Privacy Policy
Last updated: June 2025
Welcome to Belunoresortreport (the "Website"), operated at belunoresortreport.com. Your privacy is of paramount importance to us. This Privacy Policy explains how collects, uses, discloses, and safeguards your personal data when you visit our Website, make reservations, use our services, or otherwise interact with us. This Policy has been drafted in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act ("PIPEDA") and its provincial equivalents.
Please read this Privacy Policy carefully. By accessing or using our Website and services, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with the terms of this Privacy Policy, please discontinue use of our Website immediately.
1. Data Controller
The entity responsible for the collection and processing of your personal data (the "Data Controller") is:
| Company Name | |
|---|---|
| Trading Name | Belunoresortreport |
| Legal Address | |
| Country of Registration | Canada |
| Website | belunoresortreport.com |
| Privacy Contact Email | info@belunoresortreport.com |
As the Data Controller, determines the purposes and means of processing your personal data and is fully accountable for ensuring that such processing complies with all applicable data protection laws.
2. Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our data protection strategy and ensure compliance with data protection legislation. You may contact our DPO for any questions, concerns, or requests related to the processing of your personal data:
| DPO Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@belunoresortreport.com |
Our DPO is available to handle all enquiries relating to this Privacy Policy and your rights as a data subject. We will respond to all legitimate requests without undue delay and within the timeframes required by applicable law (generally within 30 calendar days).
3. Scope of This Privacy Policy
This Privacy Policy applies to:
- Visitors to our Website at belunoresortreport.com;
- Individuals who make reservations or enquiries for hotel accommodation, dining, spa, or casino services;
- Registered members of our loyalty or rewards programmes;
- Casino patrons and gaming participants;
- Recipients of our marketing communications and newsletters;
- Individuals who contact our customer support team;
- Job applicants and prospective employees;
- Business partners, contractors, and suppliers (natural persons or representatives thereof).
This Policy does not apply to third-party websites, applications, or services that may be linked from our Website. We encourage you to review the privacy policies of any third-party platforms before providing them with your personal data.
4. Personal Data We Collect
We collect and process various categories of personal data depending on your interaction with us. Personal data means any information relating to an identified or identifiable natural person. The categories we may collect include:
4.1 Identity and Contact Data
- Full name (first name, last name, title);
- Date of birth and age verification data;
- Gender (where voluntarily provided);
- Nationality and country of residence;
- Postal address, billing address, and delivery address;
- Email address;
- Telephone and mobile numbers;
- Government-issued identification details (e.g., passport number, driver's licence) where required by law or for check-in purposes.
4.2 Reservation and Stay Data
- Room type, dates of arrival and departure, number of guests;
- Special requests, preferences, and accessibility requirements;
- Dining and spa booking details;
- Records of previous stays and service interactions;
- Complaints and feedback received during or after your stay.
4.3 Financial and Transaction Data
- Credit and debit card numbers (processed securely via PCI-DSS compliant payment processors);
- Bank account information where applicable;
- Billing and invoicing records;
- Transaction history, receipts, and refund records.
4.4 Casino and Gaming Data
- Gaming account registration details and player profiles;
- Gaming activity, wagers, winnings, and losses;
- Responsible gambling declarations and self-exclusion requests;
- Age verification and identity verification data required by gaming regulations;
- Anti-money laundering (AML) checks and source-of-funds documentation;
- CCTV and surveillance footage captured within gaming areas.
4.5 Technical and Usage Data
- Internet Protocol (IP) address;
- Browser type and version;
- Operating system and device identifiers;
- Pages visited, time spent on pages, and clickstream data;
- Referring URLs and exit pages;
- Cookie identifiers and similar tracking technologies (see our Cookie Policy);
- Log files and server access data.
4.6 Marketing and Communications Data
- Marketing preferences and opt-in/opt-out records;
- Communication history with our marketing team;
- Survey responses and competition entries;
- Loyalty programme membership details and points balances.
4.7 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data (sensitive data) as defined under GDPR Article 9. These may include:
- Health and dietary information (e.g., allergy disclosures, accessibility or disability-related requests);
- Biometric data (where used for identity verification in compliance with applicable law);
- Data concerning gambling addiction or problem gambling disclosures.
We process such sensitive data only where we have a valid legal basis under GDPR Article 9(2), such as your explicit consent, the protection of vital interests, or compliance with legal obligations. We apply enhanced safeguards to all special category data.
4.8 Data Collected from Third Parties
We may also receive personal data about you from the following sources:
- Online travel agencies and booking platforms (e.g., Booking.com, Expedia);
- Corporate travel management companies;
- Payment processors and fraud detection services;
- Government agencies and regulatory authorities (for AML and identity verification);
- Social media platforms (where you interact with our profiles or use social login features);
- Credit reference and background check agencies.
5. Legal Basis for Processing Personal Data
We process your personal data only where we have a valid legal basis to do so, as required by GDPR Article 6. The legal bases we rely upon are as follows:
5.1 Performance of a Contract (Article 6(1)(b))
We process your personal data when it is necessary to perform a contract to which you are a party or to take pre-contractual steps at your request. This applies to:
- Processing hotel and dining reservations;
- Managing casino gaming accounts;
- Processing payments and issuing invoices;
- Delivering services you have requested during your stay;
- Managing loyalty programme memberships.
5.2 Compliance with Legal Obligations (Article 6(1)(c))
We process your personal data where necessary to comply with a legal obligation to which we are subject, including:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations under applicable Canadian law;
- Gaming regulatory requirements and licensing conditions;
- Tax and accounting obligations;
- Identity verification required by law;
- Responding to lawful requests from law enforcement or regulatory authorities;
- Age verification for access to casino and gambling services.
5.3 Legitimate Interests (Article 6(1)(f))
We process your personal data where it is necessary for the purposes of our legitimate interests, or the legitimate interests of a third party, provided that such interests are not overridden by your interests or fundamental rights and freedoms. Our legitimate interests include:
- Ensuring the security and integrity of our premises and IT systems;
- Operating CCTV surveillance for the safety of guests and staff;
- Preventing and detecting fraud, theft, and other criminal activity;
- Improving and personalising our Website and services;
- Conducting internal analytics and business intelligence;
- Managing and enforcing our legal rights and contractual obligations;
- Direct marketing to existing customers for similar services (subject to your right to object);
- Maintaining the integrity of our gaming operations and responsible gambling monitoring.
Where we rely on legitimate interests, we conduct a balancing test to ensure that our interests do not override your rights. You have the right to object to processing based on legitimate interests (see Section 10).
5.4 Consent (Article 6(1)(a))
Where required, we will ask for your explicit consent before processing your personal data. We rely on consent for:
- Sending you marketing and promotional communications (newsletters, special offers, event invitations);
- Placing non-essential cookies and similar tracking technologies on your device;
- Processing special categories of sensitive personal data (e.g., health information beyond what is strictly necessary);
- Sharing your data with selected third-party partners for their own marketing purposes.
Where we rely on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at info@belunoresortreport.com.
5.5 Protection of Vital Interests (Article 6(1)(d))
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person. For example, sharing health information with emergency medical services where there is an immediate risk to life.
5.6 Public Task (Article 6(1)(e))
In limited circumstances, we may process personal data in the performance of a task carried out in the public interest or in the exercise of official authority, such as cooperating with public health or law enforcement authorities.
6. How We Use Your Personal Data
We use your personal data only for the purposes described in this Privacy Policy. The following table sets out the main purposes for which we process your data and the corresponding legal bases:
| Purpose of Processing | Legal Basis |
|---|---|
| Processing and managing hotel reservations and check-in/check-out | Contract performance |
| Managing casino gaming accounts and processing wagers | Contract performance; Legal obligation |
| Processing payments and preventing payment fraud | Contract performance; Legitimate interests |
| Providing customer support and handling complaints | Contract performance; Legitimate interests |
| Sending booking confirmations and service communications | Contract performance |
| Operating loyalty and rewards programmes | Contract performance; Consent |
| Conducting identity and age verification | Legal obligation; Contract performance |
| Anti-money laundering and fraud prevention checks | Legal obligation; Legitimate interests |
| Operating CCTV surveillance for security purposes | Legitimate interests; Legal obligation |
| Responsible gambling monitoring and self-exclusion management | Legal obligation; Vital interests |
| Sending direct marketing, newsletters, and promotional offers | Consent; Legitimate interests (existing customers) |
| Personalising your experience on our Website and in our facilities | Consent; Legitimate interests |
| Conducting website analytics and performance monitoring | Consent; Legitimate interests |
| Improving our products, services, and Website functionality | Legitimate interests |
| Managing and enforcing our contractual rights | Legitimate interests; Legal obligation |
| Complying with tax, accounting, and regulatory obligations | Legal obligation |
| Responding to regulatory, law enforcement, or court requests | Legal obligation |
| Processing job applications and managing recruitment | Pre-contractual steps; Legitimate interests |
We will not use your personal data for purposes that are incompatible with the original purpose for which it was collected, unless we have your consent or are required to do so by law.
8. Sharing Your Personal Data
We respect your privacy and do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients in order to operate our business and deliver our services:
8.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions, in accordance with GDPR Article 28. These include:
- Cloud hosting and IT infrastructure providers;
- Payment processing and fraud prevention companies;
- Reservation and property management system providers;
- Casino gaming software and platform operators;
- Email marketing and CRM platform providers;
- Website analytics and performance monitoring services;
- Customer support and live chat software providers;
- Printing, fulfilment, and postal services;
- Security and CCTV monitoring services.
All processors are required to maintain appropriate technical and organisational security measures and are prohibited from using your data for any purpose other than those specified in our Data Processing Agreements.
8.2 Business Partners
We may share data with carefully selected business partners where you have requested services that involve those partners, or where we have obtained your prior consent. These may include:
- Affiliated resort, hotel, and entertainment venues;
- Tour operators and concierge service providers;
- Restaurant and hospitality partners featured in our facilities.
8.3 Online Travel Agencies and Booking Platforms
When you make a reservation through a third-party booking platform, we may receive and share data with that platform in order to complete and manage your reservation.
8.4 Regulatory and Legal Authorities
We may disclose your personal data to government bodies, law enforcement agencies, gaming regulators, tax authorities, or courts where we are required to do so by applicable law, court order, or regulatory requirement, or where disclosure is necessary to protect the legal rights and interests of
8.5 Professional Advisors
We may share personal data with our lawyers, auditors, accountants, insurers, and other professional advisors where necessary for the provision of professional services, subject to binding confidentiality obligations.
8.6 Corporate Transactions
In the event of a merger, acquisition, restructuring, sale of assets, or other corporate transaction, your personal data may be transferred to the acquiring or successor entity. We will notify you of any such transfer and the choices available to you in accordance with applicable law.
8.7 International Data Transfers
is based in Canada. Some of our service providers and partners may be located in other countries, including within the European Economic Area (EEA), the United Kingdom, or third countries that may not offer the same level of data protection as Canada or the EEA. Where we transfer personal data outside Canada or the EEA, we ensure that appropriate safeguards are in place, such as:
- European Commission Standard Contractual Clauses (SCCs) as adopted under GDPR Article 46;
- Adequacy decisions issued by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Other lawful transfer mechanisms approved under applicable data protection law.
You may request a copy of the safeguards in place for international transfers by contacting our DPO at info@belunoresortreport.com.
9. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, resolve disputes, and enforce our agreements. The retention periods we apply are based on legal requirements, regulatory guidance, and business necessity. The following retention periods apply as general guidelines:
| Category of Data | Retention Period |
|---|---|
| Guest reservation and stay records | 7 years from the date of check-out |
| Financial and payment transaction records | 7 years (in accordance with Canadian tax and accounting laws) |
| Casino gaming account data and activity records | 5–7 years from account closure or last activity (as required by gaming regulations) |
| AML and identity verification records | 5–10 years from the end of the business relationship (as required by AML legislation) |
| CCTV footage from hotel and casino premises | 30–90 days, unless required for ongoing investigation or legal proceedings |
| Marketing communication preferences and consent records | Until consent is withdrawn, plus 3 years for audit purposes |
| Customer support and complaint records | 3 years from resolution |
| Website analytics and log data | 13 months (analytics); 12 months (server logs) |
| Cookie consent records | 3 years from the date of consent |
| Job application data (unsuccessful candidates) | 12 months from the date of application |
| Responsible gambling and self-exclusion records | Duration of self-exclusion plus 5 years |
At the end of the applicable retention period, your personal data will be securely deleted, anonymised, or pseudonymised. In cases where data cannot be immediately deleted due to technical constraints, it will be isolated and protected from further processing until deletion is possible.
10. Your Rights as a Data Subject
Under the GDPR and applicable data protection law, you have the following rights with respect to your personal data. We are committed to honouring these rights promptly and without undue delay. We will respond to all verified requests within 30 calendar days. In complex cases, we may extend this by a further two months, in which case we will notify you of the extension within the initial 30-day period.
10.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation of whether we are processing your personal data and, if so, to receive a copy of that data along with information about how and why it is processed. We will provide the first copy free of charge; subsequent copies may be subject to a reasonable fee.
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate personal data we hold about you, and the right to have incomplete data completed. We will promptly update our records and notify relevant third parties where appropriate.
10.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data in the following circumstances:
- The data is no longer necessary for the purposes for which it was collected;
- You withdraw consent and there is no other legal basis for processing;
- You object to processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed;
- Erasure is required to comply with a legal obligation.
Please note that this right is not absolute. We may be required to retain certain data to comply with legal obligations (e.g., AML, tax, gaming regulation requirements).
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data, when processing is unlawful but you oppose erasure, or when you have objected to processing pending verification of our legitimate grounds.
10.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
10.6 Right to Object (Article 21 GDPR)
You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where such processing is based on legitimate interests (Article 6(1)(f)) or the public task (Article 6(1)(e)). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time, including profiling to the extent it relates to such direct marketing.
10.7 Rights Related to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you. Where we use automated decision-making processes (e.g., for fraud detection or credit assessment), you have the right to request human review, express your point of view, and contest the decision.
10.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us at info@belunoresortreport.com or use the unsubscribe link in marketing communications.
10.9 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority. In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada (OPC):
- Website: www.priv.gc.ca
- Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3, Canada
- Telephone: 1-800-282-1376
If you are located in the European Economic Area (EEA) or the United Kingdom, you may also have the right to lodge a complaint with the data protection supervisory authority in your country of residence or place of work.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact our DPO in the first instance at info@belunoresortreport.com.
10.10 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to our DPO by email at info@belunoresortreport.com or by post to:
The Data Protection Officer
We may need to verify your identity before processing your request to protect your privacy and security. We will acknowledge receipt of your request and advise you of the expected response timeline. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.
11. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, alteration, or disclosure. Our security measures include, but are not limited to:
- Encryption of data in transit using TLS (Transport Layer Security) protocols;
- Encryption of sensitive data at rest;
- Strict access controls and role-based permissions limiting access to personal data to authorised personnel only;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Firewalls, intrusion detection systems, and anti-malware software;
- PCI-DSS compliant payment processing systems;
- Physical security measures for our data centres and premises;
- Staff training on data protection and information security;
- Documented incident response and data breach management procedures.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33. Where required, we will also notify you directly without undue delay, as required by GDPR Article 34.
While we employ robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We therefore cannot guarantee the absolute security of your data, but we are committed to continuously improving our security practices.
12. Children's Privacy
Our Website and casino services are strictly intended for adults aged 19 years and over (or the applicable legal gambling age in your jurisdiction). We do not knowingly collect personal data from children under the age of 18. If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will take prompt steps to delete such data from our records.
If you believe that we may have collected personal data from a child, please contact us immediately at info@belunoresortreport.com.
13. Direct Marketing and Profiling
We may use your personal data to send you marketing communications about our services, special offers, events, and promotions that may be of interest to you. We will only send you marketing communications where we have your consent or where we have a legitimate interest in doing so as an existing customer.
We may use profiling techniques to tailor our marketing communications to your interests and preferences, based on your history of interactions with us. Profiling is used to improve the relevance of our communications and is not used for any automated decision-making that produces legal or similarly significant effects.
You may opt out of receiving marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email;
- Updating your preferences in your online account settings;
- Contacting us at info@belunoresortreport.com;
- Writing to our DPO at the address provided in Section 2.
Please note that even if you opt out of marketing communications, we may still send you non-promotional service communications (e.g., booking confirmations, account notifications, and important policy updates).
14. Responsible Gambling and Data Processing
As a casino operator, we have a legal and ethical duty to promote responsible gambling. We may use your gaming data to monitor patterns of play and identify potential problem gambling behaviour. This processing is carried out in the public interest, as a legal obligation, and to protect your vital interests.
Where applicable, we may:
- Set deposit, wagering, or time limits on your gaming account;
- Contact you with responsible gambling information and resources;
- Process and maintain records of self-exclusion requests;
- Share self-exclusion data with gaming regulatory bodies as required by law.
If you wish to set limits or self-exclude, please contact our team directly. Self-exclusion data will be retained for the duration of the exclusion period and for a minimum of five years thereafter for regulatory and audit purposes.
15. Third-Party Links and External Websites
Our Website may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of such third parties and this Privacy Policy does not apply to any external sites. We encourage you to read the privacy policies of any third-party website you visit. The inclusion of a link does not imply endorsement by
16. Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our practices, legal requirements, or technological developments. When we make material changes, we will:
- Update the "Last updated" date at the top of this Policy;
- Post a prominent notice on our Website;
- Where required by law, notify you by email or other direct communication.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our Website and services after the publication of an updated Policy constitutes your acceptance of the changes.
Previous versions of this Privacy Policy are available upon request from our DPO.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, or if you wish to exercise any of your data subject rights, please do not hesitate to contact us:
| Data Protection Officer | The Data Protection Officer, |
|---|---|
| info@belunoresortreport.com | |
| Postal Address | |
| Website | www.belunoresortreport.com |
We are committed to working with you to resolve any concerns about your privacy. If you are not satisfied with our response, you have the right to escalate your complaint to the relevant data protection supervisory authority as described in Section 10.9 of this Policy.