, or the exercise of your rights, please do not hesitate to contact us:
| Data Controller | |
|---|---|
| Contact Person | The Data Protection Officer |
| Address | |
| privacy@quietmeadowlabs.com | |
| Website | quietmeadowlabs.com |
We are committed to working with you to obtain a fair resolution of any complaint or concern relating to privacy. We will endeavour to acknowledge your enquiry within 5 business days and to resolve the matter within 30 days, or such other timeframe as required by law.