Privacy Policy

Last updated: June 2025

This Privacy Policy describes how Velmorithotelspa Inc. (hereinafter referred to as "we", "us", "our", or "the Hotel") collects, uses, discloses, and protects the personal data of individuals who visit our website at velmorithotelspa.com, make reservations, use our hotel, spa, and casino services, or otherwise interact with us. We are committed to protecting your privacy and processing your personal data in a transparent, fair, and lawful manner, in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Personal Information Protection and Electronic Documents Act (PIPEDA), and all other applicable Canadian and international privacy legislation.

Please read this Privacy Policy carefully before using our website or services. By accessing our website or providing us with your personal data, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our website and services.

1. Data Controller

The data controller responsible for the processing of your personal data is:

Company Name Velmorithotelspa Inc.
Registration Number Corporation No. 8062947
VAT / Tax Number GST/HST No. 806 294 715 RT0001
Registered Address 721 Main Street, Canmore, AB T1W 2B2, Canada
Registration Country Canada
Website velmorithotelspa.com
Privacy Contact Email privacy@velmorithotelspa.com

1.1 Data Protection Officer (DPO)

We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with applicable privacy laws. You may contact our Data Protection Officer directly for any privacy-related inquiries, requests, or concerns:

Name / Title The Data Protection Officer
Organisation Velmorithotelspa Inc.
Address 721 Main Street, Canmore, AB T1W 2B2, Canada
Email privacy@velmorithotelspa.com

2. Personal Data We Collect

We collect various categories of personal data depending on your interaction with us. Personal data means any information relating to an identified or identifiable natural person. We collect data in the following categories:

2.1 Identity and Contact Data

  • Full name (first name, last name)
  • Date of birth and age verification information
  • Gender
  • Nationality and country of residence
  • Passport number, driver's licence, or other government-issued identification details (required for hotel check-in and casino regulatory compliance)
  • Email address
  • Telephone number (landline and/or mobile)
  • Postal address (home and/or billing address)

2.2 Reservation and Booking Data

  • Arrival and departure dates
  • Room type and preferences
  • Number and ages of guests
  • Special requests (e.g., dietary requirements, accessibility needs, room configurations)
  • Booking reference numbers and history
  • Source of reservation (direct, travel agency, online travel agent, corporate)
  • Corporate account or travel agent information

2.3 Payment and Financial Data

  • Payment card details (card number truncated, expiry date, card type — full card details are processed securely by our PCI-DSS compliant payment processor and are not stored by us)
  • Billing address
  • Transaction history and invoices
  • Bank account details (where applicable for refunds)
  • Currency preferences

2.4 Stay and Service Data

  • Records of services used during your stay (restaurant, spa, room service, fitness centre, casino)
  • Loyalty programme membership details and points balance
  • Guest preferences and feedback collected during or after your stay
  • Maintenance or housekeeping requests
  • In-room entertainment preferences (where applicable)

2.5 Casino and Gaming Data

In connection with our casino operations, we are legally obligated to collect and process certain categories of information in compliance with applicable gaming regulations, anti-money laundering (AML) laws, and responsible gambling obligations:

  • Government-issued identity verification documents
  • Age verification records
  • Gaming activity records (games played, bets placed, wins and losses — where legally required)
  • Player exclusion and self-exclusion records
  • Anti-money laundering (AML) screening and due diligence records
  • Source of funds information (where required by AML regulations)
  • Responsible gambling assessments and communications

2.6 Technical and Usage Data

  • IP address and approximate geolocation derived therefrom
  • Browser type and version
  • Operating system and device type
  • Pages visited on our website and time spent on each page
  • Referral URL (the page that referred you to our website)
  • Clickstream data and interaction data
  • Cookie identifiers and tracking technology data (see our Cookie Policy for full details)
  • Session identifiers and log files

2.7 CCTV and Security Data

  • CCTV footage and images captured in public areas of the hotel and casino (lobbies, corridors, gaming floor, car park, entrances and exits)
  • Access control records (key card usage logs)
  • Security incident reports where your personal data is referenced

2.8 Communication and Marketing Data

  • Email correspondence and inquiries submitted via our website contact forms
  • Social media interactions (where you engage with our social media accounts)
  • Survey responses and competition entries
  • Marketing preferences and opt-in/opt-out records
  • Records of marketing communications sent to you

2.9 Special Categories of Personal Data

In certain circumstances we may need to process special categories of personal data as defined under Article 9 GDPR. We do so only where strictly necessary and where an appropriate legal basis applies:

  • Health and disability information: Where you inform us of a disability, medical condition, or dietary requirement for the purpose of providing appropriate accommodations, accessible rooms, or suitable food options.
  • Religious or philosophical beliefs: Where relevant to dietary requirements (e.g., Halal, Kosher, or other religiously prescribed meals).
  • Biometric data: Only if and where biometric access systems are deployed (guests will be separately notified in such cases).

We process special category data only on the basis of your explicit consent (Article 9(2)(a) GDPR), or where processing is necessary for reasons of substantial public interest under applicable law (Article 9(2)(g) GDPR), or where necessary to protect your vital interests (Article 9(2)(c) GDPR).

2.10 Data Collected from Third Parties

We may receive personal data about you from third parties, including:

  • Online travel agents and booking platforms (e.g., Booking.com, Expedia, Hotels.com)
  • Travel agents and tour operators
  • Corporate account holders making reservations on your behalf
  • Credit reference and fraud prevention agencies
  • Government and regulatory authorities (in connection with AML or gaming compliance)
  • Social media platforms (where you interact with our pages or use social login features)

2.11 Data You Are Not Required to Provide

Where the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract with us, we will inform you of this at the point of collection. Where providing personal data is optional, we will make this clear. Failure to provide mandatory data may result in our inability to provide certain services.

4. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

4.1 Providing Accommodation and Hospitality Services

  • Processing and confirming your reservation, including sending booking confirmation and pre-arrival communications
  • Managing your check-in and check-out process
  • Providing room service, housekeeping, concierge, and other in-stay services
  • Facilitating spa appointments and treatments
  • Managing restaurant reservations and food and beverage services
  • Providing accessibility and special needs accommodations

4.2 Casino and Gaming Operations

  • Verifying your identity and age before permitting access to the casino floor
  • Administering casino player accounts and gaming activities
  • Operating player loyalty and rewards programmes within the casino
  • Implementing responsible gambling measures, including self-exclusion programmes
  • Conducting AML and counter-terrorism financing (CTF) due diligence and monitoring
  • Complying with reporting obligations to gaming regulatory authorities

4.3 Payment Processing and Financial Administration

  • Processing payments for all services rendered
  • Issuing invoices, receipts, and financial records
  • Managing refunds and chargebacks
  • Recovering unpaid debts
  • Maintaining financial records for tax and accounting purposes

4.4 Customer Service and Communications

  • Responding to your enquiries, feedback, complaints, and requests
  • Sending you service-related communications (e.g., booking confirmations, pre-arrival information, post-stay surveys)
  • Managing your loyalty programme account and communicating rewards and offers
  • Providing assistance in the event of an emergency during your stay

4.5 Marketing and Promotional Activities

  • Sending you personalised marketing communications about our hotel, spa, casino, and related offers where you have consented or where we have a legitimate interest to do so
  • Conducting prize draws, competitions, and promotional campaigns
  • Displaying targeted advertising on third-party platforms (e.g., social media advertising) based on your profile and interests
  • Analysing the effectiveness of our marketing campaigns

You may opt out of receiving marketing communications at any time by clicking the "unsubscribe" link in any marketing email, by contacting us at privacy@velmorithotelspa.com, or by updating your preferences in your guest account.

4.6 Security and Safety

  • Operating CCTV surveillance systems to ensure the safety and security of guests, staff, and the premises
  • Managing access control and preventing unauthorised entry
  • Investigating security incidents, theft, and other criminal activity
  • Ensuring the integrity of gaming operations and preventing cheating or fraud on the casino floor

4.7 Legal and Regulatory Compliance

  • Fulfilling our obligations under applicable laws and regulations
  • Co-operating with law enforcement and regulatory investigations
  • Establishing, exercising, or defending legal claims
  • Managing risk and conducting compliance audits

4.8 Business Improvement and Analytics

  • Analysing website usage data to improve the functionality and user experience of our website
  • Conducting market research and guest satisfaction surveys
  • Developing new products, services, and offers
  • Internal reporting, business planning, and performance monitoring

5. Sharing Your Personal Data

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients only to the extent necessary and in accordance with applicable data protection law:

5.1 Service Providers and Data Processors

We engage trusted third-party service providers who process personal data on our behalf and in accordance with our instructions. These include:

  • IT and technology providers: Property management system (PMS) providers, cloud hosting and data storage providers, cybersecurity providers
  • Payment processors: PCI-DSS compliant payment gateway and card processing providers
  • Booking and reservation platforms: Online travel agents and booking engine providers
  • Marketing and communications providers: Email marketing platforms, CRM systems, and digital advertising platforms
  • Customer service platforms: Help desk software and live chat providers
  • Analytics providers: Website analytics services (e.g., Google Analytics)
  • Casino software providers: Gaming system operators and casino management system providers
  • Security and surveillance providers: CCTV system providers and monitoring services
  • Professional service providers: Legal advisors, accountants, auditors, and insurance providers

All service providers are subject to contractual data processing agreements requiring them to maintain appropriate security measures and process personal data only as instructed by us.

5.2 Regulatory and Government Authorities

We may be required to share personal data with regulatory, law enforcement, and government authorities, including:

  • The Alberta gaming regulator (AGLC)
  • The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) for AML reporting purposes
  • The Canada Revenue Agency (CRA)
  • Royal Canadian Mounted Police (RCMP) and other law enforcement agencies, where required by law or court order
  • Any other competent public authority where disclosure is required by applicable law

5.3 Business Partners

Where you have consented, or where we have a legitimate interest to do so, we may share certain data with carefully selected business partners, including:

  • Tour operators and travel agents (to manage group bookings or corporate accounts)
  • Restaurant and entertainment partners operating within or affiliated with the hotel
  • Spa and wellness service providers (where third-party specialists are engaged)

5.4 Corporate Group

We may share personal data within our corporate group of companies for internal administrative purposes, including financial consolidation, shared IT infrastructure, and centralised customer relationship management, in each case subject to appropriate internal data sharing agreements.

5.5 Business Transfers

In the event of a merger, acquisition, sale of assets, or other business restructuring, personal data held by us may be transferred to a successor entity, subject to appropriate confidentiality and data protection obligations. We will notify you of any such transfer where required by law.

5.6 International Transfers

Some of our service providers and partners are located outside of Canada and the European Economic Area (EEA). Where we transfer personal data to countries that do not provide an equivalent level of data protection, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions issued by the European Commission recognising the destination country as providing an adequate level of protection
  • Binding Corporate Rules (BCRs) where applicable
  • Certification schemes such as the EU-US Data Privacy Framework (where applicable)

You may request a copy of the applicable transfer safeguards by contacting our Data Protection Officer at privacy@velmorithotelspa.com.

6. Data Retention

We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required or permitted by applicable law. Our retention periods are determined with reference to the nature of the data, the purpose of processing, and applicable legal and regulatory obligations. The following general retention periods apply:

Category of Data Retention Period Basis
Guest reservation and stay records 7 years from the date of stay Legal obligation (tax and accounting records); contractual
Payment and financial records 7 years from the date of transaction Legal obligation (CRA requirements)
Casino and gaming records 5–10 years, as required by gaming regulations Legal obligation (AGLC and FINTRAC requirements)
AML due diligence and screening records 5 years from the end of the business relationship or date of transaction Legal obligation (Proceeds of Crime (Money Laundering) and Terrorist Financing Act)
Identity verification documents As required by applicable regulation (minimum 5 years) Legal obligation
CCTV footage 31 days (extended if required for investigation or legal proceedings) Legitimate interests; legal obligation (gaming licence conditions)
Marketing consent and preference records Duration of marketing relationship plus 3 years Legitimate interests; legal obligation (to demonstrate consent)
Customer service and complaint records 3 years from resolution of the complaint Legitimate interests; legal claims
Website usage and cookie data Up to 24 months (see Cookie Policy) Consent; legitimate interests
Self-exclusion records (casino) Duration of exclusion plus minimum 5 years Legal obligation; vital interests
Legal claims and dispute records Until final resolution plus applicable limitation period (generally 6 years) Legitimate interests; legal obligation

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data retention and disposal procedures. Where data is anonymised rather than deleted, the anonymised data may be retained indefinitely for statistical and analytical purposes.

7. Your Rights Under GDPR and Applicable Privacy Law

Depending on your location and the applicable legal framework, you may have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month of receipt, and we will not charge a fee for the exercise of your rights unless your request is manifestly unfounded, excessive, or repetitive.

7.1 Right of Access (Article 15 GDPR)

You have the right to request confirmation of whether we process personal data about you, and if so, to receive a copy of that data along with information about how and why it is being processed, the categories of data concerned, the recipients with whom it has been shared, the applicable retention periods, and information about your other rights.

7.2 Right to Rectification (Article 16 GDPR)

You have the right to request that we correct any inaccurate personal data we hold about you, and to have any incomplete personal data completed, including by providing a supplementary statement.

7.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)

You have the right to request that we delete your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where you withdraw consent on which processing was based, where you object to processing and there are no overriding legitimate grounds, or where the data has been unlawfully processed. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

7.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request that we restrict the processing of your personal data in certain circumstances, for example where you contest the accuracy of the data, where processing is unlawful but you oppose erasure, where we no longer need the data but you require it for legal claims, or where you have objected to processing pending verification of whether our legitimate grounds override your interests.

7.5 Right to Data Portability (Article 20 GDPR)

Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller where technically feasible.

7.6 Right to Object (Article 21 GDPR)

You have the right to object to the processing of your personal data at any time where we rely on our legitimate interests as the legal basis for processing. Upon receipt of your objection, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.

You have an absolute right to object to processing for direct marketing purposes, and we will stop processing your data for this purpose immediately upon receipt of your objection.

7.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we engage in such processing, we will inform you and provide you with the opportunity to request human review, express your point of view, and challenge the decision. At present, we do not make solely automated decisions that produce legal or similarly significant effects, but we may use profiling for marketing personalisation purposes subject to your consent.

7.8 Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

7.9 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority. In Canada, the applicable authority is the Office of the Privacy Commissioner of Canada (OPC):

If you are located in the European Economic Area (EEA), you may also lodge a complaint with the data protection supervisory authority in your country of residence or place of work.

We encourage you to contact us in the first instance so that we may address your concerns directly.

7.10 Exercising Your Rights

To exercise any of the rights described above, please submit a written request to our Data Protection Officer:

  • By email: privacy@velmorithotelspa.com
  • By post: The Data Protection Officer, Velmorithotelspa Inc., 721 Main Street, Canmore, AB T1W 2B2, Canada

We may need to verify your identity before processing your request. We will ask you to provide reasonable proof of identity to ensure that personal data is not disclosed to an unauthorised party. We will respond to your request within 30 calendar days. In complex cases or where we receive a large number of requests, we may extend this period by a further two months, and we will notify you of any such extension within the initial 30-day period.

8. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to provide functionality, improve your browsing experience, analyse site traffic, and deliver personalised advertising. Cookies are small text files placed on your device when you visit a website.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for the website to function and cannot be switched off. They are set in response to actions made by you (such as setting privacy preferences, logging in, or completing forms). These cookies do not require your consent.
  • Performance and Analytics Cookies: Allow us to measure and improve the performance of our website by collecting information about how visitors use our site (e.g., pages visited, time spent, error messages). These cookies require your consent.
  • Functionality Cookies: Enable enhanced functionality and personalisation (e.g., remembering your language preferences or room type preferences). These cookies may require your consent.
  • Targeting and Advertising Cookies: Set by our advertising partners to build a profile of your interests and show you relevant advertising on other websites. These cookies require your consent.

When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or decline non-essential cookies. You may also update your cookie preferences at any time by accessing the cookie settings link on our website. For full details on the cookies we use, their purposes, and how to manage them, please refer to our separate Cookie Policy available on our website.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures include, but are not limited to:

  • SSL/TLS encryption for all data transmitted via our website
  • Encryption of personal data at rest and in transit
  • Access controls and role-based permissions limiting access to personal data to authorised personnel only
  • Regular security assessments, penetration testing, and vulnerability scanning
  • PCI-DSS compliant payment processing (we do not store full payment card numbers)
  • Staff training on data protection and information security
  • Incident response and data breach management procedures
  • Physical security measures at our premises

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and will communicate the breach to you without undue delay where required by applicable law.

10. Children's Privacy

Our casino services are strictly restricted to persons aged 18 years and over. We do not knowingly collect personal data from children under the age of 13 (or the applicable age of digital consent in your jurisdiction) without verifiable parental consent. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us at privacy@velmorithotelspa.com and we will take prompt steps to delete such information from our records.

Where children are guests of the hotel accompanying adult guests, we may collect limited personal data (such as names and ages) for operational purposes, in which case the accompanying adult is responsible for ensuring that any data shared with us relating to the child is done with appropriate authority.

12. Automated Decision-Making and Profiling

We may use automated tools and profiling techniques to analyse data about our guests in order to improve our services, personalise marketing communications, and tailor offers to your interests. For example, we may use data about your previous stays, spending patterns, and preferences to recommend relevant room types or packages.

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects without human review. Where automated profiling is used for marketing personalisation, this is based on your consent, which you may withdraw at any time.

In connection with casino operations, we may use automated monitoring systems for fraud prevention, AML compliance, and responsible gambling screening. Where such systems flag a concern, human review is conducted before any consequential decision is made.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or our services. When we make material changes, we will notify you by posting a prominent notice on our website, by sending you an email notification (where we hold your email address), or by other appropriate means. The date of the most recent revision will always be displayed at the top of this Privacy Policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website or services following notification of changes will constitute your acknowledgement of the updated Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please do not hesitate to contact us. We are committed to addressing your enquiries promptly and transparently.

Data Protection Officer

Name / Title The Data Protection Officer
Organisation Velmorithotelspa Inc.
Postal Address 721 Main Street, Canmore, AB T1W 2B2, Canada
Email Address privacy@velmorithotelspa.com
Website www.velmorithotelspa.com

General Contact

Hotel Name Velmorithotelspa
Legal Entity Velmorithotelspa Inc.
Address 721 Main Street, Canmore, AB T1W 2B2, Canada
Corporation Number Corporation No. 8062947
GST/HST Number GST/HST No. 806 294 715 RT0001

We aim to respond to all privacy-related enquiries and requests within 30 calendar days of receipt. If your request is particularly complex, we may extend this period by up to two additional months, in which case we will notify you within the first 30 days and provide an explanation for the delay. Where we are unable to comply with a request, we will provide reasons for our decision and inform you of your right to lodge a complaint with the applicable supervisory authority.