Privacy Policy
Last updated: June 2025
Welcome to (accessible at silverfieldstudio.com). We are committed to protecting your personal data and respecting your privacy in full compliance with the European Union General Data Protection Regulation (EU) 2016/679 ("GDPR") and all applicable data protection legislation. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use and share it, how long we retain it, and what rights you have in relation to your personal data.
Please read this Privacy Policy carefully before using our website or any of our services. By accessing or using silverfieldstudio.com, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with this Privacy Policy, please discontinue use of our website immediately.
1. Data Controller
For the purposes of the GDPR, the data controller responsible for your personal data is:
| Legal Entity Name | |
|---|---|
| Trading Name | |
| Registration Country | European Union (EU) |
| Registration Number | N/A |
| VAT Number | N/A |
| Legal Address | 110 Laurier Avenue West, Ottawa, ON K1P 1J1, Canada |
| Website | silverfieldstudio.com |
| Privacy Contact Email | privacy@silverfieldstudio.com |
As a data controller, determines the purposes and means of processing your personal data. We take this responsibility seriously and have implemented appropriate technical and organisational measures to ensure the security and lawful processing of your personal information.
1.1 Data Protection Officer (DPO)
In accordance with Article 37 of the GDPR, we have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and ensuring compliance with data protection laws. You may contact our DPO directly for any questions, concerns, or requests relating to your personal data:
| DPO Name / Title | The Data Protection Officer |
|---|---|
| Organisation | |
| Postal Address | 110 Laurier Avenue West, Ottawa, ON K1P 1J1, Canada |
| Email Address | privacy@silverfieldstudio.com |
2. Scope and Application
This Privacy Policy applies to all personal data collected and processed by through:
- Our website located at silverfieldstudio.com and all associated subdomains;
- Hotel reservation systems, check-in and check-out processes, and on-property services;
- Casino services, gaming activities, loyalty programmes, and related promotions;
- Food and beverage services, event bookings, spa and leisure facilities;
- Customer service interactions including telephone, email, and live chat;
- Social media platforms and online advertising campaigns managed by us;
- Mobile applications linked to our brand, where applicable;
- Third-party referral and booking platform partnerships;
- CCTV, security monitoring, and access control systems on our premises.
This Policy applies to guests, registered members, website visitors, job applicants, business partners, and any other individuals whose personal data we process. It does not apply to the data practices of third-party websites that may be linked from our website, and we encourage you to review those parties' privacy policies independently.
3. Categories of Personal Data We Collect
Depending on how you interact with us — whether as a hotel guest, casino patron, website visitor, loyalty programme member, or in another capacity — we may collect and process the following categories of personal data:
3.1 Identity and Contact Information
- Full name, title, date of birth, and gender;
- Postal address, email address, and telephone numbers;
- Passport or national identity card details (for hotel check-in and regulatory compliance);
- Nationality and country of residence;
- Emergency contact details (provided voluntarily).
3.2 Reservation and Stay Information
- Booking reference numbers, room preferences, and special requests;
- Arrival and departure dates, length of stay, and number of guests;
- Records of services used during your stay (dining, spa, room service, etc.);
- Folio charges, itemised bills, and payment history;
- Accessibility requirements and dietary preferences where disclosed.
3.3 Financial and Payment Information
- Credit and debit card details (processed securely via PCI-DSS compliant payment processors);
- Bank account information for refunds or direct billing arrangements;
- Transaction records, invoices, and receipts;
- Deposit and advance payment records.
3.4 Casino and Gaming Data
- Player account information, gaming history, and win/loss records;
- Loyalty programme membership details, points accumulated, and rewards redeemed;
- Identity verification documents required under anti-money laundering (AML) and Know Your Customer (KYC) obligations;
- Self-exclusion records and responsible gambling declarations;
- Details of gaming preferences and activity patterns for regulatory compliance and responsible gambling purposes.
3.5 Technical and Usage Data
- IP address, browser type and version, operating system, and device identifiers;
- Pages visited, time spent on pages, hyperlinks clicked, and referring URLs;
- Cookie identifiers and similar tracking technology data (see our Cookie Policy for details);
- Log files, session data, and access timestamps;
- Wi-Fi network usage data when using our on-property internet services.
3.6 Communications and Preference Data
- Records of email, telephone, and live chat communications with our team;
- Survey responses, feedback forms, and online reviews submitted to us;
- Marketing preferences, subscription status, and opt-out records;
- Social media interactions, comments, and messages directed to our official accounts.
3.7 Special Categories of Personal Data
In limited circumstances, we may process special categories of personal data as defined under Article 9 of the GDPR. This may include:
- Health or disability information disclosed voluntarily to facilitate accessibility needs or dietary requirements;
- Data relating to problem gambling or self-exclusion that may implicitly reveal health-related information;
- Biometric data where used for access control or identity verification on premises (where lawfully permitted and with appropriate safeguards).
We will only process special category data where we have a valid legal basis under Article 9(2) GDPR, such as your explicit consent, necessity for the establishment or defence of legal claims, or compliance with a legal obligation. We apply heightened protections to this category of data at all times.
3.8 CCTV and Security Data
- Video footage captured by closed-circuit television (CCTV) cameras operating throughout our hotel and casino premises;
- Access control logs recording entry to restricted areas;
- Incident reports and security records involving identified individuals.
3.9 Data Collected from Third Parties
We may also receive personal data about you from third parties, including:
- Online travel agencies (OTAs) and booking platforms through which reservations are made;
- Corporate clients making group bookings on behalf of their employees or guests;
- Fraud prevention agencies and credit reference agencies;
- Regulatory authorities sharing information relevant to AML/KYC compliance;
- Social media platforms when you interact with our branded content.
4. Legal Basis for Processing Personal Data
We process your personal data only where we have a valid lawful basis to do so. In accordance with Article 6 of the GDPR, we rely on the following legal bases:
4.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract. This includes:
- Processing hotel reservations, managing your stay, and fulfilling service requests;
- Operating loyalty programme membership and processing points and rewards;
- Processing payments for hotel, casino, dining, and other on-property services;
- Administering casino player accounts and fulfilling gaming obligations;
- Responding to pre-booking enquiries and providing quotations.
4.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where it is necessary to comply with a legal obligation to which we are subject, including:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations, including identity verification and transaction monitoring;
- Know Your Customer (KYC) requirements imposed by gaming and financial regulatory authorities;
- Tax compliance, accounting, and statutory reporting obligations;
- Hotel guest registration requirements under applicable national legislation;
- Responding to lawful requests from law enforcement, courts, or regulatory bodies;
- Responsible gambling obligations, including maintaining self-exclusion registers.
4.3 Protection of Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process personal data where it is necessary to protect the vital interests of you or another natural person, for example, in the event of a medical emergency on our premises.
4.4 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for the purposes of the legitimate interests pursued by us or by a third party, provided that your interests, rights, and freedoms do not override those interests. Our legitimate interests include:
- Improving and personalising the services we offer to guests and visitors;
- Conducting internal analytics to understand usage patterns and optimise our website and operations;
- Preventing and detecting fraud, theft, cheating, and other unlawful activity;
- Operating CCTV systems for the safety and security of our guests, staff, and premises;
- Sending direct marketing communications to existing customers (subject to your right to opt out);
- Managing and defending legal claims and disputes;
- Conducting market research and customer satisfaction surveys;
- Network and information security, including monitoring for unauthorised access.
Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests are not overridden by your rights and freedoms. You may request a copy of our legitimate interests assessment by contacting our DPO.
4.5 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will always request your consent clearly and separately before processing begins. You have the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal. Processing activities based on consent include:
- Sending promotional newsletters, special offers, and marketing communications via email or SMS where you are a new subscriber;
- Placing non-essential cookies and similar tracking technologies on your device (managed via our Cookie Consent Tool);
- Processing special category data such as health-related accessibility requirements where you choose to disclose them;
- Sharing your data with selected partners for joint marketing purposes (where applicable and separately disclosed).
To withdraw your consent at any time, please contact us at privacy@silverfieldstudio.com or use the unsubscribe link in any marketing email.
4.6 Public Task (Article 6(1)(e) GDPR)
In limited circumstances, we may process personal data where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us, such as cooperation with regulatory oversight of the gaming and hospitality industries.
5. How We Use Your Personal Data
We use the personal data we collect for the following purposes:
5.1 Providing Hotel and Hospitality Services
- Managing and confirming room reservations, including pre-arrival communications;
- Processing check-in and check-out, including identity verification as required by law;
- Fulfilling special requests, accessibility arrangements, and dietary preferences;
- Coordinating concierge, room service, housekeeping, and other hotel services;
- Processing payment for all hotel charges and issuing invoices and receipts.
5.2 Operating Casino and Gaming Services
- Creating and managing player accounts and loyalty programme memberships;
- Verifying player identity in compliance with gaming regulatory requirements;
- Recording and monitoring gaming activity for regulatory, security, and responsible gambling purposes;
- Administering jackpots, promotions, tournaments, and reward programmes;
- Enforcing self-exclusion orders and responsible gambling commitments;
- Complying with AML, KYC, and suspicious activity reporting obligations.
5.3 Marketing and Communications
- Sending you information about promotions, special offers, events, and news relevant to our hotel and casino;
- Personalising marketing communications based on your preferences and history with us;
- Managing your marketing preferences and processing opt-out requests promptly;
- Conducting customer satisfaction surveys and seeking feedback on your experience;
- Running targeted advertising campaigns on digital platforms (subject to your cookie and consent preferences).
5.4 Website and Digital Services Management
- Operating, maintaining, and improving the functionality and content of silverfieldstudio.com;
- Personalising your online experience based on your browsing behaviour and preferences;
- Analysing website traffic and user behaviour using analytics tools;
- Ensuring the security and integrity of our digital systems and preventing cyberattacks;
- Managing online reservations, enquiries, and account registration.
5.5 Security, Fraud Prevention, and Compliance
- Monitoring CCTV footage and access logs to ensure the safety of guests, staff, and property;
- Detecting and investigating fraud, cheating, theft, and other unlawful activities;
- Screening against sanctions lists and conducting enhanced due diligence where required;
- Cooperating with law enforcement and regulatory authorities as legally required;
- Maintaining records required for audit, compliance, and legal defence purposes.
5.6 Business Operations and Administration
- Managing supplier, vendor, and business partner relationships;
- Handling complaints, disputes, and requests from guests and third parties;
- Processing job applications and managing employee data (governed by a separate employee privacy notice);
- Conducting business analytics, financial reporting, and strategic planning;
- Maintaining accurate internal records and guest history for service continuity.
7. How We Share Your Personal Data
We do not sell, rent, or trade your personal data to third parties for their own independent marketing purposes. However, we may share your personal data with carefully selected third parties in the following circumstances:
7.1 Service Providers and Data Processors
We engage trusted third-party companies to perform services on our behalf. These parties act as data processors and are only permitted to process your data in accordance with our documented instructions and applicable data protection law. They include:
- Payment processing providers and banking partners;
- Cloud hosting and IT infrastructure providers;
- Customer relationship management (CRM) and loyalty programme software vendors;
- Email marketing and communication platform providers;
- Website analytics and advertising technology providers;
- Fraud detection and identity verification service providers;
- Hotel property management system (PMS) operators;
- Casino management system (CMS) and gaming platform vendors;
- CCTV monitoring and security service providers;
- Cleaning, catering, and other facility management subcontractors with access to guest-related information.
7.2 Booking Platforms and Online Travel Agencies
If you make a reservation through a third-party online travel agency, booking platform, or tour operator, we may receive your personal data from them and may share booking-related information back with them to confirm or modify your reservation.
7.3 Regulatory and Law Enforcement Authorities
We may share personal data with regulatory bodies, law enforcement agencies, courts, or government authorities where required or permitted by law, including:
- Gaming regulatory and licensing authorities;
- Financial intelligence units and AML supervisory bodies;
- Tax authorities;
- Police and national security agencies pursuant to lawful requests or court orders;
- Immigration authorities where required by hotel registration law.
7.4 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or insolvency proceeding involving , your personal data may be transferred to the relevant successor entity as part of that transaction. We will notify you via a prominent notice on our website or by direct communication if such a transfer materially affects the processing of your personal data.
7.5 Group Companies
Where operates as part of a wider corporate group, we may share personal data with affiliated group entities for internal administrative purposes, group-wide security monitoring, and consolidated reporting, subject to appropriate intra-group data sharing agreements that impose equivalent data protection standards.
7.6 With Your Consent
We may share your personal data with other third parties not listed above where we have obtained your prior explicit consent to do so.
7.7 International Data Transfers
Some of our service providers and partners may be located outside the European Economic Area (EEA). Where we transfer personal data to countries not recognised by the European Commission as providing an adequate level of data protection, we implement appropriate safeguards in accordance with Chapter V of the GDPR, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Reliance on derogations under Article 49 GDPR only in limited, specific circumstances where necessary.
You may request further information about the specific safeguards applicable to any international data transfer by contacting our DPO at privacy@silverfieldstudio.com.
8. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, regulatory, and reporting requirements. The criteria we use to determine retention periods include:
- The nature and sensitivity of the personal data;
- The purpose for which the data was collected and whether that purpose has been fulfilled;
- Any legal, regulatory, or contractual obligation to retain data for a minimum period;
- The potential risk of harm from unauthorised use or disclosure;
- Whether the data is necessary for the establishment, exercise, or defence of legal claims.
The following indicative retention periods apply to our main categories of data:
| Category of Data | Indicative Retention Period | Legal Basis / Reason |
|---|---|---|
| Hotel guest registration records | 5 to 10 years after departure | Legal obligation (hotel registration law, tax law) |
| Financial and payment transaction records | 7 years from the date of transaction | Legal obligation (accounting, tax, AML legislation) |
| Casino player account and gaming history | 5 years after account closure or last activity | Legal obligation (gaming regulation, AML/KYC requirements) |
| AML/KYC identity verification documents | 5 years from the end of the business relationship | Legal obligation (anti-money laundering legislation) |
| Self-exclusion and responsible gambling records | Duration of exclusion plus 5 years | Legal obligation (gaming regulatory compliance) |
| Marketing preferences and consent records | 3 years from last interaction or until opt-out | Legitimate interests / consent record-keeping |
| Website cookies and analytics data | Up to 24 months (varies by cookie type) | Consent / legitimate interests |
| CCTV footage | 30 days (unless required for an ongoing investigation) | Legitimate interests (security); legal obligation if incident recorded |
| Customer communications and complaints | 3 years from resolution of the matter | Legitimate interests / legal claims defence |
| Employment application data (unsuccessful candidates) | 6 months from notification of outcome | Legitimate interests |
Upon expiry of the relevant retention period, personal data will be securely deleted, anonymised, or destroyed using appropriate methods to prevent unauthorised recovery or reconstruction. Where anonymisation is applied, the resulting data may be retained indefinitely for statistical and research purposes.
9. Your Rights Under the GDPR
As a data subject under the GDPR, you have the following rights in relation to your personal data. We are committed to facilitating the exercise of these rights promptly and without undue delay, and in any event within one calendar month of receiving a valid request (extendable by a further two months where requests are complex or numerous, with notification of the extension provided to you).
9.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation from us as to whether or not we are processing your personal data, and where we are, to receive a copy of that data together with information about: the purposes of processing; the categories of data concerned; the recipients or categories of recipients; the planned retention period; and your other rights in relation to the data.
9.2 Right to Rectification (Article 16 GDPR)
You have the right to require us to correct any inaccurate personal data we hold about you, and to have incomplete personal data completed, including by providing a supplementary statement.
9.3 Right to Erasure / Right to be Forgotten (Article 17 GDPR)
You have the right to request the deletion of your personal data where, for example, the data is no longer necessary for the purpose for which it was collected, where you withdraw consent (and no other lawful basis exists), or where the data has been unlawfully processed. Please note that this right is not absolute and may be subject to overriding legal obligations requiring us to retain certain data.
9.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where processing is unlawful but you oppose erasure, or where we no longer need the data but you require it for legal claims. During any restriction, we will continue to store the data but will not otherwise process it without your consent (except in limited circumstances).
9.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to have that data transmitted directly to another controller where technically feasible.
9.6 Right to Object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where we rely on legitimate interests as our legal basis, including profiling based on legitimate interests. Upon receiving your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.
You also have an unconditional right to object to the processing of your personal data for direct marketing purposes at any time, and we will honour this promptly.
9.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
Where we make decisions about you solely by automated means (without human involvement) that produce legal or similarly significant effects, you have the right to: request human review of the decision; express your point of view; and challenge the decision. We will always inform you if such automated decision-making applies to you and explain the logic involved.
9.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. To withdraw consent, please contact us at privacy@silverfieldstudio.com or use the unsubscribe mechanism in any marketing communication.
9.9 Right to Lodge a Complaint with a Supervisory Authority (Article 77 GDPR)
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent data protection supervisory authority in your EU member state of habitual residence, place of work, or place of the alleged infringement. A full list of EU supervisory authorities is available on the European Data Protection Board (EDPB) website at edpb.europa.eu.
We encourage you to contact us directly in the first instance so that we can seek to resolve any concern informally and promptly.
9.10 How to Exercise Your Rights
To exercise any of the rights listed above, please submit a written request to our Data Protection Officer:
- By email: privacy@silverfieldstudio.com
- By post: The Data Protection Officer, , 110 Laurier Avenue West, Ottawa, ON K1P 1J1, Canada
To protect your privacy and security, we may need to verify your identity before processing your request. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act on the request, with written explanation provided.
10. Data Security
We take the security of your personal data very seriously and have implemented comprehensive technical and organisational measures appropriate to the nature of the data and the risks involved, in accordance with Article 32 of the GDPR. Our security measures include, but are not limited to:
- Encryption of data in transit using industry-standard TLS (Transport Layer Security) protocols;
- Encryption of sensitive data at rest, including financial and identity verification records;
- Strict access controls and role-based permissions ensuring that only authorised personnel can access personal data;
- Multi-factor authentication for access to sensitive internal systems;
- Regular penetration testing, vulnerability assessments, and security audits;
- Staff training and awareness programmes on data protection and information security;
- Physical security measures at our premises, including access control and CCTV monitoring;
- PCI-DSS compliance for all payment card data processing;
- Data minimisation and pseudonymisation practices where technically feasible;
- Incident response and data breach management procedures in accordance with Articles 33 and 34 GDPR.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our obligations under Article 34 GDPR, and will report the breach to the relevant supervisory authority within 72 hours where required by Article 33 GDPR.
While we employ robust security measures, please be aware that no method of transmission over the internet or method of electronic storage is 100% secure. We therefore cannot guarantee absolute security but commit to reviewing and enhancing our measures continuously.
11. Children's Privacy
Our casino services are strictly restricted to adults aged 18 years and over. We do not knowingly collect or process personal data from individuals under the age of 18 in connection with gaming or gambling activities. Individuals under 18 are prohibited from accessing or using our casino facilities.
With regard to our hotel services and general website, we do not knowingly collect personal data from children under the age of 16 without verifiable parental or guardian consent, in accordance with Article 8 of the GDPR. If you believe that a child under 16 has provided us with personal data without appropriate consent, please contact us immediately at privacy@silverfieldstudio.com and we will take prompt steps to delete such data.
12. Third-Party Websites and Links
Our website may contain hyperlinks to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices or the content of their privacy policies. We encourage you to read the privacy notice of every website you visit.
13. Profiling and Automated Decision-Making
We may use automated processing techniques, including profiling as defined in Article 4(4) GDPR, to analyse your personal data and better understand your preferences and behaviour. This may be used to:
- Personalise marketing content and special offers;
- Recommend hotel room types, dining options, or casino promotions based on past activity;
- Assess risk in the context of fraud prevention and AML compliance screening;
- Monitor gaming patterns for responsible gambling purposes.
Where any automated decision-making produces legal or similarly significant effects on you, we will ensure that a human review mechanism is available and will inform you accordingly. You have the right to object to profiling for direct marketing purposes at any time (see Section 9.6 above).
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable laws, or regulatory guidance. The date of the most recent revision will be displayed at the top of this page. Where changes are material, we will provide prominent notice on our website and/or notify you directly by email where we hold your contact details.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our website and services following the posting of changes constitutes your acknowledgement of the updated Privacy Policy.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please do not hesitate to contact us:
| Organisation | |
|---|---|
| Attention | The Data Protection Officer |
| Postal Address | 110 Laurier Avenue West, Ottawa, ON K1P 1J1, Canada |
| Email Address | privacy@silverfieldstudio.com |
| Website | silverfieldstudio.com |
We are committed to resolving any complaints or concerns about our privacy practices fairly and promptly. If you are not satisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority as described in Section 9.9 above.