Privacy Policy
Last updated: June 2025
This Privacy Policy explains how (hereinafter referred to as “we”, “us”, or “the Company”) collects, uses, stores, shares, and protects the personal data of users and visitors of the website dorivaresorthouse.com (hereinafter referred to as “the Website”), as well as guests and customers of Dorivaresort House hotel-casino located in Vancouver, Canada.
This Privacy Policy is drafted in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Personal Information Protection and Electronic Documents Act (PIPEDA), the British Columbia Personal Information Protection Act (PIPA), and other applicable data protection legislation. We are committed to ensuring the lawful, fair, and transparent processing of your personal data and to respecting your rights as a data subject.
Please read this Privacy Policy carefully before using our Website, making a reservation, or otherwise engaging with our services. By accessing our Website or providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The data controller responsible for the processing of your personal data is:
| Company Name | |
|---|---|
| Trading Name | Dorivaresort House |
| Registration Country | Canada |
| Registration Number | 14237894 |
| VAT Number | 897426153RT0002 |
| Legal Address | |
| Website | dorivaresorthouse.com |
| Privacy Email | info@dorivaresorthouse.com |
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that such processing is carried out in compliance with applicable data protection laws.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer responsible for overseeing our data protection strategy and ensuring compliance with applicable data protection legislation. If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, you may contact our Data Protection Officer as follows:
| Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | |
| info@dorivaresorthouse.com |
We encourage you to contact our DPO in the first instance for any privacy-related enquiries. We will respond to all legitimate requests within 30 days of receipt.
3. Personal Data We Collect
We collect and process various categories of personal data depending on your interaction with our Website, our hotel-casino facilities, and our services. Personal data means any information relating to an identified or identifiable natural person. We only collect personal data that is necessary, relevant, and adequate for the purposes described in this Privacy Policy.
3.1 Data You Provide Directly
- Identity and Contact Data: Full name, date of birth, gender, nationality, email address, telephone number, postal address, and passport or government-issued identification number (required for check-in and regulatory compliance).
- Reservation and Booking Data: Arrival and departure dates, room preferences, number of guests, special requests, dietary requirements, and any accessibility needs.
- Payment and Financial Data: Credit or debit card details (card number, expiry date, and CVV — processed securely via PCI-DSS compliant payment processors), billing address, transaction history, and invoicing information.
- Account Registration Data: Username, password (stored in encrypted form), and profile preferences when you create an account on our Website.
- Loyalty and Membership Programme Data: Membership number, points balance, redemption history, and tier status.
- Casino-Specific Data: Player identification, gaming activity records, win/loss history, responsible gambling preferences, self-exclusion requests, and age verification documentation as required by gaming regulations.
- Communications Data: The content of messages, emails, or enquiries you send to us, including feedback, complaints, and service requests.
- Marketing Preferences: Your opt-in or opt-out status for marketing communications, preferred channels of communication, and areas of interest.
3.2 Data We Collect Automatically
- Technical and Usage Data: IP address, browser type and version, operating system, device type and identifier, time zone setting, pages visited, links clicked, session duration, and referring URL.
- Cookie and Tracking Data: Information collected via cookies, web beacons, pixels, and similar tracking technologies as described in our Cookie Policy (see Section 12).
- Log Data: Server logs recording access times, request types, and error logs for security and operational purposes.
3.3 Data We Collect from Third Parties
- Booking Platforms and Travel Agents: Reservation details and contact information shared with us by online travel agencies (OTAs) or travel agents acting on your behalf.
- Payment Service Providers: Transaction authorisation and fraud prevention signals.
- Identity Verification Services: Age and identity verification results required by gaming licensing authorities.
- Social Media Platforms: If you interact with our social media pages or use social login features, we may receive profile information consistent with your privacy settings on those platforms.
- Credit Reference and Fraud Prevention Agencies: Credit checks and fraud signals where required for high-value transactions or regulatory compliance.
3.4 Special Categories of Personal Data
We may, in limited circumstances, process special categories of personal data as defined under Article 9 of the GDPR, including:
- Health Data: Dietary requirements or accessibility needs that you voluntarily provide to enable us to accommodate you appropriately.
- Responsible Gambling Data: Information relating to gambling behaviour, self-exclusion requests, or problem gambling indicators, processed for the purpose of complying with responsible gambling obligations.
We process special categories of data only where you have given your explicit consent (Article 9(2)(a) GDPR), where processing is necessary for reasons of substantial public interest (Article 9(2)(g) GDPR), or where processing is necessary to protect your vital interests (Article 9(2)(c) GDPR).
3.5 Data Relating to Children
Our Website, hotel, and casino services are not directed to individuals under the age of 19 (the legal age for casino gambling in British Columbia) or under the age of 18 for general hotel services. We do not knowingly collect personal data from children without verifiable parental consent. If we become aware that we have inadvertently collected personal data from a child without appropriate authorisation, we will take prompt steps to delete that information. If you believe we may have collected data from a minor, please contact us at info@dorivaresorthouse.com.
4. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your personal data only where a lawful basis exists for doing so. The following legal bases apply to our processing activities:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing your reservation, booking, and check-in.
- Managing your stay, room preferences, and requests.
- Processing payments for hotel and casino services.
- Administering your loyalty or membership account.
- Responding to enquiries and service requests.
4.2 Compliance with Legal Obligations (Article 6(1)(c) GDPR)
We process your personal data where it is necessary to comply with a legal obligation to which we are subject, including:
- Identity verification and age verification required by gaming licensing authorities, including the British Columbia Lottery Corporation (BCLC) and applicable provincial gaming regulations.
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations.
- Tax reporting and financial record-keeping obligations.
- Health and safety obligations.
- Responding to lawful requests from public authorities, regulators, or law enforcement.
- Compliance with immigration and hospitality regulations.
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for the purposes of our legitimate interests or those of a third party, provided that your interests, fundamental rights, and freedoms do not override those interests. Our legitimate interests include:
- Improving and developing our Website, services, and facilities.
- Ensuring the security and integrity of our Website, IT systems, and premises.
- Fraud detection and prevention.
- Managing and investigating complaints, disputes, or legal claims.
- Conducting analytics and research to better understand our guests’ preferences.
- Sending service-related communications and updates to existing customers.
- Operating CCTV surveillance on our premises for security purposes.
- Business continuity and internal administrative purposes.
Where we rely on legitimate interests, we conduct a balancing test to ensure our interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests (see Section 9).
4.4 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as a legal basis, we will collect it in a clear, specific, and informed manner. Consent-based processing includes:
- Sending you direct marketing communications about promotions, offers, and events.
- Setting non-essential cookies and similar tracking technologies on your device.
- Processing special categories of data (including health and dietary information).
- Profiling for personalised marketing purposes.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at info@dorivaresorthouse.com or use the unsubscribe mechanism in any marketing email we send you.
4.5 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect your vital interests or those of another natural person, such as in a medical emergency on our premises.
4.6 Public Task (Article 6(1)(e) GDPR)
We may, in certain circumstances, process personal data in the exercise of official authority vested in us or for the performance of a task carried out in the public interest, for example, when cooperating with regulatory authorities or public bodies in relation to gaming compliance.
5. How We Use Your Personal Data
We use your personal data for the following specific purposes. We will only use your personal data for the purpose for which it was originally collected unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose.
- Reservation Management: To process, confirm, modify, and manage your hotel room and facility bookings.
- Guest Services: To provide you with personalised service during your stay, including room service, concierge assistance, spa bookings, and dining reservations.
- Payment Processing: To process payments for accommodation, dining, entertainment, gaming, and other services, and to issue receipts and invoices.
- Casino Operations: To administer your gaming activity, verify your identity and age, manage responsible gambling measures, and comply with gaming regulations.
- Account Management: To create and manage your online account or loyalty programme membership.
- Customer Communications: To respond to your enquiries, complaints, feedback, and service requests.
- Marketing and Promotions: To send you promotional offers, newsletters, event invitations, and personalised recommendations where you have consented to receive such communications or where we have a legitimate interest to do so as an existing customer.
- Website Personalisation: To personalise your experience on our Website, remember your preferences, and display relevant content.
- Security and Fraud Prevention: To monitor and protect against fraudulent transactions, unauthorised access, security threats, and criminal activity on our premises and digital platforms.
- Legal and Regulatory Compliance: To comply with our legal, regulatory, and gaming licensing obligations, including anti-money laundering checks, tax obligations, and mandatory reporting to authorities.
- Analytics and Improvement: To analyse usage patterns on our Website and in our facilities, conduct guest satisfaction surveys, and improve our products and services.
- Dispute Resolution: To investigate and resolve complaints, disputes, and potential legal claims.
- CCTV Monitoring: To operate CCTV cameras on our premises for the security of guests, staff, and assets.
6. How We Share Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share your personal data with the following categories of recipients only where necessary, and subject to appropriate contractual and security safeguards:
6.1 Service Providers and Data Processors
We engage third-party service providers who process personal data on our behalf as data processors. These include:
- Payment Processors: Secure payment gateway providers who process credit and debit card transactions on our behalf in compliance with PCI-DSS standards.
- IT and Cloud Service Providers: Providers of hosting, database management, cybersecurity, and technical support services.
- Property Management System (PMS) Providers: Software providers that manage hotel reservations, check-in/check-out, and guest profiles.
- Casino Management System Providers: Technology providers that manage gaming operations and player tracking.
- Email and Marketing Platform Providers: Platforms used to manage and deliver email communications and marketing campaigns.
- Analytics Providers: Providers of website analytics tools to help us understand usage patterns.
- Customer Support Platforms: Tools used to manage guest enquiries and complaints.
All data processors are bound by data processing agreements obliging them to process personal data only on our documented instructions, to maintain appropriate security measures, and to comply with applicable data protection laws.
6.2 Business Partners
- Online Travel Agencies (OTAs) and Booking Platforms: Where a reservation is made through a third-party booking platform, we may exchange necessary booking data with that platform to fulfil your reservation.
- Restaurant, Spa, and Entertainment Vendors: On-site partners who provide services within our resort and require your data to fulfil specific service requests.
6.3 Regulatory and Government Authorities
We may be required to disclose your personal data to regulatory authorities, law enforcement agencies, courts, or other government bodies where we are legally obliged to do so, including:
- The British Columbia Lottery Corporation (BCLC) and gaming regulators.
- The Canada Revenue Agency (CRA) for tax reporting purposes.
- The Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) for AML reporting.
- Law enforcement agencies pursuant to a lawful request or court order.
- The Office of the Privacy Commissioner of Canada (OPC) or the Office of the Information and Privacy Commissioner for British Columbia (OIPC) where required.
6.4 Professional Advisors
We may share your personal data with our legal advisors, accountants, auditors, and insurers where necessary for the purposes of obtaining professional advice or managing legal claims.
6.5 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or insolvency proceedings involving the Company, your personal data may be transferred to the relevant successor entity or prospective buyer, subject to appropriate confidentiality obligations and applicable data protection requirements.
6.6 International Data Transfers
Some of our service providers and technology partners may be located outside of Canada or the European Economic Area (EEA). Where personal data is transferred to countries that do not provide an equivalent level of data protection, we ensure that appropriate safeguards are in place in accordance with applicable law, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions issued by relevant data protection authorities.
- Binding Corporate Rules (BCRs) where applicable.
- Contractual safeguards consistent with PIPEDA and PIPA requirements.
You may request further information about international transfers and the safeguards in place by contacting us at info@dorivaresorthouse.com.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means.
The following general retention periods apply:
| Category of Data | Retention Period | Reason |
|---|---|---|
| Guest reservation and stay records | 7 years | Legal and tax obligations; dispute resolution |
| Payment and financial records | 7 years | Canadian tax and accounting obligations (CRA requirements) |
| Casino player records and gaming activity | 7 years | Gaming regulatory compliance; AML obligations |
| Identity and age verification records | 5 years from last interaction | Gaming licensing and AML regulatory requirements |
| Loyalty programme account data | Duration of membership + 3 years | Account management; contractual obligations |
| Marketing preferences and consent records | Until consent withdrawn + 3 years | Evidence of consent and lawful marketing |
| Website usage and cookie data | Up to 2 years | Analytics and security purposes |
| CCTV footage | 30 days (unless required for an investigation) | Security monitoring; proportionality |
| Customer service communications | 3 years | Service quality; dispute resolution |
| Responsible gambling and self-exclusion records | Minimum 5 years | Gaming regulatory compliance and duty of care |
| Legal claim and dispute records | Duration of proceedings + 6 years | Legal obligation; limitation periods |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or pseudonymised in accordance with our data disposal procedures. In some circumstances, we may retain anonymised data (which can no longer be linked to you) for statistical and research purposes without further notice.
8. Your Rights as a Data Subject
Depending on your location and applicable data protection law, you have certain rights regarding the personal data we hold about you. Under the GDPR, you have the following rights:
8.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, along with information about how we process it, the legal basis for processing, the recipients to whom it has been disclosed, the retention period, and your other rights. We will provide this information in the form of a Subject Access Request (SAR) response, free of charge, within 30 days.
8.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. We will correct or complete the data within 30 days of your request.
8.3 Right to Erasure / “Right to Be Forgotten” (Article 17 GDPR)
You have the right to request that we delete your personal data in certain circumstances, including where:
- The data is no longer necessary for the purposes for which it was collected.
- You withdraw your consent (where processing was consent-based) and there is no other legal basis.
- You object to processing based on legitimate interests and there are no overriding interests.
- The data has been unlawfully processed.
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations, exercise legal claims, or meet regulatory requirements.
8.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while we verify the accuracy of the data you have contested, or while we assess an objection you have raised.
8.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, and processing is carried out by automated means, you have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format, and to request that we transmit that data directly to another data controller where technically feasible.
8.6 Right to Object (Article 21 GDPR)
You have the right to object to the processing of your personal data at any time where:
- Processing is based on legitimate interests (Article 6(1)(f)): we will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.
- Processing is for direct marketing purposes: you have an absolute right to object, and we will stop processing for marketing purposes immediately upon receipt of your objection.
8.7 Rights Relating to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Where we carry out such automated processing, we will inform you and, upon request, explain the logic involved and the significance and consequences of such processing. You may request human review of any automated decision.
8.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we rely on your consent as the legal basis for processing, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out prior to the withdrawal. To withdraw consent, please contact us at info@dorivaresorthouse.com or use the opt-out mechanism in our marketing communications.
8.9 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to:
- Email: info@dorivaresorthouse.com
- Postal Address: The Data Protection Officer, ,
We may need to verify your identity before processing your request to protect your data from unauthorised access. We will not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse the request. We will respond within 30 calendar days of receipt of your request. If your request is complex or numerous, we may extend this period by a further two months, in which case we will notify you within the initial 30-day period.
9. Data Security
We implement and maintain appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, disclosure, or unlawful processing. These measures include, but are not limited to:
- Encryption of personal data in transit using TLS (Transport Layer Security) protocols.
- Encryption of personal data at rest using industry-standard encryption technologies.
- Access controls and role-based permissions limiting access to personal data to authorised personnel on a need-to-know basis.
- Regular security assessments, penetration testing, and vulnerability scanning.
- PCI-DSS compliant payment processing systems.
- Secure server infrastructure with firewall protection and intrusion detection systems.
- Regular staff training on data protection and information security.
- Incident response and data breach management procedures.
- Physical security measures at our premises, including restricted access areas and CCTV monitoring.
- Regular review and testing of our security measures.
Notwithstanding these measures, no method of electronic transmission or storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under Article 34 of the GDPR and applicable Canadian privacy legislation. We will also notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where required by applicable law.
11. Third-Party Websites and Links
Our Website may contain links to third-party websites, platforms, or services, including social media platforms, booking engines operated by third parties, and partner websites. This Privacy Policy applies solely to data collected by us through our Website and services. We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Responsible Gambling and Data Protection
As a licensed casino operator, we are subject to obligations under British Columbia gaming regulations, including duties relating to responsible gambling. We process certain personal data, including gaming activity and player behaviour information, to:
- Detect signs of problem gambling and provide appropriate support and intervention.
- Administer self-exclusion programmes and exclusion lists.
- Comply with responsible gambling requirements mandated by the BCLC and applicable regulations.
- Share self-exclusion data with other gaming facilities and regulatory bodies as required by law.
We process this data on the basis of legal obligation (Article 6(1)(c) GDPR) and, where applicable, on the basis of substantial public interest (Article 9(2)(g) GDPR). Responsible gambling data is handled with the highest level of confidentiality and security.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or operational changes. When we make material changes, we will notify you by updating the “Last Updated” date at the top of this page and, where appropriate, by sending you an email notification or displaying a prominent notice on our Website.
We encourage you to review this Privacy Policy periodically. Your continued use of our Website or services following the publication of an updated Privacy Policy constitutes your acknowledgment of the changes.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data by , please contact us using the details below:
| Data Controller | |
|---|---|
| Attn | The Data Protection Officer |
| Postal Address | |
| info@dorivaresorthouse.com | |
| Website | dorivaresorthouse.com |
We are committed to addressing your concerns promptly and transparently. All privacy-related requests will be acknowledged within 5 business days and resolved within 30 calendar days, unless extended in accordance with applicable law.