Privacy Policy
Last updated: June 2025
Welcome to (hereinafter referred to as "we", "us", or "our"). We operate the website copperplainmedia.com (the "Website"), which provides information and services related to our hotel-casino located in North Battleford, Canada. Protecting your personal data is of paramount importance to us. This Privacy Policy explains what personal data we collect, how we use it, on what legal basis, with whom we share it, how long we retain it, and what rights you have in relation to your personal data.
This Privacy Policy has been prepared in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), applicable Canadian privacy legislation including the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and other relevant data protection laws. If you are accessing our Website from within the European Economic Area (EEA), the GDPR applies to the processing of your personal data.
Please read this Privacy Policy carefully before using our Website or providing any personal data to us. By using our Website, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The entity responsible for processing your personal data (the "Data Controller") is:
| Company Name | |
|---|---|
| Legal Address | |
| Registration Country | Canada |
| Website | copperplainmedia.com |
| Contact Email | info@copperplainmedia.com |
As the Data Controller, we determine the purposes and means of processing your personal data. We are committed to ensuring that your personal data is processed lawfully, fairly, and transparently.
1.1 Data Protection Officer (DPO)
We have appointed a Data Protection Officer who is responsible for overseeing our data protection practices and ensuring compliance with applicable privacy laws. You may contact our DPO at any time regarding data protection matters:
| DPO Name | The Data Protection Officer |
|---|---|
| Organisation | |
| Address | |
| info@copperplainmedia.com |
2. Personal Data We Collect
We collect personal data that you voluntarily provide to us and data that is collected automatically when you use our Website. "Personal data" means any information relating to an identified or identifiable natural person. The categories of personal data we may collect include the following:
2.1 Data You Provide to Us Directly
- Identity Data: Full name, date of birth, gender, nationality, and a copy of government-issued identification (where required for casino regulatory compliance or age verification purposes).
- Contact Data: Email address, telephone number, postal address, and city/country of residence.
- Reservation and Booking Data: Check-in and check-out dates, room preferences, number of guests, special requests, and booking reference numbers.
- Payment Data: Credit or debit card details, billing address, and transaction history. Payment card data is processed through secure, PCI-DSS-compliant payment processors and is not stored on our servers in full.
- Account and Profile Data: Username, password, loyalty programme membership number, preferences, feedback, and survey responses.
- Casino-Related Data: Gaming activity history, wins and losses (where required by applicable gaming regulations), self-exclusion requests, responsible gambling programme participation, and any information required under anti-money laundering (AML) legislation.
- Communications Data: The content of messages, enquiries, complaints, or feedback you send to us via email, contact forms, or other communication channels.
- Marketing Preferences: Your preferences regarding receiving marketing communications and your opt-in or opt-out status.
2.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device type, device identifiers, and time zone setting.
- Usage Data: Information about how you use our Website, including pages visited, links clicked, referral URLs, time spent on pages, and the date and time of your visit.
- Cookie and Tracking Data: Data collected via cookies, web beacons, pixel tags, and similar tracking technologies. Please refer to our Cookie Policy for more detailed information.
- Location Data: General geographic location data derived from your IP address. We do not collect precise GPS-level location data unless you expressly consent.
2.3 Data Received from Third Parties
- Online Travel Agencies and Booking Platforms: If you make a reservation through a third-party booking platform (e.g., Booking.com, Expedia), we receive your booking details and contact information from that platform.
- Payment Service Providers: Transaction confirmation and fraud-prevention signals.
- Identity Verification Services: Results of identity and age verification checks where required by gaming or AML regulations.
- Analytics Providers: Aggregated or pseudonymous data about website performance and user behaviour.
2.4 Special Categories of Personal Data
We do not intentionally collect or process special categories of personal data (such as health data, racial or ethnic origin, religious beliefs, or biometric data) unless strictly required by law or with your explicit consent. If you voluntarily disclose special category data (for example, a disability-related accessibility request), we will process it solely for the purpose for which it was provided and with appropriate safeguards in place.
2.5 Data Relating to Children
Our hotel-casino services are not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age. The casino area of our premises and online casino services are restricted to adults only. If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete such data. If you believe we have collected data from a minor, please contact us at info@copperplainmedia.com.
3. Legal Basis for Processing
In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases. Where more than one legal basis may apply, we have indicated the primary basis for each processing activity.
3.1 Performance of a Contract (Article 6(1)(b) GDPR)
We process your personal data where it is necessary to fulfil a contract to which you are party or to take steps at your request prior to entering into a contract. This includes:
- Processing hotel room reservations and managing your stay.
- Processing casino membership registrations and gaming activity.
- Handling payments for accommodation, food and beverage, and gaming credits.
- Responding to enquiries and service requests prior to your arrival.
- Managing loyalty programme memberships and associated benefits.
3.2 Compliance with a Legal Obligation (Article 6(1)(c) GDPR)
We process your personal data where necessary to comply with a legal obligation to which we are subject, including:
- Anti-money laundering (AML) and counter-terrorism financing (CTF) obligations, including identity verification and transaction monitoring under applicable Canadian and international legislation.
- Gaming and casino regulatory requirements, including responsible gambling obligations and player registers.
- Tax and accounting obligations requiring the retention of financial transaction records.
- Responding to lawful requests from regulatory authorities, law enforcement agencies, or courts.
- Health and safety obligations, including fire safety registers.
3.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your personal data where it is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests, fundamental rights, or freedoms. Our legitimate interests include:
- Improving, developing, and personalising our Website, services, and guest experience.
- Preventing fraud, money laundering, and other criminal activities on our premises and Website.
- Ensuring the security of our IT systems, networks, and premises.
- Conducting market research, data analytics, and statistical analysis to understand our customers better.
- Sending direct marketing communications to existing customers about similar products and services (where permitted by applicable law, including the right to opt out).
- Managing and resolving complaints and disputes efficiently.
- Protecting and asserting our legal rights where necessary.
Where we rely on legitimate interests, we have carried out a balancing test to ensure that our interests are not overridden by your rights. You have the right to object to processing based on legitimate interests. Please see Section 8 for further details.
3.4 Vital Interests (Article 6(1)(d) GDPR)
In exceptional circumstances, we may process your personal data where it is necessary to protect your vital interests or those of another person. This may occur, for example, in a medical emergency on our premises.
3.5 Public Task (Article 6(1)(e) GDPR)
We may process personal data where necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us. This may be applicable in the context of gaming regulation and public safety obligations.
3.6 Consent (Article 6(1)(a) GDPR)
Where we rely on your consent as the legal basis for processing, we will obtain your clear and affirmative consent before processing your personal data for that purpose. Consent-based processing includes:
- Sending you marketing communications and promotional offers where you are not an existing customer or where required by law.
- Placing non-essential cookies and tracking technologies on your device.
- Processing special categories of personal data (e.g., health-related accessibility requests).
- Subscribing you to our newsletter or promotional mailing lists.
You have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. To withdraw consent, please contact us at info@copperplainmedia.com or use the unsubscribe mechanism in any marketing email we send you.
4. How We Use Your Personal Data
We use the personal data we collect for the following purposes, in accordance with the legal bases outlined in Section 3:
4.1 Providing Hotel and Accommodation Services
- Processing and confirming room reservations and cancellations.
- Coordinating check-in and check-out procedures.
- Fulfilling special requests (e.g., accessible rooms, dietary requirements).
- Charging for accommodation and ancillary services.
- Communicating with you about your reservation before, during, and after your stay.
4.2 Providing Casino and Gaming Services
- Registering and verifying your identity as required by gaming regulations.
- Managing your gaming account, credits, and transaction history.
- Administering responsible gambling measures, including self-exclusion programmes.
- Complying with AML/CTF monitoring requirements.
- Detecting and preventing fraudulent or suspicious gaming activity.
4.3 Customer Account Management
- Creating and managing your user account and loyalty programme membership.
- Personalising your experience on the Website and during your visit.
- Maintaining records of your preferences, past stays, and interactions.
4.4 Payment Processing
- Processing payments, refunds, and chargebacks securely.
- Detecting and preventing payment fraud and unauthorised transactions.
- Maintaining financial records for accounting and tax compliance purposes.
4.5 Marketing and Communications
- Sending you information about our services, offers, events, and promotions (subject to your consent or our legitimate interests where applicable).
- Personalising marketing communications based on your preferences and stay history.
- Conducting customer satisfaction surveys and collecting feedback.
- Managing your marketing preferences and opt-out requests.
4.6 Website Operation and Improvement
- Operating, maintaining, and improving the functionality and security of our Website.
- Analysing how visitors use our Website to enhance user experience.
- Diagnosing technical problems and managing IT infrastructure.
- Administering cookies and tracking technologies in accordance with your preferences.
4.7 Legal Compliance and Security
- Complying with our legal and regulatory obligations.
- Preventing, detecting, and investigating fraud, criminal activity, and security incidents.
- Establishing, exercising, or defending legal claims.
- Cooperating with regulatory authorities, law enforcement agencies, and courts.
4.8 Automated Decision-Making and Profiling
We may use automated tools to personalise your experience on our Website (e.g., recommending services based on browsing behaviour). Where we engage in automated decision-making that produces legal or similarly significant effects for you, we will inform you specifically and ensure that appropriate safeguards are in place, including your right to request human review of such decisions. You have the right not to be subject to solely automated decision-making, including profiling, that produces significant effects. Please contact us to exercise this right.
5. Sharing Your Personal Data
We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients in the circumstances described below:
5.1 Service Providers and Data Processors
We engage trusted third-party service providers who process personal data on our behalf and under our instructions. These include:
- IT and Cloud Service Providers: Web hosting, database management, and cloud storage providers.
- Payment Processors: Secure payment gateway providers and banking institutions.
- Booking and Reservation Platforms: Third-party booking engines and online travel agencies.
- Marketing and Analytics Providers: Email marketing platforms, analytics services, and advertising technology providers.
- Customer Support Tools: Helpdesk and customer relationship management (CRM) platforms.
- Identity Verification Services: Age and identity verification providers required under gaming or AML regulations.
- Security and Fraud Prevention Services: Cybersecurity and fraud detection providers.
All service providers are required to process personal data in accordance with our instructions and applicable data protection law. We enter into data processing agreements with all processors as required by Article 28 of the GDPR.
5.2 Regulatory and Government Authorities
We may disclose your personal data to regulatory bodies, gaming authorities, tax authorities, law enforcement agencies, or courts where we are legally required to do so, or where disclosure is necessary to prevent fraud, money laundering, or other criminal activity.
5.3 Business Partners
We may share your personal data with carefully selected business partners (e.g., event organisers, entertainment providers, or concierge service partners) where this is necessary to deliver a service you have requested. We will inform you of such sharing where required by law.
5.4 Corporate Transactions
In the event of a merger, acquisition, restructuring, or sale of all or part of our business assets, your personal data may be transferred to the acquiring entity as part of that transaction. We will notify you of any such change in Data Controller in accordance with applicable law.
5.5 With Your Consent
We may share your personal data with third parties where you have given your explicit consent for us to do so.
5.6 International Data Transfers
Some of our service providers and partners may be located outside Canada or the European Economic Area (EEA). Where personal data is transferred to countries that do not provide an adequate level of data protection as determined by applicable law, we ensure that appropriate safeguards are in place, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Binding Corporate Rules (BCRs) where applicable.
- Adequacy decisions issued by the European Commission.
- Other legally recognised transfer mechanisms.
You may request further information about international data transfers and the safeguards in place by contacting us at info@copperplainmedia.com.
6. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting, or reporting requirements. The criteria used to determine our retention periods include:
- The nature and sensitivity of the personal data.
- The purposes for which we collected and use the data.
- Applicable legal and regulatory obligations specifying minimum or maximum retention periods.
- Whether there is an ongoing legal claim, dispute, or regulatory investigation that requires the retention of relevant data.
6.1 Indicative Retention Periods
| Category of Data | Indicative Retention Period | Legal Basis / Reason |
|---|---|---|
| Hotel reservation and guest records | 7 years after the date of stay | Legal obligation (tax and accounting); legitimate interests |
| Payment and financial transaction records | 7 years from the date of transaction | Legal obligation (tax, accounting, AML) |
| Casino gaming records and AML/CTF records | 5–7 years as required by applicable gaming and AML legislation | Legal obligation |
| Customer account and loyalty programme data | Duration of account plus 3 years after closure | Contract; legitimate interests |
| Marketing preferences and opt-in records | Until opt-out, then 3 years for record-keeping | Consent; legitimate interests |
| Website usage and analytics data | Up to 26 months (anonymised or aggregated thereafter) | Legitimate interests |
| Customer communications and complaints | 3 years from resolution of the matter | Legitimate interests; legal claims |
| Cookie consent records | 1 year from date of consent | Legal obligation (consent records) |
| Identity verification documents | As required by gaming/AML regulation, typically 5 years | Legal obligation |
Upon expiry of the applicable retention period, we will securely delete or anonymise your personal data in accordance with our data disposal procedures. If deletion is not immediately possible (e.g., due to backup cycles), we will isolate the data and prevent further processing until deletion can be carried out.
7. Your Rights Under GDPR and Applicable Data Protection Law
Depending on your jurisdiction and the legal basis for processing, you have the following rights in relation to your personal data. If you are located in the EEA or the United Kingdom, these rights are provided under the GDPR and applicable national implementing legislation. Residents of Canada have similar rights under PIPEDA and applicable provincial privacy legislation.
7.1 Right of Access (Article 15 GDPR)
You have the right to request a copy of the personal data we hold about you, as well as information about how we process it. This is known as a Subject Access Request (SAR). We will respond to your request within one month of receipt. If the request is complex or numerous, we may extend this period by a further two months, informing you accordingly.
7.2 Right to Rectification (Article 16 GDPR)
You have the right to request that we correct any inaccurate personal data we hold about you or complete any incomplete data. We will take reasonable steps to verify the accuracy of any data we correct.
7.3 Right to Erasure / "Right to Be Forgotten" (Article 17 GDPR)
You have the right to request the deletion of your personal data in the following circumstances:
- The personal data is no longer necessary for the purposes for which it was collected or processed.
- You withdraw consent and there is no other legal basis for processing.
- You object to processing based on legitimate interests and there are no overriding legitimate grounds.
- The personal data has been unlawfully processed.
- The personal data must be erased to comply with a legal obligation.
Please note that this right is not absolute and may be subject to limitations where we are required to retain data to comply with legal obligations, establish, exercise, or defend legal claims, or for other permitted grounds.
7.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances, including:
- You contest the accuracy of the data, pending our verification.
- Processing is unlawful and you request restriction rather than erasure.
- We no longer need the data but you require it for legal claims.
- You have objected to processing and we are considering whether our legitimate grounds override yours.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or the performance of a contract, and processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. This right applies to data you have provided to us directly.
7.6 Right to Object (Article 21 GDPR)
You have the right to object to the processing of your personal data at any time in the following circumstances:
- Legitimate Interests: You may object to processing based on our legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
- Direct Marketing: You have an unconditional right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing. We will cease such processing immediately upon receipt of your objection.
7.7 Rights in Relation to Automated Decision-Making and Profiling (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects for you. Where we engage in such processing, you have the right to request human review of the decision, to express your point of view, and to contest the decision.
7.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. To withdraw consent, please contact us using the details in Section 9 or use the unsubscribe link in any marketing email.
7.9 Right to Lodge a Complaint with a Supervisory Authority (Article 77 GDPR)
If you believe that we have processed your personal data in a manner that violates applicable data protection law, you have the right to lodge a complaint with the competent data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.
In Canada, the relevant authority is the Office of the Privacy Commissioner of Canada (OPC):
- Website: www.priv.gc.ca
- Telephone: 1-800-282-1376
If you are located in the EEA, you should contact the data protection authority in your EU member state. A list of EEA supervisory authorities is available at the European Data Protection Board website: www.edpb.europa.eu.
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, so please do contact us in the first instance.
7.10 Exercising Your Rights
To exercise any of the rights described above, please submit a written request to us using the contact details in Section 9. We will respond to all legitimate requests within one month. We may need to verify your identity before processing your request. This verification process is a necessary security measure to ensure that your personal data is not disclosed to any person who has no right to receive it.
We will not charge a fee to respond to valid requests unless your request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or refuse to act, informing you accordingly.
9. Data Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, alteration, or disclosure. These measures include:
- Encryption of personal data in transit using Secure Socket Layer (SSL) / Transport Layer Security (TLS) technology.
- Encryption of sensitive data at rest where appropriate.
- Access controls and role-based permissions to limit access to personal data to authorised personnel only.
- Regular security assessments, vulnerability testing, and penetration testing.
- Staff training on data protection and information security.
- Incident response procedures for addressing data breaches promptly.
- PCI-DSS compliant payment processing to protect cardholder data.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by Article 34 of the GDPR.
Please note that no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.
10. Third-Party Links and Services
Our Website may contain links to third-party websites, services, or social media platforms. This Privacy Policy applies only to our Website and services. We are not responsible for the privacy practices of third-party websites and encourage you to review their respective privacy policies before providing any personal data to them.
Our Website may also include social media features (e.g., Facebook Like button, Instagram feed) and widgets. These features may collect your IP address and set cookies to enable them to function properly. Social media features and widgets are hosted by third parties and your interactions with them are governed by the privacy policy of the company providing them.
11. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or for other operational, legal, or regulatory reasons. When we make material changes, we will notify you by:
- Updating the "Last updated" date at the top of this Privacy Policy.
- Posting a prominent notice on our Website.
- Sending you an email notification where you have provided your email address and where required by law.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of our Website after any changes to this Privacy Policy constitutes your acknowledgment of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please do not hesitate to contact us using the details below. We are committed to resolving any privacy-related concerns promptly and transparently.
| Data Controller | |
|---|---|
| Postal Address | |
| Email Address | info@copperplainmedia.com |
| Data Protection Officer | The Data Protection Officer |
| DPO Email | info@copperplainmedia.com |
| Website | copperplainmedia.com |
For Subject Access Requests or to exercise any of your data protection rights, please write to us at the postal address or email address above, clearly indicating the nature of your request and providing sufficient information to allow us to verify your identity. We aim to respond to all legitimate requests within 30 days.
If you are not satisfied with our response to your complaint or enquiry, you have the right to escalate the matter to the Office of the Privacy Commissioner of Canada or, if you are located in the EEA, to the relevant data protection supervisory authority in your member state, as described in Section 7.9 above.